Cyber Security Jobs Organizational Cyber Security 2 — Questions and Answers
Question 1: An organization wants a single document that defines acceptable use, access rules, and consequences for employees. Which artifact is this?
- Security policy (Correct answer)
- Network diagram
- Penetration test report
- Incident log
Correct answer: Security policy
A security policy formally defines acceptable use, access rules, and enforcement consequences.
Question 2: Which framework is most commonly used in the US to organize cybersecurity risk management across functions like Identify, Protect, Detect, Respond, and Recover?
- NIST Cybersecurity Framework (Correct answer)
- GDPR
- PCI forensic standard
- ITIL
Correct answer: NIST Cybersecurity Framework
The NIST CSF organizes risk management into Identify, Protect, Detect, Respond, and Recover.
Question 3: Separation of duties is primarily intended to reduce which risk?
- Fraud or error by a single individual (Correct answer)
- Slow internet speeds
- Hardware failure
- Software licensing costs
Correct answer: Fraud or error by a single individual
Splitting critical tasks among people prevents any one person from committing or hiding fraud.
Question 4: What is the main goal of a security awareness training program?
- Reduce human-error-based incidents like phishing (Correct answer)
- Replace antivirus software
- Eliminate the need for firewalls
- Increase server uptime
Correct answer: Reduce human-error-based incidents like phishing
Awareness training targets human behavior, the cause of most phishing and social-engineering incidents.
Question 5: A company classifies data as Public, Internal, Confidential, and Restricted. This practice is called:
- Data classification (Correct answer)
- Data deduplication
- Data masking
- Data sharding
Correct answer: Data classification
Data classification labels information by sensitivity to apply appropriate controls.
Question 6: Which role is typically accountable for the overall information security strategy in a large organization?
- Chief Information Security Officer (CISO) (Correct answer)
- Help desk technician
- Marketing director
- Database administrator
Correct answer: Chief Information Security Officer (CISO)
The CISO owns the enterprise information security strategy and program.
Question 7: What does the principle of least privilege require?
- Granting users only the access needed for their job (Correct answer)
- Giving all users admin rights
- Disabling all user accounts
- Sharing one account among staff
Correct answer: Granting users only the access needed for their job
Least privilege limits each user's access to only what their role requires.
An organization wants a single document that defines acceptable use, access rules, and consequences for employees.
Which artifact is this?