
Get Latest [Sep-2021] Conduct effective penetration tests using ValidTorrent CISMP-V9
Penetration testers simulate CISMP-V9 exam PDF
NEW QUESTION 29
What types of web application vulnerabilities continue to be the MOST prolific according to the OWASP Top 10?
- A. Poor Password Management.
- B. Security Misconfiguration
- C. Injection Flaws.
- D. Insecure Deserialsiation.
Answer: C
NEW QUESTION 30
Which of the following is an asymmetric encryption algorithm?
- A. DES.
- B. ATM.
- C. RSA.
https://www.omnisecu.com/security/public-key-infrastructure/asymmetric-encryption-algorithms.php - D. AES.
Answer: C
NEW QUESTION 31
Which of the following statements relating to digital signatures is TRUE?
- A. A digital signature that uses a signer's private key is illegal.
- B. Digital signatures are rarely legally enforceable even if the signers know they are signing a legal document.
- C. Digital signatures are valid and enforceable in law in most countries in the world.
- D. Digital signatures are legal unless there is a statutory requirement that predates the digital age.
Answer: D
NEW QUESTION 32
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?
- A. System Integrity.
- B. Sandboxing.
- C. Intrusion Prevention System.
- D. Defence in depth.
https://en.wikipedia.org/wiki/Defense_in_depth_(computing)
Answer: D
NEW QUESTION 33
How does the use of a "single sign-on" access control policy improve the security for an organisation implementing the policy?
- A. Access control logs are centrally located.
- B. Helps prevent the likelihood of users writing down passwords.
- C. Password is better encrypted for system authentication.
- D. Decreases the complexity of passwords users have to remember.
Answer: A
NEW QUESTION 34
Which of the following is the MOST important reason for undertaking Continual Professional Development (CPD) within the Information Security sphere?
- A. IT certifications require CPD and Security needs to remain credible.
- B. CPD is a prerequisite of any Chartered Institution qualification.
- C. Professional qualification bodies demand CPD.
- D. Information Security changes constantly and at speed.
Answer: D
NEW QUESTION 35
Why should a loading bay NEVER be used as a staff entrance?
- A. Loading bays are often dirty places, and staff could find their clothing damaged or made less appropriate for the office.
- B. Loading bays are intrinsically vulnerable, so minimising the people traffic makes securing the areas easier and more effective.
- C. Most countries have specific legislation covering loading bays and breaching this could impact on insurance status.
- D. Staff should always enter a facility via a dedicated entrance to ensure smooth access and egress.
Answer: D
NEW QUESTION 36
What term refers to the shared set of values within an organisation that determine how people are expected to behave in regard to information security?
- A. System Operating Procedures.
- B. Security Culture.
- C. Security Policy Framework.
https://www.cpni.gov.uk/developing-security-culture#:~:text=Developing%20a%20Security%20Culture,-What%20type%20of&text=Security%20culture%20refers%20to%20the,think%20about%20and%20approach%20security.&text=Employees%20are%20more%20likley%20to%20think%20and%20act%20in%20a%20security%20conscious%20manner - D. Code of Ethics.
Answer: B
NEW QUESTION 37
Ensuring the correctness of data inputted to a system is an example of which facet of information security?
- A. Integrity.
- B. Availability.
- C. Authenticity.
- D. Confidentiality.
Answer: A
NEW QUESTION 38
When an organisation decides to operate on the public cloud, what does it lose?
- A. Control over Intellectual Property Rights relating to its applications.
- B. The right to audit and monitor access to its information.
- C. Physical access to the servers hosting its information.
- D. The ability to determine in which geographies the information is stored.
Answer: B
NEW QUESTION 39
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?
- A. Security Engine.
- B. Guest Manager
- C. OS Kernal
- D. Hypervisor.
Answer: B
NEW QUESTION 40
By what means SHOULD a cloud service provider prevent one client accessing data belonging to another in a shared server environment?
- A. By using a hypervisor in all shared severs.
- B. By ensuring appropriate data isolation and logical storage segregation.
- C. By increasing deterrent controls through warning messages.
- D. By employing intrusion detection systems in a VMs.
Answer: D
NEW QUESTION 41
Geoff wants to ensure the application of consistent security settings to devices used throughout his organisation whether as part of a mobile computing or a BYOD approach.
What technology would be MOST beneficial to his organisation?
- A. SIEM.
- B. IDS.
- C. MDM.
- D. VPN.
Answer: C
NEW QUESTION 42
Once data has been created In a standard information lifecycle, what step TYPICALLY happens next?
- A. Data Archiving.
- B. Data Publication
- C. Data Deletion.
- D. Data Storage.
Answer: C
NEW QUESTION 43
When establishing objectives for physical security environments, which of the following functional controls SHOULD occur first?
- A. Drop.
- B. Deter.
- C. Delay.
- D. Deny.
Answer: B
NEW QUESTION 44
When considering the disposal of confidential data, equipment and storage devices, what social engineering technique SHOULD always be taken into consideration?
- A. Shoulder Surfing.
- B. Tailgating.
- C. Spear Phishing.
- D. Dumpster Diving.
Answer: C
NEW QUESTION 45
What Is the PRIMARY difference between DevOps and DevSecOps?
- A. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
- B. DevSecOps includes security on the same level as continuous integration and delivery.
- C. DevOps mandates that security is integrated at the beginning of the development lifecycle.
https://www.viva64.com/en/b/0710/#:~:text=DevOps%20is%20a%20methodology%20aiming,in%20the%20software%20development%20process.&text=DevSecOps%20is%20a%20further%20development,code%20quality%20and%20reliability%20assurance. - D. DevSecOps focuses solely on iterative development cycles.
Answer: B
NEW QUESTION 46
Which type of facility is enabled by a contract with an alternative data processing facility which will provide HVAC, power and communications infrastructure as well computing hardware and a duplication of organisations existing "live" data?
- A. Cold site.
- B. Hot site.
- C. Spare site
- D. Warm site.
Answer: A
NEW QUESTION 47
A system administrator has created the following "array" as an access control for an organisation.
Developers: create files, update files.
Reviewers: upload files, update files.
Administrators: upload files, delete fifes, update files.
What type of access-control has just been created?
- A. Task based access control.
- B. Rule based access control.
- C. Mandatory access control.
- D. Role based access control.
Answer: B
NEW QUESTION 48
Which of the following is often the final stage in the information management lifecycle?
- A. Publication.
https://timg.co.nz/blog-the-information-management-life-cycle/ - B. Use.
- C. Creation.
- D. Disposal.
Answer: D
NEW QUESTION 49
......
Tested Material Used To CISMP-V9 Test Engine: https://www.validtorrent.com/CISMP-V9-valid-exam-torrent.html