首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
admin
2013-12-19
64
问题
The following scenario applies to questions 29, 30, and 31.
Barry has just been hired as the company security officer at an international financial institution. He has reviewed the company’s data protection policies and procedures. He sees that the company stores its sensitive data within a secured database. The database is located in a network segment all by itself, which is monitored by a network-based intrusion detection system. The database is hosted on a server kept within a server room, which can only be accessed by personnel with the correct PIN value and smart card. Barry finds that the sensitive data backups are not being properly secured and requests that the company implement a secure courier service that moves backup tapes to a secured location. His management states that this option is too expensive, so Barry implements a local hierarchy storage management system that properly protects the sensitive data.
Which of the following best describes the control types the company originally had in place?
选项
A、Administrative preventive controls are the policies and procedures. Technical preventive controls are securing the system, network segmentation, and intrusion detection system. Physical detective controls are the physical location of the database and PIN and smart card access controls.
B、Administrative preventive controls are the policies. Technical preventive controls are securing the system and intrusion detection system. Physical preventive controls are the physical location of the database and PIN and smart card access controls.
C、Administrative corrective controls are the policies and procedures. Technical preventive controls are securing the system, network segmentation, and intrusion detection system. Physical preventive controls are the physical location of the database and PIN
D、Administrative preventive controls are the policies and procedures. Technical preventive controls are securing the system and network segmentation. The technical detective control is the intrusion detection system. Physical preventive controls are the phy
答案
D
解析
D正确。行政预防控制指的是政策和过程。技术预防控制是为了确保系统和网络部门的安全。技术检测控制指的是入侵检测系统,物理预防控制指的是数据库、PIN和智能卡访问控制的物理位置。
A不正确。因为入侵检测系统不是一种预防控制,这是一个检测控制的例子。保证恰当的预防控制和检测控制至关重要。
B不正确。因为这个选项是一个行政防御控制,它没有提到过程。这个答案也错误地将入侵检测系统描述为预防控制,而不是检测控制。
C不正确。因为这个答案错误地将入侵检测系统描述为一组预防控制,而不是检测控制。这个答案也描述了政策和过程是矫正控制,但是它们是预防控制。
转载请注明原文地址:https://kaotiyun.com/show/FNhZ777K
0
CISSP认证
相关试题推荐
Themassmediaisabigpartofourculture,yetitcanalsobeahelper,adviserandteachertoouryounggeneration.Themass
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Thecountry’sinadequatementalhealthsystemgetsthemostattentionafterinstancesofmassviolencethatthenationhasseen
Individualsandbusinesseshavelegalprotectionforintellectualpropertytheycreateandown.Intellectualproper【C1】______fro
Thetranslatormusthaveanexcellent,up-to-dateknowledgeofhis【C1】______languages,fullfacilityinthehandlingofhistarg
TimeintheAnimalWorldRhythmcontrolseverythinginNature.41Thesunprovidesabasictimerhythmforalllivingcr
Fastingglucose(葡萄糖)andinsulin(胰岛素)levelsremainwithinnormalrangeforwomenusinginjectableororalcontraception,withonl
Writealettertoacompanydecliningajoboffer.Inyourletter,youshouldappreciatethejoboffer,andstateyourreason(s)
"Thisisareallyexcitingtime—aneweraisstarting,"saysPeterBazalgette,thechiefcreativeofficerofEndemol,thetelev
"THESERVANT"(1963)isoneofthosefilmsthatitisimpossibletoforget.Theservantexploitshismaster’sweaknessesuntilh
随机试题
正常呼气末,肺内的气体量相当于
甲在国外旅游,见有人兜售高仿真人民币,用1万元换取10万元假币,将假币夹在书中寄回国内。(事实一)赵氏调味品公司欲设加盟店,销售具有注册商标的赵氏调味品,派员工赵某物色合作者。甲知道自己不符加盟条件,仍找到赵某送其2万元真币和10万元假币,请其帮
甲公司与乙公司发生纠纷向工商局申请公开乙公司的工商登记信息。该局公开了乙公司的名称、注册号、住所、法定代表人等基本信息,但对经营范围、从业人数、注册资本等信息拒绝公开。甲公司向法院起诉,法院受理。关于此事,下列哪一说法是正确的?
桥梁静载试验中,某挠度测点的初始值为0.02mm,试验控制荷载作用下的加载测值为4.22mm,卸载后测值为0.22mm,计算挠度为5.00mm,则挠度校验系数为()。
建设单位在施工阶段进行施工质量控制的目标是()。
某零售企业在十几年的经营中通过对国内外零售企业进行考察学习,并不断对自身经验进行总结,制定出一套科学成功的选址程序:在每开设一家新店前,都要利用一年左右的时间对所在区域的人员构成、消费水平、人口增长、居住条件、消费者兴趣爱好、高收入人群比例等进行细致的市场
詹姆士的自尊公式是()
TheissueofonlineprivacyintheInternetagefoundnewurgencyfollowingtheSept.11terroristattacks,sparkingdebateover
Howlonghasthemagazinebeenonsale?WhichkindofpeopledoesAlexBakerprefertoworkwith?
Imaginingbeingaskedtospendtwelveorsoyearsofyourlifeinasocietywhich【B1】_____onlyofmembersofyourownsex,how
最新回复
(
0
)