Updated Jan-2022 100% Cover Real ISMP Exam Questions - 100% Pass Guarantee [Q10-Q33]

Share

Updated Jan-2022 100% Cover Real ISMP Exam Questions - 100% Pass Guarantee

Use Real EXIN Dumps - 100% Free ISMP Exam Dumps

NEW QUESTION 10
A security architect argues with the internal fire prevention team about the statement in the information security policy, that doors to confidential areas should be locked at all times. The emergency response team wants to access to those areas in case of fire.
What is the best solution to this dilemma?

  • A. The doors should stay closed in case of fire to prevent access to confidential areas.
  • B. The security architect will be informed when there is a fire.
  • C. The doors will automatically open in case of fire.

Answer: C

 

NEW QUESTION 11
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?

  • A. When decision makers have been informed of uncontrolled risks and proper authority groups decide to leave the risks in place
  • B. Once the controls are implemented
  • C. Once the transference of the risk is complete
  • D. When the risk analysis is completed

Answer: A

 

NEW QUESTION 12
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?

  • A. The security manager
  • B. The Board of Directors
  • C. The operational manager
  • D. The user

Answer: A

 

NEW QUESTION 13
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person's picture on the smart card?

  • A. To verify the iris of the card owner
  • B. To authorize the owner of the card
  • C. To authenticate the owner of the card
  • D. To identify the role of the card owner

Answer: C

 

NEW QUESTION 14
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?

  • A. Computer room and storage facility
  • B. Lobby and public restaurant
  • C. Boardroom and general office space
  • D. Meeting rooms and Human Resource rooms

Answer: B

 

NEW QUESTION 15
What is a key item that must be kept in mind when designing an enterprise-wide information security program?

  • A. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
  • B. Put an incident management and log file analysis program in place immediately
  • C. When defining controls follow an approach and framework that is consistent with organizational culture
  • D. Determine controls in the light of specific risks an organization is facing

Answer: D

 

NEW QUESTION 16
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?

  • A. Plan
  • B. Act
  • C. Check
  • D. Do

Answer: A

 

NEW QUESTION 17
A security manager for a large company has the task to achieve physical protection for corporate data stores.
Through which control can physical protection be achieved?

  • A. Using a firewall to prevent access to the network infrastructure
  • B. Using key access controls for employees needing access
  • C. Using access control lists to prevent logical access to organizational infrastructure
  • D. Having visitors sign in and out of the corporate datacenter

Answer: B

 

NEW QUESTION 18
What is the main reason to use a firewall to separate two parts of your internal network?

  • A. To separate areas with different confidentiality requirements
  • B. To decrease network loads
  • C. To control traffic intensity between two network segments
  • D. To enable the installation of an Intrusion Detection System

Answer: A

 

NEW QUESTION 19
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?

  • A. Investigate the contents of the workstation of the employee
  • B. Investigate the private mailbox of the employee
  • C. Seize and investigate the private laptop of the employee
  • D. Put a phone tap on the employee's business phone

Answer: A

 

NEW QUESTION 20
When is revision of an employee's access rights mandatory?

  • A. At least each year
  • B. At all moments stated in the information security policy
  • C. After any position change
  • D. At hire

Answer: B

 

NEW QUESTION 21
What is a risk treatment strategy?

  • A. Risk exclusion
  • B. Software installation
  • C. Mobile updates
  • D. Risk acceptance

Answer: D

 

NEW QUESTION 22
......

ISMP Dumps PDF - ISMP Real Exam Questions Answers: https://www.realvce.com/ISMP_free-dumps.html