InfoSec Program Development and Management Flashcards

1
Q

Is it okay for some employees to not receive security awareness training?

A

No, it is essential for all employees to complete security training.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does GDPR require of a DPO

A

The DPO mus report to the highest level in an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an alternative to MFA?

A

Implement adaptive MFA with business rules that represent an acceptable compromise (e.g., registered company devices).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can a CISO best estimate the resources required to support security operations in an organization?

A

Consult with industry analysts and experts to get the best initial estimates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does WAF stand for?

A

Web application firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A SIEM addresses which business problem?

A

Identification of unwanted security events in the entire technology stack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which groups should be involved in SIEM acquisition?

A

Security governance, security operations, IT operations, audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the best consideration for classifying assets for an e-commerce company?

A

Knowing whether assets contain cardholder data, PII, and encryption keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Name categories for asset classification

A

Data sensitivity, geographic location, business process alignment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the primary stages of SDLC?

A

Initiation, development of acquisition, implementation, operation or maintenance, disposal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 5 agreement types?

A
  1. OLA Operational Level Agreement
  2. SLA Service Level Agreement
  3. ISA IntercoWhnnection Security Agreement
  4. MOU/A: Memo of Understanding/Agreement
  5. BPA: Business Partner Agreement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the meaning of the phrase “identify the new perimeter”?

A

Everything (technology and people) is moving to the cloud or outside the network perimeter, and internal firewalls are no longer relevant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are SMART goals?

A

Specific, Measurable, Attainable, Realistic, and Timely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly