Domain 5 Questions
- Which one of the following risk assessment activities does not require advanced authorization from the target organization?
A. Penetration testing
B. Open source reconnaissance
C. Social engineering
D. Vulnerability scanning
- Ryan is developing a security awareness training program and would like to include information about the person employees should approach if they need to clarify who may access different types of information. What role in an organization has this responsibility?
A. Privileged user
B. System owner
C. Data owner
D. Executive user
- Which one of the following statements is not true about security awareness programs?
A. Some categories of employee do not require any security training.
B. System administrators should receive specialized technical training.
C. Awareness training should be customized to a user's role in the organization.
D. Training updates should occur when there are significant new threats.
- Belinda is negotiating with an...