[Nov-2021] Latest BCS CISMP-V9 Certification Practice Test Questions [Q56-Q78]

Share

[Nov-2021] Latest BCS CISMP-V9  Certification Practice Test Questions

Verified CISMP-V9 Dumps Q&As - 1 Year Free & Quickly Updates

NEW QUESTION 56
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?

  • A. Deny.
  • B. Delay.
  • C. Deter.
  • D. Drop.

Answer: C

 

NEW QUESTION 57
Which of the following is often the final stage in the information management lifecycle?

  • A. Use.
  • B. Disposal.
  • C. Publication.
    https://timg.co.nz/blog-the-information-management-life-cycle/
  • D. Creation.

Answer: B

 

NEW QUESTION 58
Which of the following is a framework and methodology for Enterprise Security Architecture and Service Management?

  • A. TOGAF
  • B. OWASP.
  • C. SABSA
  • D. PCI DSS.

Answer: C

 

NEW QUESTION 59
James is working with a software programme that completely obfuscates the entire source code, often in the form of a binary executable making it difficult to inspect, manipulate or reverse engineer the original source code.
What type of software programme is this?

  • A. Interpreted Source.
  • B. Free Source.
  • C. Proprietary Source.
  • D. Open Source.

Answer: A

 

NEW QUESTION 60
Which of the following is an asymmetric encryption algorithm?

  • A. AES.
  • B. DES.
  • C. RSA.
    https://www.omnisecu.com/security/public-key-infrastructure/asymmetric-encryption-algorithms.php
  • D. ATM.

Answer: C

 

NEW QUESTION 61
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?

  • A. By increasing deterrent controls through warning messages.
  • B. By using a hypervisor in all shared severs.
  • C. By ensuring appropriate data isolation and logical storage segregation.
  • D. By employing intrusion detection systems in a VMs.

Answer: D

 

NEW QUESTION 62
Which types of organisations are likely to be the target of DDoS attacks?

  • A. Online retail based organisations.
  • B. Any financial sector organisations.
  • C. Any organisation with an online presence.
  • D. Cloud service providers.

Answer: C

 

NEW QUESTION 63
Which of the following controls would be the MOST relevant and effective in detecting zero day attacks?

  • A. Vulnerability assessment
  • B. Strong OS patch management
  • C. Signature-based intrusion detection.
  • D. Anomaly based intrusion detection.
    https://www.sciencedirect.com/topics/computer-science/zero-day-attack

Answer: A

 

NEW QUESTION 64
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?

  • A. Digital devices must be forensically "clean" before investigation.
  • B. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
  • C. Digital evidence must not be altered unless absolutely necessary.
  • D. Digital evidence can only be handled by a member of law enforcement.

Answer: A

 

NEW QUESTION 65
Which of the following acronyms covers the real-time analysis of security alerts generated by applications and network hardware?

  • A. SIEM.
  • B. DDoS.
    https://en.wikipedia.org/wiki/Security_information_and_event_management
  • C. CISM.
  • D. CERT

Answer: A

 

NEW QUESTION 66
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobile computing or a BYOD approach.
What technology would be MOST beneficial to his organisation?

  • A. MDM.
  • B. IDS.
  • C. SIEM.
  • D. VPN.

Answer: A

 

NEW QUESTION 67
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?

  • A. Risks remain under constant review.
  • B. A maximum of once every other month.
  • C. When the next risk audit is due.
  • D. Once defined, they do not need reviewing.

Answer: A

 

NEW QUESTION 68
A security analyst has been asked to provide a triple A service (AAA) for both wireless and remote access network services in an organization and must avoid using proprietary solutions.
What technology SHOULD they adapt?

  • A. RADIUS.
  • B. MS Access Database.
  • C. TACACS+
  • D. Oauth.

Answer: D

 

NEW QUESTION 69
Which security framework impacts on organisations that accept credit cards, process credit card transactions, store relevant data or transmit credit card data?

  • A. Sarbanes-Oxiey
    https://digitalguardian.com/blog/what-pci-compliance
  • B. ENISA NIS.
  • C. PCI DSS.
  • D. TOGAF.

Answer: C

 

NEW QUESTION 70
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?

  • A. Parameter Tampering
  • B. XSS.
  • C. CSRF.
  • D. SQL Injection.

Answer: C

 

NEW QUESTION 71
What type of attack could directly affect the confidentiality of an unencrypted VoIP network?

  • A. Packet Sniffing.
  • B. Brute Force Attack.
  • C. Vishing Attack
  • D. Ransomware.

Answer: B

 

NEW QUESTION 72
Which of the following describes a qualitative risk assessment approach?

  • A. A subjective assessment of risk occurrence likelihood against the potential impact that determines the overall severity of a risk.
  • B. The use of Risk Tolerance and Risk Appetite values to determine the overall severity of a risk
  • C. The use of Monte-Carlo Analysis and Layers of Protection Analysis (LOPA) to determine the overall severity of a risk.
  • D. The use of verifiable data to predict the risk occurrence likelihood and the potential impact so as to determine the overall severity of a risk.

Answer: C

 

NEW QUESTION 73
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?

  • A. Hot site.
  • B. Cold site.
  • C. Spare site
  • D. Warm site.

Answer: B

 

NEW QUESTION 74
Which membership based organisation produces international standards, which cover good practice for information assurance?

  • A. OWASP.
  • B. BSI.
  • C. IETF.
  • D. ISF.

Answer: B

 

NEW QUESTION 75
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things (IoT) solutions?

  • A. Use of cloud based systems to collect loT data.
  • B. Use of proprietary networking protocols between nodes.
  • C. Much larger attack surface than traditional IT systems.
  • D. Use of 'cheap" microcontroller based sensors.

Answer: A

 

NEW QUESTION 76
Why is it prudent for Third Parties to be contracted to meet specific security standards?

  • A. Third Parties cannot connect to other sites and networks without a contract of similar legal agreement.
  • B. It is a legal requirement for Third Party support companies to meet client security standards.
  • C. All access to corporate systems must be controlled via a single set of rules if they are to be enforceable.
  • D. Vulnerabilities in Third Party networks can be malevolently leveraged to gain illicit access into client environments.

Answer: C

 

NEW QUESTION 77
Which term is used to describe the set of processes that analyses code to ensure defined coding practices are being followed?

  • A. Source code analysis.
  • B. Quality Assurance and Control
  • C. Dynamic verification.
  • D. Static verification.

Answer: A

 

NEW QUESTION 78
......

Latest 2021 Realistic Verified CISMP-V9 Dumps - 100% Free CISMP-V9 Exam Dumps: https://www.actual4dumps.com/CISMP-V9-study-material.html

Get 2021 Updated Free BCS CISMP-V9 Exam Questions & Answer: https://drive.google.com/open?id=1pY86HMZ16A6rm8mH_YdGafZ1pKDt31E3