Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Exin Information Security Management Professional based on ISO/IEC 27001 ISMP Exam Questions

Page: 1 / 5 Total 30 questions

Want more questions? Get Premium Access.

Question 1

It is important that an organization is able to prove compliance with information standards and legislation. One of the most important areas is documentation concerning access management. This process contains a

number of activities including granting rights, monitoring identity status, logging, tracking access and removing rights. Part of these controls are audit trail records which may be used as evidence for both internal and

external audits.

What component of the audit trail is the most important for an external auditor?

Correct Answer: A. Access criteria and access control mechanisms

Question 2

A company's webshop offers prospects and customers the possibility to search the catalog and place orders around the clock. In order to satisfy the needs of both customer and business several requirements have to

be met. One of the criteria is data classification.

What is the most important classification aspect of the unit price of an object in a 24h webshop?

Correct Answer: C. Availability

Question 3

An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.

Which is the main risk of PKI?

Correct Answer: A. The Certificate Authority (CA) is hacked.

Question 4

The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do-

Check-Act (PDCA) cycle of the ISMS.

In which phase should these controls be described?

Correct Answer: A. Plan

Question 5

Which security item is designed to take collections of data from multiple computers?

Correct Answer: C. Network-Based Intrusion Detection and Prevention System (Network-Based IDPS)

Question 6

A risk manager is asked to perform a complete risk assessment for a company.

What is the best method to identify most of the threats to the company?

Correct Answer: A. Have a brainstorm with representatives of all stakeholders