Preview a few questions below — answers are revealed when you take the
exam.
-
A multinational corporation is implementing a new enterprise resource planning (ERP) system. The project team needs to identify potential risks associated with the integration of the ERP system with existing legacy systems. What approach should they take to ensure a comprehensive risk assessment?
- Conduct a series of workshops with stakeholders to identify and document potential risks, followed by a quantitative risk analysis to prioritize these risks based on their likelihood and impact.
- Perform a gap analysis between the current state of the legacy systems and the requirements of the new ERP system, and then use this analysis to identify and mitigate integration risks.
- Utilize a risk management framework such as NIST SP 800-30 to guide the identification, assessment, and mitigation of risks associated with the ERP system integration.
- Implement a continuous monitoring program to detect and respond to integration risks in real-time as the ERP system is being deployed.
-
In the context of information security governance, which of the following best describes the role of a Chief Information Security Officer (CISO)?
- The CISO is responsible for developing and implementing the organization's information security policies, procedures, and standards.
- The CISO reports directly to the Chief Executive Officer (CEO) and is accountable for the overall security posture of the organization.
- The CISO oversees the day-to-day operations of the information security team and ensures that security incidents are promptly addressed.
- The CISO is primarily focused on the technical aspects of information security, such as firewall configuration and vulnerability management.
-
An organization is considering the adoption of a cloud-based software development platform. The IT governance committee needs to evaluate the potential risks and benefits of this decision. Which method solves it best?
- Conduct a cost-benefit analysis to compare the total cost of ownership (TCO) of the cloud-based platform against the expected benefits, such as increased agility and reduced capital expenditure.
- Perform a threat modeling exercise to identify and mitigate potential security risks associated with the cloud-based platform, such as data breaches and service disruptions.
- Engage with key stakeholders, including business units and IT operations, to gather their input and concerns regarding the adoption of the cloud-based platform.
- Review the service level agreements (SLAs) and compliance certifications of the cloud service provider to ensure that they meet the organization's requirements for security, reliability, and regulatory compliance.
-
Which option best evaluates the effectiveness of an organization's incident response plan?
- Conduct regular tabletop exercises and simulations to test the incident response team's ability to detect, respond to, and recover from security incidents.
- Review the incident response plan documentation to ensure that it aligns with industry best practices and regulatory requirements.
- Analyze the organization's historical incident data to identify trends, patterns, and areas for improvement in the incident response process.
- Perform a gap analysis between the current incident response capabilities and the desired state, as defined by the organization's risk appetite and tolerance.
-
How should a professional assess the maturity of an organization's information security program?
- Utilize a recognized information security maturity model, such as the Capability Maturity Model Integration (CMMI) or the NIST Cybersecurity Framework, to evaluate the organization's current security posture and identify areas for improvement.
- Conduct a series of interviews with key stakeholders, including business units, IT operations, and security teams, to gather their perspectives on the organization's information security program.
- Review the organization's information security policies, procedures, and standards to ensure that they are comprehensive, up-to-date, and aligned with industry best practices.
- Analyze the organization's historical security incident data to identify trends, patterns, and areas for improvement in the information security program.