CISMP-V9 PDF Pass Leader, CISMP-V9 Latest Real Test [Q54-Q76]

Share

CISMP-V9 PDF Pass Leader, CISMP-V9 Latest Real Test

Valid CISMP-V9 Test Answers & CISMP-V9 Exam PDF

NEW QUESTION 54
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?

  • A. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
  • B. A large increase in remote workers operating in insecure premises.
  • C. Additional physical security requirements at data centres and corporate headquarters.
  • D. Increased demand on service desks as users need additional tools such as VPNs.

Answer: D

 

NEW QUESTION 55
When a digital forensics investigator is conducting art investigation and handling the original data, what KEY principle must they adhere to?

  • A. Ensure they are competent to be able to do so and be able to justify their actions.
  • B. Ensure the data has been adjusted to meet the investigation requirements.
  • C. Ensure they do not handle the evidence as that must be done by law enforcement officers.
  • D. Ensure they are being observed by a senior investigator in all actions.

Answer: A

 

NEW QUESTION 56
What are the different methods that can be used as access controls?
1. Detective.
2. Physical.
3. Reactive.
4. Virtual.
5. Preventive.

  • A. 1, 2 and 4.
  • B. 1, 2 and 5.
  • C. 3, 4 and 5.
  • D. 1, 2 and 3.

Answer: B

 

NEW QUESTION 57
Select the document that is MOST LIKELY to contain direction covering the security and utilisation of all an organisation's information and IT equipment, as well as email, internet and telephony.

  • A. Business Continuity Plan.
  • B. Cryptographic Statement.
  • C. Security Policy Framework.
  • D. Acceptable Usage Policy.

Answer: B

 

NEW QUESTION 58
What Is the first yet MOST simple and important action to take when setting up a new web server?

  • A. Change default system passwords.
  • B. Fully encrypt the hard disk.
  • C. Patch the OS to the latest version
  • D. Apply hardening to all applications.

Answer: D

 

NEW QUESTION 59
When an organisation decides to operate on the public cloud, what does it lose?

  • A. The ability to determine in which geographies the information is stored.
  • B. Control over Intellectual Property Rights relating to its applications.
  • C. The right to audit and monitor access to its information.
  • D. Physical access to the servers hosting its information.

Answer: C

 

NEW QUESTION 60
Ensuring the correctness of data inputted to a system is an example of which facet of information security?

  • A. Authenticity.
  • B. Integrity.
  • C. Availability.
  • D. Confidentiality.

Answer: B

 

NEW QUESTION 61
In a security governance framework, which of the following publications would be at the HIGHEST level?

  • A. Policy.
  • B. Guidelines
  • C. Standards
  • D. Procedures.

Answer: D

 

NEW QUESTION 62
In terms of security culture, what needs to be carried out as an integral part of security by all members of an organisation and is an essential component to any security regime?

  • A. Access denial measures
  • B. Appropriate behaviours.
  • C. The 'need to known principle.
  • D. Verification of visitor's ID

Answer: A

 

NEW QUESTION 63
What aspect of an employee's contract of employment Is designed to prevent the unauthorised release of confidential data to third parties even after an employee has left their employment?

  • A. Segregation of Duties.
  • B. Acceptable use policy.
  • C. Security clearance.
  • D. Non-disclosure.

Answer: D

 

NEW QUESTION 64
Which of the following compliance legal requirements are covered by the ISO/IEC 27000 series?
1. Intellectual Property Rights.
2. Protection of Organisational Records
3. Forensic recovery of data.
4. Data Deduplication.
5. Data Protection & Privacy.

  • A. 1, 2 and 3
  • B. 1, 2 and 5
  • C. 2, 3 and 4
  • D. 3, 4 and 5

Answer: B

 

NEW QUESTION 65
James is working with a software programme that completely obfuscates the entire source code, often in the form of a binary executable making it difficult to inspect, manipulate or reverse engineer the original source code.
What type of software programme is this?

  • A. Interpreted Source.
  • B. Free Source.
  • C. Proprietary Source.
  • D. Open Source.

Answer: A

 

NEW QUESTION 66
What does a penetration test do that a Vulnerability Scan does NOT?

  • A. A penetration test looks for known vulnerabilities and reports them without further action.
  • B. A penetration test is always an automated process - a vulnerability scan never is.
  • C. A penetration test never uses common tools such as Nrnap, Nessus and Metasploit.
  • D. A penetration test seeks to actively exploit any known or discovered vulnerabilities.

Answer: A

 

NEW QUESTION 67
What term refers to the shared set of values within an organisation that determine how people are expected to behave in regard to information security?

  • A. System Operating Procedures.
  • B. Code of Ethics.
  • C. Security Policy Framework.
    https://www.cpni.gov.uk/developing-security-culture#:~:text=Developing%20a%20Security%20Culture,-What%20type%20of&text=Security%20culture%20refers%20to%20the,think%20about%20and%20approach%20security.&text=Employees%20are%20more%20likley%20to%20think%20and%20act%20in%20a%20security%20conscious%20manner
  • D. Security Culture.

Answer: D

 

NEW QUESTION 68
Which of the following types of organisation could be considered the MOST at risk from the theft of electronic based credit card data?

  • A. Agricultural producer.
  • B. Mail delivery business.
  • C. Online retailer.
  • D. Traditional market trader.

Answer: C

 

NEW QUESTION 69
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?

  • A. Deny.
  • B. Delay.
  • C. Deter.
  • D. Drop.

Answer: C

 

NEW QUESTION 70
Which of the following describes a qualitative risk assessment approach?

  • A. A subjective assessment of risk occurrence likelihood against the potential impact that determines the overall severity of a risk.
  • B. The use of Risk Tolerance and Risk Appetite values to determine the overall severity of a risk
  • C. The use of Monte-Carlo Analysis and Layers of Protection Analysis (LOPA) to determine the overall severity of a risk.
  • D. The use of verifiable data to predict the risk occurrence likelihood and the potential impact so as to determine the overall severity of a risk.

Answer: C

 

NEW QUESTION 71
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?

  • A. Risk = Threat * Likelihood.
  • B. Risk = Vulnerability / Threat.
  • C. Risk = Likelihood * Impact.
  • D. Risk = Likelihood / Impact.

Answer: B

 

NEW QUESTION 72
What physical security control would be used to broadcast false emanations to mask the presence of true electromagentic emanations from genuine computing equipment?

  • A. White noise generation.
  • B. Unshielded cabling.
  • C. Faraday cage.
  • D. Copper infused windows.

Answer: B

 

NEW QUESTION 73
The policies, processes, practices, and tools used to align the business value of information with the most appropriate and cost-effective infrastructure from the time information is conceived through its final disposition.
Which of the below business practices does this statement define?

  • A. Business Continuity Management.
    https://www.stitchdata.com/resources/glossary/information-lifecycle-management/#:~:text=%E2%80%9CILM%20is%20comprised%20of%20the,(SNIA%2C%20via%20Infoworld).
  • B. Total Quality Management.
  • C. Information Lifecycle Management.
  • D. Information Quality Management.

Answer: C

 

NEW QUESTION 74
What type of diagram used in application threat modeling includes malicious users as well as descriptions like mitigates and threatens?

  • A. STRIDE charts.
  • B. DREAD diagrams.
  • C. Threat trees.
  • D. Misuse case diagrams.

Answer: C

 

NEW QUESTION 75
When securing a wireless network, which of the following is NOT best practice?

  • A. Turning on SSID broadcasts to advertise security levels.
  • B. Using WPA encryption on the wireless network.
  • C. Dedicating an access point on a dedicated VLAN connected to a firewall.
  • D. Use MAC tittering on a SOHO network with a smart group of clients.

Answer: C

 

NEW QUESTION 76
......

CISMP-V9 Dumps Ensure Your Passing: https://www.exams4sures.com/BCS/CISMP-V9-practice-exam-dumps.html

CISMP-V9 exam dumps and online Test Engine: https://drive.google.com/open?id=1dXT33kYRYXz__UbPvnunU7J7WcmYzm-1