1. Which of the following is the PRIMARY purpose of data classification?
A) To determine access rights to data B) To provide a basis for protecting data C) To select encryption technologies D) To ensure integrity of data
2. Before a failover test of a critical business application is performed, it is MOST important for the information security manager to:
A) obtain a signed risk acceptation from the recovery team B) obtain senior management's approval C) inform the users that the test is taking place D) verify that the information assets have been classified properly
3. While conducting a test of a business continuity plan, which of the following is the MOST important consideration?
A) The test simulates actual prime-time processing conditions. B) The test is scheduled to reduce operational impact. C) The test involves IT members in the test process. D) The test addresses the critical components.
4. Which of the following would BEST support a business case to implement a data leakage prevention (DLP) solution?
A) An unusual upward trend in outbound email volume B) Lack of visibility into previous data leakage incidents C) Industry benchmark of DLP investments D) A risk assessment on the threat of data leakage
5. Which of the following is the MOST important reason for performing vulnerability assessments periodically?
A) Technology risks must be mitigated. B) Management requires regular reports. C) The environment changes constantly. D) The current threat levels are being assessed.
Leave a comment