The entity that is ultimately responsible for security governance is:
CISM Chapter 1

Quiz
•
Professional Development
•
Professional Development
•
Hard

Anna Löfgren
Used 9+ times
FREE Resource
10 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Chief information officer
Chief information security officer
Board of directors
Chief risk officer
Answer explanation
Correct answer:
"Board of directors"
The organization’s board of directors is ultimately responsible for security
governance.
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
An acceptable use policy is likely to contain all of the following except:
Rules regarding the use of personally owned assets
Permitted uses of corporate assets
Data retention requirements
Protection of sensitive information
Answer explanation
Correct answer:
"Data retention requirements"
An acceptable use policy (AUP) is likely to contain statements about the use
of corporate assets, personally owned assets, and information protection. Data
retention requirements are not likely to be included.
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
The best definition of governance is:
Corporate policies and procedures
Management control of business functions
Regular reporting of metrics and key performance indicators (KPIs)
Formal roles and responsibilities documented in a RACI chart
Answer explanation
Correct answer:
"Management control of business functions"
Governance is best defined as management’s control over business functions
throughout an organization.
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Under what circumstances would an organization elect to disregard a regulation and pay fines instead of complying?
The cost of the fines is less than the cost of compliance.
The cost of compliance is less than the cost of fines.
Management elected to transfer the risk.
Management elected to avoid the risk.
Answer explanation
Correct answer:
"The cost of the fines is less than the cost of compliance."
While choosing to pay fines in lieu of compliance is uncommon, it is the best answer among the choices listed.
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A database administrator (DBA) is typically responsible for all of the following except which one?
Database performance tuning
Database troubleshooting
Database capacity management
Database design
Answer explanation
Correct answer:
"Database design"
The role of database design is generally shared between the DBA and software developers/architects or is owned entirely by software developers or architects.
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the most appropriate person or group to determine applicability of a cybersecurity-related regulation?
Chief information security officer (CISO)
Chief legal counsel
Chief information risk officer (CIRO)
Security governance committee
Answer explanation
Correct answer:
"Chief legal counsel"
Only legal counsel should be determining applicability of potentially relevant laws and regulations.
None of the other is an appropriate party to interpret regulations.
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A business executive has delegated responsibility for granting access requests to the IT department. The IT department in this role is functioning as the:
Accountable
Owner
Custodian
User
Answer explanation
Correct answer is:
"Custodian"
IT is acting as a custodian in the access request process for the business application.
The business executive remains accountable for the operation. The business executive continues in the role of the system owner. IT is not the user.
Create a free account and access millions of resources
Similar Resources on Quizizz
10 questions
Military Must-Know-Words 1 - 10 (Quiz 2)

Quiz
•
Professional Development
12 questions
Practical Guide to CMMI for Development V2.0 - Assessment

Quiz
•
Professional Development
11 questions
Intro to Resume Writing

Quiz
•
Professional Development
10 questions
Searching and Applying for a Job

Quiz
•
Professional Development
10 questions
GTP Challenge - Analyst Coverage

Quiz
•
Professional Development
10 questions
SQ Smart Quiziz November 2024

Quiz
•
Professional Development
14 questions
CRISC Domain 1 MCQ

Quiz
•
Professional Development
12 questions
CyberSecurity

Quiz
•
Professional Development
Popular Resources on Quizizz
15 questions
Multiplication Facts

Quiz
•
4th Grade
20 questions
Math Review - Grade 6

Quiz
•
6th Grade
20 questions
math review

Quiz
•
4th Grade
5 questions
capitalization in sentences

Quiz
•
5th - 8th Grade
10 questions
Juneteenth History and Significance

Interactive video
•
5th - 8th Grade
15 questions
Adding and Subtracting Fractions

Quiz
•
5th Grade
10 questions
R2H Day One Internship Expectation Review Guidelines

Quiz
•
Professional Development
12 questions
Dividing Fractions

Quiz
•
6th Grade