Question: Security Assessment and Testing QUESTION 21 What is a key performance indicator (KPI)? a. A derived value that is generated by comparing multiple measurements against
Security Assessment and Testing
QUESTION 21
What is a key performance indicator (KPI)?
| a. | A derived value that is generated by comparing multiple measurements against each other or against a baseline | |
| b. | An interpretation of one or more metrics that describes the effectiveness of the ISMS | |
| c. | The value of a factor at a particular point in time | |
| d. | Any attribute of the ISMS that can be described as a value |
3.85 points
QUESTION 22
Which of the following is an advantage of using third-party auditors?
| a. | The requirement for NDAs and supervision. | |
| b. | They may have knowledge that an organization wouldnt otherwise be able to leverage. | |
| c. | Their cost. | |
| d. | Their use of automated scanners and reports. |
3.85 points
QUESTION 23
An assessment whose goal is to assess the susceptibility of an organization to social engineering attacks is best classified as
| a. | Personnel testing | |
| b. | Vulnerability testing | |
| c. | Physical testing | |
| d. | Network testing |
3.85 points
QUESTION 24
How might one test adherence to the user accounts policy?
| a. | User records auditing | |
| b. | User self-reporting | |
| c. | Penetration testing | |
| d. | Management review |
3.85 points
QUESTION 25
Code reviews include all the following except which one?
| a. | Fuzzing the code | |
| b. | Ensuring the code conforms to applicable coding standards | |
| c. | Agreeing on a disposition for the code | |
| d. | Discussing bugs, design issues, and anything else that comes up about the code |
3.85 points
QUESTION 26
Data backup verification efforts should
| a. | Focus on user data | |
| b. | Be based on the threats to the organization | |
| c. | Have the smallest scope possible | |
| d. | Maximize impact on business |
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
