1. Which of the following would BEST provide an information security manager with sufficient assurance that a service provider complies with organization's information security requirements?
A) A live demonstration of the third-party supplier's security capabilities B) Third-party security control self-assessment results C) An independent review report indicating compliance with industry standards D) The ability to audit the third-party supplier's IT systems and processes
2. A design company has multiple name and address file for its customers in several of its independent systems. Which of the following is the BEST control to ensure that the customer name and address agree across all files?
A) Use of hash totals on customer records B) Periodic review of each master file by management C) Matching of records and review of exception reports D) Use of authorized master file change forms
3. An employee who denies accusations of sending inappropriate images to other employees has been discharged. For evidential purposes, the mail database for the discharged employee's computer should be:
A) deleted as it could subject the organization to further legal liability B) impounded by physically removing the disk drive C) backed up to the server, where its access can be tightly restricted D) copied to write-once, read-many media using the computer's OS tools
4. Which of the following is MOST important for an organization to complete when planning a new marketing platform that targets advertising based on customer behavior?
A) Data privacy impact assessment B) Data quality assessment C) Cross-border data transfer assessment D) Security vulnerability assessment
5. A company converted its payroll system from an external service to an internal package. Payroll processing in April was run in parallel. To validate the completeness of data after the conversion, which of the following comparisons from the old to the new system would be MOST effective?
A) Turnaround time for payroll processing B) Employee counts and year-to-date payroll totals C) Master file employee data to payroll journals D) Cut-off dates and overwrites for a sample of employees
Leave a comment