Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

[2021] Use Valid Exam ISMP by BraindumpsIT Books For Free Website [Q17-Q34]

Share

[2021] Use Valid Exam ISMP by BraindumpsIT Books For Free Website

Free Information Security Management ISMP Official Cert Guide PDF Download

NEW QUESTION 17
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?

  • A. The security manager
  • B. The Board of Directors
  • C. The user
  • D. The operational manager

Answer: A

 

NEW QUESTION 18
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?

  • A. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)
  • B. Formulate the security requirements in the outsourcing contracts
  • C. Produce a Statement of Applicability based on risk assessments
  • D. Perform a risk assessment of the secure internet connectivity architecture of the datacenter

Answer: C

 

NEW QUESTION 19
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?

  • A. Lobby and public restaurant
  • B. Computer room and storage facility
  • C. Meeting rooms and Human Resource rooms
  • D. Boardroom and general office space

Answer: A

 

NEW QUESTION 20
An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.
Which is the main risk of PKI?

  • A. The Certificate Authority (CA) is hacked.
  • B. The users lose their public keys.
  • C. The HR department wants to be a Registration Authority (RA).
  • D. The certificate is invalid because it is on a Certificate Revocation List.

Answer: A

 

NEW QUESTION 21
A security manager just finished the final copy of a risk assessment. This assessment contains a list of identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?

  • A. Remediate the risk regardless of cost
  • B. Decide the criteria for determining if the risk can be accepted
  • C. Design appropriate controls to reduce the risk
  • D. Begin risk remediation immediately as the organization is currently at risk

Answer: B

 

NEW QUESTION 22
What is a risk treatment strategy?

  • A. Software installation
  • B. Mobile updates
  • C. Risk acceptance
  • D. Risk exclusion

Answer: C

 

NEW QUESTION 23
It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?

  • A. System-specific policies for business systems
  • B. Access criteria and access control mechanisms
  • C. Log review, consolidation and management

Answer: B

 

NEW QUESTION 24
The information security architect of a large service provider advocates an open design of the security architecture, as opposed to a secret design.
What is her main argument for this choice?

  • A. Open designs have more functionality.
  • B. Open designs are easily configured.
  • C. Open designs are tested extensively.

Answer: C

 

NEW QUESTION 25
Which security item is designed to take collections of data from multiple computers?

  • A. Firewall
  • B. Host-Based Intrusion Detection and Prevention System (Host-Based IDPS)
  • C. Network-Based Intrusion Detection and Prevention System (Network-Based IDPS)
  • D. Virtual Private Network (VPN)

Answer: C

 

NEW QUESTION 26
The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?

  • A. Identify, quantify and prioritize risks against criteria for risk acceptance
  • B. Identify, quantify and prioritize which controls are going to be used to mitigate risk
  • C. Identify, quantify and prioritize the scope of this risk assessment
  • D. Identify, quantify and prioritize each of the business-critical assets residing on the corporate infrastructure

Answer: A

 

NEW QUESTION 27
What is a key item that must be kept in mind when designing an enterprise-wide information security program?

  • A. Determine controls in the light of specific risks an organization is facing
  • B. Put an incident management and log file analysis program in place immediately
  • C. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
  • D. When defining controls follow an approach and framework that is consistent with organizational culture

Answer: A

 

NEW QUESTION 28
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?

  • A. The incident response plan
  • B. The disaster recovery plan
  • C. The Business Continuity Plan (BCP)
  • D. The risk treatment plan

Answer: A

 

NEW QUESTION 29
......

EXIN ISMP Official Cert Guide PDF: https://www.braindumpsit.com/ISMP_real-exam.html