Podcast
Questions and Answers
What is the main purpose of the (ISC)² Code of Professional Ethics?
What is the main purpose of the (ISC)² Code of Professional Ethics?
- To follow conflicting laws from different countries
- To prioritize personal interests over public trust
- To protect society and the common good (correct)
- To avoid expanding one's skills
When conflicting laws from different jurisdictions apply in a project, what should a CISSP prioritize?
When conflicting laws from different jurisdictions apply in a project, what should a CISSP prioritize?
- Personal preferences
- Ignoring all laws
- Following all laws equally
- Local jurisdiction where services are performed (correct)
What should a CISSP avoid doing to adhere to the ethics code?
What should a CISSP avoid doing to adhere to the ethics code?
- Pretending to be an expert in unfamiliar areas (correct)
- Acting honorably and responsibly
- Passing negative publicity to the profession
- Providing competent services
Which of the following accurately describes the attitude towards training for a CISSP?
Which of the following accurately describes the attitude towards training for a CISSP?
What is a key aspect of providing competent services according to the professional ethics code?
What is a key aspect of providing competent services according to the professional ethics code?
How should a CISSP handle conflicting laws in different countries or jurisdictions?
How should a CISSP handle conflicting laws in different countries or jurisdictions?
What is the goal of a secure supply chain?
What is the goal of a secure supply chain?
What does Supply Chain Risk Management (SCRM) aim to ensure about vendors in the supply chain?
What does Supply Chain Risk Management (SCRM) aim to ensure about vendors in the supply chain?
What can be a threat vector in the context of the supply chain?
What can be a threat vector in the context of the supply chain?
What is the significance of an on-site assessment before conducting business with another company?
What is the significance of an on-site assessment before conducting business with another company?
Why is it important for each link in the supply chain to be responsible and accountable?
Why is it important for each link in the supply chain to be responsible and accountable?
What is the role of third-party assessments in ensuring a secure supply chain?
What is the role of third-party assessments in ensuring a secure supply chain?
What is a threat vector?
What is a threat vector?
Which factor is derived from the concept of exposure in quantitative risk analysis?
Which factor is derived from the concept of exposure in quantitative risk analysis?
How is risk calculated in the context of threat, vulnerability, and severity of harm?
How is risk calculated in the context of threat, vulnerability, and severity of harm?
What is the relationship between threats, vulnerabilities, and risk mitigation?
What is the relationship between threats, vulnerabilities, and risk mitigation?
What must upper management decide about risks in organizations?
What must upper management decide about risks in organizations?
What is the relationship between exposure, risk, and safeguards?
What is the relationship between exposure, risk, and safeguards?
What is the primary difference between Quantitative Risk Analysis and Qualitative Risk Analysis?
What is the primary difference between Quantitative Risk Analysis and Qualitative Risk Analysis?
Why do most organizations employ a hybrid of both risk assessment methodologies?
Why do most organizations employ a hybrid of both risk assessment methodologies?
What is the purpose of risk response in the risk assessment process?
What is the purpose of risk response in the risk assessment process?
Which of the following is NOT a possible response to risk according to the text?
Which of the following is NOT a possible response to risk according to the text?
What does countermeasure selection aim to achieve in the context of risk management?
What does countermeasure selection aim to achieve in the context of risk management?
Why is it important to understand how risk assessment concepts are integrated into your environment for exam preparation?
Why is it important to understand how risk assessment concepts are integrated into your environment for exam preparation?
What is one way gamification has enhanced employee training?
What is one way gamification has enhanced employee training?
Why is it important to update training materials and security testing methods?
Why is it important to update training materials and security testing methods?
What is one drawback of using the same phishing test campaign repeatedly?
What is one drawback of using the same phishing test campaign repeatedly?
Why is it suggested to use internal social media tools for security training?
Why is it suggested to use internal social media tools for security training?
What is a key metric that should be tracked to evaluate security awareness and training?
What is a key metric that should be tracked to evaluate security awareness and training?
How can organizations improve the effectiveness of employee training?
How can organizations improve the effectiveness of employee training?