9.1 Identify and explain controls designed to protect the confidentiality of
sensitive corporate information.
1) Identify the type of information below that is least likely to be considered
"sensitive" by an organizat
...
9.1 Identify and explain controls designed to protect the confidentiality of
sensitive corporate information.
1) Identify the type of information below that is least likely to be considered
"sensitive" by an organization.
A) financial statements
B) legal documents
C) strategic plans
D) product cost information
2) Which of the following is not one of the basic actions that an organization
must take to preserve the confidentiality of sensitive information?
A) identification of information to be protected
B) backing up the information
C) controlling access to the information
D) training
3) Classification of confidential information is the responsibility of whom,
according to COBIT5?
A) external auditor
B) information owner
C) IT security professionals
D) management
4) Encryption is one of the many ways to protect information in transit over
the internet.
Answer: FALSE
1
5) Classification of confidential information is the responsibility of whom,
according to COBIT5?
A) external auditor
B) information owner
C) IT security professionals
D) management
6) Encryption is a necessary part of which information security approach?
A) defense in depth
B) time based defense
C) cloud quarantine
D) synthetic defense
7) Information rights management software can do all of the following except
A) limiting access to specific files.
B) limit action privileges to a specific time period.
C) authenticate individuals accessing information.
D) specify the actions individuals granted access to information can perform.
8) Identify the first step in protecting the confidentiality of intellectual
property below.
A) Identifying who has access to the intellectual property
B) Identifying the means necessary to protect the intellectual property
C) Identifying the weaknesses surrounding the creation of the intellectual property
D) Identifying what controls should be placed around the intellectual property
9) After the information that needs to be protected has been identified, what
step should be completed next?
A) The information needs to be placed in a secure, central area.
B) The information needs to be encrypted.
C) The information needs to be classified in terms of its value to the
organization.
D) The information needs to be depreciated.
[Show More]