Organizational Documents and Policies Flashcards

1
Q

Which of the following is not a typical best practice in a password policy?
a. Expire passwords regularly
b. Use of uppercase and lowercase letters only in passwords
c. Require password uniqueness
d. Ban use of proper names in passwords

A

Answer: b. A strong password should include uppercase letters, lowercase letters, numbers, and special characters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following is not an area typically targeted by a data loss prevention policy?
a. Cloud level
b. Network level
c. Client level
d. Storage level

A

Answer: a. Data loss prevention policies typically categorize activities at the
client, network, and storage levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An incident response policy often ends with which phase?
a. Prepare
b. Contain
c. Review
d. Eradicate

A

Answer: c. Typical phases of incident response include prepare, identify, contain, eradicate, recover, and review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What should you follow closely when installing new network equipment?
a. YouTube videos
b. Certified training courses
c. Installation and maintenance guides
d. IETF guidelines

A

Answer: c. For the highest degree of safety, you should always follow the vendor instructions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which agreement would need to be read carefully and signed by an end user
in the Sales department regarding the technology they were granted access to?
a. AUP
b. SLA
c. PUA
d. Vacation policy

A

Answer: c. A privileged user agreement (PUA) targets administrators and others who have elevated levels of access on the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

You are discussing a legally binding document that organizations might
require of both their own employees and anyone else who comes into contact
with confidential information. What is this document called?
a. NDA
b. DLP
c. SOP
d. MOU

A

Answer: a. A non-disclosure agreement (NDA) is a legally binding document
that organizations might require of both their own employees and anyone else
who comes into contact with confidential information, including vendors, consultants, and contractors. The purpose of an NDA is to protect an organization’s intellectual property and trade secrets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is often the last stage of a system life cycle used in a network?
a. Phase-out
b. Disposal
c. Support
d. Development

A

Answer: b. Typical life cycle phases are conceptual design, preliminary system
design, detailed design and development, production and construction, utilization and support, phase-out, and disposal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

You have created written instructions that detail organizational procedures to
be followed when an employee leaves the organization or is terminated. What
type of document is this?
a. Data loss prevention policy
b. Service-level agreement
c. Onboarding procedures
d. Offboarding procedures

A

Answer: d. When employees leave the organization, offboarding procedures
need to be in place to ensure that in addition to all access being removed,
equipment and data are returned. The process should be clear regarding expectations, particularly those related to confidential or internal-use-only data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly