Security Management — Exam Questions with
Correct Answers (VerifiedAnswers) Plus
Rationales 2026 Q&A Instant Download PDF
Question 1
What is the primary purpose of security management within an
organization?
A. To eliminate every possible security threat
B. To maximize the organization's profits
C. To identify, assess, and manage security risks
D. To replace all employees with automated systems
Correct Answer: C. To identify, assess, and manage security
risks
Rationale: Security management is primarily concerned with
identifying threats and vulnerabilities, assessing the risks they
create, and implementing appropriate controls to reduce those
risks to an acceptable level. No organization can realistically
eliminate every threat, so effective security management
focuses on informed risk reduction rather than absolute security.
Question 2
Which activity should generally occur first in a formal security
risk management process?
,A. Purchasing security equipment
B. Identifying assets and potential threats
C. Disciplining employees
D. Implementing incident response procedures
Correct Answer: B. Identifying assets and potential threats
Rationale: An organization must understand what it needs to
protect and what could harm those assets before selecting
appropriate security controls. Asset and threat identification
establishes the foundation for risk assessment and helps
management prioritize resources according to the
organization's actual exposure.
Question 3
What is a security policy?
A. A documented statement establishing security requirements
and expectations
B. A list of employee salaries
C. A technical configuration file
D. A replacement for security training
Correct Answer: A. A documented statement establishing
security requirements and expectations
Rationale: A security policy communicates management's
expectations regarding the protection and acceptable use of
organizational resources. It provides direction for employees
,and establishes a foundation for procedures, standards, and
technical controls. A policy does not replace training or technical
safeguards; instead, it guides them.
Question 4
Which principle requires users to receive only the access
necessary to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Availability
Correct Answer: B. Least privilege
Rationale: The principle of least privilege limits an individual's
access rights to the minimum required to perform authorized
responsibilities. Reducing unnecessary privileges limits the
potential impact of compromised accounts, insider misuse, and
accidental actions.
Question 5
What is the main purpose of separation of duties?
A. To ensure that one person controls an entire critical process
B. To prevent one individual from having excessive control over
a sensitive activity
C. To eliminate the need for auditing
D. To increase employee privileges
, Correct Answer: B. To prevent one individual from having
excessive control over a sensitive activity
Rationale: Separation of duties divides important
responsibilities among multiple individuals so that no single
person can complete a sensitive process without oversight. This
reduces opportunities for fraud, abuse, and unauthorized
activity and creates a stronger system of accountability.
Question 6
Which of the following best describes a vulnerability?
A. A potential source of harm
B. A weakness that could be exploited
C. The financial cost of an incident
D. A completed security incident
Correct Answer: B. A weakness that could be exploited
Rationale: A vulnerability is a weakness in technology, people,
processes, or physical environments that could be exploited by a
threat. A threat represents potential danger, while the
vulnerability represents the weakness that may allow the threat
to cause harm.
Question 7
Which term describes something capable of causing harm to an
organizational asset?
Correct Answers (VerifiedAnswers) Plus
Rationales 2026 Q&A Instant Download PDF
Question 1
What is the primary purpose of security management within an
organization?
A. To eliminate every possible security threat
B. To maximize the organization's profits
C. To identify, assess, and manage security risks
D. To replace all employees with automated systems
Correct Answer: C. To identify, assess, and manage security
risks
Rationale: Security management is primarily concerned with
identifying threats and vulnerabilities, assessing the risks they
create, and implementing appropriate controls to reduce those
risks to an acceptable level. No organization can realistically
eliminate every threat, so effective security management
focuses on informed risk reduction rather than absolute security.
Question 2
Which activity should generally occur first in a formal security
risk management process?
,A. Purchasing security equipment
B. Identifying assets and potential threats
C. Disciplining employees
D. Implementing incident response procedures
Correct Answer: B. Identifying assets and potential threats
Rationale: An organization must understand what it needs to
protect and what could harm those assets before selecting
appropriate security controls. Asset and threat identification
establishes the foundation for risk assessment and helps
management prioritize resources according to the
organization's actual exposure.
Question 3
What is a security policy?
A. A documented statement establishing security requirements
and expectations
B. A list of employee salaries
C. A technical configuration file
D. A replacement for security training
Correct Answer: A. A documented statement establishing
security requirements and expectations
Rationale: A security policy communicates management's
expectations regarding the protection and acceptable use of
organizational resources. It provides direction for employees
,and establishes a foundation for procedures, standards, and
technical controls. A policy does not replace training or technical
safeguards; instead, it guides them.
Question 4
Which principle requires users to receive only the access
necessary to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Availability
Correct Answer: B. Least privilege
Rationale: The principle of least privilege limits an individual's
access rights to the minimum required to perform authorized
responsibilities. Reducing unnecessary privileges limits the
potential impact of compromised accounts, insider misuse, and
accidental actions.
Question 5
What is the main purpose of separation of duties?
A. To ensure that one person controls an entire critical process
B. To prevent one individual from having excessive control over
a sensitive activity
C. To eliminate the need for auditing
D. To increase employee privileges
, Correct Answer: B. To prevent one individual from having
excessive control over a sensitive activity
Rationale: Separation of duties divides important
responsibilities among multiple individuals so that no single
person can complete a sensitive process without oversight. This
reduces opportunities for fraud, abuse, and unauthorized
activity and creates a stronger system of accountability.
Question 6
Which of the following best describes a vulnerability?
A. A potential source of harm
B. A weakness that could be exploited
C. The financial cost of an incident
D. A completed security incident
Correct Answer: B. A weakness that could be exploited
Rationale: A vulnerability is a weakness in technology, people,
processes, or physical environments that could be exploited by a
threat. A threat represents potential danger, while the
vulnerability represents the weakness that may allow the threat
to cause harm.
Question 7
Which term describes something capable of causing harm to an
organizational asset?