41.
Gathering business requirements can aid the organization in determining all of this information
about organizational assets, except:
- A.Full inventory
- B.Usefulness
- C.Value
- D.Criticality
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
When we gather information about business requirements, we need to do a complete inventory, receive accurate valuation of assets (usually from the owners of those assets), and assess criticality; this collection of information does not tell us, objectively, how useful an asset is, however. |
42.
The BIA can be used to provide information about all the following, except:
- A.Risk analysis
- B.Secure acquisition
- C.BC/DR planning
- D.Selection of security controls
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
The business impact analysis gathers asset valuation information that is beneficial for risk analysis and selection of security controls (it helps avoid putting the ten-dollar lock on the five-dollar bicycle), and criticality information that helps in BC/DR planning by letting the organization understand which systems, data, and personnel are necessary to continuously maintain. However, it does not aid secure acquisition efforts, since the assets examined by the BIA have already been acquired. |
43.
In which cloud service model is the customer required to maintain the OS?
- A.CaaS
- B.SaaS
- C.PaaS
- D.IaaS
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
In IaaS, the service is bare metal, and the customer has to install the OS and the software; the customer then is responsible for maintaining that OS. In the other models, the provider installs and maintains the OS. |
44.
In which cloud service model is the customer required to maintain and update only the
applications?
- A.CaaS
- B.SaaS
- C.PaaS
- D.IaaS
- Answer & Explanation
- Report
Answer : [C]
Explanation :
Explanation :
In PaaS, the provider supplies the hardware, connectivity, and OS; the customer installs and maintains applications. In IaaS, the customer must also install the OS, and in SaaS, the provider supplies and maintains the applications. |
45.
In which cloud service model is the customer only responsible for the data?
- A.CaaS
- B.SaaS
- C.PaaS
- D.IaaS
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
SaaS is the model in which the customer supplies only the data; in the other models, the customer also supplies the OS, the application, or both. |