01. What happens when user identities are deprovisioned?
a) They are deleted and purged from all systems.
b) They are archived and their access rights are automatically reassigned to a manager.
c) They are transferred to another system.
d) They are disabled, with data being retained according to policy.
02. What type of analysis can help one quickly observe anomalous behavior in an application without needing access to source code?
a) Static source analysis
b) Dynamic binary analysis
c) Dynamic source analysis
d) Static binary analysis
03. A renewable energy company has contracted with a third-party vendor to manage its customer service platform. Recently, there was a security incident where customer data was exposed due to the vendor's inadequate security measures. Lisa, the company’s Chief Security Officer (CSO), must reassess the security value of third-party services.
What should Lisa prioritize to ensure third-party vendors meet the company's security requirements?
a) Require vendors to comply with the company's security policies and undergo regular security assessments.
b) Establish continuous monitoring of vendor activities using advanced security tools to detect and respond to incidents.
c) Implement strict access controls and network segmentation to limit vendor access to only necessary systems.
d) Incorporate robust security clauses in vendor contracts, including penalties for non-compliance with security standards.
04. What do compliance tests determine?
a) Whether employee access lists are accurate
b) Whether the underlying transactions and account balances are accurate and complete
c) Whether a control exists and is operating appropriately
d) Whether transaction logs are properly tracked
05. Which of the following requires the most frequent use of Just-in-Time identity services?
a) User registration on websites
b) Deleting inactive user identities
c) Updating source code libraries
d) Privilege escalation for processes
06. IPv4 and IPv6 protocols are important to which layer(s) of the OSI model:
a) Layers 1 – 3
d) Layer 3
c) Layer 4
d) Layers 1 – 4
07. As a Security Manager for an international e-commerce platform, you are updating the incident response plan to address cross-border cyber incidents. Considering various legal jurisdictions, what key factor should you incorporate into the plan?
a) A unified incident response procedure applicable to all countries where the company operates
b) Delegation of incident response to local teams without centralized oversight
c) Specific legal and regulatory requirements for each jurisdiction to ensure compliance during the incident response process
d) Emphasis on public relations strategies to manage customer perceptions and company reputation globally
08. Which of the following statements best describes why threat modeling is an integral part of a broad approach to information security?
a) Effective threat modeling focuses on incident response, thus lowering the organization’s overall security risk.
b) It is part of NIST SP800-145, mandated for US federal agencies, and considered best practice.
c) It is risk-based, which is the basis for most modern cybersecurity methodologies and frameworks.
d) It specifically focuses on the threat actors' perspective, complementing traditional defense-based approaches.
09. Encrypting all the data along a communications path between connecting nodes is known as:
a) Multiprotocol labeling
b) Link encryption
c) Generic encapsulation
d) End-to-end encryption
10. An assessor must base a risk conclusion on a subset of a population rather than examining every instance. When is a small sample size still an acceptable basis for risk information, accepting that the result will be reported as indicative rather than statistically projected?
a) When time and resources are limited
b) When statistical significance is required
c) When processes are unique
d) When precision is critical