NO.1 It is MOST important that information security architecture be aligned with which of the
A. Business objectives and goals
B. Information security best practices
C. Industry best practices
D. Information technology plans
Answer: A

Information security architecture should always be properly aligned with business goals and
objectives. Alignment with IT plans or industry and security best practices is secondary by

NO.2 The cost of implementing a security control should not exceed the:
A. implementation opportunity costs.
B. cost of an incident.
C. asset value.
D. annualized loss expectancy.
Answer: C

The cost of implementing security controls should not exceed the worth of the asset. Annualized
loss expectancy represents the losses drat are expected to happen during a single calendar year. A
security mechanism may cost more than this amount (or the cost of a single incident) and still be
considered cost effective. Opportunity costs relate to revenue lost by forgoing the acquisition of an
item or the making of a business decision.

NO.3 The MOST appropriate role for senior management in supporting information security is the:
A. approval of policy statements and funding.
B. monitoring adherence to regulatory requirements.
C. assessment of risks to the organization.
D. evaluation of vendors offering security products.
Answer: A

Since the members of senior management are ultimately responsible for information security, they
are the ultimate decision makers in terms of governance and direction. They are responsible for
approval of major policy statements and requests to fund the information security practice.
Evaluation of vendors, assessment of risks and monitoring compliance with regulatory requirements
are day-to-day responsibilities of the information security manager; in some organizations, business
management is involved in these other activities, though their primary role is direction and

NO.4 Security technologies should be selected PRIMARILY on the basis of their:
A. use of new and emerging technologies.
B. evaluations in trade publications.
C. ability to mitigate business risks.
D. benefits in comparison to their costs.
Answer: C

The most fundamental evaluation criterion for the appropriate selection of any security technology
is its ability to reduce or eliminate business risks. Investments in security technologies should be
based on their overall value in relation to their cost; the value can be demonstrated in terms of risk
mitigation. This should take precedence over whether they use new or exotic technologies or how
they are evaluated in trade publications.

