Domain 5: Program Management & Oversight
15 questions · Instant feedback · 20% of the exam
A new security regulation was announced that will take effect next year. A company must comply with it to remain in business. Which of the following activities should the company perform next?
A gap analysis identifies the differences between the organization’s current state and the new regulatory requirements. This allows the company to create a clear roadmap to update policies and processes to achieve compliance.
After failing an audit twice, an organization has been ordered by a government regulatory agency to pay fines. Which of the following causes this action?
Non-compliance with regulatory standards is the reason for the fines, as the organization failed to meet the necessary requirements in their audits.
Prior to implementing a design change, the change must go through multiple steps to ensure that it does not cause any security issues. Which of the following is most likely to be one of those steps?
A management review evaluates proposed changes against organizational security policies and risk appetite. It involves stakeholders assessing how the change aligns with compliance requirements. This step prevents unauthorized or risky modifications before technical implementation.
Which of the following techniques can be used to sanitize the data contained on a hard drive while allowing for the hard drive to be repurposed?
A wipe tool is used to sanitize a hard drive by securely erasing the data, allowing the drive to be repurposed.
The Chief Information Security Officer (CISO) has determined the company is not compliant with local data privacy regulations. The CISO needs to justify the budget request for more resources. Which of the following should the CISO present to the board as the direct consequence of non-compliance?
Fines are the direct financial consequence of non-compliance with data privacy regulations.
A company is aware of a given security risk and chooses not to accept responsibility. Which of the following best describes this risk mitigation strategy?
Risk transfer involves shifting the responsibility for a risk to a third party, such as purchasing insurance.
A new employee accessed an unauthorized website. An investigation found that the employee violated the company's rules. Which of the following did the employee violate?
An AUP (Acceptable Use Policy) outlines the acceptable usage of company resources and prohibits access to unauthorized websites.
Which of the following is a reason to perform a one-time risk assessment?
A one-time risk assessment is often conducted when a major change occurs—such as retiring or decommissioning an application—to understand the residual risk and inform disposal or migration plans.
Which of the following describes the agreement between a company and a client about what will be provided and the accepted time needed to provide the company with the resources?
An SLA (Service Level Agreement) outlines the level of service a company will provide, including time frames for deliverables.
A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?
Data classification is the process of assigning labels or tags to data based on its sensitivity, value, and risk. It helps to identify what data needs to be protected and how. The administrator should first apply classifications to the data to define policies and rules for the DLP solution.
Which of the following is a qualitative approach to risk analysis?
Assigning risks as high, medium, or low is a qualitative technique that relies on expert judgment rather than numerical metrics. It enables quick categorization of risks based on perceived impact and likelihood. This method is especially useful when precise data is unavailable.
Which of the following is the best reason to perform a tabletop exercise?
A tabletop exercise helps update the Incident Response Plan (IRP) by simulating real-world scenarios to prepare for potential threats.
Which of the following allows a systems administrator to tune permissions for a file?
Access Control Lists (ACLs) enable precise configuration of which users or groups can read, write, or execute specific files. They are the standard mechanism for granular permission management at the filesystem level.
Which of the following aspects of the data management life cycle is most directly impacted by local and international regulations?
Regulations often specify how long particular data types must be retained. Data retention policies ensure compliance with these legal timeframes.
A company is required to use certified hardware when building networks. Which of the following best addresses the risks associated with procuring counterfeit hardware?
A thorough analysis of the supply chain helps ensure hardware authenticity and reduces the risk of counterfeit products.
Quiz Complete!
Domain 5: Program Management & Oversight