Questions and Answers rated A+
2025/2026
Which of the following is NOT a consideration for security professionals during mergers and
acquisitions?
A. new data types
B. new technology types
C. cost of the merger or acquisition
D. the other organization's security awareness training program - correct answer ✔C
Explanation: A security professional should not be concerned with the cost of a merger or an acquisition.
A security professional should only be concerned with issues that affect security and leave financial
issues to financial officers.
What is the first stage of the security program life cycle?
A. Plan and Organize
B. Implement
C. Operate and Maintain
D. Monitor and Evaluate - correct answer ✔A
Explanation: The four stages of the security program life cycle, in order, are as follows:
, 1. Plan and Organization
2. Implement
3. Operate and Maintain
4. Monitor and Evaluate
Which term indicates the monetary impact of each threat occurrence?
A. ARO
B. ALE
C. EF
D. SLE - correct answer ✔D
Explanation: SLE indicates the monetary impact of each threat occurrence. ARO is the estimate of how
often a given threat might occur annually. ALE is the expected risk factor of an annual threat event. EF is
the percent value or functionality of an asset that will be lost when a threat event occurs.
Which management officer implements and manages all aspects of security, including risk analysis,
security policies and procedures, training, and emerging technologies?
A. CPO
B. CFO
C. CSO
D. CIO - correct answer ✔Explanation: The chief security officer (CSO) is the officer that leads any
security effort and reports directly to the chief executive officer (CEO).