60 Practice Questions & Answers
Which of the following best describes the primary purpose of an Information Security Manager?
-
A
To implement technical controls and manage firewalls
-
B
To manage the IT help desk and user support
-
C
To conduct penetration testing on all systems
-
D
To establish and maintain an organizational security strategy aligned with business objectives
✓ Correct
Explanation
An Information Security Manager's primary role is to develop comprehensive security strategies that align with business goals, not to perform technical implementations or IT support functions.
What is the main objective of conducting a Business Impact Analysis (BIA) in the context of information security?
-
A
To determine the potential consequences of security incidents on business operations and prioritize recovery efforts
✓ Correct
-
B
To calculate the total cost of ownership for security tools
-
C
To evaluate employee compliance with security policies
-
D
To identify all technical vulnerabilities in the organization's infrastructure
Explanation
BIA identifies critical business functions and the impact of their disruption, enabling organizations to prioritize security investments and disaster recovery efforts based on business criticality.
An organization experiences a data breach affecting customer personal information. Which phase of incident management should be prioritized immediately after detection?
-
A
Post-incident analysis and lessons learned documentation
-
B
Recovery and restoration of systems to normal operations
-
C
Containment and eradication to prevent further compromise
✓ Correct
-
D
Investigation and forensic examination only
Explanation
After detection, containment and eradication are critical to stop the ongoing attack and prevent additional data loss or system compromise before moving to recovery.
Which framework provides guidance on information security governance and aligns security with organizational strategy?
-
A
NIST Cybersecurity Framework focuses primarily on technical implementation details
-
B
ISO/IEC 27001 establishes requirements for information security management systems including governance structures
-
C
COBIT provides a framework for IT governance with security as a component aligned to business objectives
-
D
Both B and C are equally appropriate
✓ Correct
Explanation
Both ISO/IEC 27001 and COBIT provide comprehensive frameworks for security governance; COBIT is specifically designed for IT governance alignment with business strategy, while ISO/IEC 27001 focuses on ISMS implementation.
What is a critical success factor when implementing a security awareness training program?
-
A
Focus exclusively on compliance requirements and policy documentation
-
B
Training content tailored to specific roles with regular reinforcement and measurement of behavioral change
✓ Correct
-
C
Mandatory annual training sessions for all employees without customization
-
D
Limiting training to IT department personnel only
Explanation
Effective awareness programs require role-specific, ongoing training with metrics to measure actual behavioral improvement, not just compliance checkboxes.
In risk management, what distinguishes risk mitigation from risk acceptance?
-
A
Both approaches are identical in their application and outcomes
-
B
Mitigation is only for technical risks, while acceptance applies to business risks
-
C
Acceptance is cheaper and always preferred over mitigation strategies
-
D
Mitigation implements controls to reduce risk, while acceptance acknowledges residual risk that remains after mitigation efforts
✓ Correct
Explanation
Risk mitigation involves implementing controls to reduce likelihood or impact, while risk acceptance is the conscious decision to tolerate remaining risk after mitigation has been applied.
Which component of a security policy framework typically provides the most detailed technical requirements for system implementation?
-
A
Guidelines that provide recommendations and best practices
-
B
Security procedures that document step-by-step operational processes
-
C
High-level security policies that establish organizational direction
-
D
Security standards that define specific technical configurations and baseline requirements
✓ Correct
Explanation
Security standards specify detailed technical requirements and configurations, while policies set direction, procedures define processes, and guidelines offer recommendations.
What is the primary benefit of implementing defense-in-depth security architecture?
-
A
It reduces the need for security monitoring and incident response capabilities
-
B
Multiple overlapping security layers ensure that compromise of one control does not result in total system compromise
✓ Correct
-
C
It eliminates the need for user education and awareness programs
-
D
It guarantees complete elimination of all security risks
Explanation
Defense-in-depth provides redundant controls so that if one layer is breached, additional layers remain to protect assets and detect intrusions.
An organization must decide whether to implement an expensive security control. Which analysis should guide this decision?
-
A
Only the initial purchase cost of the control
-
B
Matching whatever competitors are implementing regardless of organizational risk profile
-
C
The opinion of the most senior security officer without quantitative analysis
-
D
Cost-benefit analysis comparing implementation and maintenance costs against risk reduction value
✓ Correct
Explanation
Security investments should be justified through cost-benefit analysis that compares total cost of ownership against the value of risk reduction, enabling informed decision-making.
What is the most critical aspect of vendor management from an information security perspective?
-
A
Negotiating the lowest possible contract prices
-
B
Allowing vendors unlimited access to systems for support purposes
-
C
Ensuring vendors meet security requirements and maintain compliance throughout the relationship
✓ Correct
-
D
Conducting security assessments only at contract initiation
Explanation
Vendor management must include security requirement definition, ongoing monitoring, and compliance verification to manage third-party risks effectively.
How should an organization approach the management of privileged access?
-
A
Share privileged credentials among team members for operational convenience
-
B
Eliminate all privileged access by moving to cloud-only systems
-
C
Implement least privilege principle with segregation of duties, monitoring, and formal approval processes
✓ Correct
-
D
Grant administrative privileges to trusted employees without monitoring or restriction
Explanation
Privileged access management requires least privilege implementation, segregation of duties to prevent abuse, and continuous monitoring of administrative actions.
Which metric most accurately measures the effectiveness of a security control?
-
A
The percentage of IT budget allocated to security
-
B
The number of security tools deployed in the organization
-
C
The reduction in risk exposure or number of prevented security incidents correlated to the control
✓ Correct
-
D
The number of employees who pass security certification exams
Explanation
Control effectiveness is measured by actual risk reduction and incident prevention, not by budget allocation, tool quantity, or certification pass rates.
What is the primary purpose of a security incident response plan?
-
A
To eliminate the possibility of security incidents from occurring
-
B
To ensure that every security incident results in criminal prosecution
-
C
To transfer all incident response responsibility to external security vendors
-
D
To establish procedures for detecting, responding to, and recovering from security incidents with minimal business impact
✓ Correct
Explanation
An incident response plan provides documented procedures and roles to minimize incident impact, restore operations quickly, and preserve evidence for investigation.
In the context of security governance, what does 'accountability' require?
-
A
Clear assignment of security responsibilities with defined consequences for non-compliance across the organization
✓ Correct
-
B
Documenting security incidents but taking no corrective action
-
C
Holding only the Chief Information Security Officer responsible for all security outcomes
-
D
Creating security policies without mechanisms to enforce them
Explanation
Accountability means assigning clear security responsibilities at all organizational levels and establishing consequences for non-compliance to ensure security is taken seriously.
What is the relationship between risk tolerance and security control selection?
-
A
Organizations should implement maximum controls regardless of risk tolerance or business needs
-
B
Risk tolerance determines which employees require security training
-
C
Security controls should be selected based on organizational risk tolerance, ensuring control costs are justified by acceptable risk levels
✓ Correct
-
D
Risk tolerance is irrelevant to security decision-making and should be ignored
Explanation
Risk tolerance defines the level of risk an organization is willing to accept; security controls should be tailored to meet this tolerance level efficiently.
Which approach best addresses insider threat risk?
-
A
Implement extensive monitoring of all employees without any privacy considerations
-
B
Trust-based approach with no monitoring or segregation of duties implemented
-
C
Only addressing insider threats after a breach has occurred
-
D
Combination of preventive controls, detection mechanisms, and investigation procedures balanced with employee privacy
✓ Correct
Explanation
Insider threat management requires preventive controls like access management, detection capabilities, and investigation procedures while respecting employee rights.
What should be the primary focus when developing security requirements for a new system?
-
A
Focusing solely on technical security without considering operational feasibility
-
B
Copying security requirements from competitors without customization
-
C
Implementing the most advanced security technology available regardless of cost
-
D
Aligning security requirements with business objectives, regulatory requirements, and risk assessment results
✓ Correct
Explanation
Security requirements should be driven by business needs, applicable regulations, and risk assessment to ensure appropriate and cost-effective protection.
How does security architecture contribute to organizational resilience?
-
A
It eliminates all security risks permanently through technical controls alone
-
B
It focuses exclusively on preventing attacks without considering recovery capabilities
-
C
It transfers all security responsibility to external service providers
-
D
It provides layered defenses and redundant controls that maintain business continuity despite security incidents
✓ Correct
Explanation
Security architecture builds resilience through defense-in-depth, redundancy, and recovery capabilities that enable organizations to maintain operations despite incidents.
What is the primary objective of security metrics and key performance indicators (KPIs)?
-
A
To justify increasing security budgets without demonstrating value
-
B
To demonstrate that the organization has zero security incidents and perfect security
-
C
To comply with regulations by collecting unnecessary data
-
D
To provide quantifiable data on security program effectiveness and identify areas for improvement
✓ Correct
Explanation
Security metrics and KPIs measure program effectiveness, track progress toward objectives, and identify improvement opportunities through quantifiable data.
Which governance structure best ensures security decisions receive appropriate executive sponsorship?
-
A
Security decisions made entirely by IT operations staff without management involvement
-
B
No formal governance structure for security decision-making
-
C
A security steering committee with representation from business units, IT, and executive leadership that reviews major security initiatives
✓ Correct
-
D
Security decisions made exclusively by external consultants
Explanation
A security steering committee with cross-functional representation ensures security receives executive support and aligns with business objectives.
What is critical when implementing data protection controls?
-
A
Implement encryption only for data in transit, ignoring data at rest
-
B
Encrypt all data identically regardless of sensitivity level or regulatory requirements
-
C
Focus data protection efforts only on financial information
-
D
Classify data by sensitivity, apply proportionate controls based on classification, and maintain control effectiveness over time
✓ Correct
Explanation
Effective data protection requires classification, applying controls proportionate to data sensitivity and risk, and ongoing verification of control effectiveness.
How should security configuration management be approached?
-
A
Document baseline security configurations, implement change control processes, and maintain compliance through regular assessments
✓ Correct
-
B
Continuously make security changes without documenting or testing modifications
-
C
Implement security configurations once during system setup with no ongoing management
-
D
Allow each system administrator to configure security settings based on personal preference
Explanation
Configuration management requires documented baselines, formal change control, and continuous compliance verification to maintain security standards.
What distinguishes a mature information security program from an immature one?
-
A
A mature program integrates security into business processes with clear governance, measurable controls, continuous improvement, and executive accountability
✓ Correct
-
B
Maturity is achieved by implementing the most expensive security solutions
-
C
Maturity is determined solely by the number of security tools deployed
-
D
Mature programs eliminate all need for incident response planning
Explanation
Program maturity is evidenced by governance structures, integrated security processes, measurable outcomes, and continuous improvement rather than tool quantity or cost.
In security risk assessment, what is the significance of likelihood and impact evaluation?
-
A
They are used only for compliance documentation with no practical application
-
B
Likelihood is important but impact should be ignored in risk decisions
-
C
Together they determine risk level, which guides prioritization and resource allocation for control implementation
✓ Correct
-
D
They are unnecessary metrics that should be avoided in risk analysis
Explanation
Likelihood and impact together determine overall risk; this risk rating guides control prioritization and ensures resources address the most significant threats.
What role does continuous monitoring play in an information security program?
-
A
It should only occur after a security incident has been discovered through other means
-
B
Continuous monitoring is only required for regulatory compliance, not for operational security
-
C
It provides real-time visibility into security posture, detects anomalies, and enables rapid response to threats
✓ Correct
-
D
It is an unnecessary expense that provides no value to the organization
Explanation
Continuous monitoring enables organizations to maintain visibility, detect security issues early, and respond to threats before significant damage occurs.
Which of the following best describes the primary purpose of an information security program?
-
A
To ensure compliance with all applicable regulations and standards
-
B
To protect organizational assets and enable business objectives while managing risk to acceptable levels
✓ Correct
-
C
To implement the most advanced security technologies available
-
D
To eliminate all cybersecurity risks completely
Explanation
An information security program aims to protect assets and support business goals while maintaining risk at acceptable levels, not to achieve zero risk, which is impossible.
In the context of information security governance, which role is primarily responsible for establishing the organization's risk appetite and oversight of the security program?
-
A
System Administrator
-
B
Chief Information Security Officer (CISO)
-
C
Board of Directors or Executive Leadership
✓ Correct
-
D
Security Operations Center Manager
Explanation
Executive leadership and the board establish organizational risk appetite and provide governance oversight, while the CISO implements the security program within those parameters.
Which of the following is NOT a typical component of a comprehensive information security risk assessment?
-
A
Determining threat likelihood and impact
-
B
Evaluating existing controls and their effectiveness
-
C
Documenting employee salary information and performance reviews
✓ Correct
-
D
Identifying and valuing organizational assets
Explanation
Risk assessments focus on assets, threats, vulnerabilities, and controls. Employee salary and performance data are personnel matters unrelated to security risk assessment.
An organization discovers that a critical vulnerability has been exploited in its production environment. Which incident management phase should be prioritized immediately after initial detection?
-
A
Post-incident review and lessons learned documentation
-
B
Containment to limit the scope and impact of the incident
✓ Correct
-
C
Notification to external regulatory bodies
-
D
Recovery of systems to normal operations
Explanation
Containment must be prioritized immediately after detection to prevent further compromise and limit damage before beginning recovery efforts.
When designing access controls for a financial institution, which principle should guide the implementation to minimize risk while maintaining operational efficiency?
-
A
Grant all users administrative privileges for flexibility
-
B
Provide permanent access once granted to reduce administrative overhead
-
C
Establish access based on seniority level within the organization
-
D
Implement role-based access control aligned with job functions and duties
✓ Correct
Explanation
Role-based access control (RBAC) ensures users have only the access necessary for their job functions, supporting both security and operational needs.
Which of the following best represents a proactive security management approach rather than a reactive one?
-
A
Conducting regular vulnerability assessments and threat modeling before incidents occur
✓ Correct
-
B
Responding to security alerts generated by monitoring systems
-
C
Implementing patches immediately after public vulnerability disclosures
-
D
Investigating security breaches after they have impacted the organization
Explanation
Threat modeling and regular vulnerability assessments are proactive measures taken before incidents, while investigations and patch responses are reactive to discovered issues.
An information security manager is evaluating whether to implement a security control that would reduce risk by 30% but would significantly impact user productivity. What is the most appropriate approach?
-
A
Implement the control immediately as risk reduction is the only priority
-
B
Conduct a cost-benefit analysis and present findings to stakeholders for informed decision-making
✓ Correct
-
C
Delay implementation until a less intrusive alternative is found
-
D
Reject the control as productivity concerns outweigh security benefits
Explanation
Security decisions require balancing risk reduction against business impact; stakeholders should make informed decisions based on comprehensive cost-benefit analysis.
Which framework is most commonly referenced for establishing information security governance across international organizations?
-
A
ISO/IEC 27001 and ISO/IEC 27002
✓ Correct
-
B
PCI DSS exclusively
-
C
NIST Cybersecurity Framework only
-
D
HIPAA Privacy Rule
Explanation
ISO/IEC 27001 and 27002 are internationally recognized standards for information security management systems and controls, applicable across industries and regions.
In analyzing the business impact of a potential security incident, which scenario would typically have the highest priority for mitigation?
-
A
Loss of access to non-critical internal communication systems for 2 hours
-
B
Unauthorized access to a test environment containing anonymized data
-
C
Temporary degradation of a secondary backup system with no immediate customer impact
-
D
Compromise of customer payment information affecting thousands of transactions with potential legal liability
✓ Correct
Explanation
Scenarios with high financial impact, legal liability, and broad customer effects warrant highest priority mitigation due to significant business consequences.
Which approach to security culture development is most effective for sustainable, long-term behavioral change?
-
A
Conducting security awareness campaigns exclusively during incident response
-
B
Annual mandatory security training with enforcement through disciplinary action
-
C
Publishing security policies and expecting employees to self-educate
-
D
Integrating security awareness into daily operations, leadership modeling, and continuous reinforcement
✓ Correct
Explanation
Sustainable security culture requires ongoing reinforcement, leadership commitment, and integration into daily work rather than isolated training events.
When conducting a third-party risk assessment, which factor is LEAST important in determining the level of scrutiny required?
-
A
The potential business impact if the vendor fails to deliver
-
B
The sensitivity level of data the vendor will access
-
C
The vendor's existing security certifications and controls
-
D
The vendor's industry and geographic location only
✓ Correct
Explanation
While industry and location provide some context, the critical factors are data sensitivity, existing controls, and business impact—not location or industry alone.
An organization is implementing a business continuity plan that includes backup processing sites. Which consideration is most critical for ensuring plan effectiveness?
-
A
Ensuring the backup site is located at least 100 miles from the primary facility
-
B
Purchasing backup hardware identical to primary systems
-
C
Documenting all procedures in a comprehensive manual stored at the backup site
-
D
Conducting regular testing and exercises to validate the plan's actual functionality
✓ Correct
Explanation
Regular testing and exercises are critical to identify gaps and ensure the plan actually functions when needed; untested plans often fail during real incidents.
Which type of security control is exemplified by requiring multi-factor authentication for privileged account access?
-
A
Detective control
-
B
Compensating control
-
C
Preventive control
✓ Correct
-
D
Corrective control
Explanation
Multi-factor authentication prevents unauthorized access by adding additional authentication factors before access is granted, functioning as a preventive control.
An information security manager discovers that 40% of critical servers lack current patch management. What is the most appropriate immediate action?
-
A
Implement compensating controls without patching the systems
-
B
Schedule patches during the next quarterly maintenance window
-
C
Accept the risk as a normal operational condition
-
D
Assess risk exposure, prioritize critical patches, and develop an urgent remediation plan with business stakeholders
✓ Correct
Explanation
Unpatched critical systems represent significant risk; immediate risk assessment and urgent remediation planning with stakeholders is appropriate before exploitation occurs.
Which of the following BEST describes the relationship between information security strategy and business strategy?
-
A
Information security strategy and business strategy are parallel but unrelated initiatives
-
B
Information security strategy must be aligned with and support business objectives and goals
✓ Correct
-
C
Business strategy determines all information security decisions without input from security teams
-
D
Information security strategy should be developed independently of business objectives
Explanation
Effective information security strategy is integrated with and supports business objectives, enabling secure business operations rather than imposing unrelated requirements.
In security metrics and key performance indicators (KPIs), which metric would be MOST useful for assessing the maturity of an organization's incident response program?
-
A
Annual budget allocated to incident response
-
B
Average time to detect and respond to critical incidents with trends over time
✓ Correct
-
C
Number of incident response team members employed
-
D
Total number of security incidents reported per month
Explanation
Time to detect and respond indicates actual program effectiveness and improvement trends, whereas incident volume, staffing, and budget don't reflect true capability or maturity.
Which regulatory framework is specifically designed to protect the privacy of health information in the United States?
-
A
HIPAA (Health Insurance Portability and Accountability Act)
✓ Correct
-
B
NIST Cybersecurity Framework
-
C
PCI DSS (Payment Card Industry Data Security Standard)
-
D
GDPR (General Data Protection Regulation)
Explanation
HIPAA specifically governs the privacy, security, and breach notification of protected health information (PHI) in the United States healthcare industry.
An organization is considering cloud migration for its critical applications. Which security assessment should be prioritized BEFORE migration occurs?
-
A
Disaster recovery testing in the cloud environment
-
B
Post-migration performance testing and optimization
-
C
User acceptance testing of cloud-based systems
-
D
Cloud provider security controls evaluation and shared responsibility model clarification
✓ Correct
Explanation
Understanding the cloud provider's controls and clarifying the shared responsibility model is essential before migration to ensure adequate security posture is maintained.
When establishing information security policies, what is the primary purpose of a baseline standard regarding acceptable password complexity requirements?
-
A
To ensure all passwords are identical across the organization
-
B
To establish consistent minimum requirements that reduce the risk of unauthorized access through weak passwords
✓ Correct
-
C
To make it impossible for users to remember their passwords
-
D
To eliminate the need for other security controls
Explanation
Password complexity standards establish minimum requirements across the organization to reduce vulnerability to brute force and dictionary attacks.
Which of the following scenarios best exemplifies the principle of segregation of duties in financial systems?
-
A
All financial personnel having identical system access and permissions
-
B
One employee authorized to request, approve, and reconcile all financial transactions
-
C
Financial processes requiring no approval steps to improve efficiency
-
D
Different individuals responsible for requesting, approving, and reconciling financial transactions
✓ Correct
Explanation
Segregation of duties requires different individuals to handle different phases of critical transactions to prevent fraud and error through independent verification.
An organization experiences a significant data breach affecting customer personal information. Which action should be prioritized alongside immediate incident response?
-
A
Focusing entirely on internal investigation before considering external notifications
-
B
Notifying shareholders exclusively before informing regulatory bodies
-
C
Maximizing delay before notifying affected individuals to minimize panic
-
D
Determining breach scope and notifying affected parties within legally required timeframes
✓ Correct
Explanation
Breach notification laws require timely notification of affected individuals and regulators; determining scope and following legal requirements are critical parallel actions.
Which information security management practice is most critical for reducing the likelihood of successful social engineering attacks against an organization?
-
A
Developing and maintaining a strong security culture through ongoing awareness and training
✓ Correct
-
B
Restricting internet access to critical systems only
-
C
Installing advanced firewall technology throughout the network
-
D
Implementing biometric authentication on all systems
Explanation
Social engineering targets human vulnerabilities; a security culture emphasizing awareness, skepticism, and proper procedures is most effective against these attacks.
In the context of security architecture, which principle suggests that systems should be designed so that if a security mechanism fails, the system should default to a state that denies rather than grants access?
-
A
Least privilege
-
B
Defense in depth
-
C
Zero trust
-
D
Fail secure
✓ Correct
Explanation
Fail secure (or fail-closed) ensures that when mechanisms fail, access is denied rather than granted, preventing unauthorized access during unexpected failures.
Which of the following best describes the primary difference between a vulnerability and a threat in risk management?
-
A
Threats are technical flaws while vulnerabilities are only policy violations
-
B
Vulnerabilities are threats that have already caused damage to the organization
-
C
There is no meaningful distinction between vulnerabilities and threats
-
D
A vulnerability is a weakness; a threat is an entity or force that could exploit that weakness
✓ Correct
Explanation
Vulnerabilities are exploitable weaknesses in systems or controls, while threats are potential attackers or forces that could exploit those vulnerabilities.
When prioritizing security investments, an organization should PRIMARILY focus on protecting which types of assets?
-
A
Assets that are easiest to protect from a technical standpoint
-
B
All IT assets equally regardless of criticality or business value
-
C
Only the most technically sophisticated systems available
-
D
Assets that are critical to business operations and contain valuable or sensitive information
✓ Correct
Explanation
Security investments should prioritize assets critical to business continuity and those containing sensitive or high-value information to maximize risk reduction.
Which of the following best describes the primary purpose of information security governance?
-
A
To establish a framework that aligns security with business objectives and ensures accountability for information protection
✓ Correct
-
B
To conduct regular penetration testing of all organizational systems
-
C
To ensure compliance with ISO 27001 standards exclusively
-
D
To implement firewalls and intrusion detection systems across all network segments
Explanation
Information security governance focuses on aligning security initiatives with business goals, establishing accountability structures, and ensuring strategic oversight—not just technical controls. This is a foundational CISM domain concept.
An organization experiences a data breach affecting 50,000 customer records. What should be the information security manager's first priority in the immediate aftermath?
-
A
Activate the incident response plan and contain the breach to prevent further data loss
✓ Correct
-
B
Implement additional security controls to prevent similar incidents
-
C
Issue a public statement explaining the security measures in place
-
D
Conduct a full forensic investigation to identify the attacker's identity
Explanation
Containment and incident response activation are critical first steps to limit damage. Investigation, communications, and remediation follow after the breach is contained.
Which metric would be most appropriate for measuring the effectiveness of a security awareness program?
-
A
The total budget allocated to awareness training initiatives
-
B
The number of employees who completed training modules within the fiscal year
-
C
The percentage of employees who passed the final assessment exam on their first attempt
-
D
The reduction in security-related incidents attributable to human error over time
✓ Correct
Explanation
Measuring the reduction in human error incidents demonstrates actual behavioral change and program effectiveness, whereas completion rates and exam scores only measure participation and knowledge recall.
An information security manager is designing a risk assessment methodology. Which approach would be most suitable for evaluating risks across a large, complex organization with diverse asset types?
-
A
Quantitative risk assessment exclusively, calculating Annualized Loss Expectancy (ALE) for every asset
-
B
Qualitative risk assessment using standardized scoring matrices with defined probability and impact levels
-
C
Automated risk assessment using machine learning without human involvement or validation
-
D
A hybrid approach combining both quantitative and qualitative methods based on asset criticality and available data
✓ Correct
Explanation
A hybrid approach leverages the strengths of both methods: quantitative precision for high-value assets and qualitative judgment where data is limited, making it most practical for complex environments.
Which of the following is a key responsibility of the information security manager regarding third-party risk management?
-
A
Requiring all vendors to obtain ISO 27001 certification before engagement
-
B
Conducting annual penetration tests on all vendor systems and networks
-
C
Ensuring that all vendors use identical security controls as the organization
-
D
Establishing security requirements, evaluating vendor compliance, and maintaining ongoing oversight of third-party risks
✓ Correct
Explanation
Third-party risk management involves defining security expectations, assessing vendor compliance against those requirements, and continuously monitoring risk—not mandating specific certifications or identical controls.
What is the primary objective of a Business Continuity Plan (BCP) in the context of information security?
-
A
To ensure critical business functions can be restored or maintained within acceptable timeframes after a disruption
✓ Correct
-
B
To eliminate all potential security threats before they occur
-
C
To provide detailed technical specifications for all IT infrastructure components and their redundancy
-
D
To reduce the organization's insurance premiums by demonstrating preparedness
Explanation
A BCP focuses on ensuring business resilience by defining recovery objectives (RTO/RPO) and procedures to restore critical operations, which is essential for information security continuity.
An organization is evaluating whether to implement a new enterprise resource planning (ERP) system. From a security perspective, at which stage should the information security manager become involved in this decision-making process?
-
A
During the vendor selection and requirements definition phase, before contracts are finalized
✓ Correct
-
B
During the post-implementation review to identify any security gaps that need remediation
-
C
Only during the security testing phase immediately before go-live
-
D
After the system is purchased, during the implementation phase only
Explanation
Early involvement in vendor selection and requirements definition allows security considerations to influence purchasing decisions and contract terms, preventing costly rework later. This aligns with secure development lifecycle principles.
Which of the following best represents a limitation of relying solely on technical security controls to protect information assets?
-
A
Technical controls prevent all types of security breaches if implemented correctly by qualified personnel
-
B
Technical controls require constant updates and patches that disrupt normal business operations
-
C
Technical controls are too expensive for most mid-sized organizations to implement comprehensively
-
D
Technical controls cannot detect insider threats or social engineering attacks that exploit human vulnerabilities
✓ Correct
Explanation
Technical controls alone cannot address human-centric risks like social engineering, insider threats, or policy violations; they must be complemented by administrative and physical controls, plus security awareness.
An information security manager discovers that sensitive data classification standards are not consistently applied across different departments. What would be the most appropriate first action to address this issue?
-
A
Implement automated data discovery tools to classify all data without department involvement
-
B
Conduct a detailed audit to identify all non-compliant data and move it to secure storage pending reclassification
-
C
Immediately impose penalties on departments that have not complied with classification standards
-
D
Develop a comprehensive, organization-wide data classification policy and conduct training to ensure consistent understanding and application
✓ Correct
Explanation
Establishing clear policy and providing education creates sustainable compliance through shared understanding, whereas punitive measures, automated approaches without context, or reactive audits don't address the root cause of inconsistency.
Which of the following scenarios represents the greatest challenge for an information security manager in implementing a zero-trust security model within a legacy organization?
-
A
Legacy systems and applications may not support continuous authentication and authorization mechanisms required by zero-trust principles
✓ Correct
-
B
Zero-trust models are incompatible with cloud-based services and cannot be implemented in hybrid environments
-
C
The cost of implementing zero-trust architecture exceeds the organization's annual IT budget
-
D
Employees will inevitably resist any change to their access patterns regardless of security benefits
Explanation
Legacy systems often lack the capability for continuous verification and fine-grained access control that zero-trust requires, necessitating significant technical remediation, whereas costs and resistance can be managed through planning and change management.