
[2022年更新]ISMPのPDF問題完璧見込みでPassTest練習試験合格させます
質問 10
An information security officer is asked to write a retention policy for a financial system. She is aware of the fact that some data must be kept for a long time and other data must be deleted.
Where should she look for guidelines first?
- A. In company policies
- B. In legislation
- C. In finance management procedures
正解: B
質問 11
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?
- A. The risk treatment plan
- B. The incident response plan
- C. The Business Continuity Plan (BCP)
- D. The disaster recovery plan
正解: B
質問 12
What is the main reason to use a firewall to separate two parts of your internal network?
- A. To control traffic intensity between two network segments
- B. To enable the installation of an Intrusion Detection System
- C. To decrease network loads
- D. To separate areas with different confidentiality requirements
正解: D
質問 13
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
- A. Once the controls are implemented
- B. When the risk analysis is completed
- C. Once the transference of the risk is complete
- D. When decision makers have been informed of uncontrolled risks and proper authority groups decide to leave the risks in place
正解: D
質問 14
What is the best way to start setting the information security controls?
- A. Implement the security measures as prescribed by a risk analysis tool
- B. Resort back to the default factory standards
- C. Use a standard security baseline
正解: C
質問 15
What is a risk treatment strategy?
- A. Mobile updates
- B. Risk acceptance
- C. Software installation
- D. Risk exclusion
正解: B
質問 16
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?
- A. Meeting rooms and Human Resource rooms
- B. Boardroom and general office space
- C. Computer room and storage facility
- D. Lobby and public restaurant
正解: D
質問 17
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
- A. Investigate the private mailbox of the employee
- B. Investigate the contents of the workstation of the employee
- C. Seize and investigate the private laptop of the employee
- D. Put a phone tap on the employee's business phone
正解: B
質問 18
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
- A. Act
- B. Plan
- C. Do
- D. Check
正解: B
質問 19
A risk manager is asked to perform a complete risk assessment for a company.
What is the best method to identify most of the threats to the company?
- A. Have a brainstorm with representatives of all stakeholders
- B. Interview top management
- C. Send a checklist for threat identification to all staff involved in information security
正解: A
質問 20
What is a key item that must be kept in mind when designing an enterprise-wide information security program?
- A. Put an enterprise-wide network and Host-Based Intrusion Detection and Prevention System (Host-Based IDPS) into place as soon as possible
- B. Determine controls in the light of specific risks an organization is facing
- C. Put an incident management and log file analysis program in place immediately
- D. When defining controls follow an approach and framework that is consistent with organizational culture
正解: B
質問 21
Who should be asked to check compliance with the information security policy throughout the company?
- A. External forensics investigators
- B. Internal audit department
- C. The same company that checks the yearly financial statement
正解: A
質問 22
......
オンライン問題傑作練習用であなたの試験を合格してみせます:https://www.passtest.jp/EXIN/ISMP-shiken.html