00:00

QUESTION 106

- (Exam Topic 1)
Quantitative Risk Assessments have the following advantages over qualitative risk assessments:

Correct Answer: A

QUESTION 107

- (Exam Topic 5)
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
The CISO has validated audit findings, determined if compensating controls exist, and started initial remediation planning. Which of the following is the MOST logical next step?

Correct Answer: C

QUESTION 108

- (Exam Topic 5)
Which of the following is MOST useful when developing a business case for security initiatives?

Correct Answer: C

QUESTION 109

- (Exam Topic 1)
Which of the following is a benefit of information security governance?

Correct Answer: D

QUESTION 110

- (Exam Topic 5)
The rate of change in technology increases the importance of:

Correct Answer: D