
New Pass4SureQuiz CISMP-V9 Exam Questions| Real CISMP-V9 Dumps Updated on Jan 16, 2022
CISMP-V9 Braindumps – CISMP-V9 Questions to Get Better Grades
NEW QUESTION 59
Ensuring the correctness of data inputted to a system is an example of which facet of information security?
- A. Authenticity.
- B. Integrity.
- C. Availability.
- D. Confidentiality.
Answer: B
NEW QUESTION 60
When undertaking disaster recovery planning, which of the following would NEVER be considered a "natural" disaster?
- A. Lightning Strike
- B. Electromagnetic pulse
- C. Tsunami.
- D. Arson.
Answer: B
NEW QUESTION 61
What types of web application vulnerabilities continue to be the MOST prolific according to the OWASP Top 10?
- A. Poor Password Management.
- B. Insecure Deserialsiation.
- C. Injection Flaws.
- D. Security Misconfiguration
Answer: C
NEW QUESTION 62
Which of the following is an asymmetric encryption algorithm?
- A. AES.
- B. DES.
- C. RSA.
https://www.omnisecu.com/security/public-key-infrastructure/asymmetric-encryption-algorithms.php - D. ATM.
Answer: C
NEW QUESTION 63
Which of the following is NOT considered to be a form of computer misuse?
- A. Illegal access to computer systems.
- B. Illegal interception of information.
- C. Illegal retention of personal data.
- D. Downloading of pirated software.
Answer: C
NEW QUESTION 64
Which of the following cloud delivery models is NOT intrinsically "trusted" in terms of security by clients using the service?
- A. Hybrid.
- B. Community
- C. Private.
- D. Public.
Answer: B
NEW QUESTION 65
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?
- A. Risks remain under constant review.
- B. A maximum of once every other month.
- C. When the next risk audit is due.
- D. Once defined, they do not need reviewing.
Answer: A
NEW QUESTION 66
Which standard deals with the implementation of business continuity?
- A. IS0223G1.
- B. COBIT
- C. ISO/IEC 27001
- D. BS5750.
Answer: C
NEW QUESTION 67
Which of the following is NOT an accepted classification of security controls?
- A. Corrective.
- B. Detective.
- C. Preventive.
- D. Nominative.
Answer: D
NEW QUESTION 68
Which of the following types of organisation could be considered the MOST at risk from the theft of electronic based credit card data?
- A. Agricultural producer.
- B. Mail delivery business.
- C. Online retailer.
- D. Traditional market trader.
Answer: C
NEW QUESTION 69
Why have MOST European countries developed specific legislation that permits police and security services to monitor communications traffic for specific purposes, such as the detection of crime?
- A. Surveillance of a conversation or an online message by law enforcement agents was previously illegal due to the 1950 version of the Human Rights Convention.
- B. Police could previously intercept without lawful authority any communications in the course of transmission through a public post or telecoms system.
- C. Under the European Convention of Human Rights, the interception of telecommunications represents an interference with the right to privacy.
- D. GDPR overrides all previous legislation on information handling, so new laws were needed to ensure authorities did not inadvertently break the law.
Answer: B
NEW QUESTION 70
James is working with a software programme that completely obfuscates the entire source code, often in the form of a binary executable making it difficult to inspect, manipulate or reverse engineer the original source code.
What type of software programme is this?
- A. Interpreted Source.
- B. Free Source.
- C. Proprietary Source.
- D. Open Source.
Answer: A
NEW QUESTION 71
Which of the following is NOT an information security specific vulnerability?
- A. Unpatched Windows operating system.
- B. Confidential data stored in a fire safe.
- C. Use of HTTP based Apache web server.
- D. Use of an unlocked filing cabinet.
Answer: C
NEW QUESTION 72
What Is the PRIMARY reason for organisations obtaining outsourced managed security services?
- A. Managed security services are a de facto requirement for certification to core security standards such as ISG/IEC 27001
- B. Managed security services are a powerful defence against litigation in the event of a security breach or incident
- C. Managed security services provide access to specialist security tools and expertise on a shared, cost-effective basis.
- D. Managed security services permit organisations to absolve themselves of responsibility for security.
Answer: D
NEW QUESTION 73
When an organisation decides to operate on the public cloud, what does it lose?
- A. The ability to determine in which geographies the information is stored.
- B. Control over Intellectual Property Rights relating to its applications.
- C. The right to audit and monitor access to its information.
- D. Physical access to the servers hosting its information.
Answer: C
NEW QUESTION 74
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?
- A. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
- B. A large increase in remote workers operating in insecure premises.
- C. Additional physical security requirements at data centres and corporate headquarters.
- D. Increased demand on service desks as users need additional tools such as VPNs.
Answer: D
NEW QUESTION 75
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?
- A. Risk = Threat * Likelihood.
- B. Risk = Vulnerability / Threat.
- C. Risk = Likelihood * Impact.
- D. Risk = Likelihood / Impact.
Answer: B
NEW QUESTION 76
How does the use of a "single sign-on" access control policy improve the security for an organisation implementing the policy?
- A. Helps prevent the likelihood of users writing down passwords.
- B. Password is better encrypted for system authentication.
- C. Access control logs are centrally located.
- D. Decreases the complexity of passwords users have to remember.
Answer: C
NEW QUESTION 77
What aspect of an employee's contract of employment Is designed to prevent the unauthorised release of confidential data to third parties even after an employee has left their employment?
- A. Segregation of Duties.
- B. Acceptable use policy.
- C. Security clearance.
- D. Non-disclosure.
Answer: D
NEW QUESTION 78
Which of the following is often the final stage in the information management lifecycle?
- A. Use.
- B. Disposal.
- C. Publication.
https://timg.co.nz/blog-the-information-management-life-cycle/ - D. Creation.
Answer: B
NEW QUESTION 79
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?
- A. Parameter Tampering
- B. XSS.
- C. CSRF.
- D. SQL Injection.
Answer: C
NEW QUESTION 80
In order to better improve the security culture within an organisation with a top down approach, which of the following actions at board level is the MOST effective?
- A. Appointment of a Chief Information Security Officer (CISO).
- B. Adopting an organisation wide "clear desk" policy.
- C. Developing a security awareness e-learning course.
- D. Purchasing all senior executives personal firewalls.
Answer: A
NEW QUESTION 81
What advantage does the delivery of online security training material have over the distribution of printed media?
- A. Online training material is intrinsically more accurate than printed material.
- B. Printed material is a 'discoverable record' and could expose the organisation to litigation in the event of an incident.
- C. Updating online material requires a single edit. Printed material needs to be distributed physically.
- D. Online material is protected by international digital copyright legislation across most territories.
Answer: A
NEW QUESTION 82
You are undertaking a qualitative risk assessment of a likely security threat to an information system.
What is the MAIN issue with this type of risk assessment?
- A. Dealing with statistical and other numeric data can often be hard to interpret.
- B. These risk assessments are largely subjective and require agreement on rankings beforehand.
- C. There needs to be a large amount of previous data to "train" a qualitative risk methodology.
- D. It requires the use of complex software tools to undertake this risk assessment.
Answer: D
NEW QUESTION 83
......
CISMP-V9 Exam Dumps - Try Best CISMP-V9 Exam Questions: https://www.pass4surequiz.com/CISMP-V9-exam-quiz.html
Get New CISMP-V9 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1JTxHpqewMqdO0WcIKBmQONsE3bYNEgee