1. When making an outsourcing decision, which of the following functions is MOST important to retain within the organization?
A) Security management B) Incident response C) Risk assessment D) Security governance
2. Which of the following metrics is MOST useful to demonstrate the effectiveness of an incident response plan?
A) Average time to resolve an incident B) Total number of reported incidents C) Total number of incident responses D) Average time to respond to an incident
3. In a resource-restricted security program, which of the following approaches will provide the BEST use of the limited resources?
A) Cross-training B) Risk avoidance C) Risk prioritization D) Threat management
4. During an emergency security incident, which of the following would MOST likely predict the worst-case scenario?
A) Cost-benefit analysis report B) Business impact analysis (BIA) report C) Risk assessment report D) Vulnerability assessment report
5. Which of the following would be MOST important to consider when implementing security settings for a new system?
A) Results from internal and external audits B) Government regulations and related penalties C) Business objectives and related IT risk D) Industry best practices applicable to the business
Leave a comment