1. Which of the following should an IS auditor recommend be done FIRST upon learning that new data protection legislation may affect the organization?
A) Implement data protection best practices B) Implement a new security baseline for achieving compliance C) Restrict system access for noncompliant business processes D) Perform a gap analysis of data protection practices
2. Data confidentiality is a requirement for an organization's new web service. Which of the following would provide the BEST protection?
A) Telnet B) Secure Sockets Layer (SSL) C) Transport Layer Security (TLS) D) Secure File Transfer Protocol (SFTP)
3. Which of the following methods would BEST help detect unauthorized disclosure of confidential documents sent over corporate email?
A) Installing firewalls on the corporate network B) Requiring all users to encrypt documents before sending C) Monitoring all emails based on pre-defined criteria D) Reporting all outgoing emails that are marked as confidential
4. An employee has accidentally posted confidential data to the company's social media page. Which of the following is the BEST control to prevent this from recurring?
A) Require all updates to be made by the marketing director B) Implement a moderator approval process C) Perform periodic audits of social media updates D) Establish two-factor access control for social media accounts
5. Which of the following is the BEST method to prevent wire transfer fraud by bank employees?
A) Re-keying of wire dollar amounts B) Independent reconciliation C) Two-factor authentication control D) System-enforced dual control
Leave a comment