Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

ISSMP®: Information Systems Security Management Professional

Last Update 18 hours ago Total Questions : 218

The ISSMP®: Information Systems Security Management Professional content is now fully updated, with all current exam questions added 18 hours ago. Deciding to include ISSMP practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ISSMP exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ISSMP sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any ISSMP®: Information Systems Security Management Professional practice test comfortably within the allotted time.

Question # 41

Which of the following models uses a directed graph to specify the rights that a subject can transfer to an object or that a subject can take from another subject?

A.

Take-Grant Protection Model

B.

Bell-LaPadula Model

C.

Biba Integrity Model

D.

Access Matrix

Question # 42

You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access data. What is this called?

A.

Availability

B.

Encryption

C.

Integrity

D.

Confidentiality

Question # 43

Which of the following strategies is used to minimize the effects of a disruptive event on a company, and is created to prevent interruptions to normal business activity?

A.

Disaster Recovery Plan

B.

Continuity of Operations Plan

C.

Contingency Plan

D.

Business Continuity Plan

Question # 44

Which of the following statements best describes the consequences of the disaster recovery plan test?

A.

If no deficiencies were found during the test, then the test was probably flawed.

B.

The plan should not be changed no matter what the results of the test would be.

C.

The results of the test should be kept secret.

D.

If no deficiencies were found during the test, then the plan is probably perfect.

Question # 45

Which of the following is a variant with regard to Configuration Management?

A.

A CI that has the same name as another CI but shares no relationship.

B.

A CI that particularly refers to a hardware specification.

C.

A CI that has the same essential functionality as another CI but a bit different in some small manner.

D.

A CI that particularly refers to a software version.

Question # 46

Which of the following roles is responsible for review and risk analysis of all contracts on a regular basis?

A.

The Configuration Manager

B.

The Supplier Manager

C.

The Service Catalogue Manager

D.

The IT Service Continuity Manager

Question # 47

Fill in the blank with an appropriate word. _________ are used in information security to formalize security policies.

A.

Models.

Question # 48

Which of the following attacks can be mitigated by providing proper training to the employees in an organization?

A.

Social engineering

B.

Smurf

C.

Denial-of-Service

D.

Man-in-the-middle

Question # 49

Which of the following sections come under the ISO/IEC 27002 standard?

A.

Financial assessment

B.

Asset management

C.

Security policy

D.

Risk assessment

Question # 50

What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.

A.

Maintain and Monitor

B.

Organization Vulnerability

C.

Define Policy

D.

Baseline the Environment

Go to page: