Tüm alıştırma soruları
2232 soru
An enterprise security analyst reviews metrics from the company's annual security awareness program. Over the past two quarters, employee click-through rates on simulated phishing emails dropped from 22% to 4%. However, the percentage of employees actively reporting suspicious emails to the security operations team remained unchanged at 3%. Which of the following human risk management strategies best addresses this gap to improve overall threat detection capabilities?
During a Business Impact Analysis (BIA), a financial institution determines that its online payment processing service can tolerate a maximum operational outage of 12 hours before experiencing severe regulatory penalties and irreparable financial loss. Technical teams estimate that restoring infrastructure takes 7 hours, and system integrity validation takes 3 hours. Which metric defines the overarching 12-hour limit of allowable operational downtime?
A chief information security officer (CISO) is shifting the organization's security awareness program from measuring basic compliance attendance to evaluating quantifiable human risk reduction. Which of the following metrics or strategies effectively measure behavioral change and operational human risk mitigation? (Select TWO.)
Geçerli olan tümünü seçin
A publicly traded enterprise is undergoing an annual IT compliance review. The audit team discovers that application developers who manage the accounting database also hold administrative permissions to modify audit logs and approve change tickets for financial reporting software. Which regulatory requirement is directly compromised by this access control configuration, and what control must be enforced to achieve compliance?
A telecommunications company based in the United States expands operations into the European Union and deploys a network analytics service that processes subscriber location data, personal contact details, and customer payment card numbers. Which of the following legal and regulatory compliance obligations apply to this service deployment? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is conducting a Business Impact Analysis (BIA) for a hospital system's critical Single Sign-On (SSO) and Patient Identity service. The assessment establishes that the system can tolerate a maximum data loss window of 15 minutes for active user session state logs, but the authentication service itself must be restored to full operation within 2 hours of an outage to prevent severe clinical delays. Which of the following statements correctly align these parameters with Business Continuity Management (BCM) metrics? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security operations team observes that standard annual security awareness lectures have been ineffective at stopping employees from uploading sensitive company documents to unapproved personal cloud storage services. To enhance their human risk management framework, the security team seeks to implement an operational solution that delivers immediate, context-aware microlearning prompts at the exact moment a risky file-transfer action is attempted. Which of the following approaches best meets this objective?
A U.S.-based healthcare software provider is migrating its web application infrastructure to a third-party public cloud vendor. The cloud vendor will host databases containing Protected Health Information (PHI). To ensure compliance with federal privacy regulations, which of the following legal instruments must the organization execute with the cloud vendor before transferring PHI to the platform?
A regional utility provider is updating its Business Continuity Plan (BCP) following an infrastructure audit of its smart grid control systems. The audit establishes that to prevent severe grid instability, data synchronization must be recovered to a state no older than 30 minutes prior to an outage. However, technical teams are given up to 8 hours to bring the secondary control server fully back online and operational. Which business continuity metric specifically defines this 30-minute parameter for data freshness?
An organization is updating its incident response playbooks to better integrate end-user security awareness reporting with human risk management oversight. Place the following operational steps in the correct chronological sequence from initial detection by an employee to the continuous improvement of the security awareness program.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise risk analyst is auditing international compliance requirements across multiple regional jurisdictions and sector-specific legal mandates. Match each regulatory framework or law on the left with its core scope and applicability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each business continuity testing methodology on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following a simulated security assessment, a company discovers that executive assistants frequently disclose sensitive internal scheduling information and bypass identity verification during unexpected phone calls from individuals impersonating C-suite executives. Which of the following strategies represents the most effective human risk management control to address this specific vulnerability?
An enterprise security team completes a Business Impact Analysis (BIA) for a SaaS-based customer billing platform. The assessment indicates that the organization can tolerate losing a maximum of 15 minutes of transaction data during a catastrophic database outage. However, restoring full system functionality and verifying data consistency must occur within 6 hours to avoid regulatory fines. Which of the following metrics represents the maximum allowable 15-minute data loss threshold?
A healthcare organization is auditing its data handling practices prior to migrating patient health records to a cloud service provider. Which of the following statements accurately describe operational duties of a data custodian and appropriate privacy preservation techniques for this migration? (Select TWO.)
Geçerli olan tümünü seçin
A multinational streaming entertainment company based in Brazil expands operations into the European Union and the United States. During an annual audit, the Chief Information Security Officer (CISO) reviews legal and compliance obligations for managing customer profiles and payment processing environments. Which of the following requirements must the organization implement to satisfy both GDPR and PCI-DSS compliance mandates? (Select TWO.)
Geçerli olan tümünü seçin
A global financial technology enterprise is updating its analytics warehouse architecture. To comply with privacy regulations while supporting data analysis, the database team replaces primary customer identifiers with cryptographic tokens. The original identifiers and corresponding tokens are stored in a separate, highly secured lookup table, allowing authorized compliance officers to re-identify records during formal legal investigations. Which of the following privacy-enhancing controls has the enterprise implemented?
An enterprise retail logistics company recently completed a Business Impact Analysis (BIA) for its centralized inventory management platform. The assessment established a Recovery Point Objective (RPO) of minutes, a Recovery Time Objective (RTO) of hours, and a Maximum Tolerable Downtime (MTD) of hours. Which of the following technical strategies directly support these established metrics? (Select TWO.)
Geçerli olan tümünü seçin
A financial technology software vendor based in Canada is expanding its cloud platform to process personal financial records for clients operating within the European Union. The vendor plans to implement an automated artificial intelligence algorithm to evaluate individual consumer creditworthiness. Which regulatory compliance requirement MUST the organization conduct prior to deploying this high-risk data processing system?
A biotechnology organization conducts a Business Impact Analysis (BIA) for its automated high-throughput compound screening database. The assessment establishes that losing more than 2 hours of experimental data will corrupt active testing models and cause significant financial loss. However, the business units determine they can tolerate a total service disruption of up to 12 hours before catastrophic operational failure occurs. Which of the following metric configurations accurately represents these BIA findings?