Lecture 11 - Security management
questions n answers passed
What is the primary goal of IT security management?
a.
To ensure regulatory compliance.
b.
To implement user training programs.
c.
To answer what assets need to be protected, how they are threatened, and what can be done to
counter those threats.
d.
To deploy the most advanced security technologies. - correct answer ✔✔ c
What is the role of a security officer (or CISO) in IT management?
a.
To handle security incidents.
b.
Solely to implement technical security measures.
c.
To provide overall supervision and liaison with senior management.
d.
To manage financial aspects of IT security. - correct answer ✔✔ a - c
What does a 'Baseline Approach' to risk management typically involve?
,a.
Implementing industry best practices to counter common threats.
b.
Detailed risk analysis of all systems.
c.
Avoiding activities that generate risks.
d.
Sharing risk responsibility with a third party. - correct answer ✔✔ a.
In the context of IT security, what does the term 'Asset' refer to?
a.
Just the physical components of an IT infrastructure.
b.
Policies and procedures related to security.
c.
Any system resource or capability of value that requires protection.
d.
Only financial ressources of a company. - correct answer ✔✔ c.
What is the primary purpose of the NIST cybersecurity framework?
a.
To provide detailed technical instructions for IT professionals
b.
To give precise instructions to a company's CISO
c.
To aid organisations in expressing their management of cybersecurity at a high level
, d.
To offer a certification to cybersecurity experts - correct answer ✔✔ c.
What kind of threats may be identified in threat identification of IT security?
a.
Financial threats only
b.
Only external threats like hacking
c.
Solely internal threats like employees misconduct
d.
Natural and man-made threats, accidental or deliberate - correct answer ✔✔ d.
What approach to risk assessment is most sutable for large organizations with IT systems critical
to their business objectives?
a.
Combined approach
b.
Detailed risk analysis
c.
Baseline approach
d.
Informal approach - correct answer ✔✔ b.
Which of the following is not a risk treatment alternative?
a.
questions n answers passed
What is the primary goal of IT security management?
a.
To ensure regulatory compliance.
b.
To implement user training programs.
c.
To answer what assets need to be protected, how they are threatened, and what can be done to
counter those threats.
d.
To deploy the most advanced security technologies. - correct answer ✔✔ c
What is the role of a security officer (or CISO) in IT management?
a.
To handle security incidents.
b.
Solely to implement technical security measures.
c.
To provide overall supervision and liaison with senior management.
d.
To manage financial aspects of IT security. - correct answer ✔✔ a - c
What does a 'Baseline Approach' to risk management typically involve?
,a.
Implementing industry best practices to counter common threats.
b.
Detailed risk analysis of all systems.
c.
Avoiding activities that generate risks.
d.
Sharing risk responsibility with a third party. - correct answer ✔✔ a.
In the context of IT security, what does the term 'Asset' refer to?
a.
Just the physical components of an IT infrastructure.
b.
Policies and procedures related to security.
c.
Any system resource or capability of value that requires protection.
d.
Only financial ressources of a company. - correct answer ✔✔ c.
What is the primary purpose of the NIST cybersecurity framework?
a.
To provide detailed technical instructions for IT professionals
b.
To give precise instructions to a company's CISO
c.
To aid organisations in expressing their management of cybersecurity at a high level
, d.
To offer a certification to cybersecurity experts - correct answer ✔✔ c.
What kind of threats may be identified in threat identification of IT security?
a.
Financial threats only
b.
Only external threats like hacking
c.
Solely internal threats like employees misconduct
d.
Natural and man-made threats, accidental or deliberate - correct answer ✔✔ d.
What approach to risk assessment is most sutable for large organizations with IT systems critical
to their business objectives?
a.
Combined approach
b.
Detailed risk analysis
c.
Baseline approach
d.
Informal approach - correct answer ✔✔ b.
Which of the following is not a risk treatment alternative?
a.