212-89 Exam QuestionsBrowse all questions from this exam

212-89 Exam - Question 7


A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

Show Answer
Correct Answer: AC

A computer risk policy primarily focuses on preventative measures, detection, response, and recovery related to computer security incidents. Procedures to monitor the efficiency of security controls, continuously train employees authorized to access systems, and provide continuing support in case of system interruptions are all inherent aspects of maintaining and managing security risks. However, identifying security funds to hedge risk is more related to financial and business risk management, not directly to the technical or procedural aspects of a computer security risk policy.

Discussion

12 comments
Sign in to comment
s3curity01Option: A
Jul 16, 2022

A doesn't even remotely mention insurance policy. its just identifying security funds to hedge risk. identify security funds isnt even related to computer risk policy

HeadtsgOption: A
Nov 21, 2020

I think the answer is letter A

s3curity1Option: A
Aug 23, 2021

This is letter A for me. A. Procedure to identify security funds to hedge risk - This is more on financial/business side. Security doesn't really govern them. B. Procedure to monitor the efficiency of security controls - Related to risks C. Procedure for the ongoing training of employees authorized to access the system - by providing ongoing training for employees authorized to access the system, you are teaching them what to do and what not to do. This lowers the risk of those users being part/triggering an incident. D. Provisions for continuing support if there is an interruption in the system or if the system crashes - related to availability

SHSOption: C
Apr 8, 2021

Correct answer is C. Read the wording of question, it is asking about Risk and how do you hedge a risk, by taking insurance policy. So A is not the answer.

khd45
Feb 22, 2024

C is not the correct Awnser. Training employees IS apart of risk as it reduces human error.

tobesciOption: A
Jun 7, 2021

I think the key is the word "computer" because it is not about human risks.

s3curity1
Aug 23, 2021

Computer security incidents always involves human

[Removed]Option: A
Mar 30, 2024

As per book answer is A

chessDavisOption: A
Feb 7, 2021

I think also the answer is A as budgeting is not part of the risk policy and security awareness training for employees accesing the coorporate computers and networks is very important to narrow the possibilities of human error or fall victim of cyber security scams

danny069Option: A
Sep 17, 2021

Definitely the answer here is A. If you even look at the all answers without reading the question, A sticks out like it doesn't belong there.

Michela2020Option: C
Nov 24, 2021

LETTER C.

benxzOption: A
May 1, 2024

Answer is A

ITTechPassOption: A
Jul 3, 2024

Answer should be A. Not fund issue

ITTechPassOption: A
Jul 3, 2024

Answer should be A. Not fund issue