1. A security officer is conducting a lessons learned meeting. Which of the following components of that meeting should be? (Choose two).(Select 2answers)
A) Demonstration of IPS system B) Assigning the follow up items C) Review vendor selection process D) Discussion of event timeline E) Calculate the ALE for the event
2. A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that can not comply with this policy. One system will be upgraded in six months, and two are not expected to be improved or removed from the network. Which of the following processes should be followed?
A) Poses a risk matrix B) Provide a business justification for an exemption risk C) Provide a business justification to avoid the risk D) None E) Inheriting the risk for six months
3. An organization is selecting a SaaS provider to replace its legacy too, in the house of Customer Resource Management (CRM) application. Which of the following will ensure that the organization reduces the risk of managing separate user data?
A) Concerns SaaS supports sending and storing encrypted password. B) Make sure that the SaaS provider supports dual-factor authentication. C) Make sure that the SaaS provider supports directory services federation. D) Make sure that the SaaS provider supports role-based access control. E) Make sure that the SaaS provider supports secure hash file sharing.
4. Which of the following provides the best risk calculation methodology?
A) Annual Loss Expectancy (ALE) x Value of Asset B) None C) Impact x Threat x Vulnerability D) Risk Probability x Annual damage expectation (ALE) E) Potential Event Probability x Loss X control failure risk
5. An organization engages in potential data loss in the event of a disaster, and created a backup data center as a mitigation strategy. The current method of storage is a NAS by all servers in two data centers. Which of the following increases data availability in the event of a data center failure?
A) Set up a SAN that replicates between data centers. B) Adopt deduplication at various storage paths. C) Replicate NAS changes in the tape backups at the other data center. D) None E) Ensure each server has two HBAs connected via two routes to the NAS.
Leave a comment