BCS CISMP-V9 Dumps Updated Jan 23, 2023 WIith 102 Questions [Q43-Q66]

Share

BCS CISMP-V9 Dumps Updated Jan 23, 2023 WIith 102 Questions

View All CISMP-V9 Actual Free Exam Questions Jan 23, 2023 Updated


What is the duration, language, and format of the BCS CISMP-V9 Certification Exam

  • Format: Multiple choices, multiple answers
  • Language: English
  • Length of Examination: 6 hours
  • Passing Score: 70%
  • Number of Questions: 200

 

NEW QUESTION 43
In software engineering, what does 'Security by Design" mean?

  • A. The software has been designed from its inception to be secure.
  • B. All security software artefacts are subject to a code-checking regime.
  • C. All code meets the technical requirements of GDPR.
    https://en.wikipedia.org/wiki/Secure_by_design#:~:text=Secure%20by%20design%20(SBD)%2C,the%20foundation%20to%20be%20secure.&text=Malicious%20practices%20are%20taken%20for,or%20on%20invalid%20user%20input.
  • D. Low Level and High Level Security Designs are restricted in distribution.

Answer: A

 

NEW QUESTION 44
In a security governance framework, which of the following publications would be at the HIGHEST level?

  • A. Standards
  • B. Procedures.
  • C. Guidelines
  • D. Policy.

Answer: B

 

NEW QUESTION 45
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?

  • A. XSS.
  • B. Parameter Tampering
  • C. SQL Injection.
  • D. CSRF.

Answer: D

 

NEW QUESTION 46
What Is the KEY purpose of appending security classification labels to information?

  • A. To comply with whatever mandatory security policy framework is in place within the geographical location in question.
  • B. To provide guidance and instruction on implementing appropriate security controls to protect the information.
  • C. To make sure the correct colour-coding system is used when the information is ready for archive.
  • D. To ensure that should the information be lost in transit, it can be returned to the originator using the correct protocols.

Answer: B

 

NEW QUESTION 47
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a large organisation?

  • A. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.
  • B. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
  • C. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.
  • D. The organisation has significantly less control over the device than over a corporately provided and managed device.

Answer: B

 

NEW QUESTION 48
What does a penetration test do that a Vulnerability Scan does NOT?

  • A. A penetration test is always an automated process - a vulnerability scan never is.
  • B. A penetration test looks for known vulnerabilities and reports them without further action.
  • C. A penetration test never uses common tools such as Nrnap, Nessus and Metasploit.
  • D. A penetration test seeks to actively exploit any known or discovered vulnerabilities.

Answer: B

 

NEW QUESTION 49
In business continuity (BC) terms, what is the name of the individual responsible for recording all pertinent information associated with a BC exercise or real plan invocation?

  • A. Scrum Master.
  • B. Recorder.
  • C. Scribe.
  • D. Desk secretary.

Answer: B

 

NEW QUESTION 50
When undertaking disaster recovery planning, which of the following would NEVER be considered a "natural" disaster?

  • A. Arson.
  • B. Lightning Strike
  • C. Electromagnetic pulse
  • D. Tsunami.

Answer: C

 

NEW QUESTION 51
When considering outsourcing the processing of data, which two legal "duty of care" considerations SHOULD the original data owner make?
1 Third party is competent to process the data securely.
2. Observes the same high standards as data owner.
3. Processes the data wherever the data can be transferred.
4. Archive the data for long term third party's own usage.

  • A. 1 and 4.
  • B. 3 and 4.
  • C. 1 and 2.
  • D. 2 and 3.

Answer: A

 

NEW QUESTION 52
What is the name of the method used to illicitly target a senior person in an organisation so as to try to coerce them Into taking an unwanted action such as a misdirected high-value payment?

  • A. Spear-phishing.
  • B. Whaling.
  • C. C-suite spamming.
  • D. Trawling.

Answer: A

 

NEW QUESTION 53
Select the document that is MOST LIKELY to contain direction covering the security and utilisation of all an organisation's information and IT equipment, as well as email, internet and telephony.

  • A. Acceptable Usage Policy.
  • B. Security Policy Framework.
  • C. Business Continuity Plan.
  • D. Cryptographic Statement.

Answer: D

 

NEW QUESTION 54
What types of web application vulnerabilities continue to be the MOST prolific according to the OWASP Top 10?

  • A. Insecure Deserialsiation.
  • B. Security Misconfiguration
  • C. Poor Password Management.
  • D. Injection Flaws.

Answer: D

 

NEW QUESTION 55
When preserving a crime scene for digital evidence, what actions SHOULD a first responder initially make?

  • A. Remove all digital evidence from the scene to prevent unintentional damage.
  • B. Don't touch any evidence until a senior digital investigator arrives.
    https://www.ncjrs.gov/pdffiles1/nij/219941.pdf
  • C. Photograph all evidence and triage to determine whether live data capture is necessary.
  • D. Remove power from all digital devices at the scene to stop the data changing.

Answer: B

 

NEW QUESTION 56
Which standards framework offers a set of IT Service Management best practices to assist organisations in aligning IT service delivery with business goals - including security goals?

  • A. COBIT
  • B. SABSA.
  • C. ISAGA.
    https://www.cherwell.com/it-service-management/library/essential-guides/essential-guide-to-itil-framework-and-processes/
  • D. ITIL.

Answer: D

 

NEW QUESTION 57
When considering the disposal of confidential data, equipment and storage devices, what social engineering technique SHOULD always be taken into consideration?

  • A. Spear Phishing.
  • B. Dumpster Diving.
  • C. Tailgating.
  • D. Shoulder Surfing.

Answer: A

 

NEW QUESTION 58
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?

  • A. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
  • B. Additional physical security requirements at data centres and corporate headquarters.
  • C. Increased demand on service desks as users need additional tools such as VPNs.
  • D. A large increase in remote workers operating in insecure premises.

Answer: C

 

NEW QUESTION 59
When calculating the risk associated with a vulnerability being exploited, how is this risk calculated?

  • A. Risk = Vulnerability / Threat.
  • B. Risk = Likelihood * Impact.
  • C. Risk = Likelihood / Impact.
  • D. Risk = Threat * Likelihood.

Answer: A

 

NEW QUESTION 60
Which of the following cloud delivery models is NOT intrinsically "trusted" in terms of security by clients using the service?

  • A. Hybrid.
  • B. Private.
  • C. Community
  • D. Public.

Answer: C

 

NEW QUESTION 61
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?

  • A. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
  • B. Digital evidence must not be altered unless absolutely necessary.
  • C. Digital evidence can only be handled by a member of law enforcement.
  • D. Digital devices must be forensically "clean" before investigation.

Answer: D

 

NEW QUESTION 62
According to ISO/IEC 27000, which of the following is the definition of a vulnerability?

  • A. The threat that an asset or group of assets may be damaged by an exploit.
  • B. The impact of a cyber attack on an asset or group of assets.
  • C. A weakness of an asset or group of assets that can be exploited by one or more threats.
  • D. The damage that has been caused by a weakness iin a system.
    Vulnerability
    A vulnerability is a weakness of an asset or control that could potentially be exploited by one or more threats.
    An asset is any tangible or intangible thing or characteristic that has value to an organization, a control is any administrative, managerial, technical, or legal method that can be used to modify or manage risk, and a threat is any potential event that could harm an organization or system.
    https://www.praxiom.com/iso-27000-definitions.htm

Answer: C

 

NEW QUESTION 63
In order to better improve the security culture within an organisation with a top down approach, which of the following actions at board level is the MOST effective?

  • A. Developing a security awareness e-learning course.
  • B. Adopting an organisation wide "clear desk" policy.
  • C. Purchasing all senior executives personal firewalls.
  • D. Appointment of a Chief Information Security Officer (CISO).

Answer: D

 

NEW QUESTION 64
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?

  • A. When the next risk audit is due.
  • B. Risks remain under constant review.
  • C. Once defined, they do not need reviewing.
  • D. A maximum of once every other month.

Answer: B

 

NEW QUESTION 65
A system administrator has created the following "array" as an access control for an organisation.
Developers: create files, update files.
Reviewers: upload files, update files.
Administrators: upload files, delete fifes, update files.
What type of access-control has just been created?

  • A. Role based access control.
  • B. Mandatory access control.
  • C. Task based access control.
  • D. Rule based access control.

Answer: D

 

NEW QUESTION 66
......


Introduction of BCS CISMP-V9 Certification Exam

BCS CISMP-V9 certification exam is an industry-recognized certification for information security that also serves as a terminal degree program in the field of information security. BCS CISMP-V9 certification exam was developed to test your understanding of information security, and how to apply it. BCS CISMP-V9 certification exam is a dual certification where one certification required for job roles includes the information/information security area, and another requirement required for higher-level positions in information security includes the entire cybersecurity spectrum which are all included in BCS CISMP-V9 Dumps. The most important advantage of the BCS CISMP-V9 certification exam is that it allows you to pursue several career paths. It is recommended for professionals who have been working in the information security field for at least five years or who have completed a bachelor's degree majoring in computer science with a specialization in cybersecurity courses.

 

New CISMP-V9  Exam Questions Real BCS Dumps: https://www.torrentexam.com/CISMP-V9-exam-latest-torrent.html

Pass Authentic BCS CISMP-V9 with Free Practice Tests and Exam Dumps: https://drive.google.com/open?id=1INtAPbIIgxQEd9OVd2Bu5l5ThtF6u9CO