Even ChatGPT doesn't know. LOL
Both Option B and Option C could be considered valid depending on the specific context and focus of managerial control. In the realm of information security, Option C might be more specific to the security domain, whereas Option B encompasses a broader range of managerial control functions, including those related to security awareness and training.
Therefore, both Option B and Option C could be correct, and the choice may depend on the emphasis or perspective within the context of managerial control.
CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Chapter 21 "Managerial controls are those that enable the overarching administration of the security of an organization. Examples of managerial controls are planning, risk assessment, security assessments, and systems acquisition processes."
Per the Comptia CySA+ Student Guide: "Managerial—The control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls."
After looking at professormesser's SY0-601 Security+ 5.1 video he mentions
"We put security controls into three major categories. The first category is a managerial control. This is a control that focuses on the design of the security or the policy implementation associated with the security. We might have a set of security policies for our organization or set of standard operating procedures that everyone is expected to follow."
With the key words design of security or policy implementation A. would be the most likely as it uses the same key words "design and implement".
management controls are actions taken to manage the development, maintenance, and use of the system, including system-specific policies, procedures, and rules of behavior, individual roles and responsibilities, individual accountability and personnel security decisions. -NIST Website
With that being said, i interpret "B" as the correct answer.
Of the options provided, D. To ensure tactical design, selection of technology to protect data, logical access reviews, and the implementation of audit trails, best explains the function of managerial control.
Managerial control refers to the process of monitoring and regulating activities within an organization to ensure that goals are achieved effectively and efficiently. It involves various activities related to planning, organizing, directing, and controlling resources to accomplish organizational objectives
Managerial controls are those that enable the overarching administration of the security of an organization.Managerial controls are those that enable the overarching administration of the security of an organization. Examples of managerial controls are planning, risk assessment, security assessments, and systems acquisition processes.
Answer is B
management controls are actions taken to manage thedevelopment, maintenance, and use of the system, including system-specific policies, procedures, and rules of behavior, individual roles and responsibilities, individual accountability and personnel security decisions.
Source(s):
NIST SP 800-16 under Management Controls
After checking your reference, I am changing my answer to B.
Clearly this is not C as everyone pointed out as Contigency planning is part of Operational Control
I taked from book;
Managerial—The control gives oversight of the information system. Examples couldinclude risk identification or a tool allowing the evaluation and selection of othersecurity controls.
i am confusing going with B and C. contingency planning in C does not coming logical but also i going with C. i hope its correct
The answer is C, but I only know through grammatical process of elimination.
To help, to guide, to ensure are all similar. To create is the odd one out. Now to learn why...
Managerial controls ensure the organization's security policies and procedures are effectively implemented and adhered to. They play a role in overseeing the development and delivery of security training, education, and awareness programs, as well as ensuring the proper maintenance of security systems.
Managerial controls are procedural mechanisms that focus on the mechanics of the risk management process. Examples of administrative controls include periodic risk assessments, security planning exercises, and the incorporation of security into the organization's change management, service acquisition, and project management practices.
upvoted 4 times
...
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
RobV
1 year, 4 months ago[Removed]
1 year, 5 months agoTheStudiousPeepz
1 year, 5 months agoPavel019846457
1 year, 6 months agoluniafreak
1 year, 8 months agoKickuh06
1 year, 9 months agokyky
1 year, 10 months agoAbusedInk
2 years, 1 month agoWhoGuessed
2 years, 1 month agokhrid4
2 years, 1 month ago2Fish
2 years, 1 month agoabsabs
2 years, 2 months agoIanRogerStewart
2 years, 3 months agoNickDrops
2 years, 3 months agokmanb
2 years, 3 months agoforklord72
2 years, 6 months agoforklord72
2 years, 6 months agoSolventCourseisSCAM
2 years, 6 months agoR00ted
2 years, 7 months ago