BCS Related Exams
CISMP-V9 Exam
How might the effectiveness of a security awareness program be effectively measured?
1) Employees are required to take an online multiple choice exam on security principles.
2) Employees are tested with social engineering techniques by an approved penetration tester.
3) Employees practice ethical hacking techniques on organisation systems.
4) No security vulnerabilities are reported during an audit.
5) Open source intelligence gathering is undertaken on staff social media profiles.
Which term describes a vulnerability that is unknown and therefore has no mitigating control which is immediately and generally available?
Which of the following is NOT an information security specific vulnerability?