ISA 3300 CH 4 EXAM QUESTIONS WITH
CORRECT ANSWERS
Which of the following is a common element of the enterprise
| | | | | | | | | | |
information security policy? - CORRECT ANSWER✔✔-Information on the
| | | | | | |
|structure of the InfoSec organization
| | | |
When an organization demonstrates that it is continuously attempting
| | | | | | | | |
to meet the requirements of the market in which it operates, what is it
| | | | | | | | | | | | | |
ensuring? - CORRECT ANSWER✔✔-Due diligence
| | | |
In addition to specifying acceptable and unacceptable behavior, what
| | | | | | | | |
else must a policy specify? - CORRECT ANSWER✔✔-The penalties for
| | | | | | | | | |
violation of the policy | | |
Which policy is the highest level of policy and is usually created first? -
| | | | | | | | | | | | | |
CORRECT ANSWER✔✔-EISP |
Which of the following is not one of the basic rules that must be
| | | | | | | | | | | | | |
followed when shaping a policy?
| | | |
a) Policy must be properly supported and administered.
| | | | | | |
CORRECT ANSWERS
Which of the following is a common element of the enterprise
| | | | | | | | | | |
information security policy? - CORRECT ANSWER✔✔-Information on the
| | | | | | |
|structure of the InfoSec organization
| | | |
When an organization demonstrates that it is continuously attempting
| | | | | | | | |
to meet the requirements of the market in which it operates, what is it
| | | | | | | | | | | | | |
ensuring? - CORRECT ANSWER✔✔-Due diligence
| | | |
In addition to specifying acceptable and unacceptable behavior, what
| | | | | | | | |
else must a policy specify? - CORRECT ANSWER✔✔-The penalties for
| | | | | | | | | |
violation of the policy | | |
Which policy is the highest level of policy and is usually created first? -
| | | | | | | | | | | | | |
CORRECT ANSWER✔✔-EISP |
Which of the following is not one of the basic rules that must be
| | | | | | | | | | | | | |
followed when shaping a policy?
| | | |
a) Policy must be properly supported and administered.
| | | | | | |