1. When developing an incident response plan, the information manager should:
A) allow IT to decide which systems can be removed from the infrastructure B) include response scenarios that have been approved previously by business management C) require IT to invoke the business continuity plan D) determine recovery time objectives (RTOs)
2. Which of the following should be done FIRSTwhen handling multiple confirmed incidents raised at the same time?
A) Categorize incidents by the value of the affected asset. B) Inform senior management. C) Update the business impact assessment. D) Activate the business continuity plan.
3. Which of the following is the BEST indication of a successful information security culture?
A) Penetration testing is done regularly and findings remediated. B) End users know how to identify and report incidents. C) Individuals are given access based on job functions. D) The budget allocated for information security is sufficient.
4. Which of the following BEST contributes to the successful management of security incidents?
A) Tested controls B) Established procedures C) Established policies D) Current technologies
5. Which of the following is the BEST indicator of an effective employee information security program?
A) Increased management support for security B) More efficient and effective incident handling C) Increased detection and reporting of incidents D) Reduced operational cost of security
Leave a comment