
Oct-2021 Latest Prep4sures CISMP-V9 Exam Dumps with PDF and Exam Engine Free Updated Today!
Following are some new CISMP-V9 Real Exam Questions!
NEW QUESTION 57
A security analyst has been asked to provide a triple A service (AAA) for both wireless and remote access network services in an organization and must avoid using proprietary solutions.
What technology SHOULD they adapt?
- A. RADIUS.
- B. MS Access Database.
- C. TACACS+
- D. Oauth.
Answer: D
NEW QUESTION 58
When undertaking disaster recovery planning, which of the following would NEVER be considered a "natural" disaster?
- A. Lightning Strike
- B. Electromagnetic pulse
- C. Tsunami.
- D. Arson.
Answer: B
NEW QUESTION 59
Which term describes a vulnerability that is unknown and therefore has no mitigating control which is immediately and generally available?
- A. Stealthware.
- B. Zero-day.
https://en.wikipedia.org/wiki/Zero-day_(computing) - C. Advanced Persistent Threat.
- D. Trojan.
Answer: B
NEW QUESTION 60
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?
- A. Risks remain under constant review.
- B. A maximum of once every other month.
- C. When the next risk audit is due.
- D. Once defined, they do not need reviewing.
Answer: A
NEW QUESTION 61
Which membership based organisation produces international standards, which cover good practice for information assurance?
- A. OWASP.
- B. BSI.
- C. IETF.
- D. ISF.
Answer: B
NEW QUESTION 62
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?
- A. Parameter Tampering
- B. XSS.
- C. CSRF.
- D. SQL Injection.
Answer: C
NEW QUESTION 63
What Is the first yet MOST simple and important action to take when setting up a new web server?
- A. Change default system passwords.
- B. Fully encrypt the hard disk.
- C. Patch the OS to the latest version
- D. Apply hardening to all applications.
Answer: D
NEW QUESTION 64
When preserving a crime scene for digital evidence, what actions SHOULD a first responder initially make?
- A. Don't touch any evidence until a senior digital investigator arrives.
https://www.ncjrs.gov/pdffiles1/nij/219941.pdf - B. Photograph all evidence and triage to determine whether live data capture is necessary.
- C. Remove power from all digital devices at the scene to stop the data changing.
- D. Remove all digital evidence from the scene to prevent unintentional damage.
Answer: A
NEW QUESTION 65
Which three of the following characteristics form the AAA Triad in Information Security?
1. Authentication
2. Availability
3. Accounting
4. Asymmetry
5. Authorisation
- A. 1, 3 and 5.
- B. 1, 3 and 4.
- C. 1, 2 and 3.
- D. 2, 4, and 5.
Answer: A
NEW QUESTION 66
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?
- A. Hot site.
- B. Cold site.
- C. Spare site
- D. Warm site.
Answer: B
NEW QUESTION 67
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?
- A. Deny.
- B. Delay.
- C. Deter.
- D. Drop.
Answer: C
NEW QUESTION 68
What term is used to describe the testing of a continuity plan through a written scenario being used as the basis for discussion and simulation?
- A. Desk-top exercise.
- B. Non-dynamic modeling
- C. Fault stressing
- D. End-to-end testing.
Answer: A
NEW QUESTION 69
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?
- A. Digital devices must be forensically "clean" before investigation.
- B. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
- C. Digital evidence must not be altered unless absolutely necessary.
- D. Digital evidence can only be handled by a member of law enforcement.
Answer: A
NEW QUESTION 70
Which of the following is NOT considered to be a form of computer misuse?
- A. Illegal access to computer systems.
- B. Illegal interception of information.
- C. Illegal retention of personal data.
- D. Downloading of pirated software.
Answer: C
NEW QUESTION 71
In a security governance framework, which of the following publications would be at the HIGHEST level?
- A. Policy.
- B. Guidelines
- C. Standards
- D. Procedures.
Answer: D
NEW QUESTION 72
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things (IoT) solutions?
- A. Use of cloud based systems to collect loT data.
- B. Use of proprietary networking protocols between nodes.
- C. Much larger attack surface than traditional IT systems.
- D. Use of 'cheap" microcontroller based sensors.
Answer: A
NEW QUESTION 73
What physical security control would be used to broadcast false emanations to mask the presence of true electromagentic emanations from genuine computing equipment?
- A. White noise generation.
- B. Unshielded cabling.
- C. Faraday cage.
- D. Copper infused windows.
Answer: B
NEW QUESTION 74
When a digital forensics investigator is conducting art investigation and handling the original data, what KEY principle must they adhere to?
- A. Ensure they are competent to be able to do so and be able to justify their actions.
- B. Ensure the data has been adjusted to meet the investigation requirements.
- C. Ensure they do not handle the evidence as that must be done by law enforcement officers.
- D. Ensure they are being observed by a senior investigator in all actions.
Answer: A
NEW QUESTION 75
What Is the PRIMARY difference between DevOps and DevSecOps?
- A. DevSecOps focuses solely on iterative development cycles.
- B. DevOps mandates that security is integrated at the beginning of the development lifecycle.
https://www.viva64.com/en/b/0710/#:~:text=DevOps%20is%20a%20methodology%20aiming,in%20the%20software%20development%20process.&text=DevSecOps%20is%20a%20further%20development,code%20quality%20and%20reliability%20assurance. - C. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
- D. DevSecOps includes security on the same level as continuous integration and delivery.
Answer: D
NEW QUESTION 76
Which of the following is NOT an accepted classification of security controls?
- A. Corrective.
- B. Detective.
- C. Preventive.
- D. Nominative.
Answer: D
NEW QUESTION 77
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a large organisation?
- A. The organisation has significantly less control over the device than over a corporately provided and managed device.
- B. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.
- C. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
- D. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.
Answer: C
NEW QUESTION 78
What term is used to describe the act of checking out a privileged account password in a manner that bypasses normal access controls procedures during a critical emergency situation?
- A. Break Glass
- B. Multi Factor Authentication.
- C. Enterprise Security Management
- D. Privileged User Gateway
Answer: B
NEW QUESTION 79
Which of the following is often the final stage in the information management lifecycle?
- A. Use.
- B. Disposal.
- C. Publication.
https://timg.co.nz/blog-the-information-management-life-cycle/ - D. Creation.
Answer: B
NEW QUESTION 80
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?
- A. Sandboxing.
- B. Defence in depth.
https://en.wikipedia.org/wiki/Defense_in_depth_(computing) - C. Intrusion Prevention System.
- D. System Integrity.
Answer: B
NEW QUESTION 81
......
Resources From:
- 2021 Latest Prep4sures CISMP-V9 Exam Dumps (PDF & Exam Engine) Free Share: https://www.prep4sures.top/CISMP-V9-exam-dumps-torrent.html
- 2021 Latest Prep4sures CISMP-V9 PDF and CISMP-V9 Exam Dumps Free Share: https://drive.google.com/open?id=1d971mJwQthpN-64z5akMiPvYv2WFtsJ4
Free Resources from Prep4sures, We Devoted to Helping You 100% Pass All Exams!