Security
–and
Lecture
Risk Management
Notes _ Study–
Material.pdf
CISSP
Security
– Lecture
and Risk
Notes
Management
_ Study Material.pdf
– CISSP – Lecture Notes _ Study Material
Security and Risk
Management –
CISSP – Lecture
Notes / Study
Material
Security and Risk Management – CISSP
Security
–and
Lecture
Risk Management
Notes _ Study–
Material.pdf
CISSP
Security
–and
Lecture
Risk Management
Notes _ Study–
Material.pdf
CISSP – Lecture Notes _ Study Material.pdf
,Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP
Your company is establishing new employment All of the options
candidate screening processes. Which of the
following should be included?
a. Check all references.
b. Verify all education.
c. Review military records and experience.
d. Perform a background check.
Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf
,Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP
Background Physical preventive control
You are a security professional recently hired by a
publicly traded company to help manage
organizational security. The company has a main
office in Atlanta, GA, and branch offices throughout
the southeastern United States. The IT department
has a small staff housed in the Atlanta office.
Current Issues
Last year, a winter storm shut down operations in
most of your offices. While none of your facilities
were destroyed and normal operations were
restored within 24 hours, management is concerned
that no disaster recovery plan exists. You have been
asked to prepare a plan to cover this type of
disruption.
Your organization currently maintains several large
databases of digital content that are vital to your
organization's operations. Different controls are used
to manage this content. Management has asked you
to implement a solution to control the opening,
editing, printing, or copying of this data in a more
centralized manner.
Within the next six months, your company plans to
move all servers and server farms to a centralized
data center. The data center will occupy the third
floor of a six- floor building that is currently under
construction. Management has asked you to ensure
that access to the data center is tightly controlled.
During that same time, it is likely that your
Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf
, Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP
g y y
organization will be purchasing a competitor to
merge into its existing organization.
Recently, one of the intranet servers was the victim
of a denial-of-service (DoS) attack. It took the IT
department over 24 hours to return the server to
operation. During that time, personnel in the main
office were unable to access the important human
resources information available on the affected
intranet server.
Last week, you discovered that several user accounts
were used in an attempt to hack into your network.
Luckily, the accounts were locked out due to invalid
login attempts. You review the logs and determine
that three of the accounts were created for
personnel who are no longer employed by your
organization.
After pushing for years, you have received
permission from management to design and
implement a comprehensive security awareness
program across the entire organization.
You decide to implement biometrics to control
access to the data center. Which type of access
control have you implemented?
A)
administrative detective control
B)
physical preventive control
C)
physical detective control
Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf Security and Risk Management - CISSP.pdf