
[Aug 23, 2024] CISMP-V9 Questions Truly Valid For Your BCS Exam!
CISMP-V9 Actual Questions - Instant Download Tests Free Updated Today!
NEW QUESTION # 26
What Is the PRIMARY security concern associated with the practice known as Bring Your Own Device (BYOD) that might affect a large organisation?
- A. Under GDPR it is illegal for an individual to use a personal device when handling personal information under corporate control.
- B. Privately owned end user devices are not provided with the same volume nor frequency of security patch updates as a corporation.
- C. Most BYOD involves the use of non-Windows hardware which is intrinsically insecure and open to abuse.
- D. The organisation has significantly less control over the device than over a corporately provided and managed device.
Answer: C
NEW QUESTION # 27
Which algorithm is a current specification for the encryption of electronic data established by NIST?
- A. RSA.
- B. AES.
- C. PGP.
- D. DES.
Answer: B
Explanation:
The Advanced Encryption Standard (AES) is the current specification for the encryption of electronic data established by the National Institute of Standards and Technology (NIST). AES is a symmetric block cipher that can encrypt (encipher) and decrypt (decipher) information, converting data to an unintelligible form called ciphertext and back to its original form, plaintext. The AES algorithm is capable of using cryptographic keys of 128, 192, and 256 bits to encrypt and decrypt data in blocks of 128 bits. It was selected by NIST as a Federal Information Processing Standard (FIPS) to protect electronic data and is widely recognized and used for secure data encryption1.
References: The BCS Foundation Certificate in Information Security Management Principles outlines the importance of understanding various encryption algorithms, including AES, for protecting electronic data. The NIST publication on AES provides detailed information about the standard and its application1.
NEW QUESTION # 28
What type of diagram used in application threat modeling includes malicious users as well as descriptions like mitigates and threatens?
- A. Misuse case diagrams.
- B. STRIDE charts.
- C. DREAD diagrams.
- D. Threat trees.
Answer: D
NEW QUESTION # 29
In business continuity (BC) terms, what is the name of the individual responsible for recording all pertinent information associated with a BC exercise or real plan invocation?
- A. Desk secretary.
- B. Recorder.
- C. Scribe.
- D. Scrum Master.
Answer: B
NEW QUESTION # 30
When handling and investigating digital evidence to be used in a criminal cybercrime investigation, which of the following principles is considered BEST practice?
- A. Digital evidence must not be altered unless absolutely necessary.
- B. Digital evidence can only be handled by a member of law enforcement.
- C. Acquiring digital evidence cart only be carried on digital devices which have been turned off.
- D. Digital devices must be forensically "clean" before investigation.
Answer: D
NEW QUESTION # 31
What Is the PRIMARY reason for organisations obtaining outsourced managed security services?
- A. Managed security services are a de facto requirement for certification to core security standards such as ISG/IEC 27001
- B. Managed security services permit organisations to absolve themselves of responsibility for security.
- C. Managed security services are a powerful defence against litigation in the event of a security breach or incident
- D. Managed security services provide access to specialist security tools and expertise on a shared, cost-effective basis.
Answer: B
NEW QUESTION # 32
When considering the disposal of confidential data, equipment and storage devices, what social engineering technique SHOULD always be taken into consideration?
- A. Dumpster Diving.
- B. Tailgating.
- C. Spear Phishing.
- D. Shoulder Surfing.
Answer: A
Explanation:
Dumpster diving refers to the practice of sifting through commercial or residential waste to find items that have been discarded but can still be of value, particularly information. In the context of information security, dumpster diving is a significant threat because it can lead to the recovery of sensitive documents, storage devices, or other materials that contain confidential data. When disposing of such items, it's crucial to ensure they are destroyed or sanitized in a manner that prevents data reconstruction or retrieval. This aligns with the BCS Information Security Management Principles, which emphasize the importance of secure disposal methods to protect against unauthorized access to or recovery of sensitive information1234.
References: The BCS Foundation Certificate in Information Security Management Principles outlines the need for proper disposal procedures to mitigate the risks associated with data recovery from discarded materials1. Additionally, industry best practices and guidelines, such as those from the National Institute of Standards and Technology (NIST), provide detailed methods for the secure sanitization and disposal of electronic media4.
NEW QUESTION # 33
What Is the KEY purpose of appending security classification labels to information?
- A. To make sure the correct colour-coding system is used when the information is ready for archive.
- B. To provide guidance and instruction on implementing appropriate security controls to protect the information.
- C. To comply with whatever mandatory security policy framework is in place within the geographical location in question.
- D. To ensure that should the information be lost in transit, it can be returned to the originator using the correct protocols.
Answer: B
Explanation:
The primary purpose of appending security classification labels to information is to guide the implementation of appropriate security controls. These labels indicate the level of sensitivity of the information and determine the extent and nature of the controls that need to be applied to protect it. For example, information classified as
'Confidential' will require stricter access controls compared to information classified as 'Public'. The classification labels help in ensuring that information is handled and protected in accordance with its importance to the organization, and in compliance with relevant legal and regulatory requirements.
References: The BCS Foundation Certificate in Information Security Management Principles provides a framework for understanding the importance of information classification and the associated security controls. It outlines the need for organizations to classify their information assets as part of an effective information securitymanagement system to protect the confidentiality, integrity, and availability of the information1.
NEW QUESTION # 34
What type of attack attempts to exploit the trust relationship between a user client based browser and server based websites forcing the submission of an authenticated request to a third party site?
- A. Parameter Tampering
- B. CSRF.
- C. XSS.
- D. SQL Injection.
Answer: B
NEW QUESTION # 35
Which of the following is a framework and methodology for Enterprise Security Architecture and Service Management?
- A. OWASP.
- B. TOGAF
- C. SABSA
- D. PCI DSS.
Answer: C
NEW QUESTION # 36
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?
- A. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
- B. Additional physical security requirements at data centres and corporate headquarters.
- C. Increased demand on service desks as users need additional tools such as VPNs.
- D. A large increase in remote workers operating in insecure premises.
Answer: B
Explanation:
The global pandemic has accelerated the trend of remote work, which inherently increases the risk of information security breaches due to insecure premises (A) and the need for additional tools like VPNs .
There's also a higher likelihood of attackers exploiting vulnerabilities during such operational changes (D).
However, the need for additional physical security at data centres and corporate headquarters (B) is less likely to be a direct result of a pandemic since the focus shifts to remote work and digital security rather than physical premises that are less occupied.
References: The BCS Foundation Certificate in Information Security Management Principles provides a comprehensive understanding of IS management issues, including risk management, security standards, legislation, and business continuity1. It emphasizes the importance of adapting security measures to current business and technical environments, which would include the shift to remote work during a pandemic
NEW QUESTION # 37
For which security-related reason SHOULD staff monitoring critical CCTV systems be rotated regularly during each work session?
- A. To give experience to monitoring staff across a range of activities for training purposes.
- B. To reduce the chance of collusion between security staff and those being monitored.
- C. The human attention span during intense monitoring sessions is about 20 minutes.
- D. Health and Safety regulations demand that staff are rotated to prevent posture and vision related harm.
Answer: C
Explanation:
Regular rotation of staff monitoring critical CCTV systems is recommended primarily to address the limitations of the human attention span. Research suggests that the average human attention span during intense monitoring tasks is approximately 20 minutes. After this period, vigilance and alertness can significantly decrease, leading to a potential lapse in monitoring effectiveness. Rotating staff helps to ensure that individuals are always at their most attentive when observing the CCTV feeds, which is crucial for maintaining security and safety standards. This practice also helps to mitigate risks associated with fatigue and the potential for missing critical events or details.
References: = The BCS Foundation Certificate in Information Security Management Principles emphasizes the importance of procedural/people security controls, which includes the management of human factors in security monitoring. The principles suggest that understanding human behavior and limitations is key to designing effective security systems and protocols12.
NEW QUESTION # 38
How does the use of a "single sign-on" access control policy improve the security for an organisation implementing the policy?
- A. Helps prevent the likelihood of users writing down passwords.
- B. Access control logs are centrally located.
- C. Password is better encrypted for system authentication.
- D. Decreases the complexity of passwords users have to remember.
Answer: A
Explanation:
Single sign-on (SSO) is an access control policy that allows users to authenticate with multiple applications and services by logging in only once. This approach improves security by reducing the number of credentials users must manage, which in turn decreases the likelihood of users writing down passwords. When users have to remember multiple complex passwords, they are more likely to write them down, use simple passwords, or repeat the same password across different services, all of which are security risks. SSO simplifies the login process, which can lead to stronger, unique passwords and reduce the risk of password-related breaches.
References: The BCS Foundation Certificate in Information Security Management Principles provides a comprehensive overview of information security management, including the effectiveness of different types of controls, which supports the understanding of how SSO can enhance an organization's security posture1.
NEW QUESTION # 39
Which of the following is NOT a valid statement to include in an organisation's security policy?
- A. How the organisation will manage information assurance.
- B. The policy has the support of Board and the Chief Executive.
- C. The policy has been agreed and amended to suit all third party contractors.
- D. The compliance with legal and regulatory obligations.
Answer: C
Explanation:
An organization's security policy should be a reflection of its own security stance and principles, not tailored to third parties. While it may be informed by third-party requirements, the policy itself should not be amended to suit all third-party contractors. This is because the security policy is meant to establish a clear set of rules and expectations for the organization's members to maintain the confidentiality, integrity, and availability of its data. It should be defined, approved by management, and communicated to employees and relevant external parties. Amending the policy to suit all third-party contractors could lead to a dilution of the security standards and potentially compromise the organization's security posture.
References: The information provided aligns with best practices in security policy development, which emphasize the importance of having a policy that is supported by the Board and Chief Executive, manages information assurance, and ensures compliance with legal and regulatory obligations1234.
NEW QUESTION # 40
What are the different methods that can be used as access controls?
1. Detective.
2. Physical.
3. Reactive.
4. Virtual.
5. Preventive.
- A. 3, 4 and 5.
- B. 1, 2 and 3.
- C. 1, 2 and 4.
- D. 1, 2 and 5.
Answer: D
NEW QUESTION # 41
What Is the PRIMARY difference between DevOps and DevSecOps?
- A. DevSecOps focuses solely on iterative development cycles.
- B. DevOps mandates that security is integrated at the beginning of the development lifecycle.
- C. DevSecOps includes security on the same level as continuous integration and delivery.
- D. Within DevSecOps security is introduced at the end of development immediately prior to deployment.
Answer: C
Explanation:
The primary difference between DevOps and DevSecOps lies in the integration of security practices. DevOps is a methodology that emphasizes collaboration between development and operations teams to automate the software development process, including continuous integration (CI) and continuous delivery (CD). However, DevOps does not inherently prioritize security as part of the development process.
DevSecOps, on the other hand, extends the DevOps principles by integrating security into every aspect of the software development lifecycle. This approach is often summarized by the term "shift-left," which means incorporating security from the beginning and throughout the development process, rather than treating it as an afterthought or a final step before deployment. In DevSecOps, security is considered a shared responsibility among all team members, and it is addressed through continuous security processes that are as integral as CI/CD in the DevOps culture.
References: The distinction between DevOps and DevSecOps is well-documented in various sources that discuss their methodologies and the importance of integrating security into the development lifecycle12345.
NEW QUESTION # 42
In a virtualised cloud environment, what component is responsible for the secure separation between guest machines?
- A. Security Engine.
- B. Hypervisor.
- C. OS Kernal
- D. Guest Manager
Answer: B
Explanation:
In a virtualized cloud environment, the hypervisor, also known as the virtual machine monitor (VMM), is the software, firmware, or hardware that creates and runs virtual machines. It is responsible for managing the system's hardware resources so they are distributed efficiently among multiple virtual environments. The hypervisor provides the secure separation between guest machines by ensuring that each guest machine operates independently and is unaware of the other guests' existence. This isolation prevents one guest from accessing or interfering with another guest's resources, which is crucial for maintaining security in a multi-tenant environment where multiple virtual machines are hosted on a single physical server.
References: = The BCS Foundation Certificate in Information Security Management Principles provides a comprehensive understanding of information security management, including the role of the hypervisor in ensuring secure separation between guest machines in a virtualized environment12.
NEW QUESTION # 43
......
BCS CISMP-V9 (BCS Foundation Certificate in Information Security Management Principles V9.0) Certification Exam is a globally recognized certification program for professionals who work in the field of information security management. BCS Foundation Certificate in Information Security Management Principles V9.0 certification is designed to equip individuals with the knowledge and skills required to effectively manage information security risks, threats, and vulnerabilities in today's dynamic and ever-changing business environment.
Get instant access of 100% real exam questions with verified answers: https://www.dumpsquestion.com/CISMP-V9-exam-dumps-collection.html