  1. Which of the following is not a type of security control?
  2. determining
  3. _____ is a promise not to disclose to any third party information covered by the agreement.
  4. A _____ is a term that refers to a network that limits what and how computers are able to talk to each other.
  5. Which of the following are control objectives for PCI DSS?
  6. Which of the following does a policy change control board do?
  7. How is risk reduced in the LAN-to-WAN domain?
  8. The Risk IT framework process model is built on which three domains?
  9. Security _____ are the technical implementations of the policies defined by the organization.
  10. What term relates to the number of layers and number of direct reports found in an organization?
  11. Monitoring should detect which of the following?
  12. Information used to open or access a bank account is generally considered?
  13. Policies are the key to repeatable behavior. To achieve repeatable behavior, you must measure both _____ and _____.
  14. Which of the following attempts to identify where sensitive data is currently stored?
  15. Policy acceptance challenges include?
  16. What is an information security policy?
  17. PCI DSS provides highly specific technology requirements for handling _____ data.
  18. _____ conduct periodic risk-based reviews of information resources security policies and procedures.
  19. Which of the following is a generally accepted and widely used policy framework?
  20. Which of the following is the first step in establishing an information security program?
  21. Well-defined and properly implemented security policies help the business in which of the following ways?
  22. The _____ principle recommended for industry best practice, is written in order to inform owners, providers, and users of information systems, and other parties of the existence and general context of policies, responsibilities, practices, procedures, and organization for security of information systems.
  23. _____ is an international governance and controls framework and a widely accepted standard for assessing, governing, and managing IT security and risks.
  24. The ______ shifts responsibility to the owner to operate a system when certification and accreditation is achieved.
  25. Using the steps in Kotter’s Eight-Step Change Model, what are the roles and responsibilities involved in the change process?
  26. Which of the following is a PCIDSS network requirement?
  27. _____ is the ability to reasonably ensure conformity and adherence to both internal and external policies, standards, procedures, laws, and regulations?
  28. Many of the business benefits of Internet access over mobile devices include which of the following?
  29. Within the user domain, some of the ways in which risk can be mitigated include: awareness, enforcement, and ___________.
  30. Policies and procedures differ, because policies are _____ and procedures are _____.
  31. What is policy compliance?
  32. Overcoming the effects of apathy on security policies includes _____.
  33. Implementation and enforcement of policies is a challenge. The biggest hindrance to implementation of policies is the _______ factor.
  34. The _____ principle recommended for industry best practice, is written in order to consider everyone affected, including technical, administrative, organizational, operational, commercial, educational, and legal personnel.
  35. Devices and objects with built in _____________ are connected to an Internet of Things platform, which integrates data from the different devices and applies analytics to share the most valuable information with applications built to address specific needs.
  36. Which personality type often breaks through barriers that previously prevented success?
  37. Which of the following is not a key area of improvement noted after COBIT implementation?
  38. Which of the following is the best measure of success for a security policy?
  39. Security personnel need to be aware of policy and standards change requirements. Business drivers for policy and standards changes may include _____?
  40. When should a wireless security policy be initially written?
  41. The Seven Domains of a typical IT infrastructure include?
  42. You can get a basic understanding if individuals are being held accountable for adherence to security policies by examining these basic measurements.
  43. When a catastrophic security breach occurs, who is ultimately held accountable by regulators and the public?
  44. When building a policy framework, which of the following information systems factors should be considered?
  45. Among other things, security awareness programs must emphasize value, culture, and _____.
  46. To achieve repeatable behavior of policies, you must measure both _____ and _____.
  47. The basic elements of motivation include pride, success, and __________.
  48. Which type of control is associated with responding to and fixing a security incident?
  49. Good security policies mitigate risk through?
  50. Generally, remote authentication provides which of the following?
