ISC CISSP-ISSMP - Information Systems Security Management Professional - CISSP-ISSMP Exam Practice Test
Which of the following is the BEST way to validate that a vendor's claimed security certifications (e.g., ISO 27001, SOC 2) are current and valid?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Your project team has identified a project risk that must be responded to. The risk has been recorded in the risk register and the project team has been discussing potential risk responses for the risk event. The event is not likely to happen for several months but the probability of the event is high. Which one of the following is a valid response to the identified risk event?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following roles is used to ensure that the confidentiality, integrity, and availability of the services are maintained to the levels approved on the Service Level Agreement (SLA)?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following BEST describes an appropriate approach for a CISO when presenting a security roadmap to the board that requires significant multi-year investment?
Correct Answer: B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following is the PRIMARY reason organizations perform "red team" exercises in addition to standard penetration testing?
Correct Answer: B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following BEST describes why "artificial intelligence/machine learning" adoption introduces NEW categories of risk that a security manager must consider (e.g., model poisoning, adversarial inputs)?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following BEST describes the purpose of establishing a formal "Records of Processing Activities (ROPA)" under GDPR?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following plans is designed to protect critical business processes from natural or man- made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following BEST describes "indicators of compromise (IOCs)" versus "indicators of attack (IOAs)"?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following acts is a specialized privacy bill that affects any educational institution to accept any form of funding from the federal government?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following types of agreement creates a confidential relationship between the parties to protect any type of confidential and proprietary information or a trade secret?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following BEST describes the purpose of a Memorandum of Understanding (MOU) in the context of contingency planning?
Correct Answer: B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).