
Updated Apr-2022 100% Cover Real ISMP Exam Questions - 100% Pass Guarantee
Use Real EXIN Dumps - 100% Free ISMP Exam Dumps
NEW QUESTION 17
Security monitoring is an important control measure to make sure that the required security level is maintained. In order to realize 24/7 availability of the service, this service is outsourced to a partner in the cloud.
What should be an important control in the contract?
- A. The third party is certified for adhering to privacy protection controls.
- B. The third party is certified against ISO/IEC 27001.
- C. Your IT auditor has the right to audit the external party's service management processes.
- D. The network communication channel is secured by using encryption.
Answer: C
NEW QUESTION 18
What needs to be decided prior to considering the treatment of risks?
- A. Criteria for determining whether or not the risk can be accepted
- B. How to apply appropriate controls to reduce the risks
- C. The development of own guidelines
- D. Mitigation plans
Answer: A
NEW QUESTION 19
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person's picture on the smart card?
- A. To authenticate the owner of the card
- B. To verify the iris of the card owner
- C. To authorize the owner of the card
- D. To identify the role of the card owner
Answer: A
NEW QUESTION 20
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
- A. Investigate the private mailbox of the employee
- B. Put a phone tap on the employee's business phone
- C. Investigate the contents of the workstation of the employee
- D. Seize and investigate the private laptop of the employee
Answer: C
NEW QUESTION 21
What is the main reason to use a firewall to separate two parts of your internal network?
- A. To enable the installation of an Intrusion Detection System
- B. To control traffic intensity between two network segments
- C. To decrease network loads
- D. To separate areas with different confidentiality requirements
Answer: D
NEW QUESTION 22
When should information security controls be considered?
- A. As part of the scoping meeting
- B. During the risk assessment work
- C. At the kick-off meeting
- D. After the risk assessment
Answer: D
NEW QUESTION 23
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?
- A. The disaster recovery plan
- B. The risk treatment plan
- C. The incident response plan
- D. The Business Continuity Plan (BCP)
Answer: C
NEW QUESTION 24
The information security architect of a large service provider advocates an open design of the security architecture, as opposed to a secret design.
What is her main argument for this choice?
- A. Open designs are easily configured.
- B. Open designs are tested extensively.
- C. Open designs have more functionality.
Answer: B
NEW QUESTION 25
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?
- A. Send a checklist for threat identification to all staff involved in information security
- B. Interview top management
- C. Have a brainstorm with representatives of all stakeholders
Answer: C
NEW QUESTION 26
What is the best way to start setting the information security controls?
- A. Use a standard security baseline
- B. Resort back to the default factory standards
- C. Implement the security measures as prescribed by a risk analysis tool
Answer: A
NEW QUESTION 27
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
- A. When decision makers have been informed of uncontrolled risks and proper authority groups decide to leave the risks in place
- B. Once the controls are implemented
- C. When the risk analysis is completed
- D. Once the transference of the risk is complete
Answer: A
NEW QUESTION 28
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?
- A. The operational manager
- B. The Board of Directors
- C. The user
- D. The security manager
Answer: D
NEW QUESTION 29
......
ISMP Dumps PDF - ISMP Real Exam Questions Answers: https://lead2pass.examdumpsvce.com/ISMP-valid-exam-dumps.html
