5. Risk Management

Domain 5 Questions

  1. Which one of the following risk assessment activities does not require advanced authorization from the target organization?

    A. Penetration testing

    B. Open source reconnaissance

    C. Social engineering

    D. Vulnerability scanning

  2. Ryan is developing a security awareness training program and would like to include information about the person employees should approach if they need to clarify who may access different types of information. What role in an organization has this responsibility?

    A. Privileged user

    B. System owner

    C. Data owner

    D. Executive user

  3. Which one of the following statements is not true about security awareness programs?

    A. Some categories of employee do not require any security training.

    B. System ...

Get Security+® Practice Tests now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.