ISC2 CISSP-ISSMP Certification Sample Questions

CISSP-ISSMP Dumps, CISSP-ISSMP Dumps, CISSP-ISSMP PDF, CISSP-ISSMP VCE, ISC2 CISSP-ISSMP VCE, ISC2 ISSMP PDFThe purpose of this Sample Question Set is to provide you with information about the ISC2 Information Systems Security Management Professional exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CISSP-ISSMP certification test. To get familiar with real exam environment, we suggest you try our Sample ISC2 CISSP-ISSMP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISC2 Information Systems Security Management Professional (CISSP-ISSMP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISC2 CISSP-ISSMP exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium ISC2 CISSP-ISSMP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISC2 CISSP-ISSMP Sample Questions:

01. Which approach to risk assessment produces objective, discrete numeric values for the loss expected from a threat occurring within a defined time period?
a) Scenario-based
b) Qualitative
c) Semi-quantitative
d) Quantitative
 
02. How should the effectiveness of risk treatment be communicated to stakeholders?
a) By reporting the controls that were implemented, since the treatment plan was agreed when it was approved
b) On a regular cycle, using metrics that show how residual risk has moved against the agreed tolerance
c) When a major incident occurs, so that the update reaches stakeholders while their attention is high
d) In financial loss terms alone, so that the board can compare the results with other investments
 
03. Which level of the awareness, training and education continuum is exemplified when a security manager completes a formal academic course on the European Union General Data Protection Regulation (GDPR)?
a) Education
b) Awareness
c) Orientation
d) Training
 
04. Defense in depth is an approach to protecting data that is based on which concept?
a) Concentrating protection at a single hardened perimeter through which all traffic must pass
b) Granting each user and process only the access needed to carry out an assigned task
c) Applying several independent layers of control so that no single failure exposes the data
d) Reducing the attack surface by removing services, interfaces and accounts that are not required
 
05. Within an organization's security documentation hierarchy, which document type carries the highest level of precedence?
a) Guideline
b) Policy
c) Procedure
d) Standard
 
06. Security configuration checklists are also known by which of the following terms?
a) Maximum system security configurations
b) Security baselines
c) Compliance assessments
d) Enterprise security configuration framework
 
07. Which five phases make up the system development life cycle (SDLC) into which security effort must be integrated?
a) Design, development, testing, implementation, and disposal
b) Predevelopment, development, testing, implementation, and operations
c) Initiation, development, implementation, operations, and disposal
d) Initiation, design, subsystem specification, development, and implementation
 
08. A contingency plan divides response work into an activation and notification phase and a recovery phase. Which of the following activities belongs to the recovery phase rather than to activation and notification?
a) The initial assessment of damage and likely outage duration
b) The criteria on which an emergency is declared
c) Notification of the recovery personnel named in the plan
d) The prioritized sequence in which systems are restored to service
 
09. Which system development model applies short iterations of development within release increments so that stakeholders can help steer the work?
a) Waterfall
b) Agile
c) RAD
d) Spiral
 
10. Which document records the business requirements that an IT service must meet?
a) A Service Level Requirement
b) An Operational Level Agreement
c) An Underpinning Contract
d) A Service Level Agreement
e) A Service Level Objective

Answers:

Question: 01
Answer: d
Question: 02
Answer: b
Question: 03
Answer: a
Question: 04
Answer: c
Question: 05
Answer: b
Question: 06
Answer: b
Question: 07
Answer: c
Question: 08
Answer: d
Question: 09
Answer: b
Question: 10
Answer: a

Note: For any error in ISC2 Information Systems Security Management Professional (CISSP-ISSMP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (123 votes)