首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
The following scenario applies to questions 29, 30, and 31. Barry has just been hired as the company security officer at an inte
admin
2013-12-19
72
问题
The following scenario applies to questions 29, 30, and 31.
Barry has just been hired as the company security officer at an international financial institution. He has reviewed the company’s data protection policies and procedures. He sees that the company stores its sensitive data within a secured database. The database is located in a network segment all by itself, which is monitored by a network-based intrusion detection system. The database is hosted on a server kept within a server room, which can only be accessed by personnel with the correct PIN value and smart card. Barry finds that the sensitive data backups are not being properly secured and requests that the company implement a secure courier service that moves backup tapes to a secured location. His management states that this option is too expensive, so Barry implements a local hierarchy storage management system that properly protects the sensitive data.
Which are the two most common situations that require the type of control covered in the scenario to be implemented?
选项
A、Defense-in-depth is required, and the current controls only provide one protection layer.
B、Primary control costs too much or negatively affects business operations.
C、Confidentiality is the highest concern in a situation where defense-in-depth is required.
D、Availability is the highest concern in a situation where defense-in-depth is required.
答案
B
解析
B正确。之所以实施补偿控制,是因为提议的主要控制太昂贵了但仍然是必需的。所以需要确定和实施能提供相同类型的保护但较为便宜一点的控制。需要补偿控制的另一种情况就是主要控制会负面影响业务运营。
A不正确。因为尽管补偿控制可以提供深度防御,但它并不是这种类型的控制加以实施的原因。
C不正确。因为补偿控制可能会也可能不会提供保密性。但是控制提供的保密性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
D不正确。因为补偿控制可能会也可能不会提供可用性。但是控制提供的可用性方面的服务并不是实施补偿控制的原因。补偿控制是一种替换控制类型。
转载请注明原文地址:https://kaotiyun.com/show/LNhZ777K
0
CISSP认证
相关试题推荐
About3billionpeoplelivewithin100milesofthesea,anumberthatcoulddoubleinthenextdecadeashumansflocktocoasta
[A]Thefirststepinpreparingamarketingplanisthatofproducingtheinformationnecessaryfordecision-making.Usually,a
[A]Thefirststepinpreparingamarketingplanisthatofproducingtheinformationnecessaryfordecision-making.Usually,a
[A]Whattodoasastudent?[B]Variousdefinitionsofplagiarism[C]Ideasshouldalwaysbesourced[D]Ignorancecanbeforgi
Writealettertoamuseum’sstafftoaskforsomeinformationaboutahistoricalexhibition.Youshouldincludethedetailsyou
Youarethepresidentofacompany.WriteamemotoSallyCooper,theHRmanagerontheemployeestrainingoncomputerto,1
Thateveryone’stoobusythesedaysisacliche.Butonespecificcomplaintismadeespeciallymournfully:There’sneveranytim
Theconceptofmanversusmachineisatleastasoldastheindustrialrevolution,butthisphenomenontendstobemostacutely
RobertF.Kennedyoncesaidthatacountry’sGDPmeasures"everythingexceptthatwhichmakeslifeworthwhile".WithBritainv
YouhavelosttheoriginalofyourundergraduatediplomainBusinessAdministration.Writealettertothesecretaryofthedepa
随机试题
()是政府的基本财政收支计划。
目前,我国证券交易实行全额保证金制度,因此,证券登记结算机构不会发生流动性风险。()
甲企业2017年初房产原值4000万元,其中厂房原值2500万元,办公楼原值1400万元,厂办学校原值100万元,该企业2017年发生下列业务:(1)12月办理一处委托施工企业建造仓库的验收手续,按照建筑合同支付款项50万元,已转作固定资产管理,
在财务报表审计中,管理层和治理层(如适用)责任不包括()。
法治的核心是:制约国家权力的滥用、保障公民的自由权利。()
关键个案抽样指的是选择那些可以对事情产生决定性影响的个案进行的研究。目的是将这些个案中获得的结果逻辑地推论至其他个案。下列属于关键个案抽样的是()。
下列选项所列的情形中,应当依法享有继承权的是()。
TheFeverofPhilosophyDiscussionThere’sabuzzintheairattheElDiabloCoffeeCo,inSeattle,andit’s,notjustcomi
A、 B、 C、 A学校放学了,孩子们正在往家走。图片[A]符合题意。
ReviewingthedecadethatfollowedWorldWarn,Cartwrightspeaksofthe"excitementandoptimism"ofAmericansocialpsycholo
最新回复
(
0
)