
ISMP Free Update With 100% Exam Passing Guarantee [2021]
[Aug-2021] Verified EXIN Exam Dumps with ISMP Exam Study Guide
NEW QUESTION 18
A company's webshop offers prospects and customers the possibility to search the catalog and place orders around the clock. In order to satisfy the needs of both customer and business several requirements have to be met. One of the criteria is data classification.
What is the most important classification aspect of the unit price of an object in a 24h webshop?
- A. Integrity
- B. Availability
- C. Confidentiality
Answer: B
NEW QUESTION 19
What needs to be decided prior to considering the treatment of risks?
- A. How to apply appropriate controls to reduce the risks
- B. Mitigation plans
- C. The development of own guidelines
- D. Criteria for determining whether or not the risk can be accepted
Answer: D
NEW QUESTION 20
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?
- A. Perform a risk assessment of the secure internet connectivity architecture of the datacenter
- B. Produce a Statement of Applicability based on risk assessments
- C. Formulate the security requirements in the outsourcing contracts
- D. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)
Answer: B
NEW QUESTION 21
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are key terms in business continuity management (BCM). Reducing loss of data is one of the focus areas of a BCM policy.
What requirement is in the data recovery policy to realize minimal data loss?
- A. Maximize RPO
- B. Reduce RPO
- C. Reduce RTO
- D. Reduce the time between RTO and RPO
Answer: B
NEW QUESTION 22
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
- A. Put a phone tap on the employee's business phone
- B. Investigate the contents of the workstation of the employee
- C. Seize and investigate the private laptop of the employee
- D. Investigate the private mailbox of the employee
Answer: B
NEW QUESTION 23
An information security officer is asked to write a retention policy for a financial system. She is aware of the fact that some data must be kept for a long time and other data must be deleted.
Where should she look for guidelines first?
- A. In finance management procedures
- B. In legislation
- C. In company policies
Answer: B
NEW QUESTION 24
The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?
- A. Identify, quantify and prioritize each of the business-critical assets residing on the corporate infrastructure
- B. Identify, quantify and prioritize the scope of this risk assessment
- C. Identify, quantify and prioritize which controls are going to be used to mitigate risk
- D. Identify, quantify and prioritize risks against criteria for risk acceptance
Answer: D
NEW QUESTION 25
When is revision of an employee's access rights mandatory?
- A. After any position change
- B. At all moments stated in the information security policy
- C. At hire
- D. At least each year
Answer: B
NEW QUESTION 26
When should information security controls be considered?
- A. As part of the scoping meeting
- B. During the risk assessment work
- C. At the kick-off meeting
- D. After the risk assessment
Answer: D
NEW QUESTION 27
The information security architect of a large service provider advocates an open design of the security architecture, as opposed to a secret design.
What is her main argument for this choice?
- A. Open designs are tested extensively.
- B. Open designs are easily configured.
- C. Open designs have more functionality.
Answer: A
NEW QUESTION 28
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
- A. Do
- B. Check
- C. Plan
- D. Act
Answer: C
NEW QUESTION 29
It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?
- A. Log review, consolidation and management
- B. Access criteria and access control mechanisms
- C. System-specific policies for business systems
Answer: B
NEW QUESTION 30
......
Authentic Best resources for ISMP Online Practice Exam: https://www.examprepaway.com/EXIN/braindumps.ISMP.ete.file.html