Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Which statement is TRUE regarding the use of questionnaires in third party risk assessments?

A.

The total number of questions included in the questionnaire assigns the risk tier

B.

Questionnaires are optional since reliance on contract terms is a sufficient control

C.

Assessment questionnaires should be configured based on the risk rating and type of service being evaluated

D.

All topic areas included in the questionnaire require validation during the assessment

Which set of procedures is typically NOT addressed within data privacy policies?

A.

Procedures to limit access and disclosure of personal information to third parties

B.

Procedures for handling data access requests from individuals

C.

Procedures for configuration settings in identity access management

D.

Procedures for incident reporting and notification

Which factor in patch management is MOST important when conducting postcybersecurity incident analysis related to systems and applications?

A.

Configuration

B.

Log retention

C.

Approvals

D.

Testing

Which statement is TRUE regarding the onboarding process far new hires?

A.

New employees and contractors should not be on-boarded until the results of applicant screening are approved

B.

it is not necessary to have employees, contractors, and third party users sign confidentiality or non-disclosure agreements

C.

All job roles should require employees to sign non-compete agreements

D.

New employees and contactors can opt-out of having to attend security and privacy awareness training if they hold existing certifications

When conducting an assessment of a third party's physical security controls, which of the following represents the innermost layer in a ‘Defense in Depth’ model?

A.

Public internal

B.

Restricted entry

C.

Private internal

D.

Public external

Data loss prevention in endpoint security is the strategy for:

A.

Assuring there are adequate data backups in the event of a disaster

B.

Preventing exfiltration of confidential information by users who access company systems

C.

Enabling high-availability to prevent data transactions from loss

D.

Preventing malware from entering secure systems used for processing confidential information

Which statement is FALSE regarding problem or issue management?

A.

Problems or issues are the root cause of an actual or potential incident

B.

Problem or issue management involves managing workarounds or known errors

C.

Problems or issues typically lead to systemic failures

D.

Problem or issue management may reduce the likelihood and impact of incidents