[Oct-2021] Pass CISMP-V9 Exam in First Attempt UpdatedCISMP-V9 RealExamFree Exam Question [Q19-Q42]

Share

[Oct-2021] Pass CISMP-V9 Exam in First Attempt UpdatedCISMP-V9 RealExamFree Exam Question

Information security and CCP scheme certifications Dumps CISMP-V9 Exam for Full Questions - Exam Study Guide

NEW QUESTION 19
Why have MOST European countries developed specific legislation that permits police and security services to monitor communications traffic for specific purposes, such as the detection of crime?

  • A. GDPR overrides all previous legislation on information handling, so new laws were needed to ensure authorities did not inadvertently break the law.
  • B. Under the European Convention of Human Rights, the interception of telecommunications represents an interference with the right to privacy.
  • C. Police could previously intercept without lawful authority any communications in the course of transmission through a public post or telecoms system.
  • D. Surveillance of a conversation or an online message by law enforcement agents was previously illegal due to the 1950 version of the Human Rights Convention.

Answer: C

 

NEW QUESTION 20
Ensuring the correctness of data inputted to a system is an example of which facet of information security?

  • A. Integrity.
  • B. Availability.
  • C. Authenticity.
  • D. Confidentiality.

Answer: A

 

NEW QUESTION 21
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?

  • A. Security Engine.
  • B. Guest Manager
  • C. OS Kernal
  • D. Hypervisor.

Answer: B

 

NEW QUESTION 22
Which of the following acronyms covers the real-time analysis of security alerts generated by applications and network hardware?

  • A. SIEM.
  • B. CISM.
  • C. CERT
  • D. DDoS.
    https://en.wikipedia.org/wiki/Security_information_and_event_management

Answer: A

 

NEW QUESTION 23
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?

  • A. By using a hypervisor in all shared severs.
  • B. By ensuring appropriate data isolation and logical storage segregation.
  • C. By increasing deterrent controls through warning messages.
  • D. By employing intrusion detection systems in a VMs.

Answer: D

 

NEW QUESTION 24
Which of the following is the MOST important reason for undertaking Continual Professional Development (CPD) within the Information Security sphere?

  • A. IT certifications require CPD and Security needs to remain credible.
  • B. CPD is a prerequisite of any Chartered Institution qualification.
  • C. Professional qualification bodies demand CPD.
  • D. Information Security changes constantly and at speed.

Answer: D

 

NEW QUESTION 25
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?

  • A. Drop.
  • B. Deter.
  • C. Delay.
  • D. Deny.

Answer: B

 

NEW QUESTION 26
In order to better improve the security culture within an organisation with a top down approach, which of the following actions at board level is the MOST effective?

  • A. Adopting an organisation wide "clear desk" policy.
  • B. Purchasing all senior executives personal firewalls.
  • C. Developing a security awareness e-learning course.
  • D. Appointment of a Chief Information Security Officer (CISO).

Answer: D

 

NEW QUESTION 27
What Is the PRIMARY reason for organisations obtaining outsourced managed security services?

  • A. Managed security services permit organisations to absolve themselves of responsibility for security.
  • B. Managed security services are a de facto requirement for certification to core security standards such as ISG/IEC 27001
  • C. Managed security services provide access to specialist security tools and expertise on a shared, cost-effective basis.
  • D. Managed security services are a powerful defence against litigation in the event of a security breach or incident

Answer: A

 

NEW QUESTION 28
Which of the following is NOT an information security specific vulnerability?

  • A. Use of HTTP based Apache web server.
  • B. Confidential data stored in a fire safe.
  • C. Use of an unlocked filing cabinet.
  • D. Unpatched Windows operating system.

Answer: A

 

NEW QUESTION 29
How does network visualisation assist in managing information security?

  • A. Visualisation can communicate large amounts of data in a manner that is a relatively simple way for people to analyse and interpret.
  • B. Visualisation provides structured tables and lists that can be analysed using common tools such as MS Excel.
  • C. Visualisation offers unstructured data that records the entirety of the data in a flat, filterable ftle format.
  • D. Visualisation software operates in a way that is rarely and thereby it is less prone to malware infection.

Answer: D

 

NEW QUESTION 30
Which of the following statements relating to digital signatures is TRUE?

  • A. A digital signature that uses a signer's private key is illegal.
  • B. Digital signatures are rarely legally enforceable even if the signers know they are signing a legal document.
  • C. Digital signatures are valid and enforceable in law in most countries in the world.
  • D. Digital signatures are legal unless there is a statutory requirement that predates the digital age.

Answer: D

 

NEW QUESTION 31
Which of the following compliance legal requirements are covered by the ISO/IEC 27000 series?
1. Intellectual Property Rights.
2. Protection of Organisational Records
3. Forensic recovery of data.
4. Data Deduplication.
5. Data Protection & Privacy.

  • A. 1, 2 and 5
  • B. 3, 4 and 5
  • C. 1, 2 and 3
  • D. 2, 3 and 4

Answer: A

 

NEW QUESTION 32
Which of the following controls would be the MOST relevant and effective in detecting zero day attacks?

  • A. Signature-based intrusion detection.
  • B. Anomaly based intrusion detection.
    https://www.sciencedirect.com/topics/computer-science/zero-day-attack
  • C. Strong OS patch management
  • D. Vulnerability assessment

Answer: D

 

NEW QUESTION 33
As well as being permitted to access, create, modify and delete information, what right does an Information Owner NORMALLY have in regard to their information?

  • A. To access information held in the same format and file structure.
  • B. To modify associated information that may lead to inappropriate disclosure.
  • C. To assign access privileges to others.
  • D. To delete all indexed data in the dataset.

Answer: B

 

NEW QUESTION 34
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?

  • A. Risk = Threat * Likelihood.
  • B. Risk = Vulnerability / Threat.
  • C. Risk = Likelihood / Impact.
  • D. Risk = Likelihood * Impact.

Answer: B

 

NEW QUESTION 35
What Is the PRIMARY difference between DevOps and DevSecOps?

  • A. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
  • B. DevSecOps includes security on the same level as continuous integration and delivery.
  • C. DevOps mandates that security is integrated at the beginning of the development lifecycle.
    https://www.viva64.com/en/b/0710/#:~:text=DevOps%20is%20a%20methodology%20aiming,in%20the%20software%20development%20process.&text=DevSecOps%20is%20a%20further%20development,code%20quality%20and%20reliability%20assurance.
  • D. DevSecOps focuses solely on iterative development cycles.

Answer: B

 

NEW QUESTION 36
Which standards framework offers a set of IT Service Management best practices to assist organisations in aligning IT service delivery with business goals - including security goals?

  • A. ISAGA.
    https://www.cherwell.com/it-service-management/library/essential-guides/essential-guide-to-itil-framework-and-processes/
  • B. COBIT
  • C. SABSA.
  • D. ITIL.

Answer: D

 

NEW QUESTION 37
What are the different methods that can be used as access controls?
1. Detective.
2. Physical.
3. Reactive.
4. Virtual.
5. Preventive.

  • A. 1, 2 and 3.
  • B. 3, 4 and 5.
  • C. 1, 2 and 5.
  • D. 1, 2 and 4.

Answer: C

 

NEW QUESTION 38
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobile computing or a BYOD approach.
What technology would be MOST beneficial to his organisation?

  • A. SIEM.
  • B. IDS.
  • C. MDM.
  • D. VPN.

Answer: C

 

NEW QUESTION 39
Which of the following uses are NOT usual ways that attackers have of leveraging botnets?

  • A. Scanning for system & application vulnerabilities.
  • B. Undertaking vishing attacks
  • C. Conducting DDOS attacks.
  • D. Generating and distributing spam messages.

Answer: B

 

NEW QUESTION 40
What Is the first yet MOST simple and important action to take when setting up a new web server?

  • A. Fully encrypt the hard disk.
  • B. Change default system passwords.
  • C. Patch the OS to the latest version
  • D. Apply hardening to all applications.

Answer: D

 

NEW QUESTION 41
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?

  • A. Digital evidence can only be handled by a member of law enforcement.
  • B. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
  • C. Digital devices must be forensically "clean" before investigation.
  • D. Digital evidence must not be altered unless absolutely necessary.

Answer: C

 

NEW QUESTION 42
......

Authentic Best resources for CISMP-V9 Online Practice Exam: https://www.realexamfree.com/CISMP-V9-real-exam-dumps.html

Get the superior quality CISMP-V9 Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1yoIWpnB3jRU5AxJciidJTay8dfTSsbvU