EMT Practice Test

1. Question Content...


Question List

Question1: What is the definition of Risk in Information Security?

Question2: Risk appetite directly affects what part of a vulnerability management program?

Question3: Which of the following activities must be completed BEFORE you can calculate risk?

Question4: The process for identifying, collecting, and producing digital information in support of legal proceedings is called

Question5: Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost effectively?

Question6: What should an organization do to ensure that they have a sound Business Continuity (BC) Plan?

Question7: From an information security perspective, information that no longer supports the main purpose of the business should be:

Question8: What is one key difference between Capital expenditures and Operating expenditures?

Question9: A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be the CISO's FIRST priority?

Question10: Which of the following BEST describes an international standard framework that is based on the security model Information Technology-Code of Practice for Information Security Management?

Question11: Which of the following reports should you as an IT auditor use to check on compliance with a service level agreement's requirement for uptime?

Question12: Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization?

Question13: Which of the following is a symmetric encryption algorithm?

Question14: A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company's building dressed like an electrician and waits in the lobby for an employee to pass through the main access gate, then the consultant follows the employee behind to get into the restricted area. Which type of attack did the consultant perform?

Question15: Which technology can provide a computing environment without requiring a dedicated hardware backend?

Question16: Which of the following would negatively impact a log analysis of a multinational organization?

Question17: Which of the following is considered a project versus a managed process?

Question18: SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs.
The CISO discovers the scalability issue will only impact a small number of network segments. What is the next logical step to ensure the proper application of risk management methodology within the two-facto implementation project?

Question19: The total cost of security controls should:

Question20: Which represents PROPER separation of duties in the corporate environment?

Question21: An organization's Information Security Policy is of MOST importance because

Question22: A newly appointed security officer finds data leakage software licenses that had never been used. The officer decides to implement a project to ensure it gets installed, but the project gets a great deal of resistance across the organization. Which of the following represents the MOST likely reason for this situation?

Question23: When a CISO considers delaying or not remediating system vulnerabilities which of the following are MOST important to take into account?

Question24: What oversight should the information security team have in the change management process for application security?

Question25: Risk is defined as:

Question26: When should IT security project management be outsourced?

Question27: Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discover that many of the controls that were put in place the previous year to correct some of the findings are not performing as needed. You have thirty days until the briefing.
To formulate a remediation plan for the non-performing controls what other document do you need to review before adjusting the controls?

Question28: Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?

Question29: A company wants to fill a Chief Information Security Officer position in the organization. They need to define and implement a more holistic security program. Which of the following qualifications and experience would be MOST desirable to find in a candidate?

Question30: As the new CISO at the company you are reviewing the audit reporting process and notice that it includes only detailed technical diagrams. What else should be in the reporting process?

Question31: The exposure factor of a threat to your organization is defined by?

Question32: Human resource planning for security professionals in your organization is a:

Question33: Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?

Question34: Which of the following is considered the MOST effective tool against social engineering?

Question35: Which of the following are the triple constraints of project management?

Question36: A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server was disconnected. Who must be informed of this incident?

Question37: The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's

Question38: Which of the following is a common technology for visual monitoring?

Question39: Many times a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture.
What would be the BEST choice of security metrics to present to the BOD?

Question40: Who is responsible for securing networks during a security incident?

Question41: You are the Chief Information Security Officer of a large, multinational bank and you suspect there is a flaw in a two factor authentication token management process. Which of the following represents your BEST course of action?

Question42: After a risk assessment is performed, a particular risk is considered to have the potential of costing the organization 1.2 Million USD. This is an example of

Question43: The process of identifying and classifying assets is typically included in the

Question44: The general ledger setup function in an enterprise resource package allows for setting accounting periods.
Access to this function has been permitted to users in finance, the shipping department, and production scheduling. What is the most likely reason for such broad access?

Question45: The implementation of anti-malware and anti-phishing controls on centralized email servers is an example of what type of security control?

Question46: A key cybersecurity feature of a Personal Identification Verification (PIV) Card is:

Question47: Which type of scan is used on the eye to measure the layer of blood vessels?

Question48: What two methods are used to assess risk impact?

Question49: Which of the following illustrates an operational control process:

Question50: An organization has implemented a change management process for all changes to the IT production environment. This change management process follows best practices and is expected to help stabilize the availability and integrity of the organization's IT environment. Which of the following can be used to measure the effectiveness of this newly implemented process:

Question51: Which of the following is the MOST effective method for discovering common technical vulnerabilities within the IT environment?

Question52: The establishment of a formal risk management framework and system authorization program is essential. The LAST step of the system authorization process is:

Question53: The single most important consideration to make when developing your security program, policies, and processes is:

Question54: Quantitative Risk Assessments have the following advantages over qualitative risk assessments:

Question55: A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security control claims.
Which of the following vendor provided documents is BEST to make your decision:

Question56: Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?

Question57: A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?

Question58: The ability to demand the implementation and management of security controls on third parties providing services to an organization is

Question59: What is the BEST way to achieve on-going compliance monitoring in an organization?

Question60: Which of the following international standards can be BEST used to define a Risk Management process in an organization?

Question61: A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determine a modification to security controls in response to the threat. This is an example of:

Question62: In terms of supporting a forensic investigation, it is now imperative that managers, first-responders, etc., accomplish the following actions to the computer under investigation:

Question63: Which of the following most commonly falls within the scope of an information security governance steering committee?

Question64: A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate action should the information security manager take?

Question65: A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?

Question66: You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget.
Using the best business practices for project management you determine that the project correct aligns with the company goals. What needs to be verified FIRST?

Question67: Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the "real workers." Which group of people should be consulted when developing your security program?

Question68: Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.
When formulating the remediation plan, what is a required input?

Question69: What type of attack requires the least amount of technical equipment and has the highest success rate?

Question70: A method to transfer risk is to:

Question71: A security officer wants to implement a vulnerability scanning program. The officer is uncertain of the state of vulnerability resiliency within the organization's large IT infrastructure. What would be the BEST approach to minimize scan data output while retaining a realistic view of system vulnerability?

Question72: You work as a project manager for TYU project. You are planning for risk mitigation. You need to quickly identify high-level risks that will need a more in-depth analysis. Which of the following activities will help you in this?

Question73: Acme Inc. has engaged a third party vendor to provide 99.999% up-time for their online web presence and had them contractually agree to this service level agreement. What type of risk tolerance is Acme exhibiting?
(choose the BEST answer):

Question74: Dataflow diagrams are used by IT auditors to:

Question75: During the 3rd quarter of a budget cycle, the CISO noticed she spent more than was originally planned in her annual budget. What is the condition of her current budgetary posture?

Question76: As the Chief Information Security Officer, you are performing an assessment of security posture to understand what your Defense-in-Depth capabilities are. Which network security technology examines network traffic flows to detect and actively stop vulnerability exploits and attacks?

Question77: Scenario: Your company has many encrypted telecommunications links for their world-wide operations.
Physically distributing symmetric keys to all locations has proven to be administratively burdensome, but symmetric keys are preferred to other alternatives.
How can you reduce the administrative burden of distributing symmetric keys for your employer?

Question78: The PRIMARY objective for information security program development should be:

Question79: SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs.
The CISO is unsure of the information provided and orders a vendor proof of concept to validate the system's scalability. This demonstrates which of the following?

Question80: When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance level of the vendor?

Question81: A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?

Question82: Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?

Question83: At which point should the identity access management team be notified of the termination of an employee?

Question84: In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents the BEST choice to achieve situational awareness?

Question85: A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?

Question86: Your incident response plan should include which of the following?

Question87: Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?

Question88: An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System. Which of the following international standards can BEST assist this organization?

Question89: If the result of an NPV is positive, then the project should be selected. The net present value shows the present value of the project, based on the decisions taken for its selection. What is the net present value equal to?

Question90: Which of the following defines the boundaries and scope of a risk assessment?

Question91: When a critical vulnerability has been discovered on production systems and needs to be fixed immediately, what is the BEST approach for a CISO to mitigate the vulnerability under tight budget constraints?

Question92: Which of the following is an accurate statement regarding capital expenses?

Question93: What is the first thing that needs to be completed in order to create a security program for your organization?

Question94: Which of the following best describes an access control process that confirms the identity of the entity seeking access to a logical or physical area?

Question95: What is the MAIN reason for conflicts between Information Technology and Information Security programs?

Question96: Credit card information, medical data, and government records are all examples of:

Question97: Which of the following has the GREATEST impact on the implementation of an information security governance model?

Question98: When you develop your audit remediation plan what is the MOST important criteria?

Question99: How often should an environment be monitored for cyber threats, risks, and exposures?

Question100: A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?

Question101: Which of the following terms is used to describe countermeasures implemented to minimize risks to physical property, information, and computing systems?

Question102: Which of the following represents the HIGHEST negative impact resulting from an ineffective security governance program?

Question103: Which of the following can the company implement in order to avoid this type of security issue in the future?

Question104: An organization has a stated requirement to block certain traffic on networks. The implementation of controls will disrupt a manufacturing process and cause unacceptable delays, resulting in sever revenue disruptions.
Which of the following is MOST likely to be responsible for accepting the risk until mitigating controls can be implemented?

Question105: An information security department is required to remediate system vulnerabilities when they are discovered.
Please select the three primary remediation methods that can be used on an affected system.

Question106: With respect to the audit management process, management response serves what function?

Question107: Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discover that many of the controls that were put in place the previous year to correct some of the findings are not performing as needed. You have thirty days until the briefing.
To formulate a remediation plan for the non-performing controls what other document do you need to review before adjusting the controls?

Question108: A newly-hired CISO needs to understand the organization's financial management standards for business units and operations. Which of the following would be the best source of this information?

Question109: Which type of physical security control scan a person's external features through a digital video camera before granting access to a restricted area?

Question110: The security team has investigated the theft/loss of several unencrypted laptop computers containing sensitive corporate information. To prevent the loss of any additional corporate data it is unilaterally decided by the CISO that all existing and future laptop computers will be encrypted. Soon, the help desk is flooded with complaints about the slow performance of the laptops and users are upset. What did the CISO do wrong?
(choose the BEST answer):

Question111: What is meant by password aging?

Question112: The Annualized Loss Expectancy (Before) minus Annualized Loss Expectancy (After) minus Annual Safeguard Cost is the formula for determining:

Question113: SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
After determining the audit findings are accurate, which of the following is the MOST logical next activity?

Question114: Which of the following strategies provides the BEST response to a ransomware attack?

Question115: Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?