
[Jan 04, 2022] Ultimate ISMP Guide to Prepare Free Latest EXIN Practice Tests Dumps
Get Top-Rated EXIN ISMP Exam Dumps Now
NEW QUESTION 15
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
- A. Investigate the contents of the workstation of the employee
- B. Seize and investigate the private laptop of the employee
- C. Put a phone tap on the employee's business phone
- D. Investigate the private mailbox of the employee
Answer: A
NEW QUESTION 16
A security manager for a large company has the task to achieve physical protection for corporate data stores.
Through which control can physical protection be achieved?
- A. Using access control lists to prevent logical access to organizational infrastructure
- B. Using a firewall to prevent access to the network infrastructure
- C. Having visitors sign in and out of the corporate datacenter
- D. Using key access controls for employees needing access
Answer: D
NEW QUESTION 17
It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and external audits.
What component of the audit trail is the most important for an external auditor?
- A. System-specific policies for business systems
- B. Access criteria and access control mechanisms
- C. Log review, consolidation and management
Answer: B
NEW QUESTION 18
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?
- A. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)
- B. Formulate the security requirements in the outsourcing contracts
- C. Produce a Statement of Applicability based on risk assessments
- D. Perform a risk assessment of the secure internet connectivity architecture of the datacenter
Answer: C
NEW QUESTION 19
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?
- A. Send a checklist for threat identification to all staff involved in information security
- B. Have a brainstorm with representatives of all stakeholders
- C. Interview top management
Answer: B
NEW QUESTION 20
When should information security controls be considered?
- A. During the risk assessment work
- B. After the risk assessment
- C. As part of the scoping meeting
- D. At the kick-off meeting
Answer: B
NEW QUESTION 21
The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?
- A. Identify, quantify and prioritize risks against criteria for risk acceptance
- B. Identify, quantify and prioritize which controls are going to be used to mitigate risk
- C. Identify, quantify and prioritize the scope of this risk assessment
- D. Identify, quantify and prioritize each of the business-critical assets residing on the corporate infrastructure
Answer: A
NEW QUESTION 22
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person's picture on the smart card?
- A. To authorize the owner of the card
- B. To verify the iris of the card owner
- C. To identify the role of the card owner
- D. To authenticate the owner of the card
Answer: D
NEW QUESTION 23
What is a key item that must be kept in mind when designing an enterprise-wide information security program?
- A. Determine controls in the light of specific risks an organization is facing
- B. Put an incident management and log file analysis program in place immediately
- C. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
- D. When defining controls follow an approach and framework that is consistent with organizational culture
Answer: A
NEW QUESTION 24
When is revision of an employee's access rights mandatory?
- A. At hire
- B. At least each year
- C. At all moments stated in the information security policy
- D. After any position change
Answer: C
NEW QUESTION 25
A security manager just finished the final copy of a risk assessment. This assessment contains a list of identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?
- A. Remediate the risk regardless of cost
- B. Decide the criteria for determining if the risk can be accepted
- C. Design appropriate controls to reduce the risk
- D. Begin risk remediation immediately as the organization is currently at risk
Answer: B
NEW QUESTION 26
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?
- A. The security manager
- B. The Board of Directors
- C. The user
- D. The operational manager
Answer: A
NEW QUESTION 27
......
Passing Key To Getting ISMP Certified Exam Engine PDF: https://www.prepawaypdf.com/EXIN/ISMP-practice-exam-dumps.html