Senior management has expressed concern that the organization ' s intrusion prevention system (IPS) may repeatedly disrupt business operations Which of the following BEST indicates that the information security manager has tuned the system to address this concern?
When developing security processes for handling credit card data on the business unit ' s information system, the information security manager should FIRST:
Implementing the principle of least privilege PRIMARILY requires the identification of:
Which of the following is MOST likely to be the cause of systems and applications missing critical patches?
An incident response team has established that an application has been breached. Which of the following should be done NEXT?
A new risk has been identified in a high availability system. The BEST course of action is to:
An information security policy was amended recently to support an organization ' s new information security strategy. Which of the following should be the information security manager ' s NEXT step?
Which of the following is the BEST way to determine the effectiveness of an incident response plan?
Which of the following tools would be MOST helpful to an incident response team?
A department has reported that a security control is no longer effective. Which of the following is the information security manager ' s BEST course of action?
What is the PRIMARY benefit to an organization that maintains an information security governance framework?
An organization wants to migrate a proprietary application to be hosted by a third-party cloud hosting provider using a Platform as a Service (PaaS) model. Prior to selecting the cloud provider, what is MOST important for the organization to ensure?
What should be an information security manager’s FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?
An organization ' s information security manager is performing a post-incident review of a security incident in which the following events occurred:
• A bad actor broke into a business-critical FTP server by brute forcing an administrative password
• The third-party service provider hosting the server sent an automated alert message to the help desk, but was ignored
• The bad actor could not access the administrator console, but was exposed to encrypted data transferred to the server
• After three hours, the bad actor deleted the FTP directory, causing incoming FTP attempts by legitimate customers to fail
Which of the following could have been prevented by conducting regular incident response testing?
Which of the following provides an information security manager with the MOST accurate indication of the organization ' s ability to respond to a cyber attack?
Which of the following is the BEST defense-in-depth implementation for protecting high value assets or for handling environments that have trust concerns?
Prior to conducting a forensic examination, an information security manager should:
Which of the following would BEST support the business case for an increase in the information security budget?
Several critical systems have been compromised with malware. Which of the following is the BEST strategy to eradicate this incident?