Study sets
English

Information Security Management Examination (SG) | Section A ISMS, Information Assets, and Business Continuity Questions 09

1 / 100.0s

Problem 1

Controls against data removal using unauthorized USB drives are classified by their primary function as preventive, detective, or corrective. Which classification is most appropriate?

View explanation

A technical control that blocks a connection is preventive because it seeks to stop the event. An alert is detective because it reports that a connection occurred, while restoring an altered system to its approved configuration is corrective. A product may have several functions, but this question classifies each control by the primary function described.

Problem 2

An organization is planning an internal audit of its access-rights management process. Employee A, who designed and operates the process, is proposed as an auditor. Which arrangement best preserves audit objectivity?

View explanation

An internal audit requires auditors who can evaluate the subject objectively and impartially, with suitable independence from the work being audited. Employee A can provide expertise, evidence, and explanations, but auditing a process that A designed and operates would be self-review. Using another auditor does not remove the need for defined criteria, scope, and evidence-based conclusions.

Problem 3

Top management is conducting a periodic ISMS management review. Which approach is most appropriate?

View explanation

A management review enables top management to judge the ISMS's continuing suitability and effectiveness. Audit and measurement results, nonconformities, objective achievement, risk assessment and treatment, and stakeholder or environmental changes support decisions about improvement, change, and resources. Merely receiving an audit report does not produce the management decisions expected from the review.

Problem 4

An audit finds that several departments use a shared administrator ID. After temporarily disabling the ID, which corrective action is most appropriate for preventing recurrence?

View explanation

Temporarily disabling the ID corrects the observed condition, but another shared ID may appear if the cause remains. Analyzing the access-request and provisioning process, moving to individual IDs, checking for similar cases, and reviewing effectiveness addresses recurrence. Renaming the account or issuing a warning alone leaves the mechanism that enabled sharing unchanged.

Problem 5

A business server is moved to another site, and both its responsible owner and network configuration change. The information asset register still contains its purchase-time information. Which asset-management response is most appropriate?

View explanation

An asset register is not merely a purchase list; it is a management record used to track an asset's location, owner, configuration, transfer, and disposal. If it does not match reality, contacts and scope may be misidentified during an outage or incident. Personal notes lack shared governance and continuity and do not replace an official register update.

Problem 6

An organization wants to measure the effectiveness of a control requiring analysts to review and address critical alerts within a deadline. Which metric and measurement method is most appropriate?

View explanation

The control's objective is timely review and response to important indicators, not production of large volumes of logs. Consistently measuring on-time review, backlog, and outcomes produces comparable results that can reveal causes of delay and the effects of improvement. Attendance hours or log volume alone do not show whether required reviews occurred.

Problem 7

System administrators can freely stop or delete the logs of their own actions stored on a business server. Which improvement best strengthens accountability?

View explanation

If administrators can erase records of their own actions, traceability and evidential value are weakened. A separate append-only repository, segregated privileges, and monitoring for logging stoppage, alteration, or storage exhaustion reduce deletion and overwrite risk. Giving deletion rights to all administrators would make attribution even more difficult.

Problem 8

During a timeline analysis, the authentication server, web server, and endpoint logs are found to differ by as much as 12 minutes, so the order of actions cannot be established. Which prevention measure is most appropriate?

View explanation

Correlating records across systems requires their clocks to be synchronized to a common trusted time source. Monitoring drift and time zones also supports anomaly detection and correction of existing timelines. File creation order alone cannot establish the precise sequence of authentication, network, and endpoint actions on different systems.

Problem 9

A disaster disables the normal approval system, and an organization plans to continue critical payment processing manually. Which approach best maintains information security during the disruption?

View explanation

Business continuity is not only about keeping work moving; it must also preserve the required level of information security during disruption. If normal controls are unavailable, compensating controls such as alternative authentication, segregation of duties, sequential records, and secure storage should be planned and tested. Without transaction evidence, reconciliation and detection of error or fraud after recovery become difficult.

Problem 10

The official procedure for securely sharing large files is unusable in actual operations, and employees repeatedly turn to unapproved services. Which continual-improvement response is most appropriate?

View explanation

Repeated violations call for examining not only awareness but also whether the rules can support legitimate business needs. A workable, approved process that preserves the security objective and is reflected in rules and training addresses a cause of shadow IT. Unrestricted use abandons risk management, while verbal department rules undermine consistency and auditability.