- (Exam Topic 2)
Which of the following activities is the MAIN purpose of the risk assessment process?
Correct Answer:
D
- (Exam Topic 3)
The ultimate goal of an IT security projects is:
Correct Answer:
C
- (Exam Topic 5)
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
Which of the following is the reason the CISO has not been able to advance the security agenda in this
organization?
Correct Answer:
C
- (Exam Topic 1)
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notifying the owner or licensee of this incident?
Correct Answer:
A
- (Exam Topic 5)
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following
principles does this best demonstrate?
Correct Answer:
B