SlideShare a Scribd company logo
1 of 12
1. Which of the following elements ensures a policy is
enforceable?
Options:
A. Compliance can be measured.
B. Appropriate sanctions are applied when the policy is
violated.
C. Appropriate administrative, technical, and physical controls
are put in place to support the policy.
D. the above.
2. Which of the following is an example of an information
asset?
Options:
A. Business plans
B. Employee records
C. Company reputation
D. All the above
3. Endorsed is one of the seven policy characteristics. Which of
the following statements best describes endorsed?
A. The policy is supported by management.
B. The policy is accepted by the organization’s employees.
C. The policy is mandatory; compliance is measured; and
appropriate sanctions are applied.
D. The policy is regulated by the government.
4. Which of the following statement about standards and
guidelines is true?
A. Standards are mandatory, whereas guidelines are not.
B. Guidelines are mandatory, whereas standards are not.
C. Both standards and guidelines are mandatory.
D. Neither standards nor guidelines are mandatory.
5. Which of the following grants users and systems a
predetermined level of access?
A. Accountability
B. Authentication
C. Authorization
D. Assurance
6. What is the purpose of the policy definition section?
A. To explain terms, abbreviations, and acronyms used in the
policy
B. To refer the reader to additional information
C. To provide the policy version number
D. To provide information about policy exceptions
7. Which of the following statement about standards and
guidelines is true?
A. Standards are mandatory, whereas guidelines are not.
B. Guidelines are mandatory, whereas standards are not.
C. Both standards and guidelines are mandatory.
D. Neither standards nor guidelines are mandatory.
8. Which of the following best describes a procedure?
A. Specifications for implementation of a policy
B. Instructions on how a policy is carried out
C. Aggregate of implementation standards and security controls
D. Teaching tools that help people conform to a policy
9. Which of the following is the topmost object in the policy
hierarchy?
A. Standards
B. Baselines
C. Guidelines
D. Guiding principles
10. Which of the following is a network of the national
standards institutes of 146 countries?
A. ISO
B. NIST
C. FIPS
D. IEC
11. Which of the following is a behavioral control that can be
used to safeguard against the loss of integrity?
A. Rotation of duties
B. Log analysis
C. Code testing
D. Digital signatures
12. Which of the following is a characteristic of the parallel
approach to information security?
A. Compliance is discretionary.
B. Security is the responsibility of the IT department.
C. Little or no organizational accountability exists.
D. All the above.
13. Which of the following is the objective of risk assessment?
A. Identify the inherent risk.
B. Determine the impact of a threat.
C. Calculate the likelihood of a threat occurrence.
D. All the above.
14. Which of the following statements best describes strategic
risk?
A. Risk that relates to monetary loss
B. Risk that relates to adverse business decisions
C. Risk that relates to a loss from failed or inadequate systems
and processes
D. Risk that relates to violation of laws, regulations, or policy
15. Which of the following statements best describes the Biba
security model?
A. No read up and write up
B. No write up and no write down
C. No read up and no write down
D. No read down and no write up
16. : Which of the following is the heist classification level
under the private sector classification system?
A. Secret
B. Protected
C. Confidential
D. Top secret
17. Which of the following best describes the purpose of
security awareness?
A. To teach skills that would allow a person to perform a
certain function
B. To focus attention on security
C. To integrate all the security skills and competencies into a
common body of knowledge
D. To involve management in the process
18. Which of the following regulations explicitly specifies the
topics that should be covered in a security awareness training?
A. FACTA
B. HIPAA
C. FCRA
D. DPPA
19. : Which of the following is a type of access control that is
defined by a policy and cannot be changed by the information
owner?
A. Mandatory access control
B. Discretionary access control
C. Role-based access control
D. Rule-based access control
20. : Which of the following is an access control that is based
on a specific job roles or functions?
A. Mandatory access control
B. Discretionary access control
C. Role-based access control
D. Rule-based access control
21. : Which of the following is used to associate a public key
with an identity?
A. Encryption
B. Digital hash
C. Digital certificate
D. Digital signature
22. : Identification of compliance requirements is done during
which of the following phases of the SDLC?
A. Initiation
B. Development
C. Implementation
D. Operational
23. Which of the following is the most common web application
vulnerability?
A. Failure to validate output
B. Failure to validate input
C. Dynamic data validation
D. Static data validation
24. Which of the following are components of PKI?
A. Certification Authority
B. Registration Authority
C. Client nodes
D. All the above
25. : Which of the following best describes the purpose of the
detection and investigation portion of the incident response
plan?
A. To describe the steps that need to be taken to prevent the
incident from spreading
B. To establish processes and knowledge base to accurately
detect and assess precursors and indicators
C. To describe incident declaration and notification
D. To describe the steps to eliminate the components of the
incident
26. : Which of the following is the total length of time an
essential business function can be unavailable without causing
significant harm to the organization?
A. Maximum tolerable downtime
B. Maximum tolerable uptime
C. Recovery time objective
D. Recovery point objective
27. Which of the following plans focuses on the initial response
and includes plan activation, notification, evacuation, and
communication?
A. Response plans
B. Contingency plans
C. Recovery plans
D. Resumption plans
28. : Which of the following agencies regulates financial
institutions not covered by other agencies?
A. Federal Trade Commission (FTC)
B. Commodity Futures Trading Commission (CFTC)
C. National Credit Union Administration (NCUA)
D. Federal Deposit Insurance Corporation (FDIC)
29. The Federal Reserve Board is responsible for regulating
which of the following?
A. Bank holding companies and member banks of the Federal
Reserve System
B. National banks, federal saving associations, and federal
branches of foreign banks
C. Federally charted credit unions
D. State-chartered banks
30. : Which of the following statements best describes a
healthcare clearing house?
A. A person or organization that provides patient or medical
services
B. An entity that provides payment for medical services
C. An entity that processes nonstandard health information it
receives from another entity
D. A person or entity that creates, receives, maintains,
transmits, accesses, or has the potential to access ePHI
31. Which of the following best describes HIPAA
administrative safeguards?
A. Retention, availability, and update requirements related to
supporting documentation
B. The use of technical security measures to protect ePHI data
C. Standards for business associate contracts and other
arrangement
D. Documented policies and procedures for managing day-to-
day operations and access to ePHI
32. : Which of the following statements best describes the
HIPAA breach notification rules?
A. Covered entities are required to notify individuals for any
ePHI breach within 60 days after the discovery of the breach.
B. Covered entities are required to notify individuals for breach
of unsecured ePHI within 60 days after the discovery of the
breach.
C. Covered entities are required to notify individuals for any
ePHI breach within 30 days after the discovery of the breach.
D. Covered entities are required to notify individuals for
breach of unsecured ePHI within 30 days after the discovery of
the breach.
33. : Which of the following is the goal of integrity control
standard?
A. Implementing technical controls that protect ePHI from
improper alteration or destruction
B. Restrict access to ePHI only to users and processes that have
been specifically authorized
C. Implementing of hardware, software, and mechanisms that
record and examine activity in information systems that contain
ePHI
D. Verification that a person or process seeking to access ePHI
is the one claimed
34. Which of the following is not one of the classification levels
for national security information?
A. Secret
B. Protected
C. Confidential
D. Sensitive but Unclassified
35. Which of the following is an evidence-based examination
that compares current practices against internal or external
criteria?
A. Testing
B. Audit
C. Assurance
D. Assessment

More Related Content

Similar to 1. Which of the following elements ensures a policy is enforceab

Please make sure the answer is right Pick the best answer1.docx
Please make sure the answer is right Pick the best answer1.docxPlease make sure the answer is right Pick the best answer1.docx
Please make sure the answer is right Pick the best answer1.docxmattjtoni51554
 
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%johnMilit
 
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%7593retzeth
 
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%johnMilit
 
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%johnMilit
 
ACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% CorrectACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% Correct0_0klister
 
ACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% CorrectACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% CorrectRieTian99
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final examgiquickly
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final exambubyslyke
 
Acc 460 final exam questions and correct answers 100% guaranteed#
Acc 460 final exam questions and correct answers 100% guaranteed#Acc 460 final exam questions and correct answers 100% guaranteed#
Acc 460 final exam questions and correct answers 100% guaranteed#siliverseyr
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final examginistays
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%sharing3444
 
1..acc 460 acc460 final exam correct 100%
1..acc 460 acc460 final exam correct 100%1..acc 460 acc460 final exam correct 100%
1..acc 460 acc460 final exam correct 100%Euroday
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%largest433
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%singup22
 
(New) acc 460 acc460 final exam entire answers with questions correct 100%
(New) acc 460 acc460 final exam entire answers with questions correct  100%(New) acc 460 acc460 final exam entire answers with questions correct  100%
(New) acc 460 acc460 final exam entire answers with questions correct 100%twiter343r
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%flyperhan
 
Cisa exam mock test questions-1
Cisa exam mock test questions-1Cisa exam mock test questions-1
Cisa exam mock test questions-1Hemang Doshi
 
The Human Resource EnvironmentWhen you have completed your exam .docx
The Human Resource EnvironmentWhen you have completed your exam .docxThe Human Resource EnvironmentWhen you have completed your exam .docx
The Human Resource EnvironmentWhen you have completed your exam .docxcherry686017
 
Project 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxProject 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxbriancrawford30935
 

Similar to 1. Which of the following elements ensures a policy is enforceab (20)

Please make sure the answer is right Pick the best answer1.docx
Please make sure the answer is right Pick the best answer1.docxPlease make sure the answer is right Pick the best answer1.docx
Please make sure the answer is right Pick the best answer1.docx
 
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
 
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ`s Correct Answers 100%
 
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
ACC 460 ACC460 Final EXAM MCQ`s Correct Answers 100%
 
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%
ACC 460 ACC/460 Final EXAM MCQ\s Correct Answers 100%
 
ACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% CorrectACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% Correct
 
ACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% CorrectACC 460 ACC/460 Final Exam 100% Correct
ACC 460 ACC/460 Final Exam 100% Correct
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final exam
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final exam
 
Acc 460 final exam questions and correct answers 100% guaranteed#
Acc 460 final exam questions and correct answers 100% guaranteed#Acc 460 final exam questions and correct answers 100% guaranteed#
Acc 460 final exam questions and correct answers 100% guaranteed#
 
Acc 460 final exam
Acc 460 final examAcc 460 final exam
Acc 460 final exam
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%
 
1..acc 460 acc460 final exam correct 100%
1..acc 460 acc460 final exam correct 100%1..acc 460 acc460 final exam correct 100%
1..acc 460 acc460 final exam correct 100%
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%
 
(New) acc 460 acc460 final exam entire answers with questions correct 100%
(New) acc 460 acc460 final exam entire answers with questions correct  100%(New) acc 460 acc460 final exam entire answers with questions correct  100%
(New) acc 460 acc460 final exam entire answers with questions correct 100%
 
Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%Acc 460 acc460 final exam correct 100%
Acc 460 acc460 final exam correct 100%
 
Cisa exam mock test questions-1
Cisa exam mock test questions-1Cisa exam mock test questions-1
Cisa exam mock test questions-1
 
The Human Resource EnvironmentWhen you have completed your exam .docx
The Human Resource EnvironmentWhen you have completed your exam .docxThe Human Resource EnvironmentWhen you have completed your exam .docx
The Human Resource EnvironmentWhen you have completed your exam .docx
 
Project 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxProject 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docx
 

More from careyshaunda

Kazaam Company, a merchandiser, recently completed its calendar-year.docx
Kazaam Company, a merchandiser, recently completed its calendar-year.docxKazaam Company, a merchandiser, recently completed its calendar-year.docx
Kazaam Company, a merchandiser, recently completed its calendar-year.docxcareyshaunda
 
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docx
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docxKatharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docx
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docxcareyshaunda
 
Juvenile JusticeClassify the developmental stages and cycles of ad.docx
Juvenile JusticeClassify the developmental stages and cycles of ad.docxJuvenile JusticeClassify the developmental stages and cycles of ad.docx
Juvenile JusticeClassify the developmental stages and cycles of ad.docxcareyshaunda
 
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docx
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docxKatetotur...Deliverable Length  4-6 slides (excluding Title a.docx
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docxcareyshaunda
 
Katy is opposed to the government in Sri Lanka and attends a march i.docx
Katy is opposed to the government in Sri Lanka and attends a march i.docxKaty is opposed to the government in Sri Lanka and attends a march i.docx
Katy is opposed to the government in Sri Lanka and attends a march i.docxcareyshaunda
 
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docx
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docxKari Martinsen Philosophy of CaringDescribe the historical backgr.docx
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docxcareyshaunda
 
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docx
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docxJUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docx
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docxcareyshaunda
 
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docxJUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docxcareyshaunda
 
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docxJUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docxcareyshaunda
 
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docx
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docxJUVENILE JUSTICEOutline disposition of juveniles.One of the .docx
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docxcareyshaunda
 
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docx
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docxJUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docx
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docxcareyshaunda
 
JUVENILE JUSTICE Research different types of early prevention with.docx
JUVENILE JUSTICE Research different types of early prevention with.docxJUVENILE JUSTICE Research different types of early prevention with.docx
JUVENILE JUSTICE Research different types of early prevention with.docxcareyshaunda
 
Kansai International AirportOpened on 4 September 1994, the airp.docx
Kansai International AirportOpened on 4 September 1994, the airp.docxKansai International AirportOpened on 4 September 1994, the airp.docx
Kansai International AirportOpened on 4 September 1994, the airp.docxcareyshaunda
 
Juvenile JusticeInstructional Objectives for this activityExplo.docx
Juvenile JusticeInstructional Objectives for this activityExplo.docxJuvenile JusticeInstructional Objectives for this activityExplo.docx
Juvenile JusticeInstructional Objectives for this activityExplo.docxcareyshaunda
 
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docx
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docxJuvenile Facing Life in  Prison, we’re doing pros and cons.I a.docx
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docxcareyshaunda
 
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docx
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docxJUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docx
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docxcareyshaunda
 
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docxJournal Entry 3 Prepare a one to two (1-2) paragraph journal en.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docxcareyshaunda
 
Journal Positive Social Change—An Evolving PerspectiveAs explor.docx
Journal Positive Social Change—An Evolving PerspectiveAs explor.docxJournal Positive Social Change—An Evolving PerspectiveAs explor.docx
Journal Positive Social Change—An Evolving PerspectiveAs explor.docxcareyshaunda
 
Journal Evaluating ResourcesPersonal experience and perception le.docx
Journal Evaluating ResourcesPersonal experience and perception le.docxJournal Evaluating ResourcesPersonal experience and perception le.docx
Journal Evaluating ResourcesPersonal experience and perception le.docxcareyshaunda
 
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docxJournal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docxcareyshaunda
 

More from careyshaunda (20)

Kazaam Company, a merchandiser, recently completed its calendar-year.docx
Kazaam Company, a merchandiser, recently completed its calendar-year.docxKazaam Company, a merchandiser, recently completed its calendar-year.docx
Kazaam Company, a merchandiser, recently completed its calendar-year.docx
 
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docx
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docxKatharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docx
Katharine Hepburn, Harvey Milk, and Fred Karomatsu all contrib.docx
 
Juvenile JusticeClassify the developmental stages and cycles of ad.docx
Juvenile JusticeClassify the developmental stages and cycles of ad.docxJuvenile JusticeClassify the developmental stages and cycles of ad.docx
Juvenile JusticeClassify the developmental stages and cycles of ad.docx
 
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docx
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docxKatetotur...Deliverable Length  4-6 slides (excluding Title a.docx
Katetotur...Deliverable Length  4-6 slides (excluding Title a.docx
 
Katy is opposed to the government in Sri Lanka and attends a march i.docx
Katy is opposed to the government in Sri Lanka and attends a march i.docxKaty is opposed to the government in Sri Lanka and attends a march i.docx
Katy is opposed to the government in Sri Lanka and attends a march i.docx
 
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docx
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docxKari Martinsen Philosophy of CaringDescribe the historical backgr.docx
Kari Martinsen Philosophy of CaringDescribe the historical backgr.docx
 
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docx
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docxJUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docx
JUVENILE JUSTICE NO MORE THAN ONE PARAGRAPH AND A HALFResearch.docx
 
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docxJUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFThis term.docx
 
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docxJUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docx
JUVENILE JUSTICE 2NO MORE THAN ONE PARAGRAPH AND A HALFSumma.docx
 
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docx
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docxJUVENILE JUSTICEOutline disposition of juveniles.One of the .docx
JUVENILE JUSTICEOutline disposition of juveniles.One of the .docx
 
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docx
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docxJUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docx
JUVENILE JUSTICE 1 NO MORE THAN ONE PARAGRAPHThe same crime ca.docx
 
JUVENILE JUSTICE Research different types of early prevention with.docx
JUVENILE JUSTICE Research different types of early prevention with.docxJUVENILE JUSTICE Research different types of early prevention with.docx
JUVENILE JUSTICE Research different types of early prevention with.docx
 
Kansai International AirportOpened on 4 September 1994, the airp.docx
Kansai International AirportOpened on 4 September 1994, the airp.docxKansai International AirportOpened on 4 September 1994, the airp.docx
Kansai International AirportOpened on 4 September 1994, the airp.docx
 
Juvenile JusticeInstructional Objectives for this activityExplo.docx
Juvenile JusticeInstructional Objectives for this activityExplo.docxJuvenile JusticeInstructional Objectives for this activityExplo.docx
Juvenile JusticeInstructional Objectives for this activityExplo.docx
 
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docx
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docxJuvenile Facing Life in  Prison, we’re doing pros and cons.I a.docx
Juvenile Facing Life in  Prison, we’re doing pros and cons.I a.docx
 
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docx
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docxJUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docx
JUVENILE JUSTICE 2 ONLY ONE PARAGRAPHIdentify the critical need fo.docx
 
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docxJournal Entry 3 Prepare a one to two (1-2) paragraph journal en.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal en.docx
 
Journal Positive Social Change—An Evolving PerspectiveAs explor.docx
Journal Positive Social Change—An Evolving PerspectiveAs explor.docxJournal Positive Social Change—An Evolving PerspectiveAs explor.docx
Journal Positive Social Change—An Evolving PerspectiveAs explor.docx
 
Journal Evaluating ResourcesPersonal experience and perception le.docx
Journal Evaluating ResourcesPersonal experience and perception le.docxJournal Evaluating ResourcesPersonal experience and perception le.docx
Journal Evaluating ResourcesPersonal experience and perception le.docx
 
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docxJournal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docx
Journal Entry 3 Prepare a one to two (1-2) paragraph journal entr.docx
 

Recently uploaded

Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Sapana Sha
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfAyushMahapatra5
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAssociation for Project Management
 
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...PsychoTech Services
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
social pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajansocial pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajanpragatimahajan3
 
fourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingfourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingTeacherCyreneCayanan
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxVishalSingh1417
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfAdmir Softic
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 

Recently uploaded (20)

Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...
IGNOU MSCCFT and PGDCFT Exam Question Pattern: MCFT003 Counselling and Family...
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
social pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajansocial pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajan
 
fourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingfourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writing
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 

1. Which of the following elements ensures a policy is enforceab

  • 1. 1. Which of the following elements ensures a policy is enforceable? Options: A. Compliance can be measured. B. Appropriate sanctions are applied when the policy is violated. C. Appropriate administrative, technical, and physical controls are put in place to support the policy. D. the above. 2. Which of the following is an example of an information asset? Options: A. Business plans B. Employee records C. Company reputation D. All the above 3. Endorsed is one of the seven policy characteristics. Which of the following statements best describes endorsed?
  • 2. A. The policy is supported by management. B. The policy is accepted by the organization’s employees. C. The policy is mandatory; compliance is measured; and appropriate sanctions are applied. D. The policy is regulated by the government. 4. Which of the following statement about standards and guidelines is true? A. Standards are mandatory, whereas guidelines are not. B. Guidelines are mandatory, whereas standards are not. C. Both standards and guidelines are mandatory. D. Neither standards nor guidelines are mandatory. 5. Which of the following grants users and systems a predetermined level of access? A. Accountability B. Authentication C. Authorization D. Assurance 6. What is the purpose of the policy definition section? A. To explain terms, abbreviations, and acronyms used in the policy
  • 3. B. To refer the reader to additional information C. To provide the policy version number D. To provide information about policy exceptions 7. Which of the following statement about standards and guidelines is true? A. Standards are mandatory, whereas guidelines are not. B. Guidelines are mandatory, whereas standards are not. C. Both standards and guidelines are mandatory. D. Neither standards nor guidelines are mandatory. 8. Which of the following best describes a procedure? A. Specifications for implementation of a policy B. Instructions on how a policy is carried out C. Aggregate of implementation standards and security controls D. Teaching tools that help people conform to a policy 9. Which of the following is the topmost object in the policy hierarchy? A. Standards B. Baselines C. Guidelines
  • 4. D. Guiding principles 10. Which of the following is a network of the national standards institutes of 146 countries? A. ISO B. NIST C. FIPS D. IEC 11. Which of the following is a behavioral control that can be used to safeguard against the loss of integrity? A. Rotation of duties B. Log analysis C. Code testing D. Digital signatures 12. Which of the following is a characteristic of the parallel approach to information security? A. Compliance is discretionary. B. Security is the responsibility of the IT department. C. Little or no organizational accountability exists. D. All the above. 13. Which of the following is the objective of risk assessment?
  • 5. A. Identify the inherent risk. B. Determine the impact of a threat. C. Calculate the likelihood of a threat occurrence. D. All the above. 14. Which of the following statements best describes strategic risk? A. Risk that relates to monetary loss B. Risk that relates to adverse business decisions C. Risk that relates to a loss from failed or inadequate systems and processes D. Risk that relates to violation of laws, regulations, or policy 15. Which of the following statements best describes the Biba security model? A. No read up and write up B. No write up and no write down C. No read up and no write down D. No read down and no write up 16. : Which of the following is the heist classification level under the private sector classification system? A. Secret
  • 6. B. Protected C. Confidential D. Top secret 17. Which of the following best describes the purpose of security awareness? A. To teach skills that would allow a person to perform a certain function B. To focus attention on security C. To integrate all the security skills and competencies into a common body of knowledge D. To involve management in the process 18. Which of the following regulations explicitly specifies the topics that should be covered in a security awareness training? A. FACTA B. HIPAA C. FCRA D. DPPA 19. : Which of the following is a type of access control that is defined by a policy and cannot be changed by the information owner? A. Mandatory access control
  • 7. B. Discretionary access control C. Role-based access control D. Rule-based access control 20. : Which of the following is an access control that is based on a specific job roles or functions? A. Mandatory access control B. Discretionary access control C. Role-based access control D. Rule-based access control 21. : Which of the following is used to associate a public key with an identity? A. Encryption B. Digital hash C. Digital certificate D. Digital signature 22. : Identification of compliance requirements is done during which of the following phases of the SDLC? A. Initiation B. Development
  • 8. C. Implementation D. Operational 23. Which of the following is the most common web application vulnerability? A. Failure to validate output B. Failure to validate input C. Dynamic data validation D. Static data validation 24. Which of the following are components of PKI? A. Certification Authority B. Registration Authority C. Client nodes D. All the above 25. : Which of the following best describes the purpose of the detection and investigation portion of the incident response plan? A. To describe the steps that need to be taken to prevent the incident from spreading B. To establish processes and knowledge base to accurately detect and assess precursors and indicators C. To describe incident declaration and notification
  • 9. D. To describe the steps to eliminate the components of the incident 26. : Which of the following is the total length of time an essential business function can be unavailable without causing significant harm to the organization? A. Maximum tolerable downtime B. Maximum tolerable uptime C. Recovery time objective D. Recovery point objective 27. Which of the following plans focuses on the initial response and includes plan activation, notification, evacuation, and communication? A. Response plans B. Contingency plans C. Recovery plans D. Resumption plans 28. : Which of the following agencies regulates financial institutions not covered by other agencies? A. Federal Trade Commission (FTC) B. Commodity Futures Trading Commission (CFTC) C. National Credit Union Administration (NCUA)
  • 10. D. Federal Deposit Insurance Corporation (FDIC) 29. The Federal Reserve Board is responsible for regulating which of the following? A. Bank holding companies and member banks of the Federal Reserve System B. National banks, federal saving associations, and federal branches of foreign banks C. Federally charted credit unions D. State-chartered banks 30. : Which of the following statements best describes a healthcare clearing house? A. A person or organization that provides patient or medical services B. An entity that provides payment for medical services C. An entity that processes nonstandard health information it receives from another entity D. A person or entity that creates, receives, maintains, transmits, accesses, or has the potential to access ePHI 31. Which of the following best describes HIPAA administrative safeguards? A. Retention, availability, and update requirements related to supporting documentation
  • 11. B. The use of technical security measures to protect ePHI data C. Standards for business associate contracts and other arrangement D. Documented policies and procedures for managing day-to- day operations and access to ePHI 32. : Which of the following statements best describes the HIPAA breach notification rules? A. Covered entities are required to notify individuals for any ePHI breach within 60 days after the discovery of the breach. B. Covered entities are required to notify individuals for breach of unsecured ePHI within 60 days after the discovery of the breach. C. Covered entities are required to notify individuals for any ePHI breach within 30 days after the discovery of the breach. D. Covered entities are required to notify individuals for breach of unsecured ePHI within 30 days after the discovery of the breach. 33. : Which of the following is the goal of integrity control standard? A. Implementing technical controls that protect ePHI from improper alteration or destruction B. Restrict access to ePHI only to users and processes that have been specifically authorized C. Implementing of hardware, software, and mechanisms that record and examine activity in information systems that contain
  • 12. ePHI D. Verification that a person or process seeking to access ePHI is the one claimed 34. Which of the following is not one of the classification levels for national security information? A. Secret B. Protected C. Confidential D. Sensitive but Unclassified 35. Which of the following is an evidence-based examination that compares current practices against internal or external criteria? A. Testing B. Audit C. Assurance D. Assessment