CSLB General Building (B) — All Questions
← Back to practice14 questions
Which document outlines acceptable and prohibited uses of an organization's IT systems by employees?
- a.Acceptable use policy✓
- b.Business impact analysis
- c.Service level agreement
- d.Memorandum of understanding
An acceptable use policy (AUP) defines how employees may and may not use company systems and data. It sets expectations and provides grounds for enforcement. Users typically acknowledge it as a condition of access.
Which risk response involves purchasing insurance to shift financial impact to a third party?
- a.Risk avoidance
- b.Risk transference✓
- c.Risk acceptance
- d.Risk mitigation
Risk transference shifts the financial consequences of a risk to another party, commonly through insurance or contracts. The risk still exists, but its impact is borne elsewhere. It is chosen when handling the risk directly is impractical or costly.
Choosing to take no action and knowingly bear a low-level risk is called:
- a.Risk avoidance
- b.Risk transference
- c.Risk acceptance✓
- d.Risk mitigation
Risk acceptance is a conscious decision to tolerate a risk, usually when the cost of controls exceeds the potential loss. It should be formally documented and approved. Acceptance is appropriate for low-impact or low-likelihood risks.
Eliminating a risky activity entirely so the risk no longer applies is known as:
- a.Risk acceptance
- b.Risk transference
- c.Risk mitigation
- d.Risk avoidance✓
Risk avoidance removes the risk by discontinuing the activity that causes it. For example, not deploying a feature that would expose sensitive data. It fully eliminates that risk but may sacrifice a business opportunity.
Which regulation governs the protection of personal data for individuals in the European Union?
- a.GDPR✓
- b.HIPAA
- c.PCI DSS
- d.SOX
The General Data Protection Regulation (GDPR) sets strict requirements for handling the personal data of EU residents. It mandates consent, breach notification, and data subject rights. Non-compliance can result in substantial fines.
Which standard governs the secure handling of payment card data?
- a.HIPAA
- b.PCI DSS✓
- c.GDPR
- d.FERPA
The Payment Card Industry Data Security Standard (PCI DSS) defines controls for organizations that store, process, or transmit cardholder data. It is a contractual requirement rather than a law. Compliance reduces the risk of payment data breaches.
Which US regulation protects the privacy and security of health information?
- a.GDPR
- b.PCI DSS
- c.HIPAA✓
- d.GLBA
The Health Insurance Portability and Accountability Act (HIPAA) sets requirements for safeguarding protected health information. It applies to healthcare providers, plans, and their business associates. Violations can lead to significant penalties.
A calculation of expected yearly loss from a risk, found by multiplying single loss expectancy by annual rate of occurrence, is the:
- a.Residual risk
- b.Risk appetite
- c.Exposure factor
- d.Annualized loss expectancy✓
Annualized loss expectancy (ALE) estimates the expected yearly cost of a risk by multiplying single loss expectancy (SLE) by the annualized rate of occurrence (ARO). It supports cost-benefit decisions about controls. Spending more than the ALE on mitigation is usually not justified.
Which assessment identifies the critical processes and the impact of their disruption to guide continuity planning?
- a.Business impact analysis✓
- b.Penetration test
- c.Vulnerability scan
- d.Gap analysis
A business impact analysis (BIA) identifies critical business functions and quantifies the effect of their disruption over time. It informs RTO and RPO targets and prioritizes recovery. It is a foundation of business continuity planning.
Which agreement defines the measurable service levels a provider must meet, such as uptime guarantees?
- a.MOU
- b.Service level agreement✓
- c.NDA
- d.BPA
A service level agreement (SLA) specifies measurable commitments like availability and response times, with consequences for missing them. It sets clear expectations between provider and customer. Monitoring against the SLA holds the provider accountable.
Which legal agreement prohibits parties from disclosing confidential information they receive?
- a.SLA
- b.MOU
- c.Non-disclosure agreement✓
- d.AUP
A non-disclosure agreement (NDA) legally binds parties to keep shared confidential information secret. It is common when sharing sensitive data with vendors, partners, or employees. Breaching it can result in legal liability.
The residual risk that remains after all controls have been applied should be:
- a.Ignored entirely
- b.Transferred automatically
- c.Eliminated completely
- d.Accepted by management✓
Residual risk is what remains after mitigations are in place, and it cannot usually be reduced to zero. Senior management should formally acknowledge and accept it. This ensures leadership is aware of and owns the remaining exposure.
Which framework provides a widely used structure for managing cybersecurity risk through functions like Identify, Protect, Detect, Respond, and Recover?
- a.NIST Cybersecurity Framework✓
- b.OWASP Top Ten
- c.MITRE ATT&CK
- d.PCI DSS
The NIST Cybersecurity Framework organizes security activities into core functions: Identify, Protect, Detect, Respond, and Recover. It offers a flexible, risk-based approach adaptable to any organization. It helps align security programs with business goals.
Regular training that teaches employees to recognize phishing and follow security policies is called:
- a.Penetration testing
- b.Security awareness training✓
- c.Change management
- d.Vulnerability management
Security awareness training educates users to recognize threats like phishing and to follow safe practices. Because people are a common attack vector, this reduces human-related risk. Ongoing and simulated exercises reinforce the behavior over time.