Which of the following should an information security manager do FIRST when a vulnerability has been disclosed?
Which of the following would be MOST effective in reducing the impact of a distributed denial of service (DDoS) attack?
An incident management team is alerted ta a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:
To inform a risk treatment decision, which of the following should the information security manager compare with the organization ' s risk appetite?
Which of the following BEST provides an information security manager with sufficient assurance that a service provider complies with the organization ' s information security requirements?
An organization has purchased an Internet sales company to extend the sales department. The information security manager ' s FIRST step to ensure the security policy framework encompasses the new business model is to:
Which of the following is the BEST method for determining whether a firewall has been configured to provide a comprehensive perimeter defense9
Which of the following is MOST important when developing an AI security awareness program?
An organization is considering using a third party to host sensitive archived data. Which of the following is MOST important to verify before entering into the relationship?
Which of the following groups is MOST important to involve in the development of information security procedures?
Which of the following is the FIRST step when conducting a post-incident review?
An organization is considering the feasibility of implementing a big data solution to analyze customer data. In order to support this initiative, the information security manager should FIRST:
Which of the following would provide the BEST evidence to senior management that security control performance has improved?
Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?
Which of the following should be the FIRST step when performing triage of a malware incident?
Which of the following should have the MOST influence on the development of information security policies?
Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?
Which of the following BEST encourages staff to report issues related to information security?
Which of the following is the BEST course of action when confidential information is inadvertently disseminated outside the organization?
Management of a financial institution accepted an operational risk that consequently led to the temporary deactivation to a critical monitoring process. Which of the following should be the information security manager ' s GREATEST concern with this situation?