00:00

QUESTION 36

Which of the following is MOST important to ensuring information stored by an organization is protected appropriately?

Correct Answer: C

QUESTION 37

Which of the following is the MOST important criterion when deciding whether to accept residual risk?

Correct Answer: A

QUESTION 38

Which of the following BEST ensures timely and reliable access to services?

Correct Answer: C

QUESTION 39

Which of the following will provide the MOST guidance when deciding the level of protection for an information asset?

Correct Answer: C
When deciding the level of protection for an information asset, the most important factor to consider is the impact to the business function. The value of the asset should be evaluated in terms of its importance to the organization's operations and how its security posture affects the organization's overall security posture. Additionally, the cost of implementing controls, the potential impact on the information security program, and the cost to replace the asset should be taken into account when determining the appropriate level of protection for the asset.

QUESTION 40

Which of the following is the MOST effective way to help staff members understand their responsibilities for information security?

Correct Answer: B