
BCS CISMP-V9 Real Exam Questions Test Engine Dumps Training With 102 Questions
CISMP-V9 Actual Questions Answers PDF 100% Cover Real Exam Questions
NEW QUESTION 57
Why should a loading bay NEVER be used as a staff entrance?
- A. Staff should always enter a facility via a dedicated entrance to ensure smooth access and egress.
- B. Most countries have specific legislation covering loading bays and breaching this could impact on insurance status.
- C. Loading bays are often dirty places, and staff could find their clothing damaged or made less appropriate for the office.
- D. Loading bays are intrinsically vulnerable, so minimising the people traffic makes securing the areas easier and more effective.
Answer: A
NEW QUESTION 58
What term is used to describe the testing of a continuity plan through a written scenario being used as the basis for discussion and simulation?
- A. Desk-top exercise.
- B. Non-dynamic modeling
- C. Fault stressing
- D. End-to-end testing.
Answer: A
NEW QUESTION 59
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?
- A. Parameter Tampering
- B. XSS.
- C. CSRF.
- D. SQL Injection.
Answer: C
NEW QUESTION 60
In business continuity, what is a battle box?
- A. An armoured box that holds all an organisation's backup databases.
- B. A list of names and addresses of staff to be utilised should industrial action prevent access to a building.
http://www.battlebox.biz/why.asp - C. A portable container that holds Items and information useful in the event of an organisational disaster.
- D. A collection of tools and protective equipment to be used in the event of civil disturbance.
Answer: C
NEW QUESTION 61
What type of attack could directly affect the confidentiality of an unencrypted VoIP network?
- A. Packet Sniffing.
- B. Brute Force Attack.
- C. Vishing Attack
- D. Ransomware.
Answer: B
NEW QUESTION 62
Which of the following types of organisation could be considered the MOST at risk from the theft of electronic based credit card data?
- A. Agricultural producer.
- B. Mail delivery business.
- C. Online retailer.
- D. Traditional market trader.
Answer: C
NEW QUESTION 63
Which algorithm is a current specification for the encryption of electronic data established by NIST?
- A. RSA.
- B. DES.
- C. PGP.
https://www.nist.gov/publications/advanced-encryption-standard-aes - D. AES.
Answer: D
NEW QUESTION 64
A penetration tester undertaking a port scan of a client's network, discovers a host which responds to requests on TCP ports 22, 80, 443, 3306 and 8080.
What type of device has MOST LIKELY been discovered?
- A. Web server
- B. Printer.
- C. File server.
- D. Firewall.
Answer: C
NEW QUESTION 65
Which of the following is often the final stage in the information management lifecycle?
- A. Use.
- B. Disposal.
- C. Publication.
https://timg.co.nz/blog-the-information-management-life-cycle/ - D. Creation.
Answer: B
NEW QUESTION 66
Which of the following international standards deals with the retention of records?
- A. RFC1918.
- B. PCI DSS.
- C. ISO/IEC 27002.
- D. IS015489.
Answer: D
NEW QUESTION 67
Which of the following statutory requirements are likely to be of relevance to all organisations no matter which sector nor geographical location they operate in?
- A. HIPAA.
- B. FSA.
- C. GDPR.
- D. Sarbanes-Oxley.
Answer: B
NEW QUESTION 68
What Is the PRIMARY reason for organisations obtaining outsourced managed security services?
- A. Managed security services are a de facto requirement for certification to core security standards such as ISG/IEC 27001
- B. Managed security services are a powerful defence against litigation in the event of a security breach or incident
- C. Managed security services provide access to specialist security tools and expertise on a shared, cost-effective basis.
- D. Managed security services permit organisations to absolve themselves of responsibility for security.
Answer: D
NEW QUESTION 69
What form of risk assessment is MOST LIKELY to provide objective support for a security Return on Investment case?
- A. CPNI.
- B. ISO/IEC 27001.
- C. Quantitative
- D. Qualitative.
Answer: C
NEW QUESTION 70
Which of the following acronyms covers the real-time analysis of security alerts generated by applications and network hardware?
- A. SIEM.
- B. DDoS.
https://en.wikipedia.org/wiki/Security_information_and_event_management - C. CISM.
- D. CERT
Answer: A
NEW QUESTION 71
Which term is used to describe the set of processes that analyses code to ensure defined coding practices are being followed?
- A. Source code analysis.
- B. Quality Assurance and Control
- C. Dynamic verification.
- D. Static verification.
Answer: A
NEW QUESTION 72
One traditional use of a SIEM appliance is to monitor for exceptions received via syslog.
What system from the following does NOT natively support syslog events?
- A. Windows Desktop Systems.
- B. Enterprise Stateful Firewall.
- C. Enterprise Wireless Access Point.
- D. Linux Web Server Appliances.
Answer: D
NEW QUESTION 73
In business continuity (BC) terms, what is the name of the individual responsible for recording all pertinent information associated with a BC exercise or real plan invocation?
- A. Scribe.
- B. Recorder.
- C. Scrum Master.
- D. Desk secretary.
Answer: B
NEW QUESTION 74
Which term describes the acknowledgement and acceptance of ownership of actions, decisions, policies and deliverables?
- A. Confidentiality.
https://hr.nd.edu/assets/17442/behavior_model_4_ratings_3_.pdf - B. Responsibility.
- C. Accountability.
- D. Credibility.
Answer: C
NEW QUESTION 75
Which of the following is NOT considered to be a form of computer misuse?
- A. Illegal access to computer systems.
- B. Illegal interception of information.
- C. Illegal retention of personal data.
- D. Downloading of pirated software.
Answer: C
NEW QUESTION 76
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?
- A. Hot site.
- B. Cold site.
- C. Spare site
- D. Warm site.
Answer: B
NEW QUESTION 77
Which of the following is NOT a valid statement to include in an organisation's security policy?
- A. The policy has been agreed and amended to suit all third party contractors.
- B. How the organisation will manage information assurance.
- C. The policy has the support of Board and the Chief Executive.
- D. The compliance with legal and regulatory obligations.
Answer: B
NEW QUESTION 78
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?
- A. By increasing deterrent controls through warning messages.
- B. By using a hypervisor in all shared severs.
- C. By ensuring appropriate data isolation and logical storage segregation.
- D. By employing intrusion detection systems in a VMs.
Answer: D
NEW QUESTION 79
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?
- A. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
- B. A large increase in remote workers operating in insecure premises.
- C. Additional physical security requirements at data centres and corporate headquarters.
- D. Increased demand on service desks as users need additional tools such as VPNs.
Answer: D
NEW QUESTION 80
What physical security control would be used to broadcast false emanations to mask the presence of true electromagentic emanations from genuine computing equipment?
- A. White noise generation.
- B. Unshielded cabling.
- C. Faraday cage.
- D. Copper infused windows.
Answer: B
NEW QUESTION 81
......
NewPassLeader CISMP-V9 Exam Practice Test Questions : https://www.newpassleader.com/BCS/CISMP-V9-exam-preparation-materials.html
CISMP-V9 Exam questions and answers: https://drive.google.com/open?id=1FeZupGxpySAiWtyME9OKZt8rtgJ_RCkE