Information technology managers are often in a bind when a new exploit is discovered in
the wild. They can respond by updating the affected software or hardware with new code
provided by the manufacturer, which runs the risk that a flaw in the update will break the
system. Or they can wait until the new code has been extensively tested, but that runs the
risk that they will be compromised by the exploit during the testing period. Dealing with
these issues is referred to as
patch management.
Which of the following statements regarding COBIT is false?
COBIT is not sufficiently detailed to comply with SOX requirements.
In which of the COBIT domains would the activity “Define a strategic plan” reside?
Plan and Organize
In which of the COBIT domains would the activity “Ensure system security” reside?
Deliver and Support
This is an authorized attempt by an internal audit team or an external security consultant to
attempt to break into the organization’s information system.
Penetration test
When new employees are hired by Folding Squid Technologies, they are assigned user
names and passwords and provided with laptop computers that have an integrated
fingerprint reader. In order to log in, the user’s fingerprint must be recognized by the
reader. This is an example of a(an)
biometric device.
Which of the following preventive controls are necessary to provide adequate security for
social engineering threats?
Awareness training