IT Exam Items Repository Which of the following is a nontechnical method often used by cybercriminals to gather sensitive information about an organization?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsWhich industry-specific law governs payment card data protection?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsAn organization does not have policies in place to establish standardization for approved applications and operating system configurations. What type of policies does it need to develop?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsMatching. Select from lists and then submit. Match the data governance role to the correct function.ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsWhich of the following measures can an organization implement to manage user threats?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsAn organization takes responsible steps to eliminate risk. Some risks still exist, but the team implements multiple controls to prevent potential loss. What term best describes this practice?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsMatching. Select from lists and then submit. Part of asset management is the understanding of an asset’s lifecycle. Put the five states of the asset lifecycle in the correct order.ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsYou have implemented policies and procedures in your organization that deal with how sensitive information needs to be handled. What control type did you implement?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity Essentials@Apollo performs a risk analysis for its storage area network. The total asset value is $250,000. The team has identified drive failure as one threat event. The manufacturer’s data and company records provide the following data: EF = 5% and ARO = 2. What is the SLE?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsWhich of the following is used to calculate the threshold for evaluating the cost/benefit ratio of a given countermeasure?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsWhat will an organization evaluate when performing a qualitative risk analysis? (Select two correct answers)ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsYou are asked to perform a risk analysis of an organization. You request the organization’s asset database that contains a list of all equipment along with its value to the organization. Which type of risk analysis could you perform based on this information?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsAn employee is asked to evaluate the security posture of @Apollo. They look at past attempts to break into the company and evaluates the threats and exposures to create a report, which also takes into consideration what is most important for @Apollo. What type of risk analysis are they performing?ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity Essentials@Apollo hires a new security officer. One of the officer’s first projects is to take an inventory of the company assets and create a comprehensive database. What information should be captured in the asset database? (Select three correct answers)ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity EssentialsAn @Apollo employee has completed a six-month project to identify all data stores and catalog their location. The next step is to classify the data and produce some criteria for data sensitivity. What steps can be taken to classify the data? (Select two correct answers)ITExamAnswers Editorial Team asked 4 years ago • Cybersecurity Essentials