Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

ISSMP®: Information Systems Security Management Professional

Last Update 18 hours ago Total Questions : 218

The ISSMP®: Information Systems Security Management Professional content is now fully updated, with all current exam questions added 18 hours ago. Deciding to include ISSMP practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ISSMP exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ISSMP sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any ISSMP®: Information Systems Security Management Professional practice test comfortably within the allotted time.

Question # 11

Della works as a security manager for SoftTech Inc. She is training some of the newly recruited personnel in the field of security management. She is giving a tutorial on DRP. She explains that the major goal of a disaster recovery plan is to provide an organized way to make decisions if a disruptive event occurs and asks for the other objectives of the DRP. If you are among some of the newly recruited personnel in SoftTech Inc, what will be your answer for her question? Each correct answer represents a part of the solution. Choose three.

A.

Protect an organization from major computer services failure.

B.

Minimize the risk to the organization from delays in providing services.

C.

Guarantee the reliability of standby systems through testing and simulation.

D.

Maximize the decision-making required by personnel during a disaster.

Question # 12

Configuration Management (CM) is an Information Technology Infrastructure Library (ITIL) IT Service Management (ITSM) process. Configuration Management is used for which of the following? 1.To account for all IT assets 2.To provide precise information support to other ITIL disciplines 3.To provide a solid base only for Incident and Problem Management 4.To verify configuration records and correct any exceptions

A.

1, 3, and 4 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

2, 3, and 4 only

Question # 13

Which of the following architecturally related vulnerabilities is a hardware or software mechanism, which was installed to permit system maintenance and to bypass the system's security protections?

A.

Maintenance hook

B.

Lack of parameter checking

C.

Time of Check to Time of Use (TOC/TOU) attack

D.

Covert channel

Question # 14

Which of the following backup sites takes the longest recovery time?

A.

Cold site

B.

Hot site

C.

Warm site

D.

Mobile backup site

Question # 15

You company suspects an employee of sending unauthorized emails to competitors. These emails are alleged to contain confidential company dat a. Which of the following is the most important step for you to take in preserving the chain of custody?

A.

Preserve the email server including all logs.

B.

Seize the employee's PC.

C.

Make copies of that employee's email.

D.

Place spyware on the employee's PC to confirm these activities.

Question # 16

Which of the following steps is the initial step in developing an information security strategy?

A.

Perform a technical vulnerabilities assessment.

B.

Assess the current levels of security awareness.

C.

Perform a business impact analysis.

D.

Analyze the current business strategy.

Question # 17

Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.

A.

Acquire

B.

Analyze

C.

Authenticate

D.

Encrypt

Question # 18

An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?

A.

Network security policy

B.

Backup policy

C.

Privacy policy

D.

User password policy

Question # 19

Eric is the project manager of the NQQ Project and has hired the ZAS Corporation to complete part of the project work for Eric's organization. Due to a change request the ZAS Corporation is no longer needed on the project even though they have completed nearly all of the project work. Is Eric's organization liable to pay the ZAS Corporation for the work they have completed so far on the project?

A.

Yes, the ZAS Corporation did not choose to terminate the contract work.

B.

It depends on what the outcome of a lawsuit will determine.

C.

It depends on what the termination clause of the contract stipulates.

D.

No, the ZAS Corporation did not complete all of the work.

Question # 20

In which of the following phases of the SDLC does the software and other components of the system faithfully incorporate the design specifications and provide proper documentation and training?

A.

Programming and training

B.

Evaluation and acceptance

C.

Initiation

D.

Design

Go to page: