CORPORATE COMPUTER SECURITY
CERTIFICATION EVALUATION SOLVED
QUESTIONS WITH VERIFIED ANSWER KEY
●● An IT security professional's main job is
Answer: defense
●● Which is more important: security management or security
technology
Answer: security management is far more important that security
technology; security management is abstract
●● comprehensive security
Answer: closing all routes of attack into a system to attackers; does not
come by accident
●● Weakest link failure
Answer: A failure in any component will lead to failure for the entire
system; human actions are often the weakest link in security protections
●● Why security management is difficult:
Answer: Comprehensive security doesn't come by accident; weakest link
failures; the need to protect many resources
,●● Processes
Answer: Planned series of actions; security management is to complex
to be managed informally and processes are needed
●● Driving firms to use formal governance frameworks to guide
security processes
Answer: Compliance laws and regulations
●● Complex
Answer: cannot be managed informally
●● plan-protect-respond cycle
Answer: a highest-level security management process, which most firms
today use to protect against threats
●● Planning
Answer: First step of plan-protect respond cycle; without an excellent
plan you will never have comprehensive security
●● Protection
Answer: Plan based creation and operation of countermeasures; second
step in plan-protect-respond cycle
, ●● Systems Development Life Cycle (SDLC)
Answer: The overall process for developing information systems from
planning and analysis through implementation and maintenance
●● systems life cycle
Answer: A traditional methodology for developing an information
system that partitions the systems development process into formal
stages that must be completed sequentially with a very formal division
of labor between end users and information systems specialists.
●● Response
Answer: Recovery according to plan; third step of plan-protect-respond
cycle; speed and accuracy of the essence
●● Vision in planning
Answer: IT security's vision about its role with respect to your company,
its employees, and the outside world drives everything else.
●● Security as an enabler
Answer: our security vision must focus on security as an enabler rather
than as a preventer, because strong security can open new markets, bring
better information flows and lead to lower operational costs
CERTIFICATION EVALUATION SOLVED
QUESTIONS WITH VERIFIED ANSWER KEY
●● An IT security professional's main job is
Answer: defense
●● Which is more important: security management or security
technology
Answer: security management is far more important that security
technology; security management is abstract
●● comprehensive security
Answer: closing all routes of attack into a system to attackers; does not
come by accident
●● Weakest link failure
Answer: A failure in any component will lead to failure for the entire
system; human actions are often the weakest link in security protections
●● Why security management is difficult:
Answer: Comprehensive security doesn't come by accident; weakest link
failures; the need to protect many resources
,●● Processes
Answer: Planned series of actions; security management is to complex
to be managed informally and processes are needed
●● Driving firms to use formal governance frameworks to guide
security processes
Answer: Compliance laws and regulations
●● Complex
Answer: cannot be managed informally
●● plan-protect-respond cycle
Answer: a highest-level security management process, which most firms
today use to protect against threats
●● Planning
Answer: First step of plan-protect respond cycle; without an excellent
plan you will never have comprehensive security
●● Protection
Answer: Plan based creation and operation of countermeasures; second
step in plan-protect-respond cycle
, ●● Systems Development Life Cycle (SDLC)
Answer: The overall process for developing information systems from
planning and analysis through implementation and maintenance
●● systems life cycle
Answer: A traditional methodology for developing an information
system that partitions the systems development process into formal
stages that must be completed sequentially with a very formal division
of labor between end users and information systems specialists.
●● Response
Answer: Recovery according to plan; third step of plan-protect-respond
cycle; speed and accuracy of the essence
●● Vision in planning
Answer: IT security's vision about its role with respect to your company,
its employees, and the outside world drives everything else.
●● Security as an enabler
Answer: our security vision must focus on security as an enabler rather
than as a preventer, because strong security can open new markets, bring
better information flows and lead to lower operational costs