1. During an incident, which of the following entities would MOST likely be contacted directly by an organization's incident response team without management approval?
A) Industry regulators B) Technology vendor C) Law enforcement D) Internal audit
2. The BEST way to minimize errors in the response to an incident is to:
A) follow standard operating procedures. B) analyze the situation during the incident. C) implement vendor recommendations. D) reference system administration manuals.
3. The PRIMARY goal of a security infrastructure design is the:
A) reduction of security incidents. B) protection of corporate assets. C) elimination of risk exposures. D) optimization of IT resources.
4. Which of the following will provide the MOST guidance when deciding the level of protection for an information asset?
A) Cost of controls B) Cost to replace C) Classification of information D) Impact to business function
5. When outsourcing information security administration, it is MOST important for an organization to include:
A) nondisclosure agreements (NDAs) B) contingency plans C) insurance requirements D) service level agreements (SLAs)
Leave a comment