单选题 An organization is the victim of a major data breach just one month after passing an external cyber security audit. Which of the following is the likely reason for this situation?

A、 Both the auditor and the organization validated the controls to be accurate.
B、 The organization had the minimum level of controls in place to pass the audit.
C、 The auditor performed an in-depth analysis of the required controls.
D、 The audit was initiated by appropriate levels of management in the organization.
下载APP答题
由4l***d0提供 分享 举报 纠错

相关试题

单选题 What industry-recognized document could be used as a baseline reference that is related to data security and business operations for conducting a security assessment?

A、Service Organization Control (SOC) 1 Type 2
B、Service Organization Control (SOC) 1 Type 1
C、Service Organization Control (SOC) 2 Type 2
D、Service Organization Control (SOC) 2 Type 1

单选题 Which security feature fully encrypts code and data as it passes to the servers and only decrypts below the hypervisor layer?

A、File-system level encryption
B、Transport Layer Security (TLS)
C、Key management service
D、Trusted execution environments

单选题 The application owner of a system that handles confidential data leaves an organization. It is anticipated that a replacement will be hired in approximately six months. During that time, which of the following should the organization do?

A、Gram temporary access to the former application owner's account
B、Assign a temporary application owner to the system.
C、Restrict access to the system until a replacement application owner rs hired.
D、Prevent changes to the confidential data until a replacement application owner is hired.

单选题 A security professional needs to find a secure and efficient method of encrypting data on an endpoint. Which solution includes a root key?

A、Bitlocker
B、Trusted Platform Module (TPM)
C、Virtual storage array network (VSAN)
D、Hardware security module (HSM)

单选题 What is the FIRST step prior to executing a test of an organisation's disaster recovery (DR) or business continuity plan (BCP)?

A、identify key stakeholders,
B、Develop recommendations for disaster scenarios.
C、Identify potential failure points.
D、Develop clear evaluation criteria.

单选题 In a quarterly system access review, an active privileged account was discovered that did not exist in the prior review on the production system. The account was created one hour after the previous access review. Which of the following is the BEST option to reduce overall risk in addition to quarterly access reviews?

A、Implement bi-annual reviews.
B、Create policies for system access.
C、Implement and review risk-based alerts.
D、Increase logging levels.

单选题 A company needs to provide employee access to travel services, which are hosted by a third-party service provider, Employee experience is important, and when users are already authenticated, access to the travel portal is seamless. Which of the following methods is used to share information and grant user access to the travel portal?

A、Security Assertion Markup Language (SAML) access
B、Single sign-on (SSO) access
C、Open Authorization (OAuth) access
D、Federated access

单选题 The Chief Information Security Officer (CISO) of an organization has requested that a Service Organization Control (SOC) report be created to outline the security and availability of a particular system over a 12- month period. Which type of SOC report should be utilized?

A、SOC 1 Type 1
B、SOC 2 Type 2
C、SOC 2 Type 2
D、SOC 3 Type 1