FINAL EXAM PART 2 QUIZZES WITH RIGHT
ANSWERS 2025 - 2026
Which,of,the,following,is,the,MOST,effective,approach,to,identify,events,that,may,affect,information,secu
rity,across,a,large,multinational,enterprise?,,ANS,-
,Develop,communication,channels,throughout,the,enterprise.
Which,of,the,following,elements,is,MOST,important,when,developing,an,information,security,strategy?,,A
NS,-,Defined,objectives
Serious,security,incidents,typically,lead,to,renewed,focus,on,information,security,by,management.,To,BES
T,use,this,attention,,the,information,security,manager,should,make,the,case,for:,,ANS,-
,improving,integration,of,business,and,information,security,processes.
An,organization,has,recently,developed,and,approved,an,access,control,policy.,Which,of,the,following,will
,be,MOST,effective,in,communicating,the,access,control,policy,to,the,employees?,,ANS,-
,Requiring,employees,to,formally,acknowledge,receipt,of,the,policy
Which,of,the,following,requirements,would,have,the,LOWEST,level,of,priority,in,information,security?,,AN
S,-,Technical
Which,of,the,following,activities,MOST,commonly,falls,within,the,scope,of,an,information,security,govern
ance,steering,committee?,,ANS,-,Prioritizing,information,security,initiatives
Which,of,the,following,is,the,BEST,justification,to,convince,management,to,invest,in,an,information,securi
ty,program?,,ANS,-,Increased,business,value
Requirements,for,an,information,security,program,should,be,based,PRIMARILY,on,which,of,the,following,
choices?,,ANS,-,Desired,outcomes
Which,of,the,following,is,an,indicator,of,effective,governance?,,ANS,-
,An,established,risk,management,program
,Which,of,the,following,would,be,the,BEST,indicator,that,an,organization,has,good,governance?,,ANS,-
,Maturity,level
It,is,MOST,important,that,a,privacy,statement,on,a,company's,e-commerce,web,site,includes:,,ANS,-
,a,statement,regarding,what,the,company,will,do,with,the,information,it,collects.
Which,of,the,following,is,the,GREATEST,security,concern,when,an,incident,log,is,stored,on,the,production,
database,server?,,ANS,-,The,database,administrator,may,tamper,with,the,log,information.
Which,of,the,following,roles,is,responsible,for,ensuring,that,information,is,classified?,,ANS,-
,The,data,owner
What,is,the,PRIMARY,basis,for,the,selection,of,controls,and,countermeasures?,,ANS,-,Cost-benefit,balance
Which,of,the,following,is,the,MOST,usable,deliverable,of,an,information,security,risk,analysis?,,ANS,-
,List,of,action,items,to,mitigate,risk
Objectives,for,preventive,controls,should,be,developed,PRIMARILY,on,the,basis,of:,,ANS,-
,risk,levels,aligned,with,the,enterprise,risk,appetite.
Controls,are,effective,when:,,ANS,-,residual,risk,is,at,a,level,acceptable,to,the,organization.
Which,of,the,following,is,the,FIRST,action,to,be,taken,when,the,information,security,manager,notes,that,t
he,controls,for,a,critical,application,are,inadequate?,,ANS,-
,Perform,a,risk,assessment,to,determine,the,level,of,exposure.
The,assessment,of,risk,is,always,subjective.,To,improve,accuracy,,which,of,the,following,is,the,MOST,impo
rtant,action,to,take?,,ANS,-,Train,or,calibrate,the,assessor.
Which,of,the,following,choices,is,MOST,likely,to,achieve,cost-
effective,risk,mitigation,across,the,organization?,,ANS,-,Assurance,process,integration
, A,control,policy,is,MOST,likely,to,address,which,of,the,following,implementation,requirements?,,ANS,-
,Failure,modes
Who,should,be,responsible,for,enforcing,access,rights,to,application,data?,,ANS,-,Security,administrators
The,MOST,important,reason,that,statistical,anomaly-
based,intrusion,detection,systems,(stat,IDSs),are,less,commonly,used,than,signature-
based,IDSs,,is,that,stat,IDSs:,,ANS,-,generate,false,alarms,from,varying,user,or,system,actions.
For,virtual,private,network,access,to,the,corporate,network,,the,infonnation,security,manager,is,requiring
,strong,authentication.,Which,of,the,following,is,the,strongest,method,to,ensure,that,logging,onto,the,net
work,is,secure?,,ANS,-,Two-factor,authentication
What,is,a,desirable,sensitivity,setting,for,a,biometric,access,control,system,that,protects,a,high-
security,data,center?,,ANS,-,A,high,false,reject,rate
What,is,the,MAIN,advantage,of,implementing,automated,password,synchronization?,,ANS,-
,It,reduces,overall,administrative,workload.
Which,of,the,following,choices,is,the,WEAKEST,link,in,the,authorized,user,registration,process?,,ANS,-
,The,registration,authority's,private,key
When,designing,an,intrusion,detection,system,,the,information,security,manager,should,recommend,that
,it,be,placed:,,ANS,-,on,a,screened,subnet.
Which,of,the,following,BEST,accomplishes,secure,customer,use,of,an,e-commerce,application?,,ANS,-
,Data,encryption
Why,is,it,important,to,develop,an,information,security,baseline?,The,security,baseline,helps,define:,,ANS,-
,the,minimum,acceptable,security,to,be,implemented.
Which,of,the,following,is,the,MOST,important,element,to,ensure,the,success,of,a,disaster,recovery,test,at,
a,vendor-provided,hot,site?,,ANS,-,Business,management,actively,participates.
ANSWERS 2025 - 2026
Which,of,the,following,is,the,MOST,effective,approach,to,identify,events,that,may,affect,information,secu
rity,across,a,large,multinational,enterprise?,,ANS,-
,Develop,communication,channels,throughout,the,enterprise.
Which,of,the,following,elements,is,MOST,important,when,developing,an,information,security,strategy?,,A
NS,-,Defined,objectives
Serious,security,incidents,typically,lead,to,renewed,focus,on,information,security,by,management.,To,BES
T,use,this,attention,,the,information,security,manager,should,make,the,case,for:,,ANS,-
,improving,integration,of,business,and,information,security,processes.
An,organization,has,recently,developed,and,approved,an,access,control,policy.,Which,of,the,following,will
,be,MOST,effective,in,communicating,the,access,control,policy,to,the,employees?,,ANS,-
,Requiring,employees,to,formally,acknowledge,receipt,of,the,policy
Which,of,the,following,requirements,would,have,the,LOWEST,level,of,priority,in,information,security?,,AN
S,-,Technical
Which,of,the,following,activities,MOST,commonly,falls,within,the,scope,of,an,information,security,govern
ance,steering,committee?,,ANS,-,Prioritizing,information,security,initiatives
Which,of,the,following,is,the,BEST,justification,to,convince,management,to,invest,in,an,information,securi
ty,program?,,ANS,-,Increased,business,value
Requirements,for,an,information,security,program,should,be,based,PRIMARILY,on,which,of,the,following,
choices?,,ANS,-,Desired,outcomes
Which,of,the,following,is,an,indicator,of,effective,governance?,,ANS,-
,An,established,risk,management,program
,Which,of,the,following,would,be,the,BEST,indicator,that,an,organization,has,good,governance?,,ANS,-
,Maturity,level
It,is,MOST,important,that,a,privacy,statement,on,a,company's,e-commerce,web,site,includes:,,ANS,-
,a,statement,regarding,what,the,company,will,do,with,the,information,it,collects.
Which,of,the,following,is,the,GREATEST,security,concern,when,an,incident,log,is,stored,on,the,production,
database,server?,,ANS,-,The,database,administrator,may,tamper,with,the,log,information.
Which,of,the,following,roles,is,responsible,for,ensuring,that,information,is,classified?,,ANS,-
,The,data,owner
What,is,the,PRIMARY,basis,for,the,selection,of,controls,and,countermeasures?,,ANS,-,Cost-benefit,balance
Which,of,the,following,is,the,MOST,usable,deliverable,of,an,information,security,risk,analysis?,,ANS,-
,List,of,action,items,to,mitigate,risk
Objectives,for,preventive,controls,should,be,developed,PRIMARILY,on,the,basis,of:,,ANS,-
,risk,levels,aligned,with,the,enterprise,risk,appetite.
Controls,are,effective,when:,,ANS,-,residual,risk,is,at,a,level,acceptable,to,the,organization.
Which,of,the,following,is,the,FIRST,action,to,be,taken,when,the,information,security,manager,notes,that,t
he,controls,for,a,critical,application,are,inadequate?,,ANS,-
,Perform,a,risk,assessment,to,determine,the,level,of,exposure.
The,assessment,of,risk,is,always,subjective.,To,improve,accuracy,,which,of,the,following,is,the,MOST,impo
rtant,action,to,take?,,ANS,-,Train,or,calibrate,the,assessor.
Which,of,the,following,choices,is,MOST,likely,to,achieve,cost-
effective,risk,mitigation,across,the,organization?,,ANS,-,Assurance,process,integration
, A,control,policy,is,MOST,likely,to,address,which,of,the,following,implementation,requirements?,,ANS,-
,Failure,modes
Who,should,be,responsible,for,enforcing,access,rights,to,application,data?,,ANS,-,Security,administrators
The,MOST,important,reason,that,statistical,anomaly-
based,intrusion,detection,systems,(stat,IDSs),are,less,commonly,used,than,signature-
based,IDSs,,is,that,stat,IDSs:,,ANS,-,generate,false,alarms,from,varying,user,or,system,actions.
For,virtual,private,network,access,to,the,corporate,network,,the,infonnation,security,manager,is,requiring
,strong,authentication.,Which,of,the,following,is,the,strongest,method,to,ensure,that,logging,onto,the,net
work,is,secure?,,ANS,-,Two-factor,authentication
What,is,a,desirable,sensitivity,setting,for,a,biometric,access,control,system,that,protects,a,high-
security,data,center?,,ANS,-,A,high,false,reject,rate
What,is,the,MAIN,advantage,of,implementing,automated,password,synchronization?,,ANS,-
,It,reduces,overall,administrative,workload.
Which,of,the,following,choices,is,the,WEAKEST,link,in,the,authorized,user,registration,process?,,ANS,-
,The,registration,authority's,private,key
When,designing,an,intrusion,detection,system,,the,information,security,manager,should,recommend,that
,it,be,placed:,,ANS,-,on,a,screened,subnet.
Which,of,the,following,BEST,accomplishes,secure,customer,use,of,an,e-commerce,application?,,ANS,-
,Data,encryption
Why,is,it,important,to,develop,an,information,security,baseline?,The,security,baseline,helps,define:,,ANS,-
,the,minimum,acceptable,security,to,be,implemented.
Which,of,the,following,is,the,MOST,important,element,to,ensure,the,success,of,a,disaster,recovery,test,at,
a,vendor-provided,hot,site?,,ANS,-,Business,management,actively,participates.