Deck 11: Security and Personnel

Full screen (f)
exit full mode
Question
Each CISSP concentration exam consists of 25 to 50 questions.
Use Space or
up arrow
down arrow
to flip the card.
Question
The SSCP covers ten domains.
Question
Information security should be visible to the users.
Question
The organization should integrate the security awareness education into a new hire's ongoing job orientation and make it a part of every employee's on-the-job security training.
Question
The use of standard job descriptions can increase the degree of professionalism in the information security field.
Question
In many organizations,information security teams lacks established roles and responsibilities.
Question
Organizations are not required by law to protect employee information that is sensitive or personal.
Question
To maintain a secure facility,all contract employees should be escorted from room to room,as well as into and out of the facility.
Question
All of the existing certifications are fully understood by hiring organizations.
Question
The process of integrating information security perspectives into the hiring process begins with reviewing and updating all job descriptions.
Question
The position of security technician can be offered as an entry-level position.
Question
The general management community of interest must work with the information security professionals to integrate solid information security concepts into the personnel management practices of the organization.
Question
Builders operate and administrate the security tools and the security monitoring function and continuously improve the processes,performing all the day-to-day work.
Question
ISSEP was developed under a joint agreement between the FBI and the United States National Security Agency,Information Assurance Directorate.
Question
The security manager position is much more general than that of CISO.
Question
In most cases,organizations look for a technically qualified information security generalist who has a solid understanding of how an organization operates.
Question
The information security function cannot be placed within protective services.
Question
Security managers are accountable for the day-to-day operation of the information security program.
Question
The SCNA track focuses on firewalls and intrusion detection.
Question
In the business world,background checks determine the individual's level of security classification,a requirement for many positions.
Question
A study of information security positions,done by Schwartz,Erwin,Weafer,and Briney,found that positions can be classified into one of ____ areas.

A)two
B)three
C)four
D)five
Question
ISACA stands for Information Systems Automation and Control Association._________________________
Question
GIAC stands for Global Information Architecture Certification._________________________
Question
ISSAP stands for Information Systems Security Architecture Professional._________________________
Question
The information security function can be placed within the ____.

A)insurance and risk management function
B)administrative services function
C)legal department
D)All of the above
Question
The CISA certification is for information security management professionals._________________________
Question
Many information security professionals enter the field from traditional ____ assignments.

A)HR
B)BA
C)IT
D)All of the above
Question
____ are often involved in national security and cyber-security tasks and move from those environments into the more business-oriented world of information security.

A)Marketing managers
B)Military personnel
C)Business analysts
D)Lawyers
Question
Friendly departures include termination for cause,permanent downsizing,temporary lay-off,or some instances of quitting._________________________
Question
ISSMP stands for Information Systems Security Monitoring Professional._________________________
Question
The general management community of interest must plan for the proper staffing for the information security function._________________________
Question
Administrators provide the policies,guidelines and standards in the Schwartz,Erwin,Weafer,and Briney classification._________________________
Question
ISSEP stands for Information Systems Security Expert Professional._________________________
Question
Upper management should learn more about the budgetary needs of the information security function and the positions within it._________________________
Question
The model used often by large organizations places the information security department within the ____ department.

A)management
B)information technology
C)financial
D)production
Question
Many hiring managers in the information security field prefer to recruit a security professional who has already proven HR skills._________________________
Question
A mandatory furlough provides the organization with the ability to audit the work of an individual._________________________
Question
SCP stands for Security Certified Program._________________________
Question
Security managers accomplish objectives identified by the CISO and resolve issues identified by technicians._________________________
Question
The most common qualification for the CISO type of position is the SSCP accreditation._________________________
Question
The ____ examination is designed to provide CISSPs with a mechanism to demonstrate competence in the more in-depth and concentrated requirements of information security management.

A)ISSMP
B)ISSAP
C)CISSPM
D)CISSMP
Question
Many organizations use a(n)____ interview to remind the employee of contractual obligations,such as nondisclosure agreements,and to obtain feedback on the employee's tenure in the organization.

A)hostile
B)departure
C)exit
D)termination
Question
System Administration,Networking,and Security Organization is better known as ____.

A)SANO
B)SAN
C)SANS
D)SANSO
Question
The SSCP exam consists of ____ multiple-choice questions,and must be completed within three hours.

A)75
B)100
C)125
D)225
Question
In recent years,the ____ certification program has added a set of concentration exams.

A)ISSEP
B)ISSMP
C)ISSAP
D)CISSP
Question
____ are the technically qualified individuals tasked to configure firewalls,deploy IDSs,implement security software,diagnose and troubleshoot problems,and coordinate with systems and network administrators to ensure that an organization's security technology is properly implemented.

A)CSOs
B)CISOs
C)Security managers
D)Security technicians
Question
The ____ program focuses more on building trusted networks,including biometrics and PKI.

A)NFC
B)SCNP
C)PKI
D)SCNA
Question
CISOs are ____________________ managers first.
Question
The __________________________________________________ acts as the spokesperson for the information security team.
Question
It is important to gather employee ____________________ early about the information security program and respond to it quickly.
Question
Once an information security function's organizational position has been determined,the challenge is to design a(n)____________________ structure for the information security function that balances the competing needs of each of the communities of interest.
Question
The applicant for the CISA must provide evidence of ____ years of professional work experience in the field of information security,with a waiver or substitution of up to two years for education or previous certification.

A)five
B)eight
C)ten
D)twelve
Question
____ is a cornerstone in the protection of information assets and in the prevention of financial loss.

A)Fire protection
B)Business separation
C)Separation of duties
D)Collusion
Question
____ is the requirement that every employee be able to perform the work of another employee.

A)Two-man control
B)Collusion
C)Duty exchange
D)Task rotation
Question
____ are hired by the organization to serve in a temporary position or to supplement the existing workforce.

A)Temporary employees
B)Consultants
C)Contractors
D)Self-employees
Question
The breadth and depth covered in each of the domains makes the ____ one of the most difficult-to-attain certifications on the market.

A)NSA
B)CISO
C)CISSP
D)ISEP
Question
The organization should conduct a behavioral feasibility study before the ____________________ phase.
Question
____ are the real techies who create and install security solutions.

A)Builders
B)Administrators
C)Senior managers
D)Definers
Question
The ____ position is typically considered the top information security officer in the organization.

A)CISO
B)CFO
C)CTO
D)CEO
Question
____ was designed to recognize mastery of an international standard for information security and a common body of knowledge (sometimes called the CBK).

A)CISSP
B)ISSMP
C)SSCP
D)All of the above
Question
Separation of ____________________ is used to reduce the chance of an individual violating information security and breaching the confidentiality,integrity,or availability of information.
Question
What tasks must be performed when an employee prepares to leave an organization?
Question
What functions does the CISO perform?
Question
Job ____________________ can greatly increase the chance that an employee's misuse of the system or abuse of the information will be detected by another.
Question
Related to the concept of separation of duties is that of ____________________,the requirement that two individuals review and approve each other's work before the task is categorized as finished.
Question
The SCP certification provides three tracks: the SCNS (Security Certified Network Specialist);the SCNP (Security Certified Network Professional);and the SCNA (Security Certified Network ____________________).
Question
____________________ departures include resignation,retirement,promotion,or relocation.
Question
Employees should be provided access to the minimal amount of information for the minimal amount of time necessary for them to perform their duties.This is referred to as the principle of ____________________.
Question
The ____________________________________________________________ certification requires both the successful completion of the examination and an endorsement by a qualified third party,typically another CISSP-certified professional,the candidate's employer,or a licensed,certified,or commissioned professional.
Question
SANS developed a series of technical security certifications in 1999 that are known as the Global Information ____________________ Certification or GIAC family of certifications.
Question
Describe the concept of separation of duties.
Question
Sometimes onsite contracted employees are self-employed or are employees of an organization hired for a specific,one-time purpose.These people are typically referred to as ____________________.
Question
Security ____________________ are accountable for the day-to-day operation of the information security program.
Question
The ____________________ of (ISC)² program is geared toward those who want to take the CISSP or SSCP exams before obtaining the requisite experience for certification.
Question
Once a candidate has accepted a job offer,the ____________________ becomes an important security instrument.
Question
The Information Systems ____________________ and Control Association offers the CISA certification for auditing,networking,and security professionals.
Question
A(n)"____________________ agency" is an agency that provides specifically qualified individuals at the paid request of another company.
Question
When new employees are introduced into the organization's culture and workflow,they should receive as part of their ____________________ an extensive information security briefing.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/78
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 11: Security and Personnel
1
Each CISSP concentration exam consists of 25 to 50 questions.
False
2
The SSCP covers ten domains.
False
3
Information security should be visible to the users.
False
4
The organization should integrate the security awareness education into a new hire's ongoing job orientation and make it a part of every employee's on-the-job security training.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
5
The use of standard job descriptions can increase the degree of professionalism in the information security field.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
6
In many organizations,information security teams lacks established roles and responsibilities.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
7
Organizations are not required by law to protect employee information that is sensitive or personal.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
8
To maintain a secure facility,all contract employees should be escorted from room to room,as well as into and out of the facility.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
9
All of the existing certifications are fully understood by hiring organizations.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
10
The process of integrating information security perspectives into the hiring process begins with reviewing and updating all job descriptions.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
11
The position of security technician can be offered as an entry-level position.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
12
The general management community of interest must work with the information security professionals to integrate solid information security concepts into the personnel management practices of the organization.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
13
Builders operate and administrate the security tools and the security monitoring function and continuously improve the processes,performing all the day-to-day work.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
14
ISSEP was developed under a joint agreement between the FBI and the United States National Security Agency,Information Assurance Directorate.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
15
The security manager position is much more general than that of CISO.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
16
In most cases,organizations look for a technically qualified information security generalist who has a solid understanding of how an organization operates.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
17
The information security function cannot be placed within protective services.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
18
Security managers are accountable for the day-to-day operation of the information security program.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
19
The SCNA track focuses on firewalls and intrusion detection.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
20
In the business world,background checks determine the individual's level of security classification,a requirement for many positions.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
21
A study of information security positions,done by Schwartz,Erwin,Weafer,and Briney,found that positions can be classified into one of ____ areas.

A)two
B)three
C)four
D)five
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
22
ISACA stands for Information Systems Automation and Control Association._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
23
GIAC stands for Global Information Architecture Certification._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
24
ISSAP stands for Information Systems Security Architecture Professional._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
25
The information security function can be placed within the ____.

A)insurance and risk management function
B)administrative services function
C)legal department
D)All of the above
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
26
The CISA certification is for information security management professionals._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
27
Many information security professionals enter the field from traditional ____ assignments.

A)HR
B)BA
C)IT
D)All of the above
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
28
____ are often involved in national security and cyber-security tasks and move from those environments into the more business-oriented world of information security.

A)Marketing managers
B)Military personnel
C)Business analysts
D)Lawyers
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
29
Friendly departures include termination for cause,permanent downsizing,temporary lay-off,or some instances of quitting._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
30
ISSMP stands for Information Systems Security Monitoring Professional._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
31
The general management community of interest must plan for the proper staffing for the information security function._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
32
Administrators provide the policies,guidelines and standards in the Schwartz,Erwin,Weafer,and Briney classification._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
33
ISSEP stands for Information Systems Security Expert Professional._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
34
Upper management should learn more about the budgetary needs of the information security function and the positions within it._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
35
The model used often by large organizations places the information security department within the ____ department.

A)management
B)information technology
C)financial
D)production
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
36
Many hiring managers in the information security field prefer to recruit a security professional who has already proven HR skills._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
37
A mandatory furlough provides the organization with the ability to audit the work of an individual._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
38
SCP stands for Security Certified Program._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
39
Security managers accomplish objectives identified by the CISO and resolve issues identified by technicians._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
40
The most common qualification for the CISO type of position is the SSCP accreditation._________________________
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
41
The ____ examination is designed to provide CISSPs with a mechanism to demonstrate competence in the more in-depth and concentrated requirements of information security management.

A)ISSMP
B)ISSAP
C)CISSPM
D)CISSMP
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
42
Many organizations use a(n)____ interview to remind the employee of contractual obligations,such as nondisclosure agreements,and to obtain feedback on the employee's tenure in the organization.

A)hostile
B)departure
C)exit
D)termination
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
43
System Administration,Networking,and Security Organization is better known as ____.

A)SANO
B)SAN
C)SANS
D)SANSO
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
44
The SSCP exam consists of ____ multiple-choice questions,and must be completed within three hours.

A)75
B)100
C)125
D)225
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
45
In recent years,the ____ certification program has added a set of concentration exams.

A)ISSEP
B)ISSMP
C)ISSAP
D)CISSP
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
46
____ are the technically qualified individuals tasked to configure firewalls,deploy IDSs,implement security software,diagnose and troubleshoot problems,and coordinate with systems and network administrators to ensure that an organization's security technology is properly implemented.

A)CSOs
B)CISOs
C)Security managers
D)Security technicians
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
47
The ____ program focuses more on building trusted networks,including biometrics and PKI.

A)NFC
B)SCNP
C)PKI
D)SCNA
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
48
CISOs are ____________________ managers first.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
49
The __________________________________________________ acts as the spokesperson for the information security team.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
50
It is important to gather employee ____________________ early about the information security program and respond to it quickly.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
51
Once an information security function's organizational position has been determined,the challenge is to design a(n)____________________ structure for the information security function that balances the competing needs of each of the communities of interest.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
52
The applicant for the CISA must provide evidence of ____ years of professional work experience in the field of information security,with a waiver or substitution of up to two years for education or previous certification.

A)five
B)eight
C)ten
D)twelve
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
53
____ is a cornerstone in the protection of information assets and in the prevention of financial loss.

A)Fire protection
B)Business separation
C)Separation of duties
D)Collusion
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
54
____ is the requirement that every employee be able to perform the work of another employee.

A)Two-man control
B)Collusion
C)Duty exchange
D)Task rotation
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
55
____ are hired by the organization to serve in a temporary position or to supplement the existing workforce.

A)Temporary employees
B)Consultants
C)Contractors
D)Self-employees
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
56
The breadth and depth covered in each of the domains makes the ____ one of the most difficult-to-attain certifications on the market.

A)NSA
B)CISO
C)CISSP
D)ISEP
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
57
The organization should conduct a behavioral feasibility study before the ____________________ phase.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
58
____ are the real techies who create and install security solutions.

A)Builders
B)Administrators
C)Senior managers
D)Definers
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
59
The ____ position is typically considered the top information security officer in the organization.

A)CISO
B)CFO
C)CTO
D)CEO
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
60
____ was designed to recognize mastery of an international standard for information security and a common body of knowledge (sometimes called the CBK).

A)CISSP
B)ISSMP
C)SSCP
D)All of the above
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
61
Separation of ____________________ is used to reduce the chance of an individual violating information security and breaching the confidentiality,integrity,or availability of information.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
62
What tasks must be performed when an employee prepares to leave an organization?
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
63
What functions does the CISO perform?
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
64
Job ____________________ can greatly increase the chance that an employee's misuse of the system or abuse of the information will be detected by another.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
65
Related to the concept of separation of duties is that of ____________________,the requirement that two individuals review and approve each other's work before the task is categorized as finished.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
66
The SCP certification provides three tracks: the SCNS (Security Certified Network Specialist);the SCNP (Security Certified Network Professional);and the SCNA (Security Certified Network ____________________).
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
67
____________________ departures include resignation,retirement,promotion,or relocation.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
68
Employees should be provided access to the minimal amount of information for the minimal amount of time necessary for them to perform their duties.This is referred to as the principle of ____________________.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
69
The ____________________________________________________________ certification requires both the successful completion of the examination and an endorsement by a qualified third party,typically another CISSP-certified professional,the candidate's employer,or a licensed,certified,or commissioned professional.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
70
SANS developed a series of technical security certifications in 1999 that are known as the Global Information ____________________ Certification or GIAC family of certifications.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
71
Describe the concept of separation of duties.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
72
Sometimes onsite contracted employees are self-employed or are employees of an organization hired for a specific,one-time purpose.These people are typically referred to as ____________________.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
73
Security ____________________ are accountable for the day-to-day operation of the information security program.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
74
The ____________________ of (ISC)² program is geared toward those who want to take the CISSP or SSCP exams before obtaining the requisite experience for certification.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
75
Once a candidate has accepted a job offer,the ____________________ becomes an important security instrument.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
76
The Information Systems ____________________ and Control Association offers the CISA certification for auditing,networking,and security professionals.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
77
A(n)"____________________ agency" is an agency that provides specifically qualified individuals at the paid request of another company.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
78
When new employees are introduced into the organization's culture and workflow,they should receive as part of their ____________________ an extensive information security briefing.
Unlock Deck
Unlock for access to all 78 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 78 flashcards in this deck.