Cyber Security Policies & Standards (CY-703 (B)) - Important Questions
-
Unit 314 Marks High Priority
Explain the organizational implications of web threats and social media risks. Describe the main types of threats, give real-world examples, and discuss technical and managerial controls, including policy measures, that organizations should implement to mitigate these risks.
Core Unit 3 topic combining web threats and social media risks; appears most frequently in past-analytics (heatmap).
-
Unit 310 Marks Medium Priority
Explain the CIA Triad and discuss specific controls and practices used to ensure Confidentiality, Integrity and Availability of organizational assets exposed via web applications and social media platforms.
Fundamental security concept applied to organizational web and social media environments; recurring core question in past analytics.
-
Unit 310 Marks Medium Priority
Describe an incident response lifecycle tailored for web-based incidents and social media breaches. Explain phases, roles and responsibilities, evidence preservation considerations and coordination with legal and PR teams.
Incident response is a standard expectation for Unit 3; focuses on handling web- and social-media-originated incidents.
-
Unit 37 Marks Medium Priority
Discuss privacy risks and data leakage scenarios arising from employee and corporate use of social media and web services. Recommend technical and administrative controls, including data classification, DLP, and awareness training.
Privacy and data leakage via web/social channels is a repeated organizational concern; aligns with privacy topics in analytics.
-
Unit 310 Marks Medium Priority
Explain how a corporate information security policy should align with a National Cyber Security Policy specifically with respect to web threats and social media risks. Identify key components that need alignment and explain why.
Alignment of corporate policies with national policy is highlighted in global analytics; here applied to web/social threats.
-
Unit 37 Marks Medium Priority
Analyze the legal and regulatory implications for organizations in dealing with web threats and social media incidents, including relevant provisions of the IT Act, 2000. What compliance and reporting obligations should organizations consider?
Legal/regulatory implications frequently accompany organizational security questions; IT Act is a common reference in analytics.
-
Unit 37 Marks Low Priority
List best practices for secure use of social media by employees and outline a concise organizational social media policy template covering acceptable use, disclosure rules, incident reporting and enforcement.
Practical policy design question useful for examination and assignments; predicted but less frequent in past papers.
-
Unit 37 Marks Low Priority
Discuss emerging web threats such as supply-chain attacks and deepfakes that can impact an organization's reputation via social media. Propose strategic policy and technical responses to mitigate these emerging risks.
Emerging threats are important for higher-order questions; predicted and recommended for advanced answers.
Quick Add to Notes
Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.
Create free accountHave an account? Log in
Notes Panel