When the impact severity is classified as significant and the vulnerability is judged to be medium,
what should happen to controls?
Controls should be improved.
Controls should be kept intact.
Controls must be improved.
The certification that requires a completed exam, adherence to a code of ethics, and work
experience in information security is the:
SysAdmin, Audit, Network, Security Certification.
Certification Information System Security Professional.
Certified Information Security Manager.
Global Information Assurance Certification.
The set of guidelines that devotes considerable attention to the user behavior that is expected if the
program is to be successful is named:
BSI IT Baseline Protection Manual.
ISF Standard of Good Practice.
Which type of information security risk can be caused by a hacker?
unauthorized modification
unauthorized disclosure and theft
unauthorized destruction and denial of service
Which type of threat is a computer program that can replicate itself without being observable to the
user, and embed copies of itself in other programs and boot sectors?
A