LEGAL ISSUES IN INFORMATION SECURITY - C841 EXAM LATEST 2026
UPDATED QUESTIONS AND VERIFIED 100% SOLUTIONS (2026/2027)
|A+ GRADED |GUARANTEED PASS
What is a framework? - Answers -It is a loose structure that guides an organization toward a
particular goal. A framework is intended to be flexible
What is a methodology? - Answers -is a set of defined principles and practices that lead toward
a particular goal. A methodology is intended to be inclusive of all tasks needed to accomplish a
goal.
What are the 14 sections ot the ISO/IEC 27002 for specific IT controls? - Answers -1, Information
security policy
2. Information security organization
3. Human resources security
4. Asset management
5. Asset Control
6. Cryptography
7 Physical and environmental security
8 Operations Security
9 Communications Security
10 Information system acquisition, development, and maintenance
11 Supplier relationships
12 Information security incident management
13 Information security business continuity management
1|Page
,14 Compliance
What are some other SOX governance provisions? - Answers -Independent directors —SOX
requires a public company to create an independent board of directors. Directors are
independent when they do not have financial ties to the company. In some cases, the
independence rules extend to members of the director's immediate family.
Audit committee —SOX requires public companies to have an audit committee on their board of
directors. This committee works with outside auditors to make sure that financial reports are
accurate.
Conflicts of interest —SOX requires executives to disclose certain types of conflicts of interest
What are the three major corproate privacy concerns? - Answers -1, Privacy of employee data
2. Privacy of customer data
3. Privacy of corporate data
What ypes of companies must follow the Sarbanes-Oxley Act provisions? - Answers -Public (A)
A dividend is a shareholder's earnings in a company. True or false? - Answers -True (A)
What is teh main goal of the Sarbanes-Oxley Act? - Answers -The main goal is put in place
monitoring and disclosure rules for financial records of public companies. This was to improve
investor confidence after the Enron scandal.
2|Page
,How many days after a major event must a company file Form 8-K? - Answers -Four (C)
Which corporate scandals led to the creation of the Sarbanes-Oxley Act? - Answers -All of these
are correct (E)
[Enron, Worldcom, Adelphia, Tyco]
What are internal controls over financial reporting (ICRR)? - Answers -This is a company's
internal tracking and monitoring controls and mechanism for company financial health including
financial transctions and the like.
How many members of the Public Company Accounting Oversight Board may be certified public
accoutants - Answers -Two (D)
Sarbanes-oxley Act Section 404 tells organizations the types of controls that they must
implement in their IT system to protect financial reporting. True of false? - Answers -FALSE (B)
Which framework has the U.S. Securities and Exchange Commission officially approved as
suitable evaluation criteria for internal controls? - Answers -COSO (B)
Which Sarbanes-Oxley Act provision causes the most concern for information technology
professionals? - Answers -Section 404 (C)
3|Page
, A company's chief information security officer and chief financial officer must sign a Section 302
certification. - Answers -False (B)
How often must the U.S. Securities and Exchange Commission review a public company's Form
10-K and Form 10-Q reports? - Answers -Every 3 years (D)
What does the ICFR do? - Answers -It helps to determine internal control framework and
mechanism for Financial reporting.
Under the Sarbanes-Oxley Act, how many years must public companies keep audit papers? -
Answers -Seven (C)
A public company must file a form 10-K at the end of each quarter. True or False? - Answers -
False (B)
That's the 10-Q
What is Information Security Governance (ISG)? - Answers -The executive management team is
responscle to protect an organization's information assets. ISG makes protecting information
assets a business decision. To do this, an organization must align its information security goals
to its business needs. ISG move information security beyong technical decisions and makes
security a strategic decision.
4|Page
UPDATED QUESTIONS AND VERIFIED 100% SOLUTIONS (2026/2027)
|A+ GRADED |GUARANTEED PASS
What is a framework? - Answers -It is a loose structure that guides an organization toward a
particular goal. A framework is intended to be flexible
What is a methodology? - Answers -is a set of defined principles and practices that lead toward
a particular goal. A methodology is intended to be inclusive of all tasks needed to accomplish a
goal.
What are the 14 sections ot the ISO/IEC 27002 for specific IT controls? - Answers -1, Information
security policy
2. Information security organization
3. Human resources security
4. Asset management
5. Asset Control
6. Cryptography
7 Physical and environmental security
8 Operations Security
9 Communications Security
10 Information system acquisition, development, and maintenance
11 Supplier relationships
12 Information security incident management
13 Information security business continuity management
1|Page
,14 Compliance
What are some other SOX governance provisions? - Answers -Independent directors —SOX
requires a public company to create an independent board of directors. Directors are
independent when they do not have financial ties to the company. In some cases, the
independence rules extend to members of the director's immediate family.
Audit committee —SOX requires public companies to have an audit committee on their board of
directors. This committee works with outside auditors to make sure that financial reports are
accurate.
Conflicts of interest —SOX requires executives to disclose certain types of conflicts of interest
What are the three major corproate privacy concerns? - Answers -1, Privacy of employee data
2. Privacy of customer data
3. Privacy of corporate data
What ypes of companies must follow the Sarbanes-Oxley Act provisions? - Answers -Public (A)
A dividend is a shareholder's earnings in a company. True or false? - Answers -True (A)
What is teh main goal of the Sarbanes-Oxley Act? - Answers -The main goal is put in place
monitoring and disclosure rules for financial records of public companies. This was to improve
investor confidence after the Enron scandal.
2|Page
,How many days after a major event must a company file Form 8-K? - Answers -Four (C)
Which corporate scandals led to the creation of the Sarbanes-Oxley Act? - Answers -All of these
are correct (E)
[Enron, Worldcom, Adelphia, Tyco]
What are internal controls over financial reporting (ICRR)? - Answers -This is a company's
internal tracking and monitoring controls and mechanism for company financial health including
financial transctions and the like.
How many members of the Public Company Accounting Oversight Board may be certified public
accoutants - Answers -Two (D)
Sarbanes-oxley Act Section 404 tells organizations the types of controls that they must
implement in their IT system to protect financial reporting. True of false? - Answers -FALSE (B)
Which framework has the U.S. Securities and Exchange Commission officially approved as
suitable evaluation criteria for internal controls? - Answers -COSO (B)
Which Sarbanes-Oxley Act provision causes the most concern for information technology
professionals? - Answers -Section 404 (C)
3|Page
, A company's chief information security officer and chief financial officer must sign a Section 302
certification. - Answers -False (B)
How often must the U.S. Securities and Exchange Commission review a public company's Form
10-K and Form 10-Q reports? - Answers -Every 3 years (D)
What does the ICFR do? - Answers -It helps to determine internal control framework and
mechanism for Financial reporting.
Under the Sarbanes-Oxley Act, how many years must public companies keep audit papers? -
Answers -Seven (C)
A public company must file a form 10-K at the end of each quarter. True or False? - Answers -
False (B)
That's the 10-Q
What is Information Security Governance (ISG)? - Answers -The executive management team is
responscle to protect an organization's information assets. ISG makes protecting information
assets a business decision. To do this, an organization must align its information security goals
to its business needs. ISG move information security beyong technical decisions and makes
security a strategic decision.
4|Page