EMT Practice Test

1. Question Content...


Question List

Question1: A security manager for a large company has the task to achieve physical protection for corporate data stores.
Through which control can physical protection be achieved?

Question2: When should information security controls be considered?

Question3: When is revision of an employee's access rights mandatory?

Question4: It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?

Question5: An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.
Which is the main risk of PKI?

Question6: A security architect argues with the internal fire prevention team about the statement in the information security policy, that doors to confidential areas should be locked at all times. The emergency response team wants to access to those areas in case of fire.
What is the best solution to this dilemma?

Question7: In a company the IT strategy is migrating towards a Service Oriented Architecture (SOA) so that migrating to the cloud is better feasible in the future. The security architect is asked to make a first draft of the security architecture.
Which elements should the security architect draft?

Question8: Which security item is designed to take collections of data from multiple computers?

Question9: The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?

Question10: The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?