[Nov-2021] Updated Information security and CCP scheme certifications CISMP-V9 Exam Questions BUNDLE PACK [Q46-Q66]

Share

[Nov-2021] Updated Information security and CCP scheme certifications CISMP-V9 Exam Questions BUNDLE PACK

Master The BCS Content CISMP-V9 EXAM DUMPS WITH GUARANTEED SUCCESS!

NEW QUESTION 46
One traditional use of a SIEM appliance is to monitor for exceptions received via syslog.
What system from the following does NOT natively support syslog events?

  • A. Linux Web Server Appliances.
  • B. Windows Desktop Systems.
  • C. Enterprise Stateful Firewall.
  • D. Enterprise Wireless Access Point.

Answer: A

 

NEW QUESTION 47
When undertaking disaster recovery planning, which of the following would NEVER be considered a "natural" disaster?

  • A. Lightning Strike
  • B. Arson.
  • C. Electromagnetic pulse
  • D. Tsunami.

Answer: C

 

NEW QUESTION 48
Which of the following cloud delivery models is NOT intrinsically "trusted" in terms of security by clients using the service?

  • A. Public.
  • B. Hybrid.
  • C. Private.
  • D. Community

Answer: D

 

NEW QUESTION 49
Select the document that is MOST LIKELY to contain direction covering the security and utilisation of all an organisation's information and IT equipment, as well as email, internet and telephony.

  • A. Business Continuity Plan.
  • B. Cryptographic Statement.
  • C. Acceptable Usage Policy.
  • D. Security Policy Framework.

Answer: B

 

NEW QUESTION 50
When preserving a crime scene for digital evidence, what actions SHOULD a first responder initially make?

  • A. Remove all digital evidence from the scene to prevent unintentional damage.
  • B. Don't touch any evidence until a senior digital investigator arrives.
    https://www.ncjrs.gov/pdffiles1/nij/219941.pdf
  • C. Remove power from all digital devices at the scene to stop the data changing.
  • D. Photograph all evidence and triage to determine whether live data capture is necessary.

Answer: B

 

NEW QUESTION 51
Which of the following subjects is UNLIKELY to form part of a cloud service provision laaS contract?

  • A. Intellectual Property Rights.
  • B. Liability
  • C. End-of-service.
  • D. User security education.

Answer: B

 

NEW QUESTION 52
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?

  • A. Parameter Tampering
  • B. SQL Injection.
  • C. XSS.
  • D. CSRF.

Answer: D

 

NEW QUESTION 53
A system administrator has created the following "array" as an access control for an organisation.
Developers: create files, update files.
Reviewers: upload files, update files.
Administrators: upload files, delete fifes, update files.
What type of access-control has just been created?

  • A. Mandatory access control.
  • B. Rule based access control.
  • C. Role based access control.
  • D. Task based access control.

Answer: B

 

NEW QUESTION 54
Which membership based organisation produces international standards, which cover good practice for information assurance?

  • A. IETF.
  • B. OWASP.
  • C. ISF.
  • D. BSI.

Answer: D

 

NEW QUESTION 55
A penetration tester undertaking a port scan of a client's network, discovers a host which responds to requests on TCP ports 22, 80, 443, 3306 and 8080.
What type of device has MOST LIKELY been discovered?

  • A. File server.
  • B. Firewall.
  • C. Printer.
  • D. Web server

Answer: A

 

NEW QUESTION 56
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?

  • A. Digital evidence must not be altered unless absolutely necessary.
  • B. Digital evidence can only be handled by a member of law enforcement.
  • C. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
  • D. Digital devices must be forensically "clean" before investigation.

Answer: D

 

NEW QUESTION 57
James is working with a software programme that completely obfuscates the entire source code, often in the form of a binary executable making it difficult to inspect, manipulate or reverse engineer the original source code.
What type of software programme is this?

  • A. Proprietary Source.
  • B. Open Source.
  • C. Free Source.
  • D. Interpreted Source.

Answer: D

 

NEW QUESTION 58
Which of the following is NOT an accepted classification of security controls?

  • A. Preventive.
  • B. Nominative.
  • C. Detective.
  • D. Corrective.

Answer: B

 

NEW QUESTION 59
What term refers to the shared set of values within an organisation that determine how people are expected to behave in regard to information security?

  • A. Security Policy Framework.
    https://www.cpni.gov.uk/developing-security-culture#:~:text=Developing%20a%20Security%20Culture,-What%20type%20of&text=Security%20culture%20refers%20to%20the,think%20about%20and%20approach%20security.&text=Employees%20are%20more%20likley%20to%20think%20and%20act%20in%20a%20security%20conscious%20manner
  • B. Security Culture.
  • C. Code of Ethics.
  • D. System Operating Procedures.

Answer: B

 

NEW QUESTION 60
Which of the following is an accepted strategic option for dealing with risk?

  • A. Detection.
  • B. Correction.
  • C. Acceptance
  • D. Forbearance.

Answer: B

 

NEW QUESTION 61
Which cryptographic protocol preceded Transport Layer Security (TLS)?

  • A. Simple Network Management Protocol (SNMP).
  • B. Hypertext Transfer Protocol Secure (HTTPS)
  • C. Secure Sockets Layer (SSL).
  • D. Public Key Infrastructure (PKI).

Answer: C

 

NEW QUESTION 62
What form of risk assessment is MOST LIKELY to provide objective support for a security Return on Investment case?

  • A. Qualitative.
  • B. Quantitative
  • C. ISO/IEC 27001.
  • D. CPNI.

Answer: B

 

NEW QUESTION 63
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?

  • A. Warm site.
  • B. Spare site
  • C. Cold site.
  • D. Hot site.

Answer: C

 

NEW QUESTION 64
Why is it prudent for Third Parties to be contracted to meet specific security standards?

  • A. It is a legal requirement for Third Party support companies to meet client security standards.
  • B. All access to corporate systems must be controlled via a single set of rules if they are to be enforceable.
  • C. Vulnerabilities in Third Party networks can be malevolently leveraged to gain illicit access into client environments.
  • D. Third Parties cannot connect to other sites and networks without a contract of similar legal agreement.

Answer: B

 

NEW QUESTION 65
What type of attack could directly affect the confidentiality of an unencrypted VoIP network?

  • A. Ransomware.
  • B. Vishing Attack
  • C. Packet Sniffing.
  • D. Brute Force Attack.

Answer: D

 

NEW QUESTION 66
......

Pass BCS CISMP-V9 Exam – Experts Are Here To Help You: https://www.pass4training.com/CISMP-V9-pass-exam-training.html

Get Latest Information security and CCP scheme certifications CISMP-V9 Practice Test For Quick Preparation: https://drive.google.com/open?id=1zsUmTKoDtKDE-KiM3yhCkFGp6JvbiRJC