A company stores customer names, credit card numbers, and addresses. Employees who work with this data must complete annual training on how to handle and protect it. What managerial control is the company using?
A company allows employees to access customer data but never trains them on privacy laws or how to handle sensitive data. Which risk is the company MOST likely to face?
A hospital trains employees on how to protect patient records and explains that medical data must remain private and secure. Why is this training important?
Which of the following is an example of an operational security practice?
An employee emails a spreadsheet with customer Social Security numbers using a personal email account because it was more convenient. What type of problem does this represent?
A company creates a document that lists which encryption algorithms employees are allowed to use and the minimum key length required. What is this document called?
Why do organizations require minimum key lengths for encryption?
A company encrypts its customer data but stores the encryption key in a text file on the same server as the encrypted data. What is the main security problem?
Why is secure key generation important?
A company launches a new website that stores customer information but never tests the website for security vulnerabilities. What policy is missing?
When should a web application be tested for security vulnerabilities?
A company discovers a serious vulnerability that allows attackers to access customer data but decides to fix it “eventually” because fixing it is expensive. What is the main problem with this decision?
Why do companies fix vulnerabilities based on risk level?
A company gives all employees full access to payroll records, customer data, and company financial information, even though most employees do not need that access. Which security principle is being violated?
Why is the principle of least privilege important?
An attacker gains access to a low-level employee account, but the attacker cannot access financial data or customer databases because the employee did not have permission to access those systems. What security principle helped limit the damage?
A company does not train employees on how to recognize phishing emails. An employee clicks a fake login link and enters their password, allowing an attacker into the system. What managerial control could have prevented this?
A company has a policy that requires security testing every time an application is updated and requires high-risk vulnerabilities to be fixed within 48 hours. What type of policy is this?