最新的ISC CISSP-ISSMP - Information Systems Security Management Professional - CISSP-ISSMP免費考試真題
Which of the following BEST describes why "measuring security ROI (Return on Investment)" is inherently challenging compared to typical business investments?
正確答案: B
說明:(僅 Fast2test 成員可見)
You work as the Network Administrator for a defense contractor. Your company works with sensitive materials and all IT personnel have at least a secret level clearance. You are still concerned that one individual could perhaps compromise the network (intentionally or unintentionally) by setting up improper or unauthorized remote access. What is the best way to avoid this problem?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which of the following are the process steps of OPSEC? Each correct answer represents a part of the solution. Choose all that apply.
正確答案: B,C,D
說明:(僅 Fast2test 成員可見)
Which of the following BEST distinguishes a "threat" from a "vulnerability"?
正確答案: B
說明:(僅 Fast2test 成員可見)
Which of the following BEST describes "separation of duties" as a control?
正確答案: A
說明:(僅 Fast2test 成員可見)
Which of the following BCP teams handles financial arrangement, public relations, and media inquiries in the time of disaster recovery?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following BEST describes why "artificial intelligence/machine learning" adoption introduces NEW categories of risk that a security manager must consider (e.g., model poisoning, adversarial inputs)?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which of the following is the PRIMARY reason to conduct a lessons-learned session after a disaster recovery test, even if the test was "successful"?
正確答案: A
說明:(僅 Fast2test 成員可見)
You are the project manager of the GHE Project. You have identified the following risks with the characteristics as shown in the following figure:

How much capital should the project set aside for the risk contingency reserve?

How much capital should the project set aside for the risk contingency reserve?
正確答案: A
說明:(僅 Fast2test 成員可見)
Andy works as a security manager for SoftTech Inc. He is involved in the BIA phase to create a document to be used to help understand what impact a disruptive event would have on the business. Choose and reorder the required steps that he will take to accomplish the BIA phase.


正確答案:

Explanation:
The required steps that Andy will take to accomplish the BIA phase are as follows :
1.Gathering the needed assessment materials.
2.Performing the vulnerability assessment.
3.Analyzing the information compiled.
4.Documenting the results and presenting recommendations.
Reference: CISM Review Manual 2010, Contents: "Incident management and response"
You are the project manager of the NGQQ Project for your company. To help you communicate project status to your stakeholders, you are going to create a stakeholder register. All of the following information should be included in the stakeholder register except for which one?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following plans is documented and organized for emergency response, backup operations, and recovery maintained by an activity as part of its security program that will ensure the availability of critical resources and facilitates the continuity of operations in an emergency situation?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following are known as the three laws of OPSEC? Each correct answer represents a part of the solution. Choose three.
正確答案: A,C,D
說明:(僅 Fast2test 成員可見)
Which of the following BEST describes why "dependency mapping" is a critical input to contingency planning?
正確答案: D
說明:(僅 Fast2test 成員可見)