
ISC ISSMP:Information Systems Security Management Professional - ISSMP Exam Questions
QUESTION NO: 1
Which of the following attacks can be mitigated by providing proper training to the employees in an organization?
Which of the following attacks can be mitigated by providing proper training to the employees in an organization?
Correct Answer: C
QUESTION NO: 2
Which of the following relies on a physical characteristic of the user to verify his identity?
Which of the following relies on a physical characteristic of the user to verify his identity?
Correct Answer: B
QUESTION NO: 3
Which of the following is the default port for Secure Shell (SSH)?
Which of the following is the default port for Secure Shell (SSH)?
Correct Answer: C
QUESTION NO: 4
Which of the following is a variant with regard to Configuration Management?
Which of the following is a variant with regard to Configuration Management?
Correct Answer: D
QUESTION NO: 5
Which of the following can be prevented by an organization using job rotation and separation of duties policies?
Which of the following can be prevented by an organization using job rotation and separation of duties policies?
Correct Answer: A
QUESTION NO: 6
Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures?
Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures?
Correct Answer: D
QUESTION NO: 7
Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC) is based on the Mandatory Access Control (MAC) policy?
Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC) is based on the Mandatory Access Control (MAC) policy?
Correct Answer: D
QUESTION NO: 8
Which of the following tools works by using standard set of MS-DOS commands and can create an MD5 hash of an entire drive, partition, or selected files?
Which of the following tools works by using standard set of MS-DOS commands and can create an MD5 hash of an entire drive, partition, or selected files?
Correct Answer: B
QUESTION NO: 9
Mark works as a security manager for SoftTech Inc. He is involved in the BIA phase to create a document to be used to help understand what impact a disruptive event would have on the business. The impact might be financial or operational. Which of the following are the objectives related to the above phase in which Mark is involved? Each correct answer represents a part of the solution. Choose three.
Mark works as a security manager for SoftTech Inc. He is involved in the BIA phase to create a document to be used to help understand what impact a disruptive event would have on the business. The impact might be financial or operational. Which of the following are the objectives related to the above phase in which Mark is involved? Each correct answer represents a part of the solution. Choose three.
Correct Answer: A,B,D
QUESTION NO: 10
You are the project manager of the HJK Project for your organization. You and the project team have created risk responses for many of the risk events in the project. Where should you document the proposed responses and the current status of all identified risks?
You are the project manager of the HJK Project for your organization. You and the project team have created risk responses for many of the risk events in the project. Where should you document the proposed responses and the current status of all identified risks?
Correct Answer: D




