Updated BCS Foundation Certificate In Information Security Management Principles V9.0 CISMP-V9 Study Guide

Want to know Examcollection CISMP-V9 Exam practice test features? Want to lear more about BCS BCS Foundation Certificate in Information Security Management Principles V9.0 certification experience? Study Printable BCS CISMP-V9 answers to Abreast of the times CISMP-V9 questions at Examcollection. Gat a success with an absolute guarantee to pass BCS CISMP-V9 (BCS Foundation Certificate in Information Security Management Principles V9.0) test on your first attempt.

Free CISMP-V9 Demo Online For BCS Certifitcation:

NEW QUESTION 1
How does network visualisation assist in managing information security?

  • A. Visualisation can communicate large amounts of data in a manner that is a relatively simple way for people to analyse and interpret.
  • B. Visualisation provides structured tables and lists that can be analysed using common tools such as MS Excel.
  • C. Visualisation offers unstructured data that records the entirety of the data in a flat, filterable ftle format.
  • D. Visualisation software operates in a way that is rarely and thereby it is less prone to malware infection.

Answer: D

NEW QUESTION 2
Which of the following is NOT considered to be a form of computer misuse?

  • A. Illegal retention of personal data.
  • B. Illegal interception of information.
  • C. Illegal access to computer systems.
  • D. Downloading of pirated software.

Answer: A

NEW QUESTION 3
What term is used to describe the act of checking out a privileged account password in a manner that bypasses normal access controlsprocedures during a critical emergency situation?

  • A. Privileged User Gateway
  • B. Enterprise Security Management
  • C. Multi Factor Authentication.
  • D. Break Glass

Answer: C

NEW QUESTION 4
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a largeorganisation?

  • A. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
  • B. The organisation has significantly less control over the device than over a corporately provided and managed device.
  • C. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.
  • D. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.

Answer: A

NEW QUESTION 5
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things(IoT) solutions?

  • A. Use of 'cheap" microcontroller based sensors.
  • B. Much larger attack surface than traditional IT systems.
  • C. Use of proprietary networking protocols between nodes.
  • D. Use of cloud based systems to collect loT data.

Answer: D

NEW QUESTION 6
When a digital forensics investigator is conducting art investigation and handling the original data, what KEY principle must they adhere to?

  • A. Ensure they are competent to be able to do so and be able to justify their actions.
  • B. Ensure they are being observed by a senior investigator in all actions.
  • C. Ensure they do not handle the evidence as that mustbe done by law enforcement officers.
  • D. Ensure the data has been adjusted to meet the investigation requirements.

Answer: A

NEW QUESTION 7
When considering outsourcing the processing of data, which two legal "duty of care" considerations SHOULD the original data owner make?
* 1 Third party is competent to process the data securely.
* 2. Observes the same high standards as data owner.
* 3. Processes the data wherever the data can be transferred.
* 4. Archive the data for long term third party's own usage.

  • A. 2 and 3.
  • B. 3 and 4.
  • C. 1 and 4.
  • D. 1 and 2.

Answer: C

NEW QUESTION 8
Why have MOST European countries developed specific legislation that permits police and security services to monitor communications trafficfor specific purposes, such as the detection of crime?

  • A. Under the European Convention of Human Rights, the interception of telecommunications represents aninterference with the right toprivacy.
  • B. GDPR overrides all previous legislation on information handling, so new laws were needed to ensure authorities did not inadvertentlybreak the law.
  • C. Police could previously intercept without lawful authority any communications in the course of transmission through a public post ortelecoms system.
  • D. Surveillance of a conversation or an online message by law enforcement agents was previously illegaldue to the 1950 version of theHuman Rights Convention.

Answer: C

NEW QUESTION 9
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?

  • A. Guest Manager
  • B. Hypervisor.
  • C. Security Engine.
  • D. OS Kernal

Answer: A

NEW QUESTION 10
Which of the following is a framework and methodology for Enterprise Security Architecture and Service Management?

  • A. TOGAF
  • B. SABSA
  • C. PCI DSS.
  • D. OWASP.

Answer: B

NEW QUESTION 11
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?

  • A. Risk = Likelihood * Impact.
  • B. Risk = Likelihood / Impact.
  • C. Risk = Vulnerability / Threat.
  • D. Risk = Threat * Likelihood.

Answer: C

NEW QUESTION 12
What are the different methods that can be used as access controls?
* 1. Detective.
* 2. Physical.
* 3. Reactive.
* 4. Virtual.
* 5. Preventive.

  • A. 1, 2 and 4.
  • B. 1, 2 and 3.
  • C. 1, 2 and 5.
  • D. 3, 4 and 5.

Answer: C

NEW QUESTION 13
When securing a wireless network, which of the following is NOT best practice?

  • A. Using WPA encryption on the wireless network.
  • B. Use MAC tittering on a SOHO network with a smart group of clients.
  • C. Dedicating an access point on a dedicated VLAN connected to a firewall.
  • D. Turning on SSID broadcasts to advertise security levels.

Answer: C

NEW QUESTION 14
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobilecomputing or a BYOD approach.
What technology would be MOST beneficial to his organisation?

  • A. VPN.
  • B. IDS.
  • C. MDM.
  • D. SIEM.

Answer: C

NEW QUESTION 15
Which type of facility is enabled by a contract with an alternative data processing facility which willprovide HVAC, power and communicationsinfrastructure as well computing hardware and a duplication of organisations existing "live" data?

  • A. Cold site.
  • B. Warm site.
  • C. Hot site.
  • D. Spare site

Answer: A

NEW QUESTION 16
You are undertaking a qualitative risk assessment of a likely security threat to an information system. What is the MAIN issue with this type of risk assessment?

  • A. These risk assessments are largely subjective and require agreement on rankings beforehand.
  • B. Dealing with statistical and other numeric data can often be hard to interpret.
  • C. There needs to be a large amount of previous data to "train" a qualitative risk methodology.
  • D. It requires the use of complex software tools to undertake this risk assessment.

Answer: D

NEW QUESTION 17
When seeking third party digital forensics services, what two attributes should one seek when making a choice of service provider?

  • A. Appropriate company accreditation and staff certification.
  • B. Formal certification to ISO/IEC 27001 and alignment withISO 17025.
  • C. Affiliation with local law enforcement bodies and local government regulations.
  • D. Clean credit references as well as international experience.

Answer: B

NEW QUESTION 18
Which membership based organisation produces international standards, which cover good practice for information assurance?

  • A. BSI.
  • B. IETF.
  • C. OWASP.
  • D. ISF.

Answer: A

NEW QUESTION 19
......

Recommend!! Get the Full CISMP-V9 dumps in VCE and PDF From Dumps-hub.com, Welcome to Download: https://www.dumps-hub.com/CISMP-V9-dumps.html (New 100 Q&As Version)