Security CHP 4

Réussis tes devoirs et examens dès maintenant avec Quizwiz!

The Children's Online Privacy Protection Act (COPPA) restricts the collection of information online from children. What is the cutoff age for COPPA regulation?

13

Which one of the following is the best example of an authorization control?

Access control lists

Tom is the IT manager for an organization that experienced a server failure that affected a single business function. What type of plan should guide the organization's recovery effort?

Business continuity plan (BCP)

Which item in a Bring Your Own Device (BYOD) policy helps resolve intellectual property issues that may arise as the result of business use of personal devices?

Data ownership

Dawn is selecting an alternative processing facility for her organization's primary data center. She would like to have a facility that balances cost and switchover time. What would be the best option in this situation?

Warm site

What is the first step in a disaster recovery effort?

Ensure that everyone is safe.

Which one of the following is an example of a direct cost that might result from a business disruption?

Facility repair

What compliance regulation applies specifically to the educational records maintained by schools about students?

Family Education Rights and Privacy Act (FERPA)

Betsy recently assumed an information security role for a hospital located in the United States. What compliance regulation applies specifically to healthcare providers?

HIPAA

Which one of the following is an example of a reactive disaster recovery control?

Moving to a warm site

What is NOT a commonly used endpoint security technique?

Network firewall

What level of technology infrastructure should you expect to find in a cold site alternative data center facility?

No technology infrastructure

Holly would like to run an annual major disaster recovery test that is as thorough and realistic as possible. She also wants to ensure that there is no disruption of activity at the primary site. What option is best in this scenario?

Parallel test

A hospital is planning to introduce a new point-of-sale system in the cafeteria that will handle credit card transactions. Which one of the following governs the privacy of information handled by those point-of-sale terminals?

Payment Card Industry Data Security Standard (PCI DSS)

Alan is developing a business impact assessment for his organization. He is working with business units to determine the maximum allowable time to recover a particular function. What value is Alan determining?

Recovery time objective (RTO)

Which formula is typically used to describe the components of information security risks?

Risk = Threat X Vulnerability

George is the risk manager for a U.S. federal government agency. He is conducting a risk assessment for that agency's IT risk. What methodology is best suited for George's use?

Risk Management Guide for Information Technology Systems (NIST SP800-30)

Earl is preparing a risk register for his organization's risk management program. Which data element is LEAST likely to be included in a risk register?

Risk survey results

What is NOT one of the three tenets of information security?

Safety

As a follow-up to her annual testing, Holly would like to conduct quarterly disaster recovery tests that introduce as much realism as possible but do not require the use of technology resources. What type of test should Holly conduct?

Simulation test


Ensembles d'études connexes

Evaluating the Six Trigonometric Functions

View Set

Area and Perimeter of triangles and quadrilaterals CPM Area Review (6th Grade CC1)

View Set

Antipsychotic Drugs for HESI Comp

View Set

Writing Workshop: Effective Professional Communication

View Set

NUR 232 Pharm EAQ - Chapter 101: Basic Principles of Cancer Chemotherapy

View Set

Unit 3: Nutrition Essentials 3rd Edition

View Set

CND - Module 2 Threats and attacks

View Set