BANK 300 MULTIPLE CHOICE QUESTIONS WITH
ANSWERS AND RATIONALES LATEST UPDATE OF THIS
YEAR .ASSURED PASS!!!
Section 1: FMC Security Gaps Overview (Questions 1-30)
Question 1
What was the overarching concern identified by Pruhart Consulting regarding
FMC's systems?
A) Lack of security policies
B) All FMC-connected systems are senescent (outdated)
C) Absence of MFA
D) Lack of antivirus protection
Answer: B) All FMC-connected systems are senescent (outdated)
Rationale: Pruhart identified that all FMC-connected systems are senescent and
require analysis, ranking, compliance improvements, and a maintenance plan. This
overarching concern affects all other security gaps identified in the assessment .
,---
Question 2
Which of the following is NOT a security gap identified in FMC's Security
Assessment Report?
A) Lack of antivirus and endpoint protection
B) Outdated systems design
C) Excessive security controls causing operational delays
D) Lack of MFA
Answer: C) Excessive security controls causing operational delays
Rationale: The SAR identified six specific security gaps, including lack of
antivirus/endpoint protection, outdated systems design, lack of MFA, inadequate
PCI DSS compliance, lack of secure government access, and insecure PII storage.
Excessive security controls was not identified as a gap .
---
Question 3
What was the first security gap identified by Pruhart Security Consulting?
,A) Lack of MFA
B) Workstations lack the necessary and correct antivirus protection
C) Inadequate endpoint protection
D) Lack of secure PII storage
Answer: B) Workstations lack the necessary and correct antivirus protection
Rationale: The first identified gap was that workstations connected to the network
switches lack the necessary and correct antivirus protection. This fundamental
security control gap leaves systems vulnerable to malware infections .
---
Question 4
FMC's planned POS system for medical equipment sales cannot meet compliance
requirements for which standard?
A) HIPAA
B) FISMA
C) PCI DSS
D) SOX
Answer: C) PCI DSS
, Rationale: The SAR identified that FMC's inability to meet PCI DSS compliance
requirements for the planned POS system is a significant gap. FMC must
implement secure networks, firewalls, remove vendor-supplied defaults, and
install antivirus solutions to address this gap .
---
Question 5
FMC is a federally-funded healthcare facility that must comply with which federal
requirements?
A) HIPAA only
B) FISMA requirements and mandates
C) SOX only
D) GLBA only
Answer: B) FISMA requirements and mandates
Rationale: As a federally-funded healthcare facility, FMC falls under Federal
Information Security Management Act (FISMA) requirements and mandates, in
addition to healthcare-specific regulations .
---
Question 6