Question No.181

Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?

  1. Upper management support

  2. More frequent project milestone meetings

  3. More training of staff members

  4. Involve internal audit

Correct Answer: A

Question No.182

A recommended method to document the respective roles of groups and individuals for a given process is to:

  1. Develop a detailed internal organization chart

  2. Develop a telephone call tree for emergency response

  3. Develop an isolinear response matrix with cost benefit analysis projections

  4. Develop a Responsible, Accountable, Consulted, Informed (RACI) chart

Correct Answer: D

Question No.183

A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security control claims. Which of the following vendor provided documents is BEST to make your decision:

  1. Vendor#39;s client list of reputable organizations currently using their solution

  2. Vendor provided attestation of the detailed security controls from a reputable accounting firm

  3. Vendor provided reference from an existing reputable client detailing their implementation

  4. Vendor provided internal risk assessment and security control documentation

Correct Answer: B

Question No.184

You manage a newly created Security Operations Center (SOC), your team is being inundated with security alerts and don#39;t know what to do. What is the BEST approach to handle this situation?

  1. Tell the team to do their best and respond to each alert

  2. Tune the sensors to help reduce false positives so the team can react better

  3. Request additional resources to handle the workload

  4. Tell the team to only respond to the critical and high alerts

Correct Answer: B

Question No.185

Risk appetite is typically determined by which of the following organizational functions?

  1. Security

  2. Business units

  3. Board of Directors

  4. Audit and compliance

Correct Answer: B

Question No.186

This occurs when the quantity or quality of project deliverables is expanded from the original project plan.

  1. Scope creep

  2. Deadline extension

  3. Scope modification

  4. Deliverable expansion

Correct Answer: A

Question No.187

Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?

  1. Allow the business units to decide which controls apply to their systems, such as the encryption of sensitive data

  2. Create separate controls for the business units based on the types of business and functions they perform

  3. Ensure business units are involved in the creation of controls and defining conditions under which they must be applied

  4. Provide the business units with control mandates and schedules of audits for compliance validation

Correct Answer: C

Question No.188

Which of the following best summarizes the primary goal of a security program?

  1. Provide security reporting to all levels of an organization

  2. Create effective security awareness to employees

  3. Manage risk within the organization

  4. Assure regulatory compliance

Correct Answer: C

Question No.189

When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain a strong security posture during these difficult times?

  1. Download open source security tools and deploy them on your production network

  2. Download trial versions of commercially available security tools and deploy on your production network

  3. Download open source security tools from a trusted site, test, and then deploy on production network

  4. Download security tools from a trusted source and deploy to production network

Correct Answer: C

Question No.190

Which of the following is a major benefit of applying risk levels?

  1. Risk management governance becomes easier since most risks remain low once mitigated

  2. Resources are not wasted on risks that are already managed to an acceptable level

  3. Risk budgets are more easily managed due to fewer identified risks as a result of using a methodology

  4. Risk appetite can increase within the organization once the levels are understood

Correct Answer: B

