Chapter 16 – Managing Security Operations Flashcards
1
Q
- An organization ensures that users are granted access to only the data they need to perform specific work task. What principle are they following?
Need-to-know
A
Need-to-know
2
Q
- An administrator is granting permissions to database. What is the default level of access the administrator should grant to new users in the organization?
No access
A
No access
3
Q
- Which of the following statements best statements best describes why separation of duties is important for security purposes?
It prevents any single IT security person from making major security changes without involving other individuals
A
It prevents any single IT security person from making major security changes without involving other individuals
4
Q
- What is a primary benefit of job rotation and separation of duties policies?
Preventing fraud
A
Preventing fraud
5
Q
- A financial organization commonly has employees switch duty responsibilities every six months. What security principle are they employing?
Job rotation
A
Job rotation
6
Q
- Which of the following is one of the primary reasons an organization enforces a mandatory vacation policy?
To detect fraud
A
To detect fraud
7
Q
- An organization wants to reduce vulnerabilities against fraud from malicious employees. Of the following choices, what would help with this goal? (Choose all that apply.)
Job rotation, Separation of duties, Mandatory vacations
A
Job rotation, Separation of duties, Mandatory vacations
8
Q
- Of the following choices, what is not a valid security practice related to special privileges?
Grant access equally to administrators and operators.
A
Grant access equally to administrators and operators.
9
Q
- Which of the following identifies vendor responsibilities and can include monetary penalties if the vendor doesn’t meet the stated responsibilities?
Service-level agreement (SLA)
A
Service-level agreement (SLA)
10
Q
- What should be done with equipment that is at the end of its lifecycle and is being donated to a charity?
Sanitize it.
A
Sanitize it.