上海信息化培训中心CISM 模拟题倾情奉献,让你小试牛刀
cisa吧
全部回复
仅看楼主
level 4
上海信息化培训中心CISM 模拟题倾情奉献,让你小试牛刀
1、privacy statement on a company’s e-commerce web site should include:
A. a statement regarding what the company will do with the information it collects.
B. a disclaimer regarding the accuracy of information on its web site.
C. technical information regarding how information is protected.
D. a statement regarding where the information is being hosted.
Answer:A
Explanation: Most privacy laws and regulations require disclosure on how information will be used. A disclaimer is not necessary since it does not refer to data privacy. Technical details regarding how information is protected are not mandatory to publish on the web site and in fact would not be desirable. It is not mandatory to say where information is being hosted.
2、Phishing is BEST mitigated by which of the following?
A. Security monitoring software
B. Encryption
C. Two-factor authentication
D. User awareness
Answer:D
Explanation: Phishing is a type of electronic mail (email) attack that attempts to convince a user that the originator is genuine, but with the intention of obtaining information for use in social engineering. It can best be mitigated by appropriate user awareness. Security monitoring software would provide some protection, but would not be as effective as user awareness. Encryption and two-factor authentication would not mitigate this threat
3、Which of the following do security policies need to be MOST closely aligned with?
A. Industry best practices
B. Organizational needs
C. Generally accepted standards
D. Local laws and regulations
Answer:B
Explanation: The needs of the organization should always take precedence. Best practices and local regulations are important, but they do not take into account the total needs of an organization.
4、When an information security manager is developing a strategic plan for information security, the timeline for the plan should be:
A. aligned with the IT strategic plan.
B. based on the current rate of technological change.
C. three-to-five years for both hardware and software.
D. aligned with the business strategy.
Answer:D
Explanation: Any planning for information security should be properly aligned with the needs of the business.Technology should not come before the needs of the business, nor should planning be done on an artificial timetable that ignores business needs.
5、What responsibility do data owners normally have?
A. Applying emergency changes to application data
B. Administering security over database records
C. Migrating application code changes to production
D. Determining the level of application security required
Answer:D
Explanation: Data owners approve access to data and determine the degree of protection that should be applied (data classification). Administering database security, making emergency changes to data and migrating code to production are infrastructure tasks performed by custodians of the data.
2016年09月27日 08点09分 1
1