
Pass Your EXIN Exam with ISMP Exam Dumps (Updated 31 Questions)
ISMP Exam Dumps - EXIN Practice Test Questions
NEW QUESTION 12
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?
- A. Interview top management
- B. Have a brainstorm with representatives of all stakeholders
- C. Send a checklist for threat identification to all staff involved in information security
Answer: B
NEW QUESTION 13
It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?
- A. Log review, consolidation and management
- B. Access criteria and access control mechanisms
- C. System-specific policies for business systems
Answer: B
NEW QUESTION 14
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?
- A. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)
- B. Perform a risk assessment of the secure internet connectivity architecture of the datacenter
- C. Produce a Statement of Applicability based on risk assessments
- D. Formulate the security requirements in the outsourcing contracts
Answer: C
NEW QUESTION 15
When should information security controls be considered?
- A. After the risk assessment
- B. During the risk assessment work
- C. At the kick-off meeting
- D. As part of the scoping meeting
Answer: A
NEW QUESTION 16
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?
- A. The disaster recovery plan
- B. The incident response plan
- C. The risk treatment plan
- D. The Business Continuity Plan (BCP)
Answer: B
NEW QUESTION 17
The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?
- A. Identify, quantify and prioritize which controls are going to be used to mitigate risk
- B. Identify, quantify and prioritize risks against criteria for risk acceptance
- C. Identify, quantify and prioritize the scope of this risk assessment
- D. Identify, quantify and prioritize each of the business-critical assets residing on the corporate infrastructure
Answer: B
NEW QUESTION 18
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?
- A. Computer room and storage facility
- B. Lobby and public restaurant
- C. Boardroom and general office space
- D. Meeting rooms and Human Resource rooms
Answer: B
NEW QUESTION 19
What is the best way to start setting the information security controls?
- A. Use a standard security baseline
- B. Implement the security measures as prescribed by a risk analysis tool
- C. Resort back to the default factory standards
Answer: A
NEW QUESTION 20
An information security officer is asked to write a retention policy for a financial system. She is aware of the fact that some data must be kept for a long time and other data must be deleted.
Where should she look for guidelines first?
- A. In company policies
- B. In legislation
- C. In finance management procedures
Answer: B
NEW QUESTION 21
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person's picture on the smart card?
- A. To verify the iris of the card owner
- B. To authorize the owner of the card
- C. To authenticate the owner of the card
- D. To identify the role of the card owner
Answer: C
NEW QUESTION 22
When is revision of an employee's access rights mandatory?
- A. At least each year
- B. At all moments stated in the information security policy
- C. After any position change
- D. At hire
Answer: B
NEW QUESTION 23
What needs to be decided prior to considering the treatment of risks?
- A. Mitigation plans
- B. Criteria for determining whether or not the risk can be accepted
- C. The development of own guidelines
- D. How to apply appropriate controls to reduce the risks
Answer: B
NEW QUESTION 24
......
Pass Your ISMP Exam Easily with Accurate PDF Questions: https://www.test4cram.com/ISMP_real-exam-dumps.html