ED
OV
PR
AP
?_
IA
UV
ST
, TABLE OF CONTENTS
Test Bank: Management of Cybersecurity, 7th Edition
Authors: Michael Whitman, Herbert Mattord
ST
Chapter 1. Introduction to the Management of Cybersecurity
Chapter 2. Governance and Strategic Planning for Cybersecurity
UV
Chapter 3. Risk Management: Assessing Risk
Chapter 4. Risk Management: Treating Risk
Chapter 5. Compliance: Law and Ethics
IA
Chapter 6. Cybersecurity Policy
Chapter 7. Developing the Cybersecurity Program
Chapter 8. Cybersecurity Management Models
?_
Chapter 9. Cybersecurity Management Practices
Chapter 10. Planning for Contingencies
AP
Chapter 11. Cybersecurity Maintenance
Chapter 12. Cybersecurity Protection Mechanisms
PR
OV
ED
? ?
,Chapter 01 - Introduction
1. Which statement best supports who has cybersecurity responsibility in the company? (Choose all that apply.)
a. Cybersecurity is the responsibility of a small dedicated group of professionals in the company.
ST
b. Cybersecurity is the responsibility of employees.
c. Cybersecurity is the responsibility of an employee's family.
d. Cybersecurity is the responsibility of the managers in the company.
UV
ANSWER: a, b, d
2. Which of the following statements is correct?
a. The primary focus of cybersecurity is protecting information assets.
IA
b. The primary focus of cybersecurity is protecting physical assets.
c. The primary focus of cybersecurity is monitoring network traffic.
d. The primary focus of cybersecurity is securing computing devices.
?_
ANSWER: a
3. What characteristic of the CIA triad is concerned with preventing unauthorized access to data?
AP
a. confidentiality
b. integrity
c. availability
PR
d. authenticity
ANSWER: a
4. What characteristic of the CIA triad is concerned with ensuring the data is accurate and valid?
OV
a. confidentiality
b. integrity
c. availability
ED
d. authenticity
ANSWER: b
??
, Chapter 01 - Introduction
5. Which characteristic of the CIA triad should you prioritize when implementing a backup system to recover data in
the event of a disaster?
a. confidentiality
ST
b. integrity
c. availability
d. authentication
UV
ANSWER: c
6. Tom is tasked with ensuring that the company's database remains available to users even during a hardware failure.
Which of the following actions should Tom take to achieve this, focusing on the appropriate CIA triad attribute of
IA
availability?
a. Encrypt the database to prevent unauthorized access.
?_
b. Implement RAID (Redundant Array of Independent Disks) to protect against data loss.
c. Apply checksums and hashing algorithms to verify data integrity.
d. Set up multi-factor authentication for accessing the database.
AP
ANSWER: b
7. Mary is configuring user access controls in Microsoft Active Directory to ensure that only authorized personnel can
access sensitive data. Which specific action should Mary take to address the appropriate CIA triad attribute of
PR
confidentiality?
a. Set up user permissions to limit access to confidential files.
b. Schedule regular backups to ensure data recovery.
OV
c. Implement checksums to verify data accuracy.
d. Enable logging to track user activities.
ANSWER: a
ED
8. An organization wants to ensure that their data remains accessible even if a disk fails. Which action should they
take to address the appropriate CIA triad attribute of availability?
a. Encrypt all sensitive data stored on the disks.
??
b. Implement a RAID (Redundant Array of Independent Disks) system.
c. Use digital signatures to verify data authenticity.
d. Set up detailed logging and monitoring.
ANSWER: b