Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the CIMA Strategic P3 Questions and answers with ValidTests

Exam P3 All Questions
Exam P3 Premium Access

View all detail and faqs for the P3 exam

Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions
Questions # 81:

ABC produces fashion garments for sale m its chain of high street retail outlets.

Which THREE of the following activities would result m the organisation having to review its cyber security risks management program?

Options:

A.

ABC is introducing a loyalty bonus store-card for regular shoppers

B.

ABC is introducing online shopping for certain limited ranges of clothing

C.

ABC has acquired an overseas garment manufacturer

D.

ABC has announced year-on-year trading figures with 5% increase

E.

ABC is shipping the new season range of fashionwear to the retail outlets

F.

ABC's sales figures show strong seasonal bios

Expert Solution
Questions # 82:

Some sensitive computer systems are particularly attractive to cyber criminals. Passwords may be used as one element of restricting access to legitimate users, but the password systems should be designed with great care.

Which of the following methods would enhance a password access system?

Options:

A.

The use of a two level system, a primary password plus questions correctly answered from set of queries, logged at system set up time.

B.

The use of drop down menus, using screen coordinates rather than transmitting keystrokes over a communication link.

C.

The logging and reporting of failed password attempts.

D.

The password should be typed quickly.

E.

The use of family members names, known only to the individual and not known by colleagues.

F.

The use of a sequence of passwords, using upper and lower case with numbers, easy to remember but regularly changed for example; November 11, December12, January01.

Expert Solution
Questions # 83:

P is a consulting firm that provides technical advice to the oil industry. The company has consulting teams that specialise in specific areas, namely drilling, off-shore, health and safety, oil well management and ng management. Each team's consultants are charged out to clients at the same daily rate.

The demand for different skill sets varies constantly due to factors such as movements in oil prices. Exploration increases when the oil price rises and there is a greater focus on maintaining existing wells when the price fans.

The performance of P's sales team is measured in terms of revenue, based on the number of consultancy days sold Frequently the sales team agree to contracts without first checking that the relevant consulting team has consultants available. The work then has to be undertaken by subcontractors at P's expense. Sub-contractors cost more and their use can also lead to P's own consultants being under-utilised when assignments could have been scheduled more efficiently.

Which TWO of the following would correct this behavior?

Options:

A.

Measure the performance of P's sales team on margin contribution rather than revenue.

B.

Reduce the number of consultants within P's teams.

C.

Employ the sub-contractor stall as lull time P employees.

D.

Award additional incentives for selling P's own staff

E.

Allow P's consultants to go out on any job, regardless of specialism.

Expert Solution
Questions # 84:

An oil company has entered into a joint venture with a competing oil company to develop a new oil field. The joint venture arrangement is intended to mitigate the risks associated with developing the oil field.

The following disclosure appears in the oil company's risk report:

"Many of our large projects and operations are conducted through joint ventures. These arrangements involve complex risk allocation and indemnification arrangements and we have less control over these activities than we would have if we had full ownership and control. Our partners may have economic or business interests that are opposed to ours, and may exercise the right to block key decisions or actions. We believe the joint arrangement is in our best interest."

Which of the following statements are correct?

Options:

A.

The risk report means that the shareholders know exactly how bad the risk is.

B.

The risk report says nothing useful about the risk.

C.

Now the shareholders know the directors are aware of the risk.

D.

If the risk report had not reported the risk the shareholders might not have been aware of the risk.

E.

The shareholders now have more useful information.

Expert Solution
Questions # 85:

 D is a large oil refinery.

The managers have identified four risks shown in the risk map below:

Which of the risk mitigations listed below would be the best for dealing with the two risks classified as medium likelihood and high impact?

Options:

A.

Accept

B.

Reduce

C.

Transfer

D.

Avoid

Expert Solution
Questions # 86:

XYZ is unhappy with the way it decides on the likelihood and impact of risks when it completes the TARA matrix XYZ has decided to try other ways to get more consensus over the evaluation of risks as high, medium and low impact and likelihood

Which of the following methods is likely to be most successful?

Options:

A.

Searching online to see how the risks are evaluated in other companies

B.

Sending questionaires to all employees

C.

Using the Delphi method

D.

Allowing the risk manager to decide.

Expert Solution
Questions # 87:

BCD has recently experienced a cyber security breach which fortunately was carried out by someone more interested in demonstrating the weakness in its defence than by someone malicious

This has made BCD realise that its cyber defence is inadequate BCD has engaged a cyber security consultant who has advised BCD to set up a Computer Incident Response Team (GIRT)

What THREE of the following activities would this CIRT have responsibility for?

Recruit specialist security staff to avoid an incident

Options:

A.

Carry out or assist with any investigations of an incident

B.

Ensure all security policies are carried out to avoid an incident.

C.

Restore normal operations as soon as possible after an incident.

D.

Manage or assist with any communications throughout an incident

E.

Advise on best products against malware attacks to prevent an incident.

Expert Solution
Questions # 88:

ZZ is a data security company that is responsible for cyber security m a large shopping mall 21 uses Network Configuration Management (NCM) to assist it in meeting the various needs of the mall's user community.

Which THREE of the following are advantages provided by NCM?

Options:

A.

NCM allows ZZ to prevent data corruption for different user groups in the mall

B.

NCM allows ZZ to provide different service levels for different user groups in the mall

C.

NCM allows ZZ to segregate traffic for different user groups in the mall

D.

NCM allows ZZ to prevent scanners being used on the public WiFi for different user groups in the mall

E.

NCM allows ZZ to restrict traffic for different user groups in the mall

F.

NCM allows ZZ to stop malware from being spread for different user groups in the mall

Expert Solution
Questions # 89:

As part of risk assessment exercise for a low-cost airline you are requested to match the risks listed below with the most approriate method of minimising or dealing with each risk.

Question # 89

Options:

Expert Solution
Questions # 90:

P Ltd manufactures and sells electrical goods through retail outlets.

N is P Ltd's Sales Director. He has been recently promoted from a senior sales position with P Ltd. He has been forced to spend the first six months as Sales Director on dealing with an administrative mess left behind by the previous sales director.

You are a Senior Management Accountant at P Ltd. You have worked with N for many years.

N has worked hard and has made many changes that have brought significant benefit to the business.

N has asked you to postpone the recording of some purchase invoices so that he will meet his quarterly targets on profit margin.

What should you do?

Options:

A.

Collect all the facts, distance yourself from the situation but say nothing.

B.

Write up the facts of the issue and put it on your files.

C.

Document the situation and present the facts to your manager.

D.

Do nothing, no rules have been broken, tell N that you cannot do as he asks and that he needs to abide by the professional codes.

Expert Solution
Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions