Module 02 Control Mechanisms, Standards and Frameworks
Which of the following ISO framework provides requirements for an information security management system and focuses on managing information security within an organization? 27701 31000 27001 27002
27001
Which of the following standards provide guidelines for hardening a Webserver? Cloud Control Matrix (CCM) Statements on Standards for Attestation Engagements (SSAE) International Organization for Standardization (ISO) Center for Internet Security (CIS)
Center for Internet Security (CIS)
Which type of control identifies a security risk that might be present in a policy, process, or procedure? Preventative Compensating Detective Deterrent Corrective
Detective
Which of the following are examples of technical control? [Choose all that apply] Dead-bolted steel doors A non-disclosure agreement (NDA) Firewall Router Alarm systems
Firewall Router
Which of the following standard/law focuses on protecting the financial non-public information? Federal Information Security Management Act (FISMMA) Health Insurance Portability and Accountability Act (HIPAA) US Privacy Act of 1974 GRAMM-LEACH-BILLEY ACT (GLBA)
GRAMM-LEACH-BILLEY VACT (GLBA)