WGU D489 TASK 1 : Cybersecurity
Management Plan |Latest Update
with Complete Solution
1. What are the three distinct groups of managers and professionals, or
communities of interest, in cybersecurity management?
A) Executives, Managers, and Staff
B) Those in information security, those in IT, and those from the rest of
the organization
C) Internal auditors, external auditors, and compliance officers
D) Board of Directors, CISO, and Security Analysts
Correct Answer: B
Rationale: The three communities of interest in cybersecurity are: (1)
those in information security who protect information assets, (2) those in
IT who build and maintain systems, and (3) those from the rest of the
organization who use these systems .
1
, 2. What is the primary responsibility of the information security
community within an organization?
A) To develop new software applications
B) To protect the organization's information assets from threats
C) To manage the organization's financial records
D) To oversee human resources functions
Correct Answer: B
Rationale: The information security community is responsible for
protecting the organization's information assets from the many threats
they face .
3. Which role is ultimately accountable for cybersecurity risk in an
organization?
A) Security Analyst
B) IT Manager
2
,
C) Executive leadership (CIO/CISO/Board)
D) Compliance Officer
Correct Answer: C
Rationale: Risk ownership rests at the executive and board level. The
CISO typically manages cybersecurity operations but executive leadership
bears ultimate accountability for cybersecurity risk .
4. What is the primary purpose of a cybersecurity management plan?
A) To document all IT assets
B) To align security controls with business objectives and risk
C) To list all security incidents
D) To develop software code
Correct Answer: B
3
, Rationale: Cybersecurity management plans connect security strategy to
organizational goals, ensuring that security controls are aligned with
business objectives and risk tolerance .
5. In a RACI matrix for security governance, what does "A" stand for?
A) Action
B) Accountable
C) Authority
D) Approval
Correct Answer: B
Rationale: A RACI matrix defines roles as Responsible, Accountable,
Consulted, and Informed. The "Accountable" person is ultimately
answerable for the task's completion and decision-making .
6. According to the NIST Cybersecurity Framework, which function
involves developing and implementing appropriate safeguards to ensure
delivery of critical services?
4
Management Plan |Latest Update
with Complete Solution
1. What are the three distinct groups of managers and professionals, or
communities of interest, in cybersecurity management?
A) Executives, Managers, and Staff
B) Those in information security, those in IT, and those from the rest of
the organization
C) Internal auditors, external auditors, and compliance officers
D) Board of Directors, CISO, and Security Analysts
Correct Answer: B
Rationale: The three communities of interest in cybersecurity are: (1)
those in information security who protect information assets, (2) those in
IT who build and maintain systems, and (3) those from the rest of the
organization who use these systems .
1
, 2. What is the primary responsibility of the information security
community within an organization?
A) To develop new software applications
B) To protect the organization's information assets from threats
C) To manage the organization's financial records
D) To oversee human resources functions
Correct Answer: B
Rationale: The information security community is responsible for
protecting the organization's information assets from the many threats
they face .
3. Which role is ultimately accountable for cybersecurity risk in an
organization?
A) Security Analyst
B) IT Manager
2
,
C) Executive leadership (CIO/CISO/Board)
D) Compliance Officer
Correct Answer: C
Rationale: Risk ownership rests at the executive and board level. The
CISO typically manages cybersecurity operations but executive leadership
bears ultimate accountability for cybersecurity risk .
4. What is the primary purpose of a cybersecurity management plan?
A) To document all IT assets
B) To align security controls with business objectives and risk
C) To list all security incidents
D) To develop software code
Correct Answer: B
3
, Rationale: Cybersecurity management plans connect security strategy to
organizational goals, ensuring that security controls are aligned with
business objectives and risk tolerance .
5. In a RACI matrix for security governance, what does "A" stand for?
A) Action
B) Accountable
C) Authority
D) Approval
Correct Answer: B
Rationale: A RACI matrix defines roles as Responsible, Accountable,
Consulted, and Informed. The "Accountable" person is ultimately
answerable for the task's completion and decision-making .
6. According to the NIST Cybersecurity Framework, which function
involves developing and implementing appropriate safeguards to ensure
delivery of critical services?
4