ISC CISSP-ISSMP - Information Systems Security Management Professional - CISSP-ISSMP무료 덤프문제 풀어보기
Which of the following BEST describes a "Cyber Kill Chain" model's value to security management?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
Policies are considered the first and highest level of documentation, from which the lower-level elements of standards, procedures, and guidelines flow. Drag and drop each policy statement according to its hierarchy level (i.e. from top to bottom).


정답:

Explanation:
A policy statement is a well-written policy. It is an important and fundamental element of a good security practice. Policies are the foremost and uppermost level of documentation, from which the lower-level elements of standards, procedures, and guidelines flow. The policy statement hierarchy from top to bottom is as follows:
1.Senior Management Statement of policy
2.General Organizational Policies
3.Functional Policies
4.Mandatory Standards
5.Recommended Guidelines
6.Detailed Procedures
Reference: The CISM Prep Guide: Mastering the Five Domains of Information Security Management, Contents: "Information Security Governance"
Which of the following is used to back up forensic evidences or data folders from the network or locally attached hard disk drives?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Software Development Life Cycle (SDLC) is a logical process used by programmers to develop software. Which of the following SDLC phases meets the audit objectives defined below:
System and data are validated.
System meets all user requirements.
System meets all control requirements.
System and data are validated.
System meets all user requirements.
System meets all control requirements.
정답: B
Which of the following BEST describes "security by design"?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
What course of action can be taken by a party if the current negotiations fail and an agreement cannot be reached?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
Which of the following characteristics are described by the DIAP Information Readiness Assessment function?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
정답: A,C,D
설명: (Fast2test 회원만 볼 수 있음)
Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee's computer while he is typing in his password at any access point such as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
Which of the following roles is typically responsible for developing and maintaining the organization's overall security awareness training program?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
Which of the following BEST describes the concept of "capability maturity" (e.g., as in CMMI or a security maturity model)?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
Which of the following BEST captures the core distinction between ISSMP and CISSP as certifications?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
Which of the following Acts enacted in United States amends Civil Rights Act of 1964, providing technical changes affecting the length of time allowed to challenge unlawful seniority provisions, to sue the federal government for discrimination and to bring age discrimination claims?
정답: A
설명: (Fast2test 회원만 볼 수 있음)