Information Security Management Examination (SG) | Section A Security Fundamentals 01
Problem 1 ・ Question 1 / 10
Which event damages the confidentiality of information?
View explanation
Confidentiality is the property that only those permitted can access the information.
Problem 1 ・ Question 2 / 10
Which measure helps ensure the integrity of information?
View explanation
Integrity is the property that information is accurate and complete and has not been altered without authorisation.
Problem 1 ・ Question 3 / 10
Which measure improves the availability of information?
View explanation
Redundancy makes it easier to keep the service running even when part of it fails.
Problem 1 ・ Question 4 / 10
Which combination makes up risk?
View explanation
Risk is assessed by considering the impact if a threat exploits a vulnerability.
Problem 1 ・ Question 5 / 10
What is the main purpose of compiling an inventory of information assets?
View explanation
Knowing where assets are, who manages them and how important they are is the basis of proper management.
Problem 1 ・ Question 6 / 10
Which risk response is taking out cyber insurance?
View explanation
Passing part of the loss to an insurer through a policy is risk transfer.
Problem 1 ・ Question 7 / 10
In a risk assessment, which risk remains after countermeasures are taken?
View explanation
The risk left after controls have been implemented is called residual risk.
Problem 1 ・ Question 8 / 10
Which is the most appropriate reason for management to approve the information security policy?
View explanation
The policy sets the direction of the organisation, so it needs management's involvement and approval.
Problem 1 ・ Question 9 / 10
Which is an example of applying the principle of least privilege?
View explanation
Limiting access rights to the minimum needed keeps down the impact of fraud and mistakes.
Problem 1 ・ Question 10 / 10
What is the main purpose of separation of duties?
View explanation
Assigning tasks such as requesting and approving to different people creates mutual checks.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Cryptography, Authentication and Controls 03
- Information Security Management Examination (SG) | Section A Security Management and Law 04
- Information Security Management Examination (SG) | Section A Risk and Access Management 05
- Information Security Management Examination (SG) | Section A Attack Mitigation and Business Continuity 06
- Information Security Management Examination (SG) | Section A Security Properties and Design Principles Questions 07
- Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08