Verified ISMP Exam Dumps Q&As - Provide ISMP with Correct Answers [Q12-Q35]

Share

Verified ISMP Exam Dumps Q&As - Provide ISMP with Correct Answers

Pass Your ISMP Dumps Free Latest EXIN Practice Tests

NEW QUESTION 12
When should information security controls be considered?

  • A. During the risk assessment work
  • B. After the risk assessment
  • C. As part of the scoping meeting
  • D. At the kick-off meeting

Answer: B

 

NEW QUESTION 13
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?

  • A. Lobby and public restaurant
  • B. Computer room and storage facility
  • C. Meeting rooms and Human Resource rooms
  • D. Boardroom and general office space

Answer: A

 

NEW QUESTION 14
What is the best way to start setting the information security controls?

  • A. Resort back to the default factory standards
  • B. Use a standard security baseline
  • C. Implement the security measures as prescribed by a risk analysis tool

Answer: B

 

NEW QUESTION 15
What is a key item that must be kept in mind when designing an enterprise-wide information security program?

  • A. Determine controls in the light of specific risks an organization is facing
  • B. Put an incident management and log file analysis program in place immediately
  • C. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
  • D. When defining controls follow an approach and framework that is consistent with organizational culture

Answer: A

 

NEW QUESTION 16
A security manager just finished the final copy of a risk assessment. This assessment contains a list of identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?

  • A. Remediate the risk regardless of cost
  • B. Decide the criteria for determining if the risk can be accepted
  • C. Design appropriate controls to reduce the risk
  • D. Begin risk remediation immediately as the organization is currently at risk

Answer: B

 

NEW QUESTION 17
It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?

  • A. System-specific policies for business systems
  • B. Access criteria and access control mechanisms
  • C. Log review, consolidation and management

Answer: B

 

NEW QUESTION 18
What needs to be decided prior to considering the treatment of risks?

  • A. Mitigation plans
  • B. Criteria for determining whether or not the risk can be accepted
  • C. How to apply appropriate controls to reduce the risks
  • D. The development of own guidelines

Answer: B

 

NEW QUESTION 19
Security monitoring is an important control measure to make sure that the required security level is maintained. In order to realize 24/7 availability of the service, this service is outsourced to a partner in the cloud.
What should be an important control in the contract?

  • A. Your IT auditor has the right to audit the external party's service management processes.
  • B. The network communication channel is secured by using encryption.
  • C. The third party is certified against ISO/IEC 27001.
  • D. The third party is certified for adhering to privacy protection controls.

Answer: A

 

NEW QUESTION 20
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?

  • A. When the risk analysis is completed
  • B. Once the controls are implemented
  • C. Once the transference of the risk is complete
  • D. When decision makers have been informed of uncontrolled risks and proper authority groups decide to leave the risks in place

Answer: D

 

NEW QUESTION 21
A security manager for a large company has the task to achieve physical protection for corporate data stores.
Through which control can physical protection be achieved?

  • A. Using access control lists to prevent logical access to organizational infrastructure
  • B. Using a firewall to prevent access to the network infrastructure
  • C. Having visitors sign in and out of the corporate datacenter
  • D. Using key access controls for employees needing access

Answer: D

 

NEW QUESTION 22
What is the main reason to use a firewall to separate two parts of your internal network?

  • A. To decrease network loads
  • B. To control traffic intensity between two network segments
  • C. To separate areas with different confidentiality requirements
  • D. To enable the installation of an Intrusion Detection System

Answer: C

 

NEW QUESTION 23
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?

  • A. Act
  • B. Do
  • C. Plan
  • D. Check

Answer: C

 

NEW QUESTION 24
......

Get Top-Rated EXIN ISMP Exam Dumps Now: https://www.actualtestsquiz.com/ISMP-test-torrent.html