Want to know Examcollection CISMP-V9 Exam practice test features? Want to lear more about BCS BCS Foundation Certificate in Information Security Management Principles V9.0 certification experience? Study Printable BCS CISMP-V9 answers to Abreast of the times CISMP-V9 questions at Examcollection. Gat a success with an absolute guarantee to pass BCS CISMP-V9 (BCS Foundation Certificate in Information Security Management Principles V9.0) test on your first attempt.
Free CISMP-V9 Demo Online For BCS Certifitcation:
NEW QUESTION 1
How does network visualisation assist in managing information security?
- A. Visualisation can communicate large amounts of data in a manner that is a relatively simple way for people to analyse and interpret.
- B. Visualisation provides structured tables and lists that can be analysed using common tools such as MS Excel.
- C. Visualisation offers unstructured data that records the entirety of the data in a flat, filterable ftle format.
- D. Visualisation software operates in a way that is rarely and thereby it is less prone to malware infection.
Answer: D
NEW QUESTION 2
Which of the following is NOT considered to be a form of computer misuse?
- A. Illegal retention of personal data.
- B. Illegal interception of information.
- C. Illegal access to computer systems.
- D. Downloading of pirated software.
Answer: A
NEW QUESTION 3
What term is used to describe the act of checking out a privileged account password in a manner that bypasses normal access controlsprocedures during a critical emergency situation?
- A. Privileged User Gateway
- B. Enterprise Security Management
- C. Multi Factor Authentication.
- D. Break Glass
Answer: C
NEW QUESTION 4
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a largeorganisation?
- A. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
- B. The organisation has significantly less control over the device than over a corporately provided and managed device.
- C. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.
- D. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.
Answer: A
NEW QUESTION 5
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things(IoT) solutions?
- A. Use of 'cheap" microcontroller based sensors.
- B. Much larger attack surface than traditional IT systems.
- C. Use of proprietary networking protocols between nodes.
- D. Use of cloud based systems to collect loT data.
Answer: D
NEW QUESTION 6
When a digital forensics investigator is conducting art investigation and handling the original data, what KEY principle must they adhere to?
- A. Ensure they are competent to be able to do so and be able to justify their actions.
- B. Ensure they are being observed by a senior investigator in all actions.
- C. Ensure they do not handle the evidence as that mustbe done by law enforcement officers.
- D. Ensure the data has been adjusted to meet the investigation requirements.
Answer: A
NEW QUESTION 7
When considering outsourcing the processing of data, which two legal "duty of care" considerations SHOULD the original data owner make?
* 1 Third party is competent to process the data securely.
* 2. Observes the same high standards as data owner.
* 3. Processes the data wherever the data can be transferred.
* 4. Archive the data for long term third party's own usage.
- A. 2 and 3.
- B. 3 and 4.
- C. 1 and 4.
- D. 1 and 2.
Answer: C
NEW QUESTION 8
Why have MOST European countries developed specific legislation that permits police and security services to monitor communications trafficfor specific purposes, such as the detection of crime?
- A. Under the European Convention of Human Rights, the interception of telecommunications represents aninterference with the right toprivacy.
- B. GDPR overrides all previous legislation on information handling, so new laws were needed to ensure authorities did not inadvertentlybreak the law.
- C. Police could previously intercept without lawful authority any communications in the course of transmission through a public post ortelecoms system.
- D. Surveillance of a conversation or an online message by law enforcement agents was previously illegaldue to the 1950 version of theHuman Rights Convention.
Answer: C
NEW QUESTION 9
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?
- A. Guest Manager
- B. Hypervisor.
- C. Security Engine.
- D. OS Kernal
Answer: A
NEW QUESTION 10
Which of the following is a framework and methodology for Enterprise Security Architecture and Service Management?
- A. TOGAF
- B. SABSA
- C. PCI DSS.
- D. OWASP.
Answer: B
NEW QUESTION 11
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?
- A. Risk = Likelihood * Impact.
- B. Risk = Likelihood / Impact.
- C. Risk = Vulnerability / Threat.
- D. Risk = Threat * Likelihood.
Answer: C
NEW QUESTION 12
What are the different methods that can be used as access controls?
* 1. Detective.
* 2. Physical.
* 3. Reactive.
* 4. Virtual.
* 5. Preventive.
- A. 1, 2 and 4.
- B. 1, 2 and 3.
- C. 1, 2 and 5.
- D. 3, 4 and 5.
Answer: C
NEW QUESTION 13
When securing a wireless network, which of the following is NOT best practice?
- A. Using WPA encryption on the wireless network.
- B. Use MAC tittering on a SOHO network with a smart group of clients.
- C. Dedicating an access point on a dedicated VLAN connected to a firewall.
- D. Turning on SSID broadcasts to advertise security levels.
Answer: C
NEW QUESTION 14
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobilecomputing or a BYOD approach.
What technology would be MOST beneficial to his organisation?
- A. VPN.
- B. IDS.
- C. MDM.
- D. SIEM.
Answer: C
NEW QUESTION 15
Which type of facility is enabled by a contract with an alternative data processing facility which willprovide HVAC, power and communicationsinfrastructure as well computing hardware and a duplication of organisations existing "live" data?
- A. Cold site.
- B. Warm site.
- C. Hot site.
- D. Spare site
Answer: A
NEW QUESTION 16
You are undertaking a qualitative risk assessment of a likely security threat to an information system. What is the MAIN issue with this type of risk assessment?
- A. These risk assessments are largely subjective and require agreement on rankings beforehand.
- B. Dealing with statistical and other numeric data can often be hard to interpret.
- C. There needs to be a large amount of previous data to "train" a qualitative risk methodology.
- D. It requires the use of complex software tools to undertake this risk assessment.
Answer: D
NEW QUESTION 17
When seeking third party digital forensics services, what two attributes should one seek when making a choice of service provider?
- A. Appropriate company accreditation and staff certification.
- B. Formal certification to ISO/IEC 27001 and alignment withISO 17025.
- C. Affiliation with local law enforcement bodies and local government regulations.
- D. Clean credit references as well as international experience.
Answer: B
NEW QUESTION 18
Which membership based organisation produces international standards, which cover good practice for information assurance?
- A. BSI.
- B. IETF.
- C. OWASP.
- D. ISF.
Answer: A
NEW QUESTION 19
......
Recommend!! Get the Full CISMP-V9 dumps in VCE and PDF From Dumps-hub.com, Welcome to Download: https://www.dumps-hub.com/CISMP-V9-dumps.html (New 100 Q&As Version)
