Sample Test Questions Domain 6 Flashcards

1
Q

the most important reason to log events remotely is ___

A

To prevent against log tampering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

a ___ transaction is a scripted process used to emulate user behavior in application testing

A

synthetic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The greatest value of security metrics is to establish the ___ and ___ that must be used by senior management to evaluate the effectiveness of an information security management system (ISMS)

A

key performance indicators (KPIs);

key risk indicators (KRIs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

No matter how technically comprehensive a report to management must be, the executive summary should never exceed ___

A

two pages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A security ___ program addresses all employees regardless of role, whereas security ___ is role specific

A

awareness; training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A(n) ___ is a comparison between the properties of a system and some predetermined standardized configuration. A(n) ___ is a related series of these.

A

test; assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A dedicated and persistent adversary will likely gain a level of knowledge of their target that rivals or exceeds that of the ___, both in breadth and accuracy

A

internal audit team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The most important practice when conducting internal audits is to ensure both that the results are actionable by operations staff and that ___

A

their importance is well understood by the management team that is responsible for actions being taken

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When testing a set of controls across a fleet of systems, if it can be determined that ___, it may make little sense to inspect each of them individually, and certainly will increase the cost of the assessment

A

they are uniformly configured and deployed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly