ITIL ITIL 4 Practitioner Information Security Management - ITIL 4 Practitioner Information Security Management Exam
Page: 3 / 4
Total 20 questions
Question #11 (Topic: Exam A)
A small organization is planning to migrate some of its IT systems from on-premise data centre to a major cloud service provider.
What should the organization do to ensure that their systems and data are adequately protected from information security threats?
What should the organization do to ensure that their systems and data are adequately protected from information security threats?
A. Keep all sensitive data on premise, migrate only non-critical systems
B. Employ a specialized service provider to protect the cloud-based data and systems
C. Update user agreements to transfer liability for possible data losses to the cloud service provider
D. Utilize information security capabilities offers by the cloud service provider and analyse the residual risks
Answer: D
Question #12 (Topic: Exam A)
An organization has implemented encryption with multi-factor authentication to protect sensitive data. It is still possible that the data might be leaked by someone with access to the encryption key.
What term is used to describe this possibility?
What term is used to describe this possibility?
A. Residual risk
B. Risk retention
C. Risk avoidance
D. Risk mitigation
Answer: A
Question #13 (Topic: Exam A)
An organization has created recovery plans for dealing with a number of different possible security breaches.
Which process activity will be used to validate that these plans are effective?
Which process activity will be used to validate that these plans are effective?
A. The ‘assess control effectiveness’ activity of the assessment and review process
B. The containment and recovery activity of the security incident management process
C. The ‘identify missing controls’ activity of the assessment and review process
D. The ‘define and agree information security controls and plans’ of the information security planning and implementation process
Answer: A
Question #14 (Topic: Exam A)
Which activity is performed by an information security manager?
A. Representing the organization in strategic conversations with regulators
B. Conducting information security training and education
C. Defining the balance between business performance and information security
D. Governing security management employees across the organization
Answer: B
Question #15 (Topic: Exam A)
An organization has very effective information security controls; its information security management plans are regularly tested. The information security team is working on integration of information security in all aspects of the organization, but this work has just begun.
Which capability level does this information security management practice demonstrate?
Which capability level does this information security management practice demonstrate?
A. Level 1
B. Level 2
C. Level 3
D. Level 4
Answer: C