When taking a risk-based approach to vulnerability management, which of the following is MOST important to consider when prioritizing a vulnerability?
Which of the following BEST enables an organization to maintain legally admissible evidence7
To confirm that a third-party provider complies with an organization ' s information security requirements, it is MOST important to ensure:
Which of the following is the BEST indicator of an organization ' s information security status?
Which of the following is the PRIMARY objective of a cyber resilience strategy?
An organization is performing due diligence when selecting a third party. Which of the following is MOST helpful to reduce the risk of unauthorized sharing of information during this process?
Which of the following is the BEST way to monitor the effectiveness of security controls?
Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?
Which of the following is the MOST important security consideration when planning to use a cloud service provider in a different country?
Which of the following is the MOST effective way to demonstrate improvement in security performance?
Which of the following BEST indicates that information assets are classified accurately?
An organization ' s HR department requires that employee account privileges be removed from all corporate IT systems within three days of termination to comply with a government regulation However, the systems all have different user directories, and it currently takes up to four weeks to remove the privileges Which of the following would BEST enable regulatory compliance?
Which of the following would be the BEST way to reduce the risk of disruption resulting from an emergency system change?
Which of the following would BEST enable a new information security manager to obtain senior management support for an information security governance program?
Which of the following is the BEST method for determining whether new risks exist in legacy systems?
Which of the following BEST enables an incident response team to determine appropriate actions during an initial investigation?
Of the following, who is BEST positioned to be accountable for risk acceptance decisions based on risk appetite?
Which of the following is the PRIMARY reason to involve stakeholders from various business units when developing an information security policy?
Which of the following is the BEST course of action after management has reviewed an identified risk and determines the risk is below the defined risk appetite?