Which of the following should an information security manager do FIRST upon confirming a privileged user ' s unauthorized modifications to a security application?
Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
Which of the following is the MOST important detail to capture in an organization ' s risk register?
Which of the following is the BEST course of action if the business activity residual risk is lower than the acceptable risk level?
An internal audit has revealed that a number of information assets have been inappropriately classified. To correct the classifications, the remediation accountability should be assigned to:
Reviewing which of the following would be MOST helpful when a new information security manager is developing an information security strategy for a non-regulated organization?
Which of the following presents the GREATEST risk associated with the use of an automated security information and event management (SIEM) system?
Which of the following is MOST important for an information security manager to consider when identifying information security resource requirements?
Which of the following activities is MOST appropriate to conduct during the eradication phase of a cyber incident response?
Which of the following will BEST facilitate timely and effective incident response?
Which of the following would be MOST useful to help senior management understand the status of information security compliance?
When determining an acceptable risk level which of the following is the MOST important consideration?
Which of the following is the PRIMARY reason to monitor key risk indicators (KRIs) related to information security?
An experienced information security manager joins a new organization and begins by conducting an audit of all key IT processes. Which of the following findings about the vulnerability management program should be of GREATEST concern?
Which of the following is the MOST effective way to detect information security incidents?
Which of the following is the responsibility of a risk owner?
Which of the following is the MOST important reason for an organization to communicate to affected parties that a security incident has occurred?
Recovery time objectives (RTOs) are BEST determined by:
Which of the following is PRIMARILY influenced by a business impact analysis (BIA)?
Which of the following should be done NEXT following senior management ' s decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?
TESTED 09 Sep 2026