
[Nov-2021] Latest BCS CISMP-V9 Certification Practice Test Questions
Verified CISMP-V9 Dumps Q&As - 1 Year Free & Quickly Updates
NEW QUESTION 56
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?
- A. Deny.
- B. Delay.
- C. Deter.
- D. Drop.
Answer: C
NEW QUESTION 57
Which of the following is often the final stage in the information management lifecycle?
- A. Use.
- B. Disposal.
- C. Publication.
https://timg.co.nz/blog-the-information-management-life-cycle/ - D. Creation.
Answer: B
NEW QUESTION 58
Which of the following is a framework and methodology for Enterprise Security Architecture and Service Management?
- A. TOGAF
- B. OWASP.
- C. SABSA
- D. PCI DSS.
Answer: C
NEW QUESTION 59
James is working with a software programme that completely obfuscates the entire source code, often in the form of a binary executable making it difficult to inspect, manipulate or reverse engineer the original source code.
What type of software programme is this?
- A. Interpreted Source.
- B. Free Source.
- C. Proprietary Source.
- D. Open Source.
Answer: A
NEW QUESTION 60
Which of the following is an asymmetric encryption algorithm?
- A. AES.
- B. DES.
- C. RSA.
https://www.omnisecu.com/security/public-key-infrastructure/asymmetric-encryption-algorithms.php - D. ATM.
Answer: C
NEW QUESTION 61
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?
- A. By increasing deterrent controls through warning messages.
- B. By using a hypervisor in all shared severs.
- C. By ensuring appropriate data isolation and logical storage segregation.
- D. By employing intrusion detection systems in a VMs.
Answer: D
NEW QUESTION 62
Which types of organisations are likely to be the target of DDoS attacks?
- A. Online retail based organisations.
- B. Any financial sector organisations.
- C. Any organisation with an online presence.
- D. Cloud service providers.
Answer: C
NEW QUESTION 63
Which of the following controls would be the MOST relevant and effective in detecting zero day attacks?
- A. Vulnerability assessment
- B. Strong OS patch management
- C. Signature-based intrusion detection.
- D. Anomaly based intrusion detection.
https://www.sciencedirect.com/topics/computer-science/zero-day-attack
Answer: A
NEW QUESTION 64
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?
- A. Digital devices must be forensically "clean" before investigation.
- B. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
- C. Digital evidence must not be altered unless absolutely necessary.
- D. Digital evidence can only be handled by a member of law enforcement.
Answer: A
NEW QUESTION 65
Which of the following acronyms covers the real-time analysis of security alerts generated by applications and network hardware?
- A. SIEM.
- B. DDoS.
https://en.wikipedia.org/wiki/Security_information_and_event_management - C. CISM.
- D. CERT
Answer: A
NEW QUESTION 66
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobile computing or a BYOD approach.
What technology would be MOST beneficial to his organisation?
- A. MDM.
- B. IDS.
- C. SIEM.
- D. VPN.
Answer: A
NEW QUESTION 67
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?
- A. Risks remain under constant review.
- B. A maximum of once every other month.
- C. When the next risk audit is due.
- D. Once defined, they do not need reviewing.
Answer: A
NEW QUESTION 68
A security analyst has been asked to provide a triple A service (AAA) for both wireless and remote access network services in an organization and must avoid using proprietary solutions.
What technology SHOULD they adapt?
- A. RADIUS.
- B. MS Access Database.
- C. TACACS+
- D. Oauth.
Answer: D
NEW QUESTION 69
Which security framework impacts on organisations that accept credit cards, process credit card transactions, store relevant data or transmit credit card data?
- A. Sarbanes-Oxiey
https://digitalguardian.com/blog/what-pci-compliance - B. ENISA NIS.
- C. PCI DSS.
- D. TOGAF.
Answer: C
NEW QUESTION 70
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?
- A. Parameter Tampering
- B. XSS.
- C. CSRF.
- D. SQL Injection.
Answer: C
NEW QUESTION 71
What type of attack could directly affect the confidentiality of an unencrypted VoIP network?
- A. Packet Sniffing.
- B. Brute Force Attack.
- C. Vishing Attack
- D. Ransomware.
Answer: B
NEW QUESTION 72
Which of the following describes a qualitative risk assessment approach?
- A. A subjective assessment of risk occurrence likelihood against the potential impact that determines the overall severity of a risk.
- B. The use of Risk Tolerance and Risk Appetite values to determine the overall severity of a risk
- C. The use of Monte-Carlo Analysis and Layers of Protection Analysis (LOPA) to determine the overall severity of a risk.
- D. The use of verifiable data to predict the risk occurrence likelihood and the potential impact so as to determine the overall severity of a risk.
Answer: C
NEW QUESTION 73
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?
- A. Hot site.
- B. Cold site.
- C. Spare site
- D. Warm site.
Answer: B
NEW QUESTION 74
Which membership based organisation produces international standards, which cover good practice for information assurance?
- A. OWASP.
- B. BSI.
- C. IETF.
- D. ISF.
Answer: B
NEW QUESTION 75
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things (IoT) solutions?
- A. Use of cloud based systems to collect loT data.
- B. Use of proprietary networking protocols between nodes.
- C. Much larger attack surface than traditional IT systems.
- D. Use of 'cheap" microcontroller based sensors.
Answer: A
NEW QUESTION 76
Why is it prudent for Third Parties to be contracted to meet specific security standards?
- A. Third Parties cannot connect to other sites and networks without a contract of similar legal agreement.
- B. It is a legal requirement for Third Party support companies to meet client security standards.
- C. All access to corporate systems must be controlled via a single set of rules if they are to be enforceable.
- D. Vulnerabilities in Third Party networks can be malevolently leveraged to gain illicit access into client environments.
Answer: C
NEW QUESTION 77
Which term is used to describe the set of processes that analyses code to ensure defined coding practices are being followed?
- A. Source code analysis.
- B. Quality Assurance and Control
- C. Dynamic verification.
- D. Static verification.
Answer: A
NEW QUESTION 78
......
Latest 2021 Realistic Verified CISMP-V9 Dumps - 100% Free CISMP-V9 Exam Dumps: https://www.actual4dumps.com/CISMP-V9-study-material.html
Get 2021 Updated Free BCS CISMP-V9 Exam Questions & Answer: https://drive.google.com/open?id=1pY86HMZ16A6rm8mH_YdGafZ1pKDt31E3