[Nov-2021] Valid Way To Pass BCS Exam Dumps with CISMP-V9 Exam Study Guide [Q54-Q79]

Share

[Nov-2021] Valid Way To Pass BCS Exam Dumps with CISMP-V9 Exam Study Guide

All CISMP-V9 Dumps and BCS Foundation Certificate in Information Security Management Principles V9.0 Training Courses Help candidates to study and pass the Exams hassle-free!

NEW QUESTION 54
Which algorithm is a current specification for the encryption of electronic data established by NIST?

  • A. RSA.
  • B. DES.
  • C. AES.
  • D. PGP.
    https://www.nist.gov/publications/advanced-encryption-standard-aes

Answer: C

 

NEW QUESTION 55
What term refers to the shared set of values within an organisation that determine how people are expected to behave in regard to information security?

  • A. System Operating Procedures.
  • B. Security Culture.
  • C. Security Policy Framework.
    https://www.cpni.gov.uk/developing-security-culture#:~:text=Developing%20a%20Security%20Culture,-What%20type%20of&text=Security%20culture%20refers%20to%20the,think%20about%20and%20approach%20security.&text=Employees%20are%20more%20likley%20to%20think%20and%20act%20in%20a%20security%20conscious%20manner
  • D. Code of Ethics.

Answer: B

 

NEW QUESTION 56
Which of the following is NOT considered to be a form of computer misuse?

  • A. Illegal access to computer systems.
  • B. Downloading of pirated software.
  • C. Illegal interception of information.
  • D. Illegal retention of personal data.

Answer: D

 

NEW QUESTION 57
You are undertaking a qualitative risk assessment of a likely security threat to an information system.
What is the MAIN issue with this type of risk assessment?

  • A. There needs to be a large amount of previous data to "train" a qualitative risk methodology.
  • B. These risk assessments are largely subjective and require agreement on rankings beforehand.
  • C. It requires the use of complex software tools to undertake this risk assessment.
  • D. Dealing with statistical and other numeric data can often be hard to interpret.

Answer: C

 

NEW QUESTION 58
What type of diagram used in application threat modeling includes malicious users as well as descriptions like mitigates and threatens?

  • A. DREAD diagrams.
  • B. Misuse case diagrams.
  • C. STRIDE charts.
  • D. Threat trees.

Answer: D

 

NEW QUESTION 59
According to ISO/IEC 27000, which of the following is the definition of a vulnerability?

  • A. The threat that an asset or group of assets may be damaged by an exploit.
  • B. A weakness of an asset or group of assets that can be exploited by one or more threats.
  • C. The impact of a cyber attack on an asset or group of assets.
  • D. The damage that has been caused by a weakness iin a system.
    Vulnerability
    A vulnerability is a weakness of an asset or control that could potentially be exploited by one or more threats.
    An asset is any tangible or intangible thing or characteristic that has value to an organization, a control is any administrative, managerial, technical, or legal method that can be used to modify or manage risk, and a threat is any potential event that could harm an organization or system.
    https://www.praxiom.com/iso-27000-definitions.htm

Answer: B

 

NEW QUESTION 60
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?

  • A. System Integrity.
  • B. Sandboxing.
  • C. Intrusion Prevention System.
  • D. Defence in depth.
    https://en.wikipedia.org/wiki/Defense_in_depth_(computing)

Answer: D

 

NEW QUESTION 61
When considering the disposal of confidential data, equipment and storage devices, what social engineering technique SHOULD always be taken into consideration?

  • A. Shoulder Surfing.
  • B. Tailgating.
  • C. Spear Phishing.
  • D. Dumpster Diving.

Answer: C

 

NEW QUESTION 62
A security analyst has been asked to provide a triple A service (AAA) for both wireless and remote access network services in an organization and must avoid using proprietary solutions.
What technology SHOULD they adapt?

  • A. RADIUS.
  • B. Oauth.
  • C. TACACS+
  • D. MS Access Database.

Answer: B

 

NEW QUESTION 63
What form of risk assessment is MOST LIKELY to provide objective support for a security Return on Investment case?

  • A. ISO/IEC 27001.
  • B. Quantitative
  • C. CPNI.
  • D. Qualitative.

Answer: B

 

NEW QUESTION 64
Which security framework impacts on organisations that accept credit cards, process credit card transactions, store relevant data or transmit credit card data?

  • A. PCI DSS.
  • B. ENISA NIS.
  • C. TOGAF.
  • D. Sarbanes-Oxiey
    https://digitalguardian.com/blog/what-pci-compliance

Answer: A

 

NEW QUESTION 65
Which of the following is often the final stage in the information management lifecycle?

  • A. Publication.
    https://timg.co.nz/blog-the-information-management-life-cycle/
  • B. Use.
  • C. Creation.
  • D. Disposal.

Answer: D

 

NEW QUESTION 66
When considering outsourcing the processing of data, which two legal "duty of care" considerations SHOULD the original data owner make?
1 Third party is competent to process the data securely.
2. Observes the same high standards as data owner.
3. Processes the data wherever the data can be transferred.
4. Archive the data for long term third party's own usage.

  • A. 1 and 2.
  • B. 2 and 3.
  • C. 3 and 4.
  • D. 1 and 4.

Answer: D

 

NEW QUESTION 67
One traditional use of a SIEM appliance is to monitor for exceptions received via syslog.
What system from the following does NOT natively support syslog events?

  • A. Enterprise Stateful Firewall.
  • B. Linux Web Server Appliances.
  • C. Windows Desktop Systems.
  • D. Enterprise Wireless Access Point.

Answer: B

 

NEW QUESTION 68
In business continuity, what is a battle box?

  • A. An armoured box that holds all an organisation's backup databases.
  • B. A portable container that holds Items and information useful in the event of an organisational disaster.
  • C. A collection of tools and protective equipment to be used in the event of civil disturbance.
  • D. A list of names and addresses of staff to be utilised should industrial action prevent access to a building.
    http://www.battlebox.biz/why.asp

Answer: B

 

NEW QUESTION 69
Which of the following is MOST LIKELY to be described as a consequential loss?

  • A. Reputation damage.
  • B. Monetary theft.
  • C. Service disruption.
  • D. Processing errors.

Answer: A

 

NEW QUESTION 70
What Is the root cause as to why SMS messages are open to attackers and abuse?

  • A. The store and forward nature of SMS means it is considered a 'fire and forget service'.
  • B. There are only two mobile phone platforms - Android and iOS - reducing the number of target environments.
  • C. SMS technology was never intended to be used to transmit high risk content such as One-time payment codes.
  • D. The vast majority of mobile phones globally support the SMS protocol inexpensively.

Answer: C

 

NEW QUESTION 71
Which of the following international standards deals with the retention of records?

  • A. PCI DSS.
  • B. ISO/IEC 27002.
  • C. IS015489.
  • D. RFC1918.

Answer: C

 

NEW QUESTION 72
Which of the following compliance legal requirements are covered by the ISO/IEC 27000 series?
1. Intellectual Property Rights.
2. Protection of Organisational Records
3. Forensic recovery of data.
4. Data Deduplication.
5. Data Protection & Privacy.

  • A. 1, 2 and 5
  • B. 3, 4 and 5
  • C. 1, 2 and 3
  • D. 2, 3 and 4

Answer: A

 

NEW QUESTION 73
In a security governance framework, which of the following publications would be at the HIGHEST level?

  • A. Guidelines
  • B. Standards
  • C. Policy.
  • D. Procedures.

Answer: D

 

NEW QUESTION 74
Which of the following statutory requirements are likely to be of relevance to all organisations no matter which sector nor geographical location they operate in?

  • A. FSA.
  • B. GDPR.
  • C. Sarbanes-Oxley.
  • D. HIPAA.

Answer: A

 

NEW QUESTION 75
Which of the following is the MOST important reason for undertaking Continual Professional Development (CPD) within the Information Security sphere?

  • A. IT certifications require CPD and Security needs to remain credible.
  • B. CPD is a prerequisite of any Chartered Institution qualification.
  • C. Professional qualification bodies demand CPD.
  • D. Information Security changes constantly and at speed.

Answer: D

 

NEW QUESTION 76
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?

  • A. By using a hypervisor in all shared severs.
  • B. By ensuring appropriate data isolation and logical storage segregation.
  • C. By increasing deterrent controls through warning messages.
  • D. By employing intrusion detection systems in a VMs.

Answer: D

 

NEW QUESTION 77
What form of training SHOULD developers be undertaking to understand the security of the code they have written and how it can improve security defence whilst being attacked?

  • A. Red Team Training.
  • B. Awareness Training.
  • C. Black Hat Training.
  • D. Blue Team Training.

Answer: C

 

NEW QUESTION 78
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?

  • A. A maximum of once every other month.
  • B. Risks remain under constant review.
  • C. When the next risk audit is due.
  • D. Once defined, they do not need reviewing.

Answer: B

 

NEW QUESTION 79
......

Get Latest [Nov-2021] Conduct effective penetration tests using  CertkingdomPDF CISMP-V9