Information Security Management Examination (SG) | Section A Security Properties and Design Principles Questions 07
Problem 1
A user connecting to a remote maintenance portal is authenticated as the registered maintenance technician they claim to be. Which information security property is directly established by this verification?
View explanation
Authenticity is the property that an entity, such as a user or system, is what it claims to be. Here, authentication verifies whether the person connecting is the registered technician they claim to be. Availability concerns being usable when required, while confidentiality concerns preventing disclosure to unauthorized entities.
Problem 2
An electronic purchasing system must retain evidence proving both an approval action and its approver in case the approver later claims, "I did not approve that order." Which property is the system primarily seeking to establish?
View explanation
Non-repudiation is the ability to prove that a claimed event or action occurred and which entity caused it. A signature or audit trail that links the approver to the approval and makes tampering detectable serves this purpose. Merely keeping the system running concerns availability, not proof of the approval action.
Problem 3
An inventory calculation system intermittently returns different totals for the same process even though its input data has not changed. Which property is most directly impaired?
View explanation
Reliability is the property of consistent intended behavior and results. Irregular results from the same valid input show that the system is not performing its intended calculation consistently. Being able to connect to the system does not by itself establish the reliability of its results.
Problem 4
A monitoring system detects one connection from an internal PC to an external server. It may be a false positive, and no harm is yet known. Which initial organizational response is most appropriate?
View explanation
An alert is an information security event indicating a possible breach or control failure; it is not automatically a major incident. The organization should assess related evidence and impact under its criteria to determine whether the event could harm assets and therefore constitutes an incident. Deleting it without review could eliminate an important opportunity to investigate.
Problem 5
An organization is reviewing its controls on the assumption that a targeted email may bypass the email gateway and its attachment may run on an employee PC. Which architecture best reflects defense in depth?
View explanation
Defense in depth assumes that one control may fail and combines controls at different layers, including the perimeter, endpoints, internal network, critical information, detection, and response. Even a stronger email gateway may be bypassed, so layers are also needed to limit execution, lateral movement, and data theft afterward.
Problem 6
A company is developing a new customer-facing cloud service. Which plan most appropriately applies security by design?
View explanation
Security by design analyzes threats early in planning and design and incorporates the necessary controls into requirements and architecture. Carrying the results into development, testing, and operations reduces omissions and costly redesign caused by adding controls later. A final vulnerability scan can be useful, but it is not a substitute for design-stage work.
Problem 7
A new smartphone app is planned to collect users' precise location continuously. Which action best reflects privacy by design?
View explanation
Privacy by design incorporates protection of individuals' rights and interests from the design stage of a personal-data activity. Before collecting location data, the organization should assess purpose, necessity, minimization, retention, access, and impact, then build the results into the feature and its operation. A long consent notice alone does not remove the risks of unnecessary collection or excessive retention.
Problem 8
Without following the IT department's approval process, the sales department subscribes to free online storage under an employee's personal account and stores customer documents there. Which assessment and response is most appropriate?
View explanation
A cloud service independently used by a department without the organization's normal introduction and approval process is shadow IT. The organization should identify the data, sharing scope, contract, and settings, assess risk, and move safely to an approved environment when necessary. Preventing recurrence also requires an evaluation and request path that can meet legitimate business needs.
Problem 9
An employee handling customer data has financial pressure, rationalizes misconduct because of dissatisfaction with the company, and also has download privileges beyond their duties with little monitoring. Which control most directly reduces "opportunity" in the fraud triangle?
View explanation
Excessive privileges, unrestricted export paths, and weak monitoring increase the opportunity to commit and conceal misconduct. Least privilege, export approval, and log monitoring directly reduce that opportunity. Support for personal pressure may address motivation, while communication of rules may address rationalization, but neither is the direct opportunity control asked for here.
Problem 10
An organization affected by ransomware restores its systems from offline backups. However, the attacker claims to have exfiltrated customer data during the intrusion. Which response is most appropriate in light of double extortion?
View explanation
Double extortion combines disruption through encryption with a threat to publish stolen data. Backups support recovery and availability, but they do not erase data already obtained by an attacker. The organization must investigate the intrusion path, outbound transfer, and affected data, then assess the impact and any reporting or individual-notification duties under applicable law and contracts.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Security Fundamentals 01
- Information Security Management Examination (SG) | Section A Threats and Attack Techniques 02
- Information Security Management Examination (SG) | Section A Cryptography, Authentication and Controls 03
- Information Security Management Examination (SG) | Section A Security Management and Law 04
- Information Security Management Examination (SG) | Section A Risk and Access Management 05
- Information Security Management Examination (SG) | Section A Attack Mitigation and Business Continuity 06