
EXIN Information Security Management Professional based on ISO/IEC 27001 - ISMP Exam Questions
QUESTION NO: 1
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
Correct Answer: B
QUESTION NO: 2
What is the best way to start setting the information security controls?
What is the best way to start setting the information security controls?
Correct Answer: A
QUESTION NO: 3
What is a key item that must be kept in mind when designing an enterprise-wide information security program?
What is a key item that must be kept in mind when designing an enterprise-wide information security program?
Correct Answer: B
QUESTION NO: 4
When should information security controls be considered?
When should information security controls be considered?
Correct Answer: C




