首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
admin
2013-12-19
67
问题
The following scenario applies to questions 29, 30, and 31.
Barry has just been hired as the company security officer at an international financial institution. He has reviewed the company’s data protection policies and procedures. He sees that the company stores its sensitive data within a secured database. The database is located in a network segment all by itself, which is monitored by a network-based intrusion detection system. The database is hosted on a server kept within a server room, which can only be accessed by personnel with the correct PIN value and smart card. Barry finds that the sensitive data backups are not being properly secured and requests that the company implement a secure courier service that moves backup tapes to a secured location. His management states that this option is too expensive, so Barry implements a local hierarchy storage management system that properly protects the sensitive data.
Which are the two most common situations that require the type of control covered in the scenario to be implemented?
选项
A、Defense-in-depth is required, and the current controls only provide one protection layer.
B、Primary control costs too much or negatively affects business operations.
C、Confidentiality is the highest concern in a situation where defense-in-depth is required.
D、Availability is the highest concern in a situation where defense-in-depth is required.
答案
B
解析
B正确。之所以实施补偿控制,是因为提议的主要控制太昂贵了但仍然是必需的。所以需要确定和实施能提供相同类型的保护但较为便宜一点的控制。需要补偿控制的另一种情况就是主要控制会负面影响业务运营。
A不正确。因为尽管补偿控制可以提供深度防御,但它并不是这种类型的控制加以实施的原因。
C不正确。因为补偿控制可能会也可能不会提供保密性。但是控制提供的保密性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
D不正确。因为补偿控制可能会也可能不会提供可用性。但是控制提供的可用性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
转载请注明原文地址:https://kaotiyun.com/show/LNhZ777K
0
CISSP认证
相关试题推荐
Nano-sizedtoothbrushesthatcancleanverysmallsurfaceshavebeendevelopedbyresearchers.Fabricatedoutofmillionsofcar
Menandwomendothinkdifferently,atleastwheretheanatomyofthebrainisconcerned,accordingtoanewstudy.Thebrainis
[A]Whattodoasastudent?[B]Variousdefinitionsofplagiarism[C]Ideasshouldalwaysbesourced[D]Ignorancecanbeforgi
[A]Marketforglasscraftsisgrowing[B]Dependenceofcomputerdevelopmentonglass[C]Behindtheadaptabilityofglass[D]
APerpetualMotionMachineisafascinatingandlong-discussedtopicthatmoveswellbeyondthescopeofphysics.Inshort,Ape
Writeanessayof160~200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
Writeanessayof160-200wordsbasedonthefollowingdrawings.Inyouressay,youshould1)describethedrawingsbriefly,
Howmenfirstlearnedtoinventwordsisunknown;inotherwords,theoriginoflanguageisamystery.Allwereallyknowistha
Inarareunanimousruling,theUSSupremeCourthasoverturnedthecorruptionconvictionofaformerVirginiagovernor,Robert
Advertisingwasjustonebusinessmodelthatpeopleconsideredatthestart.Googleoriginallythoughtmaybe15percentofthe
随机试题
与维生素B12吸收有关的内因子是由胃黏膜中的
诱发皮肤变态反应的结核菌菌体部分为
患者,男性,68岁。高血压病史5年,多次测血压170~190/90mmHg。眼底Ⅲ级。该患者可能的诊断是
中重度营养不良患儿腹泻时,哪项表现不易出现
甲公司是上市公司。2×17年9月,甲公司董事会审议同意以3000万元的价格收购乙公司70%股权的议案。2×17年9月15日,甲公司与乙公司原股东签订《股权转让协议》,约定以2×17年8月31日为股权收购基准日,上市公司有权享有乙公司于基准日之后的利润,并承
面质技术是指咨询师指出求助者的(),最终促成求助者的统一。
近年来,我国中小学音乐课程在许多地区还是没有受到足够的重视,教材内容不能与时俱进,一些音乐教师只注重技能培养而忽略了音乐教育的主旨首先应当是“树德立志”。在教授学生一部音乐作品之前,教师首先应该理解其中所表现的道德思想,然后以多样化的形式对学生的身心进行正
认识活动经过的两次飞跃,其中认识辨证过程的第二次飞跃比第一次飞跃更为重要,下列活动属于认识的第二次飞跃的是
有以下程序main(){inti:10,j=1;printf("%d,%d\n",i--,++j);}执行后输出结果是
TheBushcrowdbristlesattheuseofthe"Q-word"—quagmire(沼泽)—todescribeAmericaninvolvementinIraq.Butwithoursoldiers
最新回复
(
0
)