exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 334 discussion

Actual exam question from ISC's CISSP
Question #: 334
Topic #: 1
[All CISSP Questions]

Employee training, risk management, and data handling procedures and policies could be characterized as which type of security measure?

  • A. Preventative
  • B. Management
  • C. Non-essential
  • D. Administrative
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
krassko
Highly Voted 2 years ago
Selected Answer: D
Administrative includes preventive
upvoted 19 times
jackdryan
1 year, 4 months ago
D is correct
upvoted 1 times
...
...
rc7
Highly Voted 1 year, 11 months ago
Answer is D. Employee training, risk management, and data handling procedures and policies are all part of Administrative security measures. Preventative measures are closely aligned put with technical measures.
upvoted 6 times
...
BigITGuy
Most Recent 1 day, 19 hours ago
Selected Answer: D
NOT A. Preventative controls are a category (like technical, physical, or administrative) but the question asks for the type of control, not its function.
upvoted 1 times
...
YesPlease
9 months, 2 weeks ago
Selected Answer: D
Answer D) Administrative There are three main types of IT security controls including technical, administrative, and physical. The primary goal for implementing a security control can be preventative, detective, corrective, compensatory, or act as a deterrent. https://purplesec.us/security-controls/
upvoted 3 times
...
Soleandheel
9 months, 3 weeks ago
D. Administrative........employee training can make it seem like A is the correct answer but all the other activities mentioned are administrative controls and Employee training can also fall under that categroy making D. Administrative the best answer.
upvoted 1 times
...
bherto39
1 year ago
Selected Answer: D
Employee training, risk management, and data handling procedures and policies could be characterized as: D. Administrative These measures focus on managing and controlling security aspects within an organization, such as establishing policies, procedures, and training to ensure that security practices are followed and that risks are managed effectively.
upvoted 1 times
...
xxxBadManxxx
1 year, 1 month ago
correct answer is D: Employee training, risk management, and data handling procedures and policies could be characterized as Administrative Security Measures.
upvoted 2 times
...
Moose01
1 year, 4 months ago
A. is the correct! Employee training - that means any one of the employee in the organization - not a particular employee. Preventive is when the organization train or send awareness emails, or posters.
upvoted 2 times
...
noname4
1 year, 7 months ago
Selected Answer: A
the keyword is "type" - so the correct Anwser is A Preventative see Study Guide Figure 2.4 and following sites
upvoted 1 times
...
Ivanchun
1 year, 9 months ago
Selected Answer: D
D, procedure is the keywords
upvoted 1 times
...
Mann0302
1 year, 10 months ago
Selected Answer: A
A is correct as it is a type. B and D is the same thing.
upvoted 1 times
...
Jamati
1 year, 10 months ago
Selected Answer: A
It's preventative
upvoted 1 times
...
rdy4u
1 year, 11 months ago
Selected Answer: D
Administrative security controls refer to policies, procedures, or guidelines that define personnel or business practices in accordance with the organization's security goals.
upvoted 2 times
...
Nickolos
1 year, 11 months ago
Selected Answer: D
Administrative Security consists of policies, procedures, and personnel controls including security policies, training, and audits, technical training, supervision, separation of duties, rotation of duties, recruiting and termination procedures, user access control, background checks, performance evaluations, and disaster recovery, contingency, and emergency plans. These measures ensure that authorized users know and understand how to properly use the system in order to maintain security of data. It's D
upvoted 3 times
...
JAckThePip
1 year, 12 months ago
Be careful not to confuse security control with security measure. In this specific case it indicated measure therefore he correct answer is A
upvoted 2 times
...
Rollizo
2 years ago
Selected Answer: A
Administrative controls is a category, preventive is a type
upvoted 2 times
thanhlb
11 months, 2 weeks ago
agree with A
upvoted 1 times
...
...
CuteRabbit168
2 years ago
Selected Answer: D
Examples of administrative controls include policies, procedures, hiring practices, background checks, data classifications and labeling, security awareness and training efforts, reports and reviews, work supervision, personnel controls, and testing.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago