Domain 5: Program Management & Oversight
15 questions · Instant feedback · 20% of the exam
Which of the following factors are the most important to address when formulating a training curriculum plan for a security awareness program? (Select two).
When creating a security awareness training plan, the cadence and duration of training events and threat vectors based on the industry are most important. The cadence and duration ensure effective learning, while considering industry-specific threats tailors the training to relevant risks.
An organization is required to provide assurance that its controls are properly designed and operating effectively. Which of the following reports will best achieve the objective?
An independent audit provides assurance that security controls are properly designed and operating effectively, meeting compliance and regulatory requirements.
Which of the following objectives is best achieved by a tabletop exercise?
Tabletop exercises are designed to familiarize participants with incident response processes through discussion and scenario analysis.
An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server's password. The employee used this access to remove the mailboxes of key personnel. Which of the following security awareness concepts would help prevent this threat in the future?
Recognizing phishing is essential to preventing malicious activities like this, where a malicious link tricks an employee into making harmful changes.
Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?
Risk identification is the first step in the risk management process, where the scope and potential risks of a project are determined.
Due to a cyberattack, a company's IT systems were not operational for an extended period of time. The company wants to measure how quickly the systems must be restored in order to minimize business disruption. Which of the following would the company most likely use?
The Recovery Time Objective (RTO) measures how quickly the systems must be restored to minimize business disruption.
Which of the following is the most relevant reason a DPO would develop a data inventory?
A Data Protection Officer (DPO) develops a data inventory primarily to understand where data is stored and how it can be impacted in the event of a data breach.
An organization is implementing a COPE mobile device management policy. Which of the following should the organization include in the COPE policy? (Choose two.)
Remote wiping of the device and data encryption are essential in a COPE (Corporate Owned, Personally Enabled) policy to protect company data on mobile devices.
Which of the following is a directive managerial control?
An Acceptable Use Policy (AUP) sets rules and guidelines for employee behavior. It’s a managerial control because it directs how resources should be used.
Which of the following best ensures minimal downtime and data loss for servers located in geographically diverse areas?
Off-site replication maintains copies of data in a geographically separate location. This ensures minimal downtime and data loss in case of a disaster or outage at the primary site, as operations can be quickly switched to the replica.
A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?
The risk appetite defines the amount of risk an organization is willing to take before granting access to sensitive systems or data.
A new security regulation was announced that will take effect next year. A company must comply with it to remain in business. Which of the following activities should the company perform next?
A gap analysis identifies the differences between the organization’s current state and the new regulatory requirements. This allows the company to create a clear roadmap to update policies and processes to achieve compliance.
Several employees download a productivity program that is useful but also leaks contact information and corporate organizational structure details. Which of the following is the best way to prevent this issue?
An application allow list ensures only pre-approved software can be installed or run, blocking any unvetted programs. This control prevents the use of unauthorized tools that might exfiltrate data or introduce vulnerabilities.
A company’s security team is reviewing its business continuity plan and must determine the amount of time needed for operations to resume after a disaster. Which of the following describes the time frame the security team is trying to determine?
The Recovery Time Objective (RTO) defines the maximum acceptable duration of downtime before critical services must be restored. It guides planning for system availability and resource allocation.
A company is concerned with supply chain compromise of new servers and wants to limit this risk. Which of the following should the company review first?
Reviewing the acquisition process ensures that hardware is sourced from trusted vendors with proper verification and attestation. Securing the supply chain begins at procurement to prevent counterfeit or tampered devices from entering the environment.
Quiz Complete!
Domain 5: Program Management & Oversight