Which of the following is not a preventive operational control?
A.
Protecting laptops, personal computers and workstations.
B.
Controlling software viruses.
C.
Controlling data media access and disposal.
D.
Conducting security awareness and technical training.
The Answer Is:
D
This question includes an explanation.
Explanation:
Conducting security awareness and technical training to ensure that end users and system users are aware of the rules of behaviour and their responsibilities in protecting the organization's mission is an example of a preventive management control, therefore not an operational control.
Source: STONEBURNER, Gary et al., NIST Special publication 800-30, Risk management Guide for Information Technology Systems, 2001 (page 37).
SSCP PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"