FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Which control is most effective at protecting sensitive customer data if an attacker gains access to a database server's storage?
Encryption of data at rest, with keys held separately from the data, best protects sensitive information if storage is accessed, because the stolen content is unreadable without the keys. Backups, web application firewalls and mandatory vacations address other risks.
- AEncryption of data at rest with keys managed separately from the dataCorrect
- BA more frequent backup schedule
- CA web application firewall
- DMandatory vacation policy for administrators
Explanation
Encrypting data at rest with separately managed keys leaves stolen storage unreadable. Backups address availability, a web application firewall protects the application layer, and mandatory vacation is a fraud detection control.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank wants its cyber-resilience strategy to be integrated with enterprise risk management. Which approach best achieves this?
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of 2 hours for its payments platform. After a simulated ransomware …
- A bank's cyber strategy is assessed by a supervisor. Which finding most clearly indicates that the strategy is not aligned with sound practi…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of two hours for its payments system. Which statement best describe…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) for its payment-processing system. Which statement best describes w…
- A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration te…