NO.1 It is MOST important that information security architecture be aligned with which of the
A. Information security best practices
B. Industry best practices
C. Information technology plans
D. Business objectives and goals
Answer: D

Information security architecture should always be properly aligned with business goals and
objectives. Alignment with IT plans or industry and security best practices is secondary by

NO.2 Security technologies should be selected PRIMARILY on the basis of their:
A. ability to mitigate business risks.
B. use of new and emerging technologies.
C. benefits in comparison to their costs.
D. evaluations in trade publications.
Answer: A
The most fundamental evaluation criterion for the appropriate selection of any security technology
is its ability to reduce or eliminate business risks. Investments in security technologies should be
based on their overall value in relation to their cost; the value can be demonstrated in terms of risk
mitigation. This should take precedence over whether they use new or exotic technologies or how
they are evaluated in trade publications.

NO.3 Senior management commitment and support for information security will BEST be attained
by an information security manager by emphasizing:
A. organization wide metrics.
B. the responsibilities of organizational units.
C. security needs.
D. organizational risk.
Answer: D
Information security exists to help the organization meet its objectives. The information security
manager should identify information security needs based on organizational needs. Organizational
or business risk should always take precedence. Involving each organizational unit in information
security and establishing metrics to measure success will be viewed favorably by senior
management after the overall organizational risk is identified.

NO.4 Minimum standards for securing the technical infrastructure should be defined in a security:
A. guidelines.
B. strategy.
C. model.
D. architecture.
Answer: D

Minimum standards for securing the technical infrastructure should be defined in a security
architecture document. This document defines how components are secured and the security
services that should be in place. A strategy is a broad, high-level document. A guideline is advisory
in nature, while a security model shows the relationships between components.

