Deck 6: Human Resources Security

Full screen (f)
exit full mode
Question
Why shouldn't information about specific systems be included in a job description?

A) To make sure candidates know all systems
B) To protect against social engineering and other attacks
C) To get as many candidates as possible
D) To get more knowledgeable candidates
Use Space or
up arrow
down arrow
to flip the card.
Question
During what step of the employee life cycle are employees added to the organization's benefit system?

A) Recruitment
B) Onboarding
C) User provisioning
D) Orientation
Question
Which of the following is part of the user provisioning phase of the employee life cycle?

A) The employee is added to the organization's payroll.
B) The employee is provided with a username or smart card.
C) A background check is conducted for the employee.
D) The employee expectations of privacy are determined.
Question
Which of the following steps of the employee life cycle is considered the most dangerous?

A) Termination
B) Onboarding
C) Recruitment
D) User provisioning
Question
Which of the following best describes the purpose of security awareness?

A) To teach skills that would allow a person to perform a certain function
B) To focus attention on security
C) To integrate all the security skills and competencies into a common body of knowledge
D) To involve management in the process
Question
Which stage of the employee life cycle includes all the processes leading up to and including the hiring of a new employee?

A) Onboarding
B) Career development
C) Recruitment
D) Orientation
Question
Which of the following best describes the purpose of security training?

A) To teach skills that would allow a person to perform a certain function
B) To focus attention on security
C) To integrate all the security skills and competencies into a common body of knowledge
D) To involve management in the process
Question
Which of the following statements about security awareness is not true?

A) The purpose of security awareness is to focus attention on security.
B) Awareness is training.
C) Security awareness programs are designed to remind users of appropriate behaviors.
D) A poster reminding users not to write their password down is an example of an awareness program.
Question
During what stage of the employee life cycle are user accounts disabled?

A) Career development
B) Termination
C) User provisioning
D) Onboarding
Question
Which of the following sections of the Acceptable Use Agreement dictates how information must be stored, transmitted, and communicated?

A) Introduction
B) Data classification
C) Applicable policy statements
D) Handling standards
Question
Which of the following specifies that schools must have written permission to release any information from a student's education record?

A) FACTA
B) FCRA
C) FERPA
D) DPPA
Question
SETA is short for which of the following?

A) Security Education, Training, and Awareness
B) Social Education, Training, and Application
C) Security Education, Training, and Application
D) Social Education, Training, and Awareness
Question
Which stage of the employee life cycle includes the process for transitioning employees out of an organization?

A) Termination
B) Off-boarding
C) User provisioning
D) Onboarding
Question
Which type of employee background check includes verification of all relevant licenses, certifications, or credentials?

A) Educational
B) License/certification
C) Employment
D) Criminal history
Question
Which phase in obtaining a U.S. government security clearance includes a comprehensive background check?

A) Application phase
B) Adjudication phase
C) Investigative phase
D) Granting (or denial) of clearance at a specific level
Question
An employee should learn about which of the following during orientation?

A) The company
B) The job
C) Their co-workers
D) All of the above
Question
A confidentiality agreement for employees, contractors, and outsourcers is also known as which of the following?

A) Non-disclosure agreement
B) Acceptable use agreement
C) Handling standards
D) Internet access security
Question
Which component of an acceptable use agreement defines (and includes examples of) the classification schema adopted by the organization?

A) Introduction
B) Data classifications
C) Applicable policy statements
D) Handling standards
Question
In which stage of the employee life cycle does the employee settle into the job, integrate with the corporate culture, and establish his or her role within the organization?

A) Onboarding
B) Career development
C) User provisioning
D) Orientation
Question
Which of the following NIST publications is known as The NIST Handbook?

A) SP 800-12
B) SP 800-16
C) SP 800-50
D) SP 800-100
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/20
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 6: Human Resources Security
1
Why shouldn't information about specific systems be included in a job description?

A) To make sure candidates know all systems
B) To protect against social engineering and other attacks
C) To get as many candidates as possible
D) To get more knowledgeable candidates
To protect against social engineering and other attacks
2
During what step of the employee life cycle are employees added to the organization's benefit system?

A) Recruitment
B) Onboarding
C) User provisioning
D) Orientation
Onboarding
3
Which of the following is part of the user provisioning phase of the employee life cycle?

A) The employee is added to the organization's payroll.
B) The employee is provided with a username or smart card.
C) A background check is conducted for the employee.
D) The employee expectations of privacy are determined.
The employee is provided with a username or smart card.
4
Which of the following steps of the employee life cycle is considered the most dangerous?

A) Termination
B) Onboarding
C) Recruitment
D) User provisioning
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
5
Which of the following best describes the purpose of security awareness?

A) To teach skills that would allow a person to perform a certain function
B) To focus attention on security
C) To integrate all the security skills and competencies into a common body of knowledge
D) To involve management in the process
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
6
Which stage of the employee life cycle includes all the processes leading up to and including the hiring of a new employee?

A) Onboarding
B) Career development
C) Recruitment
D) Orientation
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
7
Which of the following best describes the purpose of security training?

A) To teach skills that would allow a person to perform a certain function
B) To focus attention on security
C) To integrate all the security skills and competencies into a common body of knowledge
D) To involve management in the process
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
8
Which of the following statements about security awareness is not true?

A) The purpose of security awareness is to focus attention on security.
B) Awareness is training.
C) Security awareness programs are designed to remind users of appropriate behaviors.
D) A poster reminding users not to write their password down is an example of an awareness program.
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
9
During what stage of the employee life cycle are user accounts disabled?

A) Career development
B) Termination
C) User provisioning
D) Onboarding
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
10
Which of the following sections of the Acceptable Use Agreement dictates how information must be stored, transmitted, and communicated?

A) Introduction
B) Data classification
C) Applicable policy statements
D) Handling standards
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
11
Which of the following specifies that schools must have written permission to release any information from a student's education record?

A) FACTA
B) FCRA
C) FERPA
D) DPPA
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
12
SETA is short for which of the following?

A) Security Education, Training, and Awareness
B) Social Education, Training, and Application
C) Security Education, Training, and Application
D) Social Education, Training, and Awareness
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
13
Which stage of the employee life cycle includes the process for transitioning employees out of an organization?

A) Termination
B) Off-boarding
C) User provisioning
D) Onboarding
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
14
Which type of employee background check includes verification of all relevant licenses, certifications, or credentials?

A) Educational
B) License/certification
C) Employment
D) Criminal history
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
15
Which phase in obtaining a U.S. government security clearance includes a comprehensive background check?

A) Application phase
B) Adjudication phase
C) Investigative phase
D) Granting (or denial) of clearance at a specific level
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
16
An employee should learn about which of the following during orientation?

A) The company
B) The job
C) Their co-workers
D) All of the above
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
17
A confidentiality agreement for employees, contractors, and outsourcers is also known as which of the following?

A) Non-disclosure agreement
B) Acceptable use agreement
C) Handling standards
D) Internet access security
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
18
Which component of an acceptable use agreement defines (and includes examples of) the classification schema adopted by the organization?

A) Introduction
B) Data classifications
C) Applicable policy statements
D) Handling standards
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
19
In which stage of the employee life cycle does the employee settle into the job, integrate with the corporate culture, and establish his or her role within the organization?

A) Onboarding
B) Career development
C) User provisioning
D) Orientation
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
20
Which of the following NIST publications is known as The NIST Handbook?

A) SP 800-12
B) SP 800-16
C) SP 800-50
D) SP 800-100
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 20 flashcards in this deck.