
EXIN ISMP Practice Test Pdf Exam Material
ISMP Answers ISMP Free Demo Are Based On The Real Exam
NEW QUESTION 13
An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.
Which is the main risk of PKI?
- A. The Certificate Authority (CA) is hacked.
- B. The users lose their public keys.
- C. The certificate is invalid because it is on a Certificate Revocation List.
- D. The HR department wants to be a Registration Authority (RA).
Answer: A
NEW QUESTION 14
When is revision of an employee's access rights mandatory?
- A. At least each year
- B. At all moments stated in the information security policy
- C. After any position change
- D. At hire
Answer: B
NEW QUESTION 15
Who should be asked to check compliance with the information security policy throughout the company?
- A. Internal audit department
- B. External forensics investigators
- C. The same company that checks the yearly financial statement
Answer: B
NEW QUESTION 16
What is the main reason to use a firewall to separate two parts of your internal network?
- A. To separate areas with different confidentiality requirements
- B. To decrease network loads
- C. To control traffic intensity between two network segments
- D. To enable the installation of an Intrusion Detection System
Answer: A
NEW QUESTION 17
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
- A. When decision makers have been informed of uncontrolled risks and proper authority groups decide to leave the risks in place
- B. Once the controls are implemented
- C. Once the transference of the risk is complete
- D. When the risk analysis is completed
Answer: A
NEW QUESTION 18
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
- A. Investigate the contents of the workstation of the employee
- B. Investigate the private mailbox of the employee
- C. Seize and investigate the private laptop of the employee
- D. Put a phone tap on the employee's business phone
Answer: A
NEW QUESTION 19
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
- A. Plan
- B. Act
- C. Check
- D. Do
Answer: A
NEW QUESTION 20
In a company the IT strategy is migrating towards a Service Oriented Architecture (SOA) so that migrating to the cloud is better feasible in the future. The security architect is asked to make a first draft of the security architecture.
Which elements should the security architect draft?
- A. Which security services are provided and in which supporting architectures are they defined
- B. Management and control of the security services
- C. The information security policy, the risk assessment and the controls in the security services
Answer: A
NEW QUESTION 21
The information security architect of a large service provider advocates an open design of the security architecture, as opposed to a secret design.
What is her main argument for this choice?
- A. Open designs have more functionality.
- B. Open designs are tested extensively.
- C. Open designs are easily configured.
Answer: B
NEW QUESTION 22
What is a key item that must be kept in mind when designing an enterprise-wide information security program?
- A. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
- B. Put an incident management and log file analysis program in place immediately
- C. When defining controls follow an approach and framework that is consistent with organizational culture
- D. Determine controls in the light of specific risks an organization is facing
Answer: D
NEW QUESTION 23
A company's webshop offers prospects and customers the possibility to search the catalog and place orders around the clock. In order to satisfy the needs of both customer and business several requirements have to be met. One of the criteria is data classification.
What is the most important classification aspect of the unit price of an object in a 24h webshop?
- A. Integrity
- B. Availability
- C. Confidentiality
Answer: B
NEW QUESTION 24
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?
- A. Interview top management
- B. Have a brainstorm with representatives of all stakeholders
- C. Send a checklist for threat identification to all staff involved in information security
Answer: B
NEW QUESTION 25
......
ISMP [Jan-2022] Newly Released] Exam Questions For You To Pass: https://www.prep4sureguide.com/ISMP-prep4sure-exam-guide.html