Get Latest Sep-2021 Conduct effective penetration tests using ValidTorrent CISMP-V9 exam [Q29-Q49]

Share

Get Latest [Sep-2021] Conduct effective penetration tests using  ValidTorrent CISMP-V9

Penetration testers simulate CISMP-V9 exam PDF

NEW QUESTION 29
What types of web application vulnerabilities continue to be the MOST prolific according to the OWASP Top 10?

  • A. Poor Password Management.
  • B. Security Misconfiguration
  • C. Injection Flaws.
  • D. Insecure Deserialsiation.

Answer: C

 

NEW QUESTION 30
Which of the following is an asymmetric encryption algorithm?

  • A. DES.
  • B. ATM.
  • C. RSA.
    https://www.omnisecu.com/security/public-key-infrastructure/asymmetric-encryption-algorithms.php
  • D. AES.

Answer: C

 

NEW QUESTION 31
Which of the following statements relating to digital signatures is TRUE?

  • A. A digital signature that uses a signer's private key is illegal.
  • B. Digital signatures are rarely legally enforceable even if the signers know they are signing a legal document.
  • C. Digital signatures are valid and enforceable in law in most countries in the world.
  • D. Digital signatures are legal unless there is a statutory requirement that predates the digital age.

Answer: D

 

NEW QUESTION 32
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?

  • A. System Integrity.
  • B. Sandboxing.
  • C. Intrusion Prevention System.
  • D. Defence in depth.
    https://en.wikipedia.org/wiki/Defense_in_depth_(computing)

Answer: D

 

NEW QUESTION 33
How does the use of a "single sign-on" access control policy improve the security for an organisation implementing the policy?

  • A. Access control logs are centrally located.
  • B. Helps prevent the likelihood of users writing down passwords.
  • C. Password is better encrypted for system authentication.
  • D. Decreases the complexity of passwords users have to remember.

Answer: A

 

NEW QUESTION 34
Which of the following is the MOST important reason for undertaking Continual Professional Development (CPD) within the Information Security sphere?

  • A. IT certifications require CPD and Security needs to remain credible.
  • B. CPD is a prerequisite of any Chartered Institution qualification.
  • C. Professional qualification bodies demand CPD.
  • D. Information Security changes constantly and at speed.

Answer: D

 

NEW QUESTION 35
Why should a loading bay NEVER be used as a staff entrance?

  • A. Loading bays are often dirty places, and staff could find their clothing damaged or made less appropriate for the office.
  • B. Loading bays are intrinsically vulnerable, so minimising the people traffic makes securing the areas easier and more effective.
  • C. Most countries have specific legislation covering loading bays and breaching this could impact on insurance status.
  • D. Staff should always enter a facility via a dedicated entrance to ensure smooth access and egress.

Answer: D

 

NEW QUESTION 36
What term refers to the shared set of values within an organisation that determine how people are expected to behave in regard to information security?

  • A. System Operating Procedures.
  • B. Security Culture.
  • C. Security Policy Framework.
    https://www.cpni.gov.uk/developing-security-culture#:~:text=Developing%20a%20Security%20Culture,-What%20type%20of&text=Security%20culture%20refers%20to%20the,think%20about%20and%20approach%20security.&text=Employees%20are%20more%20likley%20to%20think%20and%20act%20in%20a%20security%20conscious%20manner
  • D. Code of Ethics.

Answer: B

 

NEW QUESTION 37
Ensuring the correctness of data inputted to a system is an example of which facet of information security?

  • A. Integrity.
  • B. Availability.
  • C. Authenticity.
  • D. Confidentiality.

Answer: A

 

NEW QUESTION 38
When an organisation decides to operate on the public cloud, what does it lose?

  • A. Control over Intellectual Property Rights relating to its applications.
  • B. The right to audit and monitor access to its information.
  • C. Physical access to the servers hosting its information.
  • D. The ability to determine in which geographies the information is stored.

Answer: B

 

NEW QUESTION 39
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?

  • A. Security Engine.
  • B. Guest Manager
  • C. OS Kernal
  • D. Hypervisor.

Answer: B

 

NEW QUESTION 40
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?

  • A. By using a hypervisor in all shared severs.
  • B. By ensuring appropriate data isolation and logical storage segregation.
  • C. By increasing deterrent controls through warning messages.
  • D. By employing intrusion detection systems in a VMs.

Answer: D

 

NEW QUESTION 41
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobile computing or a BYOD approach.
What technology would be MOST beneficial to his organisation?

  • A. SIEM.
  • B. IDS.
  • C. MDM.
  • D. VPN.

Answer: C

 

NEW QUESTION 42
Once data has been created In a standard information lifecycle, what step TYPICALLY happens next?

  • A. Data Archiving.
  • B. Data Publication
  • C. Data Deletion.
  • D. Data Storage.

Answer: C

 

NEW QUESTION 43
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?

  • A. Drop.
  • B. Deter.
  • C. Delay.
  • D. Deny.

Answer: B

 

NEW QUESTION 44
When considering the disposal of confidential data, equipment and storage devices, what social engineering technique SHOULD always be taken into consideration?

  • A. Shoulder Surfing.
  • B. Tailgating.
  • C. Spear Phishing.
  • D. Dumpster Diving.

Answer: C

 

NEW QUESTION 45
What Is the PRIMARY difference between DevOps and DevSecOps?

  • A. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
  • B. DevSecOps includes security on the same level as continuous integration and delivery.
  • C. DevOps mandates that security is integrated at the beginning of the development lifecycle.
    https://www.viva64.com/en/b/0710/#:~:text=DevOps%20is%20a%20methodology%20aiming,in%20the%20software%20development%20process.&text=DevSecOps%20is%20a%20further%20development,code%20quality%20and%20reliability%20assurance.
  • D. DevSecOps focuses solely on iterative development cycles.

Answer: B

 

NEW QUESTION 46
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?

  • A. Cold site.
  • B. Hot site.
  • C. Spare site
  • D. Warm site.

Answer: A

 

NEW QUESTION 47
A system administrator has created the following "array" as an access control for an organisation.
Developers: create files, update files.
Reviewers: upload files, update files.
Administrators: upload files, delete fifes, update files.
What type of access-control has just been created?

  • A. Task based access control.
  • B. Rule based access control.
  • C. Mandatory access control.
  • D. Role based access control.

Answer: B

 

NEW QUESTION 48
Which of the following is often the final stage in the information management lifecycle?

  • A. Publication.
    https://timg.co.nz/blog-the-information-management-life-cycle/
  • B. Use.
  • C. Creation.
  • D. Disposal.

Answer: D

 

NEW QUESTION 49
......

Tested Material Used To CISMP-V9 Test Engine: https://www.validtorrent.com/CISMP-V9-valid-exam-torrent.html