SANS MGT514 Latest Update 2024-2025 Exam 360 Questions and 100% Verified Correct Answers Guaranteed A+
Act & advice (4:27) - CORRECT ANSWER: provides a bit more managerial control, with employees making a recommendation and taking actions unless the manager countermands their decision within a certain period of time.
Air Force leadership (4:14) - CORRECT ANSWER: the art of influencing and directing people in a way that will win their obedience, confidence, respect, and loyal cooperations in achieving a common objective
Albert Einstein (2:225) - CORRECT ANSWER: If you can't explain it simply, you don't understand it well enough.
Application Security Issues (3:149) - CORRECT ANSWER: Security Vulnerabilities - Injection, XSS, Broken Access controls; Unpatched dependencies. Identify the issues that can occur if application security is left unaddressed
Authoritarian (autocratic) (4:27) - CORRECT ANSWER: is in action when leaders tell their employees what they want done, how they want it done, without getting the advice of the team
Authoritarian Leader (4:24) - CORRECT ANSWER: Task oriented and are hard on their workers (autocratic). make little or no allowance for cooperation or collaboration.Heavily task-oriented people are very devoted to schedules
Balanced scorecard (2:191) - CORRECT ANSWER: select high value data that will tell your story in the most compelling manner. Financial Stewardship/Perfomance, Customer/Stakeholder Satisfaction, Internal Business Process/Efficiency, Learning and growth / Knowledge & innovation.
BHAG (Big Hairy Audacious Goal) (2:81) - CORRECT ANSWER: Huge and daunting goal; Defines visionary goals and common envisioned future. Understanding what you can be the best at.
Blake Mouton Managerial Model (4:24) - CORRECT ANSWER: Based on two behavioral dimensions - concern for people and concern for results Identifies five different combinations of the two Identifies leadership styles they produce.
Board of Directors Concerns (2:221) - CORRECT ANSWER: must understand their role in the organization, provide oversight & governance, not make day-to-day tactical decisions. 1 / 4
Bolman and Deal's four frame model (4:22) - CORRECT ANSWER: 1. Structural - analysis, design, facts, implementation
- Human resource - supporting, advocating, empowering
- Political - Coalition building, conflict avoidance
- Symbolic - vision, inspiration, ability to cope with change/uncertantiy
BSIMM Maturity Comparison Model Radar Chart (2:149) - CORRECT ANSWER: represents organizational maturity level compared to your overall industry for various security capabilities in the protect area of NIST Cybersecurity Framework.
Business Case (Business Innovation approach) (2:151) - CORRECT ANSWER: Business opportunities; business requirements; business risk
Business Case (Cost approach) (2:140-141) - CORRECT ANSWER: Numbers include direct and indirect costs, i.e. engaging in forensics experts, credit monitoring, in-house investigations and communication, extrapolated value of customer loss. Issues that may arise, numbers aren't always accurate - over/under estimates
Business Case (Different approaches) (2:139) - CORRECT ANSWER: Cost approach - how much does it cost to recover, Industry comparison approach - what are comparable firms doing, Business innovation approach - what can i gain from this?
Business Case (Elements) (2:153) - CORRECT ANSWER: Executive Summary - written for key decision makers and summarizes the problem at hand, your assessment of the situation and recommendation; Introduction - provides background info about business drivers and the threat landscape; Analysis - meat of your business case and includes any assumptions that you have made in your model include cost/benefit analysis and dependencies/synergies; Appendix - largely depends on what stakeholders want to see and are interested in.
Business Case (How to deliver) (2:158) - CORRECT ANSWER: Map current capabilities to maturity levels; Prioritize new initiatives to increase maturity.
Business Case (Industry comparison approach - Maturity Comparison) (2:146) -
CORRECT ANSWER: Comparing your security program to others, via Information
Sharing & Analysis Centers (ISAC), Community projects, Research and consulting organizations.
Business Case (Industry comparison approach - Spending Comparison) (2:144) -
CORRECT ANSWER: Provides a rough understanding of organizational maturity and
can indicate whether spending has been focused solely on meeting mandatory requirements, has expanded the necessary requirements.
- / 4
Business Case (Industry comparison approach) (2:144) - CORRECT ANSWER: What is reasonable for security based on Industry, size, market position, region; and can be analyzed by Spending and Maturity comparisons
Business Case (The why?) (2:136) - CORRECT ANSWER: helps to estimate costs and benefits of various initiatives; Helps management determine resource allocation.
Business case (what is it) (2:137) - CORRECT ANSWER: Captures the reason for an initiative and lays out a problem and the potential solutions. Includes underlying assumptions and rationale,
Business Email Compromise (3:132) - CORRECT ANSWER: Criminals spoof email communications from executives.
Business Model (1:41) - CORRECT ANSWER: 1. describes how you operate 2.generate revenue and make profit 3. deliver value at a reasonable cost
Capability Immaturity Model Integration (CMMI) (2:104) - CORRECT ANSWER: Defines what should be done to improve performance. Defines 5 maturity levels and 3 areas of focus including CMMI for development (CMMI-Dev) for product and service development, CMMI for services (CMMI-SVC) for service establishment and management, CMMI for aquisition (CMMI-ACQ) for product service and acquisition.
Capability Immaturity Model Integration (CMMI) Maturity Levels (2:105) - CORRECT ANSWER: Level 1 - initial, Level 2 - Repeatable, Level 3 - Defined, Level 4 - Managed, Level 5 - Optimizing.
China Cybersecurity law (3:27) - CORRECT ANSWER: focus on personal information protection and critical infrastructure protection, which includes "public communication and information services, power, traffic, water, finance, public service, electronic governance and other critical information infrastructure.
CIS Security Controls (2:109) - CORRECT ANSWER: Center for internet security; security controls developed and maintained by the CIS & are a subset of the comprehensive catalog in NIST SP 800-53
Citadel malware (1:173) - CORRECT ANSWER: password stealing bot program that is a derivative of Zeus. Attackers were able to harvest credentials Fazio used to access Targets billing system
Clayton Alderfer ERG (4:44) - CORRECT ANSWER: three groups of needs
- Existence: concerned with providing the basic requirements for material existence,
- Relationships: centers on or is built on the desire to establish and maintain
such as physiological and saftey needs
interpersonal relationships 3 / 4
- Growth: met by personal development. a person's job, career, or profession provides
for significant satisfaction
Clayton Alderfer ERG (4:45) - CORRECT ANSWER: ERG also states that more than one need may be influential at the same time. Gratification of a higher-level need is frustrated, the desire to satisfy a lower-level need will increase.
Climate (4:21) - CORRECT ANSWER: Short-term phenomenon created by the current leadership and represents employee beliefs about the "feel of the organization. is directly related to the leadership and management style of the leader, which is, in turn, based on the values, attributes, skills, actions, and priorities of the leader
COA - Course of Action Matrix (1:220) - CORRECT ANSWER: Various techniques that can be used against attackers during various phases of the kill chain
COA - Deceive (1:221) - CORRECT ANSWER: Attackers can be deceived by DNS redirects or honeypots that appear to be part of the real system, but are isolated systems specifically monitored to analyze attacks.
COA - Degrage (1:220) - CORRECT ANSWER: Queuing requests or decreasing the quality of service by using tarpits or purposely delay connections
COA - Deny (1:220) - CORRECT ANSWER: Firewalls, ACLs, NIPS, proxy filtering, and antivirus can provide a means to block attacks. Patching vulnerabilities and running in a "chroot" jail which prevents software from access files outside it's own root directory
COA - Detect (1:220) - CORRECT ANSWER: Web & Audit logs, along with NIDS/HIDS systems, provide a wealth of information about potential attacker activity.
COA - Disrupt (1:220) - CORRECT ANSWER: Attacks can be disrupted using a number of techniques such as in-line Antivirus & NIPS. To disrupt the exploitation phase, software can also be built with Data Execution Prevention - which is a feature that marks certain area of memory as "nonexecutable"
Coercive Management Style (3:107) - CORRECT ANSWER: Identify management style of your organization
Compelling Vision (4:52) - CORRECT ANSWER: Can inspire people to action, change behavior, and cause people to rise to a higher calling and intuitively follow a pathway that's been created as a result of a vision After vision is clear, the "how" almost takes care of itself. Provides motivation & inspiration that can keep us going no matter what lies ahead
Compliance by design (3:33) - CORRECT ANSWER: Policies should force compliance by design, where the desired behavior of incorporating security best practices is woven into the culture of the organization. Comprehensive security policies include
- / 4