[Oct-2021] CISMP-V9 Free PDF from Prep4sures [Q57-Q81]

Share

Oct-2021 Latest Prep4sures CISMP-V9 Exam Dumps with PDF and Exam Engine Free Updated Today!

Following are some new CISMP-V9 Real Exam Questions!

NEW QUESTION 57
A security analyst has been asked to provide a triple A service (AAA) for both wireless and remote access network services in an organization and must avoid using proprietary solutions.
What technology SHOULD they adapt?

  • A. RADIUS.
  • B. MS Access Database.
  • C. TACACS+
  • D. Oauth.

Answer: D

 

NEW QUESTION 58
When undertaking disaster recovery planning, which of the following would NEVER be considered a "natural" disaster?

  • A. Lightning Strike
  • B. Electromagnetic pulse
  • C. Tsunami.
  • D. Arson.

Answer: B

 

NEW QUESTION 59
Which term describes a vulnerability that is unknown and therefore has no mitigating control which is immediately and generally available?

  • A. Stealthware.
  • B. Zero-day.
    https://en.wikipedia.org/wiki/Zero-day_(computing)
  • C. Advanced Persistent Threat.
  • D. Trojan.

Answer: B

 

NEW QUESTION 60
In order to maintain the currency of risk countermeasures, how often SHOULD an organisation review these risks?

  • A. Risks remain under constant review.
  • B. A maximum of once every other month.
  • C. When the next risk audit is due.
  • D. Once defined, they do not need reviewing.

Answer: A

 

NEW QUESTION 61
Which membership based organisation produces international standards, which cover good practice for information assurance?

  • A. OWASP.
  • B. BSI.
  • C. IETF.
  • D. ISF.

Answer: B

 

NEW QUESTION 62
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?

  • A. Parameter Tampering
  • B. XSS.
  • C. CSRF.
  • D. SQL Injection.

Answer: C

 

NEW QUESTION 63
What Is the first yet MOST simple and important action to take when setting up a new web server?

  • A. Change default system passwords.
  • B. Fully encrypt the hard disk.
  • C. Patch the OS to the latest version
  • D. Apply hardening to all applications.

Answer: D

 

NEW QUESTION 64
When preserving a crime scene for digital evidence, what actions SHOULD a first responder initially make?

  • A. Don't touch any evidence until a senior digital investigator arrives.
    https://www.ncjrs.gov/pdffiles1/nij/219941.pdf
  • B. Photograph all evidence and triage to determine whether live data capture is necessary.
  • C. Remove power from all digital devices at the scene to stop the data changing.
  • D. Remove all digital evidence from the scene to prevent unintentional damage.

Answer: A

 

NEW QUESTION 65
Which three of the following characteristics form the AAA Triad in Information Security?
1. Authentication
2. Availability
3. Accounting
4. Asymmetry
5. Authorisation

  • A. 1, 3 and 5.
  • B. 1, 3 and 4.
  • C. 1, 2 and 3.
  • D. 2, 4, and 5.

Answer: A

 

NEW QUESTION 66
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?

  • A. Hot site.
  • B. Cold site.
  • C. Spare site
  • D. Warm site.

Answer: B

 

NEW QUESTION 67
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?

  • A. Deny.
  • B. Delay.
  • C. Deter.
  • D. Drop.

Answer: C

 

NEW QUESTION 68
What term is used to describe the testing of a continuity plan through a written scenario being used as the basis for discussion and simulation?

  • A. Desk-top exercise.
  • B. Non-dynamic modeling
  • C. Fault stressing
  • D. End-to-end testing.

Answer: A

 

NEW QUESTION 69
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?

  • A. Digital devices must be forensically "clean" before investigation.
  • B. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
  • C. Digital evidence must not be altered unless absolutely necessary.
  • D. Digital evidence can only be handled by a member of law enforcement.

Answer: A

 

NEW QUESTION 70
Which of the following is NOT considered to be a form of computer misuse?

  • A. Illegal access to computer systems.
  • B. Illegal interception of information.
  • C. Illegal retention of personal data.
  • D. Downloading of pirated software.

Answer: C

 

NEW QUESTION 71
In a security governance framework, which of the following publications would be at the HIGHEST level?

  • A. Policy.
  • B. Guidelines
  • C. Standards
  • D. Procedures.

Answer: D

 

NEW QUESTION 72
Which of the following is considered to be the GREATEST risk to information systems that results from deploying end-to-end Internet of Things (IoT) solutions?

  • A. Use of cloud based systems to collect loT data.
  • B. Use of proprietary networking protocols between nodes.
  • C. Much larger attack surface than traditional IT systems.
  • D. Use of 'cheap" microcontroller based sensors.

Answer: A

 

NEW QUESTION 73
What physical security control would be used to broadcast false emanations to mask the presence of true electromagentic emanations from genuine computing equipment?

  • A. White noise generation.
  • B. Unshielded cabling.
  • C. Faraday cage.
  • D. Copper infused windows.

Answer: B

 

NEW QUESTION 74
When a digital forensics investigator is conducting art investigation and handling the original data, what KEY principle must they adhere to?

  • A. Ensure they are competent to be able to do so and be able to justify their actions.
  • B. Ensure the data has been adjusted to meet the investigation requirements.
  • C. Ensure they do not handle the evidence as that must be done by law enforcement officers.
  • D. Ensure they are being observed by a senior investigator in all actions.

Answer: A

 

NEW QUESTION 75
What Is the PRIMARY difference between DevOps and DevSecOps?

  • A. DevSecOps focuses solely on iterative development cycles.
  • B. DevOps mandates that security is integrated at the beginning of the development lifecycle.
    https://www.viva64.com/en/b/0710/#:~:text=DevOps%20is%20a%20methodology%20aiming,in%20the%20software%20development%20process.&text=DevSecOps%20is%20a%20further%20development,code%20quality%20and%20reliability%20assurance.
  • C. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
  • D. DevSecOps includes security on the same level as continuous integration and delivery.

Answer: D

 

NEW QUESTION 76
Which of the following is NOT an accepted classification of security controls?

  • A. Corrective.
  • B. Detective.
  • C. Preventive.
  • D. Nominative.

Answer: D

 

NEW QUESTION 77
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a large organisation?

  • A. The organisation has significantly less control over the device than over a corporately provided and managed device.
  • B. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.
  • C. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
  • D. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.

Answer: C

 

NEW QUESTION 78
What term is used to describe the act of checking out a privileged account password in a manner that bypasses normal access controls procedures during a critical emergency situation?

  • A. Break Glass
  • B. Multi Factor Authentication.
  • C. Enterprise Security Management
  • D. Privileged User Gateway

Answer: B

 

NEW QUESTION 79
Which of the following is often the final stage in the information management lifecycle?

  • A. Use.
  • B. Disposal.
  • C. Publication.
    https://timg.co.nz/blog-the-information-management-life-cycle/
  • D. Creation.

Answer: B

 

NEW QUESTION 80
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?

  • A. Sandboxing.
  • B. Defence in depth.
    https://en.wikipedia.org/wiki/Defense_in_depth_(computing)
  • C. Intrusion Prevention System.
  • D. System Integrity.

Answer: B

 

NEW QUESTION 81
......


Resources From:

  1. 2021 Latest Prep4sures CISMP-V9 Exam Dumps (PDF & Exam Engine) Free Share: https://www.prep4sures.top/CISMP-V9-exam-dumps-torrent.html
  2. 2021 Latest Prep4sures CISMP-V9 PDF and CISMP-V9 Exam Dumps Free Share: https://drive.google.com/open?id=1d971mJwQthpN-64z5akMiPvYv2WFtsJ4

Free Resources from Prep4sures, We Devoted to Helping You 100% Pass All Exams!