首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
admin
2013-12-19
110
问题
The following scenario applies to questions 29, 30, and 31.
Barry has just been hired as the company security officer at an international financial institution. He has reviewed the company’s data protection policies and procedures. He sees that the company stores its sensitive data within a secured database. The database is located in a network segment all by itself, which is monitored by a network-based intrusion detection system. The database is hosted on a server kept within a server room, which can only be accessed by personnel with the correct PIN value and smart card. Barry finds that the sensitive data backups are not being properly secured and requests that the company implement a secure courier service that moves backup tapes to a secured location. His management states that this option is too expensive, so Barry implements a local hierarchy storage management system that properly protects the sensitive data.
Which are the two most common situations that require the type of control covered in the scenario to be implemented?
选项
A、Defense-in-depth is required, and the current controls only provide one protection layer.
B、Primary control costs too much or negatively affects business operations.
C、Confidentiality is the highest concern in a situation where defense-in-depth is required.
D、Availability is the highest concern in a situation where defense-in-depth is required.
答案
B
解析
B正确。之所以实施补偿控制,是因为提议的主要控制太昂贵了但仍然是必需的。所以需要确定和实施能提供相同类型的保护但较为便宜一点的控制。需要补偿控制的另一种情况就是主要控制会负面影响业务运营。
A不正确。因为尽管补偿控制可以提供深度防御,但它并不是这种类型的控制加以实施的原因。
C不正确。因为补偿控制可能会也可能不会提供保密性。但是控制提供的保密性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
D不正确。因为补偿控制可能会也可能不会提供可用性。但是控制提供的可用性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
转载请注明原文地址:https://kaotiyun.com/show/LNhZ777K
0
CISSP认证
相关试题推荐
AllSumeriancitiesrecognizedanumberofgodsincommon,includingtheskygod,thelordofstorms,andthemorningandevenin
Salt,shellsormetalsarestillusedasmoneyinout-the-waypartsoftheworldtoday.Saltmayseemratherastrange【C1】__
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Thecountry’sinadequatementalhealthsystemgetsthemostattentionafterinstancesofmassviolencethatthenationhasseen
[A]Butworkisunderwaytogetcomputerstocapturehumanlifeandrememberitaspeopledo—recallingbitsofexperiencethata
WhenGeorgeStephensonbuiltarailwayfromLiverpooltoManchesterinthe1820s,itcost45%morethanbudgetandwassubjectt
Writealettertooneofyourfriends,apologizingtohim/herforyourmakinghis/hercomputerstopworking.Youshouldwrite
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
YouaredoingyourUCLAapplicationforgraduateadmission,andyouneedtworeferenceletters.Pleaseemailyourformerforeign
"THESERVANT"(1963)isoneofthosefilmsthatitisimpossibletoforget.Theservantexploitshismaster’sweaknessesuntilh
随机试题
受刺激后,机体由活动状态转变为相对静止状态称为抑制。
S-R变异是指()
以下哪项不是糖尿病健康教育的内容()
A.去甲肾上腺素重摄取抑制剂B.5-HT重摄取抑制剂C.单胺氧化酶抑制剂D.硫杂蒽类抗精神病药E.吩噻嗪类抗精神失常药物阿米替林
工程项目施工应建立以( )为首的生产经营管理系统。
ABC公司是商业批发公司,经销的一种商品原信用政策为n/30,每天平均销量为20个,每个售价为75元,平均收账天数40天;公司销售人员提出了新的政策,以便促销,新的政策包括改变信用政策:“2/10,n/50”,同时以每个60元的价格销售,预计改变政策后每天
系统产生死锁的可能原因是()。
"Cool"isawordwithmanymeanings.Itstraditionalmeaningisusedto【C1】______atemperaturethatisfairlycool.Astheworld
Consumersandproducersobviouslymakedecisionsthatmoldtheeconomy,butthereisathirdmajor【C1】______toconsidertherole
Forthispart,youareallowed30minutestowriteashortessayentitledOfferingYourSeat-Youshouldstartwithabriefdesc
最新回复
(
0
)