最新のEXIN ISMPのPDFと問題集で(2022)無料試験問題解答 [Q13-Q31]

Share

最新のEXIN ISMPのPDFと問題集で(2022)無料試験問題解答

あなたを合格させるInformation Security Management ISMP試験問題集で2022年02月25日には31問あります

質問 13
A security manager just finished the final copy of a risk assessment. This assessment contains a list of identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?

  • A. Design appropriate controls to reduce the risk
  • B. Begin risk remediation immediately as the organization is currently at risk
  • C. Remediate the risk regardless of cost
  • D. Decide the criteria for determining if the risk can be accepted

正解: D

 

質問 14
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?

  • A. Investigate the private mailbox of the employee
  • B. Investigate the contents of the workstation of the employee
  • C. Seize and investigate the private laptop of the employee
  • D. Put a phone tap on the employee's business phone

正解: B

 

質問 15
An information security officer is asked to write a retention policy for a financial system. She is aware of the fact that some data must be kept for a long time and other data must be deleted.
Where should she look for guidelines first?

  • A. In company policies
  • B. In legislation
  • C. In finance management procedures

正解: B

 

質問 16
What is a risk treatment strategy?

  • A. Mobile updates
  • B. Risk acceptance
  • C. Software installation
  • D. Risk exclusion

正解: B

 

質問 17
The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?

  • A. Produce a Statement of Applicability based on risk assessments
  • B. Perform a risk assessment of the secure internet connectivity architecture of the datacenter
  • C. Formulate the security requirements in the outsourcing contracts
  • D. Implement the security baselines in Secure Systems Development Life Cycle (SecSDLC)

正解: A

 

質問 18
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person's picture on the smart card?

  • A. To identify the role of the card owner
  • B. To verify the iris of the card owner
  • C. To authorize the owner of the card
  • D. To authenticate the owner of the card

正解: D

 

質問 19
The security manager of a global company has decided that a risk assessment needs to be completed across the company.
What is the primary objective of the risk assessment?

  • A. Identify, quantify and prioritize which controls are going to be used to mitigate risk
  • B. Identify, quantify and prioritize each of the business-critical assets residing on the corporate infrastructure
  • C. Identify, quantify and prioritize risks against criteria for risk acceptance
  • D. Identify, quantify and prioritize the scope of this risk assessment

正解: C

 

質問 20
The Board of Directors of an organization is accountable for obtaining adequate assurance.
Who should be responsible for coordinating the information security awareness campaigns?

  • A. The Board of Directors
  • B. The user
  • C. The operational manager
  • D. The security manager

正解: D

 

質問 21
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?

  • A. Act
  • B. Plan
  • C. Do
  • D. Check

正解: B

 

質問 22
In a company the IT strategy is migrating towards a Service Oriented Architecture (SOA) so that migrating to the cloud is better feasible in the future. The security architect is asked to make a first draft of the security architecture.
Which elements should the security architect draft?

  • A. The information security policy, the risk assessment and the controls in the security services
  • B. Management and control of the security services
  • C. Which security services are provided and in which supporting architectures are they defined

正解: C

 

質問 23
Which security item is designed to take collections of data from multiple computers?

  • A. Virtual Private Network (VPN)
  • B. Host-Based Intrusion Detection and Prevention System (Host-Based IDPS)
  • C. Firewall
  • D. Network-Based Intrusion Detection and Prevention System (Network-Based IDPS)

正解: D

 

質問 24
Security monitoring is an important control measure to make sure that the required security level is maintained. In order to realize 24/7 availability of the service, this service is outsourced to a partner in the cloud.
What should be an important control in the contract?

  • A. Your IT auditor has the right to audit the external party's service management processes.
  • B. The third party is certified for adhering to privacy protection controls.
  • C. The third party is certified against ISO/IEC 27001.
  • D. The network communication channel is secured by using encryption.

正解: A

 

質問 25
......

ISMP問題集はInformation Security Management認証済み試験問題と解答:https://www.passtest.jp/EXIN/ISMP-shiken.html