WGU C725 (Information Security and Assurance) Final Exam Questions With Answers | Latest Graded A+ (VERIFIED)
This level of government/military data classification is used for data of a restricted nature. The unauthorized disclosure of data classified as secret will have significant effects and cause critical damage to national security. Secret This level of government/military data classification is used for data of a sensitive, proprietary, or highly valuable nature. The unauthorized disclosure of data with this classification level will have noticeable effects and cause serious damage to national security. This classification is used for all data between secret and sensitive but unclassified classifications. Confidential This level of government/military data classification is used for data that is for internal use or for office use only (FOUO). Often this data classification is used to protect information that could violate the privacy rights of individuals. This is not technically a classification label; instead, it is a marking or label used to indicate use or management. Sensitive But Unclassified (SBU) This level of government/military data classification is used for data that is neither sensitive nor classified. The disclosure of this type of data does not compromise confidentiality or cause any noticeable damage. This is not technically a classification label; instead, it is a marking or label used to indicate use or management. Unclassified The easy way to remember the names of the five levels of the government or military data classification scheme, U.S. Can Stop Terrorism. Top Secret Secret Confidential Sensitive But unclassified Unclassified Four common or possible business classification levels Confidential Private Sensitive Public This common business/private sector data classification level is the highest level of classification. This is used for data that is extremely sensitive and for internal use only. A significant negative impact could occur for a company if this type of data is disclosed. Sometimes the label proprietary is substituted. Sometimes proprietary data is considered a specific form of this type of information. If proprietary data is disclosed, it can have drastic effects on the competitive edge of an organization. Confidential This common business/private sector data classification level is used for data that is of a private or personal nature and intended for internal use only. A significant negative impact could occur for the company or individuals if private data is disclosed. Private This common business/private sector data classification level is used for data that is more classified than public data. A negative impact could occur for the company if sensitive data is disclosed. Sensitive This common business/private sector data classification level is the lowest level of classification. This is used for all data that does not fit in one of the higher classifications. Its disclosure does not have a serious negative impact on the organization. Public Relating to data classification or categorization, this is the formal assignment of responsibility to an individual or group. Ownership This role is assigned to the person who is ultimately responsible for the security maintained by an organization and who should be most concerned about the protection of its assets. They sign off on all policy issues. Senior Manager This Role is assigned to a trained and experienced network, systems, and security engineer who is responsible for following the directives mandated by senior management. Security Professional This role is assigned to the person who is responsible for classifying information for placement and protection within the security solution. They are typically a high-level manager who is ultimately responsible for data protection. Data Owner This role is assigned to the user who is responsible for the tasks of implementing the prescribed protection defined by the security policy and senior management. They perform all activities necessary to provide adequate protection for the CIA Triad (confidentiality, integrity, and availability) of data and to fulfill the requirements and responsibilities delegated from upper management. These activities can include performing and testing backups, validating data integrity, deploying security solutions, and managing data storage based on classification. Data Custodian This role is assigned to any person who has access to the secured system. Their access is tied to their work tasks and is limited so they have only enough access to perform the tasks necessary for their job position (the principle of least privilege). They are responsible for understanding and upholding the security policy of an organization by following prescribed operational procedures and operating within defined security parameters. User This role is responsible for reviewing and verifying that the security policy is properly implemented and the derived security solutions are adequate. They may be assigned to a security professional or a trained user. The auditor produces compliance and effectiveness reports that are reviewed by the senior manager. Auditor One of the more widely used security control frameworks. It is a documented set of best IT security practices crafted by the Information Systems Audit and Control Association (ISACA). Control Objectives for Information and Related Technology (COBIT ) Principle 1: Meeting Stakeholder Needs Principle 2: Covering the Enterprise End-to-End Principle 3: Applying a Single, Integrated Framework Principle 4: Enabling a Holistic Approach Principle 5: Separating Governance From Management COBIT 5 (Five Key principles for governance and management of enterprise IT) Defense in depth is needed to ensure that which three mandatory activities are present in a security system? A. Prevention, response, and prosecution B. Response, collection of evidence, and prosecution C. Prevention, detection, and response D. Prevention, response, and management C. Prevention, detection, and response Explanation: Defense in depth is implemented in overlapping layers that provide the three elements needed to secure assets: prevention, detection, and response. T or F Functional requirements describe what a system should do. True T or F Assurance requirements describe how functional requirements should be implemented and tested. True Which of the following best represents the two types of IT security requirements? A. Functional and logical B. Logical and physical C. Functional and assurance D. Functional and physical Functional and assurance Explanation: Functional requirements describe what a system should do. Assurance requirements describe how functional requirements should be implemented and tested. Which of the following terms best describes the probability that a threat to an information system will materialize? A. Threat B. Vulnerability C. Hole D. Risk D) Risk Explanation: Risk involves looking at what is the consequence of a loss and the likelihood that this loss will occur. Which of the following statements is true? A. Controls are implemented to eliminate risk and eliminate the potential for loss. B. Controls are implemented to mitigate risk and reduce the potential for loss. C. Controls are implemented to eliminate risk and reduce the potential for loss. D. Controls are implemented to mitigate risk and eliminate the potential for loss. B. Controls are implemented to mitigate risk and reduce the potential for loss. Explanation: Controls mitigate a wide variety of information security risks and reduce loss. Security functional requirements describe which of the following? A. What a security system should do by design B. What controls a security system must implement C. Quality assurance description and testing approach D. How to implement the system A. What a security system should do by design Question : ISC2 was formed for which of the following purposes? A. Maintaining a Common Body of Knowledge for information security B. Certifying industry professionals and practitioners in an international IS standard C. Ensuring that credentials are maintained, primarily through continuing education D. All of these D. All of these Explanation: The goals of (ISC)2 are maintaining a Common Body of Knowledge for information security, certifying industry professionals and practitioners according to the international IS standard, administering training and certification examinations and ensuring that credentials are maintained, primarily through continuing education. Which of the following statements best describes the information security Common Body of Knowledge? A. The information security Common Body of Knowledge is a compilation and distillation of all security information collected internationally of relevance to information security professionals. B. The information security Common Body of Knowledge is a volume of books published by the ISC2. C. The information security Common Body of Knowledge is a reference list of books and other publications put together by practitioners in information security. D. The information security Common Body of Knowledge is an encyclopedia of information security principles, best A. The information security Common Body of Knowledge is a compilation and distillation of all security information collected internationally of relevance to information security professionals. 1. Information Security Governance and Risk Management 2. Security Architecture and Design 3. Business Continuity and Disaster Recovery Planning 4. Legal Regulations, Investigations, and Compliance 5. Physical (Environmental) Security
Document information
- Uploaded on
- August 8, 2023
- Number of pages
- 18
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers