01. A firm is outsourcing payroll to a SaaS provider that will handle sensitive employee data. The security manager wants to retain the ability to verify the provider's security controls throughout the relationship.
What should the manager MOST ensure is included in the contract?
a) A clause transferring all breach liability to the provider
b) A fixed monthly price with penalties for service downtime
c) A requirement that the provider use the same security tools as the firm
d) A right-to-audit clause or acceptance of independent assurance reports
02. Investigations after several policy violations reveal that employees routinely bypass security procedures because senior executives are seen doing the same and openly dismissing the controls.
Which approach would MOST effectively improve the organization's security culture?
a) Have senior leadership visibly follow and endorse the expected behaviors.
b) Increase the disciplinary penalties applied to employees who violate policy.
c) Send more frequent security awareness reminders to all staff.
d) Deploy technology that blocks the actions the policy prohibits.
03. Analysts at a company are overwhelmed by alerts from many disconnected security tools and have begun to miss genuine incidents. A vendor is pitching an additional platform to help.
Before buying more tooling, what should the manager do FIRST?
a) Procure a next-generation platform to consolidate and replace all current tools
b) Assess current processes and tune existing tools to cut alert noise
c) Hire additional analysts to handle the alert volume
d) Disable the noisiest tools to cut the number of alerts
04. Over two weeks, a utility company logs several minor, seemingly unrelated events: a brief VPN login from a new country, a small configuration change, and a short-lived new administrative account. Each was individually closed as benign.
What practice would BEST improve the organisation's ability to recognise a coordinated attack in such cases?
a) Correlating events across sources and time to reveal hidden patterns
b) Lowering the severity threshold so more events are escalated automatically
c) Requiring two analysts to review every individual alert before closing it
d) Increasing the retention period for raw security logs
05. Executives judge the security program mainly by the raw number of incidents reported, and staff have begun feeling pressure to under-report minor incidents. The manager wants reporting that drives the right behavior.
What is the BEST change to make?
a) Set a target of zero reported incidents for the coming year
b) Reward the security team for driving down the reported incident count each quarter
c) Stop reporting incident numbers to executives altogether
d) Report balanced outcome metrics such as detection and response times
06. Monitoring indicates that a trusted database administrator may be copying large volumes of customer records to a personal storage service. The evidence is preliminary, and the individual still has privileged access to production systems.
What is the security manager's BEST initial action?
a) Immediately confront the administrator to obtain an explanation for the activity
b) Publicly revoke the administrator's access so other staff understand the seriousness
c) Follow the insider-incident procedure to preserve evidence and contain risk
d) Continue monitoring silently and take no containment action until a full case is built
07. Following a widespread compromise, a bank has rebuilt affected servers from known-good images and patched the exploited flaw. Management asks the incident manager to confirm the environment is clean before closing the incident.
What would BEST support that confirmation?
a) A statement from the vendor that the patch fully resolves the vulnerability
b) Confirmation that all rebuilt servers are performing normally
c) A signed acknowledgement from system owners that recovery is complete
d) Enhanced monitoring for indicators of compromise over a defined period
08. Two candidate controls each reduce the same data-loss risk. One is a preventive control that is costly to deploy; the other is a detective control that is inexpensive. The security manager must recommend one.
What should MOST drive the selection between them?
a) Whichever control the organization's framework marks as mandatory.
b) The preventive control, because prevention is always superior to detection.
c) The option that brings residual risk within appetite cost-effectively.
d) The cheaper detective control, to preserve the security budget.
09. During a risk review, the IT operations manager who runs the affected servers records a decision to accept a residual risk to a business application. An auditor later challenges the acceptance.
What is the MOST significant concern the auditor is likely raising?
a) The acceptance decision was not written into the formal risk register.
b) The risk was accepted by someone without business accountability.
c) The IT operations manager did not consult the technology vendor before accepting.
d) The acceptance did not specify a target date for eventual remediation.
10. A CISO's monthly report to the board consists of the number of patches applied and the number of attacks blocked. The board says the report does not help it make decisions about the security program.
Which change to the metrics would be MOST valuable to the board?
a) Report metrics tied to business objectives and risk reduction.
b) Add more technical detail, such as vulnerability counts broken down by system.
c) Increase the reporting frequency from monthly to weekly.
d) Benchmark the current metrics against competitors' security spending.