PREGUNTA 1 de 20
113. Which audit should be done to address the concern about the length of time the service provider has been in business?
βͺ
A)
SOC2
βͺ
B)
SOC1
βͺ
C)
SOC3
βͺ
D)
Noneoftheabove
PREGUNTA 2 de 20
114. What audit should be done to provide assurance about the availability and confidentiality of the service provider?
βͺ
A)
SOC1
βͺ
B)
SOC2
βͺ
C)
SOC3
βͺ
D)
SOC4
PREGUNTA 3 de 20
115. What type of audit should be done on the service provider?
βͺ
A)
Type I
βͺ
B)
Type II
βͺ
C)
Type III
βͺ
D)
Type IV
PREGUNTA 4 de 20
116. Which trust services principles are most appropriate for the auditor to focus on?
βͺ
A)
Confidentiality and availability
βͺ
B)
Processing integrity and privacy
βͺ
C)
Privacy and confidentiality
βͺ
D)
Security and processing integrity
PREGUNTA 5 de 20
117. List examples of security awareness sources for an awareness program.
βͺ
A)
Job skills development
βͺ
B)
Posters with reminders to change password
βͺ
C)
Procedures to test a system
βͺ
D)
Accreditation of a tested system
PREGUNTA 6 de 20
118. What control is specified in ISO 27002 concerning test data?
βͺ
A)
Test should not be done in production environments
βͺ
B)
Test data are always a clear path to test schemes
βͺ
C)
Test data are necessary in DevOps
βͺ
D)
Test data should avoid containing personally identifiable information(PII)
PREGUNTA 7 de 20
119. Third-party assessments are ________
βͺ
A)
Too costly
βͺ
B)
Slow and ineffective
βͺ
C)
Driven by some regulations
βͺ
D)
Always necessary.
PREGUNTA 8 de 20
120. What is the primary purpose of a negative test?
βͺ
A)
To verify the operating power of a system
βͺ
B)
To ensure graceful handling of unexpected input
βͺ
C)
Reconcile the identity proofing process
βͺ
D)
Allow disparate organizations to share resources
PREGUNTA 9 de 20
121. Interface testing can be used to __________
βͺ
A)
Check and verify if all the interactions between the application and a server are executed properly
βͺ
B)
Check the connections between fail-safe and fail-secure
βͺ
C)
Run test in a loop till errors are made evident.
βͺ
D)
none of the above
PREGUNTA 10 de 20
122. Once code inspection is complete, what kind of software testing occurs?
βͺ
A)
User acceptance testing
βͺ
B)
Business case testing
βͺ
C)
Unit level testing
βͺ
D)
Test sophistication
PREGUNTA 11 de 20
123. Which of the following terms is most associated with the concept of need-to-know?
βͺ
A)
Static testing
βͺ
B)
Social engineering
βͺ
C)
Compartmentalization
βͺ
D)
Non disclosure agreements
PREGUNTA 12 de 20
Which of the following is not true about privileged accounts?
βͺ
A)
Privileged account holders should be subject to more extensive background checks than regular account holders
βͺ
B)
They should be temporary.
βͺ
C)
They should be subject to more extensive auditing.
βͺ
D)
They should be granted only for remote access.
PREGUNTA 13 de 20
125. Which of the following is not a benefit the organization realized from job rotation?
βͺ
A)
Improved employee morale
βͺ
B)
Reduction in single points of failure in staffing
βͺ
C)
Elimination of the possibility of social engineering
βͺ
D)
Aids in detecting internal threats
PREGUNTA 14 de 20
126. In which phase of the information lifecycle is data moved from the production environment into long-term storage?
βͺ
A)
Create
βͺ
B)
Share
βͺ
C)
Store
βͺ
D)
Archive
PREGUNTA 15 de 20
127. What is usually the enforcement mechanism of a service-level agreement (SLA)?
βͺ
A)
Incarceration
βͺ
B)
Regulatory capture
βͺ
C)
Early withdrawal
βͺ
D)
Financial penalties
PREGUNTA 16 de 20
Which of the following is not typically reflected in the asset inventory?
βͺ
A)
The asset owner
βͺ
B)
The asset size
βͺ
C)
The asset location
βͺ
D)
The asset value
PREGUNTA 17 de 20
129. All of the following departments typically will be represented on the Change Management Board (CMB) except:
βͺ
A)
Sales/marketing
βͺ
B)
Accounting/finance
βͺ
C)
Security office
βͺ
D)
The user community
PREGUNTA 18 de 20
130. What should always be included in the patch process?
βͺ
A)
The option to roll back to the last known good system state
βͺ
B)
Contacting the patch issuer to seek clarification
βͺ
C)
Instant and immediate application of patches to all affected systems
βͺ
D)
Regulator notification
PREGUNTA 19 de 20
131_Patches should be tested ________.
βͺ
A)
daily
βͺ
B)
in a test bed that mimics the production environment
βͺ
C)
only on external, off-premise systems
βͺ
D)
in the jurisdiction in which they were issued
PREGUNTA 20 de 20
132._Which of the following is a preventative measure to counter the possibility of lost/stolen media?
βͺ
A)
Digital watermarking
βͺ
B)
Proper and thorough labeling
βͺ
C)
Online tracking mechanisms
βͺ
D)
Secure disposal
Este test aún no tiene comentarios π€