Sample Test Questions Domain 6 Flashcards
the most important reason to log events remotely is ___
To prevent against log tampering
a ___ transaction is a scripted process used to emulate user behavior in application testing
synthetic
The greatest value of security metrics is to establish the ___ and ___ that must be used by senior management to evaluate the effectiveness of an information security management system (ISMS)
key performance indicators (KPIs);
key risk indicators (KRIs)
No matter how technically comprehensive a report to management must be, the executive summary should never exceed ___
two pages
A security ___ program addresses all employees regardless of role, whereas security ___ is role specific
awareness; training
A(n) ___ is a comparison between the properties of a system and some predetermined standardized configuration. A(n) ___ is a related series of these.
test; assessment
A dedicated and persistent adversary will likely gain a level of knowledge of their target that rivals or exceeds that of the ___, both in breadth and accuracy
internal audit team
The most important practice when conducting internal audits is to ensure both that the results are actionable by operations staff and that ___
their importance is well understood by the management team that is responsible for actions being taken
When testing a set of controls across a fleet of systems, if it can be determined that ___, it may make little sense to inspect each of them individually, and certainly will increase the cost of the assessment
they are uniformly configured and deployed