In a business proposal, a potential vendor promotes being certified for international security standards as a measure of its security capability.
Before relying on this certification, it is MOST important that the information security manager confirms that the:
Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?
Application data integrity risk is MOST directly addressed by a design that includes:
The GREATEST challenge when attempting data recovery of a specific file during forensic analysis is when:
Which of the following BEST indicates misalignment of security policies with business objectives?
Which of the following would BEST help to ensure appropriate security controls are built into software?
Which of the following roles is BEST suited to validate user access requirements during an annual user access review?
When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:
Which of the following is the GREATEST benefit of classifying information security incidents?
An information security manager learns through a threat intelligence service that the organization may be targeted for a major emerging threat. Which of the following is the information security manager ' s FIRST course of action?
When a critical system incident is reported, the FIRST step of the incident handler should be to:
An organization is selecting security metrics to measure security performance, and a firewall specialist suggests tracking the number of external attacks blocked by the firewalls. Which of the following is the GREATEST concern with using this metric?
Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?
Which of the following BEST supports the incident management process for attacks on an organization ' s supply chain?
Which of the following incident response phases involves actions to help safeguard critical systems while maintaining business operations?
The GREATEST benefit of an effective information security awareness program is the organization’s ability to:
Which of the following should an information security manager do FIRST after a new cybersecunty regulation has been introduced?
Which of the following is the BEST approach for managing user access permissions to ensure alignment with data classification?
Which of the following is the MOST important consideration when updating procedures for managing security devices?
Due to changes in an organization ' s environment, security controls may no longer be adequate. What is the information security manager ' s BEST course of action?