SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISM: Certified Information Security Manager
Start Test
Study First
Subjects
:
certifications
,
cism
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Programs that act without a user's knowledge and deliberately alter a computer's operations
Fault-tolerant computer
What happened and how the breach was resolved
The information security officer
MAL wear
2. From a security standpoint - _______________________ is one of the most important topics that should be included in the contract with third-party service provider.
3. The MOST important element of an information security strategy.
Rule-based access control
Annual loss expectancy (ALE)calculations
Conduct a risk assessment
Defined objectives
4. Program that copies itself repeatedly - using up resources and possibly shutting down the computer or network
Worm
Rule-based access control
Annually or whenever there is a significant change
Resource dependency assessment
5. It is important to achieve ____________________ - and obtain inputs from various organizational entities since security needs to be aligned to the needs of the organization.
All personnel
Consensus on risks and controls
Acceptable use policies
Security awareness training for all employees
6. A trusted third party that attests to the identity of the signatory - and reliance will be a function of the level of trust afforded the CA.
Compliance with the organization's information security requirements
Certificate authority (CA)
Trusted source
Equal error rate (EER)
7. Lists only the threats that the information asset is exposed to. It does not consider the value of the asset and impact of the threat on the value.
Normalization
Deeper level of analysis
Comparison of cost of achievement
Threat assessment
8. Focuses on identifying vulnerabilities.
Penetration testing
Data owners
Tie security risks to key business objectives
Applying the proper classification to the data
9. Logging as well as monitoring - measuring - auditing - detecting viruses and intrusion.
Threat assessment
MAL wear
Detection defenses
Fault-tolerant computer
10. The MOST useful way to describe the objectives in the information security strategy is through ______________________.
11. To identify known vulnerabilities based on common misconfigurations and missing updates.
A network vulnerability assessment
Security awareness training for all employees
Exceptions to policy
Transmit e-mail messages
12. Responsible for assigning user entitlements and approving access to the systems for which they are responsible.
Identify the relevant systems and processes
Data owners
BIA (Business Impact Assessment
Security baselines
13. Provide minimum recommended settings and do not prevent introduction of control weaknesses.'
Power surge/over voltage (spike)
Security baselines
Phishing
Applying the proper classification to the data
14. A key indicator of performance measurement.
Cryptographic secure sockets layer (SSL) implementations and short key lengths
Digital certificate
Spoofing attacks
Strategic alignment of security with business objectives
15. Lists only the vulnerabilities inherent in the information asset that can attract threats. It does not consider the value of the asset and the impact of perceived threats on the value.
Waterfall chart
Vulnerability assessment
Multinational organization
Service level agreements (SLAs)
16. The PRIMARY goal in developing an information security strategy is to: _________________________.
The database administrator
Impractical and is often cost-prohibitive
Developing an information security baseline
Support the business objectives of the organization
17. Legal document to be signed by all employees - suppliers etc before they 'touch' the organization - to protect the organization's intellectual property.
Comparison of cost of achievement
The data custodian
Nondisclosure agreement (NDA)
Resource dependency assessment
18. In order to highlight to management the importance of network security - the security manager should FIRST _______________.
Hacker
Do with the information it collects
Worm
Conduct a risk assessment
19. When considering the value of assets ______________________ would give the information security manager the MOST objective basis for measurement of value delivery in information security governance
The balanced scorecard
Comparison of cost of achievement
Access control matrix
Cryptographic secure sockets layer (SSL) implementations and short key lengths
20. The MOST important element of the request for proposal (RFP) ro assess the maturity level of the organization's information security management is _______________________.
Negotiating a local version of the organization standards
Methodology used in the assessment
The data custodian
Tailgating
21. A notice that guarantees a user or a web site is legitimate
Safeguards over keys
Digital certificate
Rule-based access control
Cross-site scripting attacks
22. When defining the information classification policy - the ___________________ need to be identified.
Requirements of the data owners
Well-defined roles and responsibilities
Calculating the value of the information or asset
Patch management
23. The most important characteristic of good security policies is that they be ____________________.
Audit objectives
Conduct a risk assessment
Aligned with organizational goals
Negotiating a local version of the organization standards
24. Any event or action that could cause a loss of or damage to computer hardware - software - data - information - or processing capability
Security risk
Proficiency testing
Patch management
Cyber extortionist
25. Someone who accesses a computer or network illegally
The board of directors and senior management
Spoofing attacks
Hacker
Trusted source
26. Provide metrics to which outsourcing firms can be held accountable.
Cyber extortionist
Support the business objectives of the organization
Service level agreements (SLAs)
Centralized structure
27. A repository of historical data organized by subject to support decision makers in the org
Data warehouse
SWOT analysis
Support the business objectives of the organization
Deeper level of analysis
28. When reporting an incident to senior management - the initial information to be communicated should include an explanation of _____________________ A summary of security logs would be too technical to report to senior management. An analysis of the i
Detection defenses
Tie security risks to key business objectives
What happened and how the breach was resolved
Single sign-on (SSO) product
29. Responsible for securing the information.
Use of security metrics
Properly aligned with business goals and objectives
Control effectiveness
The data custodian
30. An information security manager has to impress upon the human resources department the need for _____________________.
Risk assessment - evaluation and impact analysis
Security awareness training for all employees
Overall organizational structure
Well-defined roles and responsibilities
31. Inject malformed input.
Cross-site scripting attacks
Skills inventory
Baseline standard and then develop additional standards
Transferred risk
32. It is more efficient to establish a ___________________for locations that must meet specific requirements.
Stress testing
The balanced scorecard
Single sign-on (SSO) product
Baseline standard and then develop additional standards
33. Will prevent unauthorized access to the laptop even when the laptop is lost or stolen.
Creation of a business continuity plan
Return on security investment (ROSI)
Its ability to reduce or eliminate business risks
Encryption of the hard disks
34. Attackers who exploit flawed ___________________________________ can sniff network traffic and crack keys to gain unauthorized access to information.
Cryptographic secure sockets layer (SSL) implementations and short key lengths
The information security officer
Virus detection
Return on security investment (ROSI)
35. ecurity design flaws require a ____________________.
Digital certificate
Deeper level of analysis
Residual risk
Digital signatures
36. The first step in a risk analysis process to determine the impact to the organization - which is the ultimate goal.
Data owners
Overall organizational structure
Calculating the value of the information or asset
Inherent risk
37. The _____________________ should be the person with the decision-making power in the department deriving the most benefit from the asset.
Platform security - intrusion detection and antivirus controls
Asset classification
Owner of the information asset
Background check
38. An effective tool but primarily focuses on malicious code from external sources - and only for those applications that are online.
Residual risk
Strategic alignment of security with business objectives
Virus detection
Security risk
39. __________________________ is of utmost importance. Understanding business objectives is critical in determining the security needs of the organization.
Alignment with business strategy
Knowledge management
Exceptions to policy
Deeper level of analysis
40. Program that hides within or looks like a legit program
Retention of business records
Detection defenses
Defining and ratifying the classification structure of information assets
Trojan horse
41. The risk that has been assumed by a third party and may not necessarily be equal to the minimal form of residual risk.
Background check
Return on security investment (ROSI)
Data isolation
Transferred risk
42. Same intent as a cracker but does not have the technical skills and knowledge
Lack of change management
Role-based access control
Rule-based access control
Script kiddie
43. Useful but only with regard to specific technical skills.
Proficiency testing
Data mart
Security awareness training for all employees
Skills inventory
44. The MAIN reason why _______________ is important to a successful information security program is because classification determines the appropriate level of protection to the asset.
Conduct a risk assessment
Data warehouse
Acceptable use policies
Asset classification
45. Also required to guarantee fulfillment of laws and regulations of the organization and - therefore - the information security manager will be obligated to comply with the law.
Trusted source
Encryption
The authentication process is broken
Monitoring processes
46. Using public key infrastructure (PKI) is currently accepted as the most secure method to _____________.
Public key infrastructure (PKI)
Requirements of the data owners
Transmit e-mail messages
Resource dependency assessment
47. Information security governance models are highly dependent on the _____________________.
Malicious software and spyware
Normalization
Cyber extortionist
Overall organizational structure
48. S small warehouse - designed for the end-user needs in a strategic business unit
Data mart
Personal firewall
A network vulnerability assessment
Resource dependency assessment
49. provides the most effective protection of data on mobile devices.
Gain unauthorized access to applications
Encryption
Risk management and the requirements of the organization
Skills inventory
50. Provides process needs but not impact.
Resource dependency assessment
Return on security investment (ROSI)
Power surge/over voltage (spike)
The database administrator