首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
admin
2013-12-19
100
问题
The following scenario applies to questions 29, 30, and 31.
Barry has just been hired as the company security officer at an international financial institution. He has reviewed the company’s data protection policies and procedures. He sees that the company stores its sensitive data within a secured database. The database is located in a network segment all by itself, which is monitored by a network-based intrusion detection system. The database is hosted on a server kept within a server room, which can only be accessed by personnel with the correct PIN value and smart card. Barry finds that the sensitive data backups are not being properly secured and requests that the company implement a secure courier service that moves backup tapes to a secured location. His management states that this option is too expensive, so Barry implements a local hierarchy storage management system that properly protects the sensitive data.
Which of the following best describes the control types the company originally had in place?
选项
A、Administrative preventive controls are the policies and procedures. Technical preventive controls are securing the system, network segmentation, and intrusion detection system. Physical detective controls are the physical location of the database and PIN and smart card access controls.
B、Administrative preventive controls are the policies. Technical preventive controls are securing the system and intrusion detection system. Physical preventive controls are the physical location of the database and PIN and smart card access controls.
C、Administrative corrective controls are the policies and procedures. Technical preventive controls are securing the system, network segmentation, and intrusion detection system. Physical preventive controls are the physical location of the database and PIN
D、Administrative preventive controls are the policies and procedures. Technical preventive controls are securing the system and network segmentation. The technical detective control is the intrusion detection system. Physical preventive controls are the phy
答案
D
解析
D正确。行政预防控制指的是政策和过程。技术预防控制是为了确保系统和网络部门的安全。技术检测控制指的是入侵检测系统,物理预防控制指的是数据库、PIN和智能卡访问控制的物理位置。
A不正确。因为入侵检测系统不是一种预防控制,这是一个检测控制的例子。保证恰当的预防控制和检测控制至关重要。
B不正确。因为这个选项是一个行政防御控制,它没有提到过程。这个答案也错误地将入侵检测系统描述为预防控制,而不是检测控制。
C不正确。因为这个答案错误地将入侵检测系统描述为一组预防控制,而不是检测控制。这个答案也描述了政策和过程是矫正控制,但是它们是预防控制。
转载请注明原文地址:https://kaotiyun.com/show/FNhZ777K
0
CISSP认证
相关试题推荐
Salt,shellsormetalsarestillusedasmoneyinout-the-waypartsoftheworldtoday.Saltmayseemratherastrange【C1】__
Themassmediaisabigpartofourculture,yetitcanalsobeahelper,adviserandteachertoouryounggeneration.Themass
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Thetranslatormusthaveanexcellent,up-to-dateknowledgeofhis【C1】______languages,fullfacilityinthehandlingofhistarg
Inthe1930s,anAmericanmeatcompanycameoutwithaspicedhamproductsoldinacan.Beforelong,Spam,asitwascalled,be
WhenGeorgeStephensonbuiltarailwayfromLiverpooltoManchesterinthe1820s,itcost45%morethanbudgetandwassubjectt
Thenewaircraftrepresentsa$250mbetbyBombardierthatMexicocouldprovidenotjustroutinelabourbutmanufacturingthat
Twentyyearsagoadebateeruptedaboutwhethertherewerespecific"Asianvalues".Butamoreintriguing,iflessnoticed,arg
Whichofthefollowingisconsideredthesecondgenerationofprogramminglanguages?
YouaretheadministratorofaSQLServer2000computer.Youarecreatingadatatransformationservicespackage.Asthefirsts
随机试题
下列属针叶树树种的是()。
根据发声时声带是否振动,可以把普通话辅音声母分为()
行政组织纵向分工的职责分配关系是:(1)最高层次的行政组织为___________;(2)中层行政组织为___________;(3)基层行政组织为___________。
A.季铵生物碱B.伯胺生物碱C.仲胺生物碱D.叔胺生物碱E.酰胺生物碱碱性最强的生物碱是()。
根据《标准施工招标文件》中对“通用合同条款”的解释,关于争议评审机制的说法,正确的有()。
甲公司2016年6月30日银行存款日记账余额为7500万元,银行对账单余额为9750万元。经核对存在下列账项:(1)银行计提公司存款利息180万元,公司尚未收到通知;(2)公司开出转账支票支付购料款2175万元,银行尚未办理入账手续;(3)公司收到转
华兴股份有限公司因经营管理不善造成亏损,未弥补的亏损达公司股本的1/4,公司董事长李某决定在2008年4月6日召开临时股东大会,讨论如何解决公司面临的困境,2008年4月1日,董事长李某发出召开2008年临时股东大会通知,内容如下,为讨论解决本公司面临的亏
红绿色盲的遗传方式是伴x染色体隐性遗传。已知一对夫妻都正常,他们的父母也正常,妻子的弟弟是色盲。则可预测该对夫妻的儿子为色盲的概率是()。
“他说你行,你不行也行;他说你不行,你行也不行。”这在哲学上属于()。
A、 B、 C、 B
最新回复
(
0
)