[2022] Use Valid New Free ISMP Exam Dumps & Answers [Q17-Q34]

Share

[2022] Use Valid New Free ISMP Exam Dumps & Answers

ISMP Braindumps PDF, EXIN ISMP Exam Cram

NEW QUESTION 17
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?

  • A. Investigate the contents of the workstation of the employee
  • B. Investigate the private mailbox of the employee
  • C. Seize and investigate the private laptop of the employee
  • D. Put a phone tap on the employee's business phone

Answer: A

 

NEW QUESTION 18
A security manager just finished the final copy of a risk assessment. This assessment contains a list of identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?

  • A. Remediate the risk regardless of cost
  • B. Begin risk remediation immediately as the organization is currently at risk
  • C. Design appropriate controls to reduce the risk
  • D. Decide the criteria for determining if the risk can be accepted

Answer: D

 

NEW QUESTION 19
An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.
Which is the main risk of PKI?

  • A. The Certificate Authority (CA) is hacked.
  • B. The users lose their public keys.
  • C. The certificate is invalid because it is on a Certificate Revocation List.
  • D. The HR department wants to be a Registration Authority (RA).

Answer: A

 

NEW QUESTION 20
What needs to be decided prior to considering the treatment of risks?

  • A. Mitigation plans
  • B. Criteria for determining whether or not the risk can be accepted
  • C. The development of own guidelines
  • D. How to apply appropriate controls to reduce the risks

Answer: B

 

NEW QUESTION 21
A company's webshop offers prospects and customers the possibility to search the catalog and place orders around the clock. In order to satisfy the needs of both customer and business several requirements have to be met. One of the criteria is data classification.
What is the most important classification aspect of the unit price of an object in a 24h webshop?

  • A. Integrity
  • B. Availability
  • C. Confidentiality

Answer: B

 

NEW QUESTION 22
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?

  • A. The security manager
  • B. The Board of Directors
  • C. The operational manager
  • D. The user

Answer: A

 

NEW QUESTION 23
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?

  • A. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)
  • B. Perform a risk assessment of the secure internet connectivity architecture of the datacenter
  • C. Produce a Statement of Applicability based on risk assessments
  • D. Formulate the security requirements in the outsourcing contracts

Answer: C

 

NEW QUESTION 24
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?

  • A. Interview top management
  • B. Have a brainstorm with representatives of all stakeholders
  • C. Send a checklist for threat identification to all staff involved in information security

Answer: B

 

NEW QUESTION 25
What is the best way to start setting the information security controls?

  • A. Use a standard security baseline
  • B. Implement the security measures as prescribed by a risk analysis tool
  • C. Resort back to the default factory standards

Answer: A

 

NEW QUESTION 26
A security architect argues with the internal fire prevention team about the statement in the information security policy, that doors to confidential areas should be locked at all times. The emergency response team wants to access to those areas in case of fire.
What is the best solution to this dilemma?

  • A. The doors should stay closed in case of fire to prevent access to confidential areas.
  • B. The security architect will be informed when there is a fire.
  • C. The doors will automatically open in case of fire.

Answer: C

 

NEW QUESTION 27
When should information security controls be considered?

  • A. After the risk assessment
  • B. During the risk assessment work
  • C. At the kick-off meeting
  • D. As part of the scoping meeting

Answer: A

 

NEW QUESTION 28
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are key terms in business continuity management (BCM). Reducing loss of data is one of the focus areas of a BCM policy.
What requirement is in the data recovery policy to realize minimal data loss?

  • A. Reduce RTO
  • B. Maximize RPO
  • C. Reduce RPO
  • D. Reduce the time between RTO and RPO

Answer: C

 

NEW QUESTION 29
......

Feel EXIN ISMP Dumps PDF Will likely be The best Option: https://www.passsureexam.com/ISMP-pass4sure-exam-dumps.html