EMT Practice Test
1. Question Content...
Question1: What is the definition of Risk in Information Security?
Question2: Risk appetite directly affects what part of a vulnerability management program?
Question3: Which of the following activities must be completed BEFORE you can calculate risk?
Question8: What is one key difference between Capital expenditures and Operating expenditures?
Question13: Which of the following is a symmetric encryption algorithm?
Question17: Which of the following is considered a project versus a managed process?
Question19: The total cost of security controls should:
Question20: Which represents PROPER separation of duties in the corporate environment?
Question21: An organization's Information Security Policy is of MOST importance because
Question25: Risk is defined as:
Question26: When should IT security project management be outsourced?
Question31: The exposure factor of a threat to your organization is defined by?
Question32: Human resource planning for security professionals in your organization is a:
Question34: Which of the following is considered the MOST effective tool against social engineering?
Question35: Which of the following are the triple constraints of project management?
Question38: Which of the following is a common technology for visual monitoring?
Question40: Who is responsible for securing networks during a security incident?
Question43: The process of identifying and classifying assets is typically included in the
Question46: A key cybersecurity feature of a Personal Identification Verification (PIV) Card is:
Question47: Which type of scan is used on the eye to measure the layer of blood vessels?
Question48: What two methods are used to assess risk impact?
Question49: Which of the following illustrates an operational control process:
Question59: What is the BEST way to achieve on-going compliance monitoring in an organization?
Question70: A method to transfer risk is to:
Question74: Dataflow diagrams are used by IT auditors to:
Question78: The PRIMARY objective for information security program development should be:
Question86: Your incident response plan should include which of the following?
Question90: Which of the following defines the boundaries and scope of a risk assessment?
Question92: Which of the following is an accurate statement regarding capital expenses?
Question96: Credit card information, medical data, and government records are all examples of:
Question98: When you develop your audit remediation plan what is the MOST important criteria?
Question99: How often should an environment be monitored for cyber threats, risks, and exposures?
Question106: With respect to the audit management process, management response serves what function?
Question111: What is meant by password aging?
Question114: Which of the following strategies provides the BEST response to a ransomware attack?