EXAM
(2025-2026)
Question and Answers
Expert Verified
(With A+ Grades Guarantee)
,Threat analysis Which of the following analyses will BEST identify the external influences to an
organization's information security?
The organization's risk tolerance Which of the following has the GREATEST influence on an organization's
information security strategy?
A detailed incident notification process Which of the following is MOST important to include in an incident response plan to
ensure incidents are responded to by the appropriate individuals?
Conducting tabletop exercises appropriate for the Which of the following is the BEST way for an organization to ensure that incident
organization response teams are properly prepared?
The risk is justified by the benefit to the business Which of the following is the PRIMARY reason for granting a security exception?
Assess impact on information security risk Which of the following activities MUST be performed by an information security
manager for change requests?
Privileged access management (PAM) system An organization's HR department requires that employee account privileges be
removed from all corporate IT systems within three days of termination to comply
with a government regulation However, the systems all have different user
directories, and it currently takes up to four weeks to remove the privileges Which of
the following would BEST enable regulatory compliance?
Report findings to senior management A penetration test was conducted by an accredited third party Which of the following
should be the information security manager's FIRST course of action?
Business risks are managed to an acceptable level What is the PRIMARY benefit to an organization that maintains an information
security governance framework?
Verify that information security requirements are included Which of the following is the BEST way to assess the risk associated with using a
in the contract Software as a Service (SaaS) vendor?
Recovery Which of the following MUST happen immediately following the identification of a
malware incident?
Assign responsibility to the database administrator (DBA) While classifying information assets an information security manager notices that
several production databases do not have owners assigned to them What is the
BEST way to address this situation?
Disconnect the device from the network What should be the FIRST step when an Internet of Things (loT) device in an
organization's network is confirmed to have been hacked?
Assess the consequences of noncompliance An information security manager determines there are a significant number of
exceptions to a newly released industry-required security standard. Which of the
following should be done NEXT?
, Incident management Which of the following activities is designed to handle a control failure that leads to
a breach?
An information security dashboard Which of the following would be the MOST effective way to present quarterly reports
to the board on the status of the information security program?
Identify and assess the risk in the context of business Which of the following should be an information security manager's FIRST course of
objectives action when a newly introduced privacy regulation affects the business?
Create an inventory When developing an asset classification program, which of the following steps
should be completed FIRST?
An increase in the identification rate during phishing Which of the following is the BEST indication of an effective information security
simulations awareness training program?
Role-based access control Security administration efforts will be greatly reduced following the deployment of
which of the following techniques?
assurance that security requirements are met An organization's quality process can BEST support security management by
providing:
Perform a risk assessment An organization is in the process of acquiring a new company Which of the following
would be the BEST approach to determine how to protect newly acquired data
assets prior to integration?
Isolate the affected network segment Which of the following is the BEST course of action when an online company
discovers a network attack in progress?
Parallel test Which is the BEST method to evaluate the effectiveness of an alternate processing
site when continuous uptime is required?
Testing response scenarios Which of the following is MOST important in increasing the effectiveness of incident
responders?
Only as needed When investigating an information security incident, details of the incident should be
shared:
Configuration management files Which of the following should be considered FIRST when recovering a
compromised system that needs a complete rebuild?
Facilitating the monitoring of risk occurrences Which of the following is the GREATEST value provided by a security information
and event management (SIEM) system?
have a better understanding of specific business needs The PRIMARY advantage of involving end users in continuity planning is that they: