Browse all practice questions for the Network Security (NETSEC) 2 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Network Security (NETSEC) 2 Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • In order for security to be an enabler, security should be involved when?
  • IT security people should maintain a negative view of users.
  • Which practice describes coordinating security controls to meet regulatory requirements?
  • Which option best describes the role of governance frameworks in security management?
  • The material recommends hard-headed thinking about security ROI analysis.
  • Single-Loss Expectancy multiplied by the Annualized Probability of Occurrence yields which metric?
  • Which statement best describes the relationship between policies and operations?
  • Codes of ethics are created to make ethical decision making more predictable.
  • Which is a primary purpose of auditing?
  • Which statement best describes the purpose of security as an enabler?
  • To ensure policy content reflects multiple departments, policies should be written by corporate teams involving people from multiple departments.
  • ________ examines organizational units for efficiency, effectiveness, and adequate controls.
  • ________ are payments made by a supplier to a corporate buyer when a purchase is made.
  • The Revised SEC Act is commonly associated with which topic?
  • Which of the following specifies how to do certification by external parties?
  • ________ are descriptions of what the best firms in the industry are doing about security.
  • Which scenario is an example of a conflict of interest?
  • Which framework is primarily associated with enterprise IT governance and management?
  • What is missing from the definition of response as 'recovery'?
  • Policies should specify implementation in detail.
  • In the plan-protect-response cycle, which stage is primarily responsible for creating and operating countermeasures?
  • Which law addresses data protection requirements for financial institutions?
  • ________ are monetary gifts to induce an employee to favor a supplier or other party.
  • In internal control terminology, a deficiency that results in more than a remote likelihood of material misstatement not being prevented or detected is called what?
  • Which statement best distinguishes standards from guidelines?
  • What does SLE stand for in loss expectancy?
  • A technical security architecture includes which of the following?
  • In FISMA, ________ is done internally by the organization.
  • The statement 'Responding to risk through risk avoidance is likely to be acceptable to other units of the firm' is true or false.
  • A company should consider list of possible remediation plans as an investment portfolio.
  • Baselines in security procedures are best described as what?
  • Which option is primarily designed to govern IT processes and alignment with business objectives?
  • Conducting stings on employees ________.
  • Which statement about informing employees of monitoring is supported by the material?
  • ________ are discretionary.
  • Central security consoles ________.
  • ______ is the plan-based creation and operation of countermeasures.
  • Which standard is focused on securing payment card data and is commonly required for merchants?
  • FISMA applies to which type of organization?
  • Informing employees that monitoring will be done is a bad idea.
  • Having realistic goals for reducing vulnerabilities ________.
  • What describes the relationship between compliance regimes and security planning?
  • Mandatory vacations should be enforced ________.
  • After performing a preliminary security assessment, a company should develop a remediation plan for EVERY security gap identified.
  • ________ is preferred by U.S. auditors.
  • When someone requests to take an action that is potentially dangerous, what protection should be put into place?
  • True/False: Different honest people can make different ethical decisions in the same situation.
  • Internal audits are performed by which party?
  • What is the worst problem with classic risk analysis?
  • It is mandatory for decision makers to consider guidelines.
  • ________ specify the low-level detailed actions that must be taken by specific employees.
  • What term entails investigating the IT security of external companies and the implications of close IT partnerships before implementing interconnectivity?
  • Which of the following is a good rule for handling exceptions?
  • HIPAA primarily governs privacy and security of patient information in which setting?
  • Which law addresses data protection requirements for health care institutions?
  • Which statement best describes the relationship between IT auditing placement and independence from IT security?
  • The factors that require a firm to change its security planning, protection, and response are called driving forces.
  • Which statement best describes COBIT's purpose?
  • It is acceptable for an employee to reveal ________.
  • Placing security within IT ________.
  • Which term means responding to risk by not taking a risky action?
  • Which approach treats remediation options as a structured, investment-like portfolio?
  • Which of the following is a way of responding to risk with active countermeasures?
  • Which security function is usually not outsourced?
  • ________ examines financial processes for efficiency, effectiveness, and adequate controls.
  • Which option correctly identifies the focus of IT auditing?
  • Which option best reflects the definitions of bribes and kickbacks as given?
  • ______ is a single countermeasure composed of multiple interdependent components in series that require all components to succeed if the countermeasure is to succeed.
  • In risk analysis, which computation approach is appropriate when costs and benefits vary over time: using either Net Present Value or Internal Rate of Return, or both?
  • Which statement describes COBIT's scope?
  • Which of the following is an example of a conflict of interest?
  • Many compliance regimes require firms to adopt specific formal governance framework to drive security planning and operational management.
  • Hotlines for reporting improper behavior are required by law to be non-anonymous.
  • According to the author, information assurance is a good name for IT security.
  • Which risk response involves transferring risk to an external party such as insurance?
  • Which statement about expressing costs and benefits in risk analyses is correct?
  • Which statement best describes handling legacy security technologies?
  • Data protection enforcement programs may include which of the following?
  • Policies should specify the details of how protections are to be applied.
  • Auditing aims to achieve which outcome?
  • To outsource some security functions, a firm can use an MISP.
  • Which of the following is a formal process?
  • The stage of the plan-protect response cycle that consumes the most time is ________.
  • Which internal control framework is commonly used in U.S. public companies for governance and reporting?
  • Independence is best provided for IT security by placing it within the IT department.
  • Which security functions are typically outsourced?
  • Electronic employee monitoring is rare.
  • PCI-DSS affects which type of companies?
  • A ________ occurs when a single security element failure defeats the overall security of a system.
  • Which combination of benefits is commonly attributed to MSSPs?
  • ________ means implementing no countermeasures and absorbing any damages that occur.
  • It is a good idea to view the security function as a police force or military organization.
  • Which option describes the ISO/IEC 2700 family as it relates to information security management systems?
  • CobiT focuses on ________.
  • Which term refers to prescriptive statements about what companies should do, assembled by trade associations and government agencies?
  • Which security function is typically outsourced?
  • The key to security being an enabler is ________.
  • The steps required to issue a new employee a password should be specified in a ________.
  • Which statements about compliance laws and security requirements are true?
  • The goal of IT security is risk elimination.
  • ________ are mandatory.
  • True or false: Companies should replace their legacy security technologies immediately.
  • Strong security can be an enabler, allowing a company to do things it could not do otherwise.
  • ______ audits are done by an organization on itself.
  • Who is ultimately accountable for a resource or control?
  • Which statement about the ISO/IEC 2700 family is accurate according to the material?
  • Senior officers often have an additional code of ethics.
  • The growing number of compliance laws and regulations is driving firms to use formal governance frameworks to guide their security processes.
  • Which framework would be best described as providing a comprehensive model for IT governance and management across the enterprise?
  • Most IT security analysts recommend placing IT security functions within the IT department.
  • Which framework is described as primarily associated with IT governance rather than financial controls?
  • Which term describes descriptions of what leading firms are doing about security?
  • Which of the following are examples of opportunity?
  • Data breach notification is triggered when what occurs to sensitive information?
  • Security professionals should minimize burdens on functional departments.
  • Vulnerability testing outsourcing is typically described as:
  • Which of the following gives the best estimate of the complete cost of a compromise?
  • What does ALE stand for in risk assessment?
  • In a firm, codes of ethics apply to which groups?
  • A(n) ________ is a statement of what should be done under specific circumstances.
  • The goal of IT security is reasonable risk reduction.
  • Employees usually must rationalize bad behavior.
  • ______ requires multiple countermeasures to be defeated for an attack to succeed.
  • Border management ________.
  • Policies drive ________.
  • Which term describes the factors that require a firm to change its security planning?
  • Which arrangement best provides backing from the IT department for security?
  • What term describes closing all routes of attack into an organization's systems?
  • In security design, what does the term 'weakest link' refer to?
  • Which framework would be best described as providing a comprehensive model for IT governance and management across the enterprise?
  • Which statement correctly describes bribes and kickbacks?
  • A MSSP provides what benefits?
  • Which statement about FTC enforcement actions for privacy protection is true?
  • What security function(s) usually is(are) not outsourced?
  • The manager of the security department is often called ________.
  • The party that is ultimately held accountable for a resource or control is ________.
  • The author's stance on information assurance as a name for IT security is:
  • Which term describes the security approach that uses multiple layers of defense to protect assets?
  • Planning, protection, and response follow a fairly strict sequence from one stage to another.
  • Which metric is used to estimate the annualized cost of security breaches?
  • Which statement best describes why companies create codes of ethics?
  • ________ examines IT processes for efficiency, effectiveness, and adequate controls.
  • In manual procedures, the segregation of duties ________.
  • ________ means responding to risk by taking out insurance.
  • Data breach notification laws typically require what?
  • Which statement best describes the relationship between security and functionality?
  • Vulnerability testing typically is not outsourced.
  • Central security consoles enable what capability?
  • Before doing a vulnerability test, a security employee must ensure that ________.
  • Using both a firewall and host hardening to protect a host is which concept?
  • The book focuses on which aspect of security?
  • Policies should be written by ________.
  • A technical security architecture should be created which of the following?
  • Once a company's resources are enumerated, the next step is to ________.
  • GLBA is primarily concerned with protecting consumer data in which sector?
  • Which framework would you consult to align IT processes with business goals across the enterprise?
  • A governance framework specifies how to do ________.
  • The ISO/IEC 2700 family focuses on ________.
  • Remediation plans should cover every security gap identified.
  • ________ are check lists of what should be done in a specific procedure.
  • Placing IT auditing in an existing auditing department would give independence from IT security.
  • In COSO, a company's overall control culture is called its ________.
  • A planned series of actions in a corporation is a(n) ________.
  • The purpose(s) of auditing is to ________.
  • The owner can delegate ________ to the trustee.
  • Which statement correctly matches the auditing type to its typical focus?
  • COSO focuses on ________.
  • The first step in developing an IT security plan is to ________.
  • Which arrangement is associated with independence from IT security?
  • What is the stated goal of IT security?
  • When risk analysis deals with costs and benefits that vary by year, which computations should be used?
  • Audits place special attention on ________.
  • Which scenario best illustrates the value of defense in depth?
  • Which of the following is not one of the three elements in the fraud and abuse triangle?
  • Security metrics allow a company to know if it is improving in its implementation of policies.
  • Which framework focuses on corporate governance at the enterprise level?
  • Where was private information often stored according to observed storage practices?
  • Exceptions in policies and procedures should be forbidden.
  • Which CobiT domain has the most control objectives?
  • A policy is best described as which of the following?
  • Which policy element is discretionary?
  • Which policy element is mandatory?
  • Guidelines are appropriate in simple and highly certain circumstances.
  • Central security consoles contribute to which of the following outcomes when used properly?
  • In order to demonstrate support for security, top management must ________.
  • Data protection regulations generally require what regarding sensitive data?
  • ________ are prescriptive statements about what companies should do and are put together by trade associations and government agencies.
  • Which framework is most closely aligned with governance over enterprise IT rather than specific security controls?
  • What term describes the low-level detailed actions that must be taken by specific employees?
  • An example of 'pressure' from the fraud triangle would include paying back embezzled money.
  • Which statement best describes COSO's focus?
  • When you wish to create a specific firewall, you should create a security policy for that firewall specifically.
  • Internal corporate attackers often have a history of a overt unacceptable behavior.
  • Which group is explicitly noted as sometimes having an additional code of ethics?
  • Which statement best describes the primary focus difference between COSO and COBIT?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy