Question 1
Which of the following is the BEST option for a security director to use in order to mitigate the risk of inappropriate use of credentials by individuals with administrative rights?
Which of the following is the BEST option for a security director to use in order to mitigate the risk of inappropriate use of credentials by individuals with administrative rights?
An organization has deployed an Identity And Access Management (IAM) tool and is expanding their information governance program. Which of the following would BEST be included in the governance for IAM?
How would blockchain technology support requirements for sharing audit information among a community of organizations?
A health care organization's new cloud-based customer-facing application is constantly receiving security events from dubious sources. What BEST describes a security event that compromises the confidentiality, integrity or availability of the application and data?
An organization has decided to advance from qualitative risk assessment to quantitative risk analysis. The information security risk analyst has been tasked with replacing the organization's qualitative likelihood scale of low, medium, and high with a quantitative approach. Which is the BEST approach for replacing the qualitative input values?
Which of the following techniques would a group use to prioritize problems?
Pareto analysis is a technique for separating input factors with the greatest impact on an outcome and prioritizing them based on their scores. It is based on the 80-20 rule, which states that 80% of a project's benefit or problems can be achieved by doing 20% of the work or fixing 20% of the causes. Pareto analysis helps to identify the top portion of causes that need to be addressed to resolve the majority of problems.Pareto Analysis - Overview, Limitations, Pareto DiagramReference:Pareto analysis - Wikipedia,What Is Pareto Analysis? How to Create a Pareto Chart and Example, APICS CPIM Part 1 Exam Content Manual (page 14)
After a recent cybersecurity incident, a manufacturing organization is interested in further hardening its Identity and Access Management (IAM) solution. Knowing that the organization limits the use of personal devices in the facility, which could BEST be implemented to enhance the manufacturing organization's IAM solution?
The primary benefit that results from the cross-training of employees is:
Cross-training employees is the process of training employees for skills and job roles they weren't initially hired for. This allows them to switch between different tasks and roles when needed, which increases the flexibility and adaptability of the workforce. Cross-training also enhances the problem-solving, communication, and collaboration skills of the employees, but the primary benefit is improved flexibility12 Reference: 1: 9 Major Benefits of Cross-Training Employees Effectively 2: Employee cross-training: 8 benefits you can't afford to miss
A security engineer must address resource sharing between various applications without adding physical hardware to the environment. Which secure design principle is used to BEST segregate applications?
A part is sold as a service part, and It is also used as a component In another part. Which of the following statements about the planning for this part is true?
The service part demand can be included in the gross requirements for the part. Gross requirements are the total demand for an item derived from all sources, such as customer orders, dependent demand, forecast, or safety stock. Service part demand is the demand for an item that is used to replace or repair a product after it has been sold to the customer. Service part demand is independent of the production of other items, and it can be forecasted based on historical data, warranty information, or customer contracts. Service part demand can be added to the gross requirements for the part, along with the dependent demand from the other part that uses it as a component.
Option A is not correct, because the low-level code of the part is not zero. Low-level code is the lowest level in the bill of material (BOM) at which an item appears as a component. An item that is not a component of any other item has a low-level code of zero. An item that is a component of another item has a low-level code equal to one plus the low-level code of the parent item. In this case, the part is a component of another part, so its low-level code is at least one.
Option B is not correct, because the material requirements for the part will not be understated. Material requirements are the net requirements for an item after deducting the available inventory and scheduled receipts from the gross requirements. If the service part demand is included in the gross requirements, the material requirements will reflect the true demand for the part. If the service part demand is not included, the material requirements will be understated, and the part may face stockouts or backorders.
Option D is not correct, because the part should have some safety stock. Safety stock is the extra inventory held to protect against uncertainties in demand, supply, or lead time. Safety stock can help reduce the risk of stockouts, improve customer service, and buffer against variability. The part should have some safety stock to account for the fluctuations in the service part demand, which may depend on factors such as product failure rate, customer behavior, or environmental conditions.
Which of the following statements about demonstrated capacity Is true?
Demonstrated capacity is the actual output achieved by a resource or a system over a period of time, such as a day, a week, or a month. It is determined from actual results, such as production records, time studies, or historical data. Demonstrated capacity reflects the past performance, not the future load, of a resource or a system. It may be lower or higher than the rated capacity, which is the theoretical or design capacity of a resource or a system. Demonstrated capacity considers utilization and efficiency factors, such as machine availability, operator skills, product mix, quality issues, or maintenance schedules, that affect the actual output.Reference:
Managing Supply Chain Operations, Chapter 5: Capacity Planning and Management, Section 5.2: Capacity Planning Decisions, page 132-133.
Manufacturing Planning and Control for Supply Chain Management: The CPIM Reference, Second Edition, Chapter 6: Capacity Management, Section 6.2: Capacity Planning, page 156-157.
CPIM 8.0 Exam Content Manual Preview, Module 5: Plan and Manage Supply, Section 5.1: Plan and Manage Capacity, page 9.
Which of the following incorporates design techniques promoted by Crime Prevention Through Environmental Design (CPTED)?
What is the BEST reason to include a Hardware Security Module (HSM) in the key management system when securing cloud storage?
An organization has identified that an individual has failed to adhere to a given standard set by the organization. Based on the needs of the organization, it was decided that an exception process will be created. What is the PRIMARY benefit of establishing an exception process?
An organization routes traffic between two of its sites using non-revenue network paths provided by peers on an Internet exchange point. What is the MOST appropriate recommendation the organization's security staff can make to prevent a compromise?