
ISC CISSP-ISSMP Exam Preparation Guide and PDF Download
Verified & Correct CISSP-ISSMP Practice Test Reliable Source Aug 08, 2026 Updated
NEW QUESTION # 118
You have created a team of HR Managers and Project Managers for Blue Well Inc. The team will concentrate on hiring some new employees for the company and improving the organization's overall security by turning employees among numerous job positions. Which of the following steps will you perform to accomplish the task?
- A. Job rotation
- B. Separation of duties
- C. Job responsibility
- D. Screening candidates
Answer: A
NEW QUESTION # 119
Which of the following is the BEST example of a "preventive" control?
- A. Post-incident forensic analysis
- B. Intrusion detection system (IDS) alert
- C. Security audit log review
- D. Firewall blocking unauthorized traffic
Answer: D
Explanation:
A firewall blocking traffic actively prevents unauthorized access before it occurs. IDS (detective), forensic analysis (corrective/investigative), and log review (detective) occur after or during an event rather than preventing it.
NEW QUESTION # 120
Which of the following BEST describes why "workforce/personnel contingency planning" should address potential loss of key personnel during a pandemic or mass-casualty event?
- A. This type of planning is identical to standard vacation coverage planning
- B. Personnel contingency planning is unnecessary if systems are redundant
- C. Personnel contingency planning applies only to executive roles
- D. Even with redundant systems, the loss or unavailability of critical staff (illness, quarantine) can disrupt operations, requiring succession and cross-training plans
Answer: D
Explanation:
Technology redundancy alone doesn't address human capital risk; pandemic-scale events can simultaneously affect large portions of the workforce, requiring specific plans for succession, cross-training, and staffing continuity beyond routine coverage.
NEW QUESTION # 121
Which of the following are the major tasks of risk management? Each correct answer represents a complete solution. Choose two.
- A. Risk control
- B. Building Risk free systems
- C. Assuring the integrity of organizational data
- D. Risk identification
Answer: A,D
Explanation:
The following are the two major tasks of risk management:
1.Risk identification
2.Risk control
Risk identification is the task of examining and documenting the security posture of an organization's information technology and the risks it faces.
Risk control is the task of applying controls to reduce risks to an organization's data and information systems.
Answer options B and A are incorrect. Building risk free systems and assuring the integrity of organizational data are the tasks related to the implementation of security measures.
Reference: "http://en.wikipedia.org/wiki/Risk_management"
NEW QUESTION # 122
Which of the following terms describes a repudiation of a contract that occurs before the time when performance is due?
- A. Anticipatory breach
- B. Expected breach
- C. Nonperforming breach
- D. Actual breach
Answer: A
Explanation:
The anticipatory breach is also known as an anticipatory repudiation. It is a term in the law of contracts that describes a declaration by the promising party to a contract that he or she does not intend to live up to his or her obligations under the contract. Anticipatory breach is an unequivocal indication that the party will not perform when performance is due, or a situation in which future non-performance is inevitable.
Answer option B is incorrect. An actual breach is an unwarranted failure to perform a contract at the time when the performance is due.
Answer options A and D are incorrect. These are not valid options.
Reference: CISM Review Manual 2010, Contents. "Information security program management"
NEW QUESTION # 123
Which of the following statements reflect the 'Code of Ethics Preamble' in the '(ISC)2 Code of Ethics'?
Each correct answer represents a complete solution. Choose all that apply.
- A. Provide diligent and competent service to principals.
- B. Safety of the commonwealth, duty to our principals, and to each other requires that we adhere, and be seen to adhere, to the highest ethical standards of behavior.
- C. Strict adherence to this Code is a condition of certification.
- D. Advance and protect the profession.
Answer: B,C
NEW QUESTION # 124
Which of the following recovery plans includes specific strategies and actions to deal with specific variances to assumptions resulting in a particular security problem, emergency, or state of affairs?
- A. Contingency plan
- B. Continuity of Operations Plan
- C. Disaster recovery plan
- D. Business continuity plan
Answer: A
NEW QUESTION # 125
Which of the following is the PRIMARY purpose of conducting a gap analysis against a framework like NIST CSF or ISO 27001?
- A. To replace the need for a risk assessment
- B. To satisfy a one-time audit requirement only
- C. To achieve certification automatically
- D. To identify differences between current security practices and the framework's requirements to prioritize improvement
Answer: D
Explanation:
A gap analysis compares current state to a target framework's control objectives, highlighting deficiencies to guide remediation planning and resource prioritization.
NEW QUESTION # 126
Which of the following concepts represent the three fundamental principles of information security?
Each correct answer represents a complete solution. Choose three.
- A. Integrity
- B. Availability
- C. Privacy
- D. Confidentiality
Answer: A,B,D
Explanation:
The following concepts represent the three fundamental principles of information security.
1.Confidentiality
2.Integrity
3.Availability
Answer option C is incorrect. Privacy, authentication, accountability, authorization and identification are also concepts related to information security, but they do not represent the fundamental principles of information security.
Reference: "http.//en.wikipedia.org/wiki/Information_security"
NEW QUESTION # 127
Which of the following statements are true about security risks? Each correct answer represents a complete solution. Choose three.
- A. They can be analyzed and measured by the risk analysis process.
- B. They can be mitigated by reviewing and taking responsible actions based on possible risks.
- C. They can be removed completely by taking proper actions.
- D. They are considered an indicator of threats coupled with vulnerability.
Answer: A,B,D
NEW QUESTION # 128
You are the program manager for your project. You are working with the project managers regarding the procurement processes for their projects. You have ruled out one particular contract type because it is considered too risky for the program. Which one of the following contract types is usually considered to be the most dangerous for the buyer?
- A. Time and materials
- B. Cost plus percentage of costs
- C. Cost plus incentive fee
- D. Fixed fee
Answer: B
NEW QUESTION # 129
Which of the following roles is used to ensure that the confidentiality, integrity, and availability of the services are maintained to the levels approved on the Service Level Agreement (SLA)?
- A. The Service Level Manager
- B. The Configuration Manager
- C. The Change Manager
- D. The IT Security Manager
Answer: D
NEW QUESTION # 130
Fill in the blank with an appropriate phrase.______________ is used to provide security mechanisms for the storage, processing, and transfer of data.
Answer:
Explanation:
Data classification
Explanation:
Data classification is used to protect the data based on its sensitivity, secrecy, and confidentiality.
It provides security mechanisms for storage, processing, and transfer of data. Data classification also helps to verify the effort, funds, and resources allocated to save the data, and controls access to it.
Reference: A Practical Guide to Security Assessment, Contents: "Data Classification"
NEW QUESTION # 131
Rachael is the project manager for a large project in her organization. A new change request has been proposed that will affect several areas of the project. One area of the project change impact is on work that a vendor has already completed. The vendor is refusing to make the changes as they've already completed the project work they were contracted to do. What can Rachael do in this instance?
- A. Refer to the contract agreement for direction.
- B. Threaten to sue the vendor if they don't complete the work.
- C. Fire the vendor for failing to complete the contractual obligation.
- D. Withhold the vendor's payments for the work they've completed.
Answer: A
NEW QUESTION # 132
Which of the following BEST describes the concept of "digital forensic readiness"?
- A. A one-time technical purchase requiring no ongoing maintenance
- B. Proactively establishing policies, tools, and processes to ensure the organization can efficiently and effectively conduct forensic investigations when needed
- C. A concept relevant only to law enforcement agencies
- D. Forensic capability that is developed only after an incident occurs
Answer: B
Explanation:
Forensic readiness means having logging, evidence preservation procedures, trained personnel, and tools in place before an incident occurs, so investigations aren't hampered by missing evidence or untrained response.
NEW QUESTION # 133
......
Overview of CISSP-ISSMP Endorsement
The CISSP-ISSMP certification is for those individuals who want to be specialized in Security Management and to align security programs with organizational goals. This qualification is suitable for those in roles such as a Chief Information Officer or Security Officer, Chief Technology Officer, and Senior Security Executive. The quality of this certificate is further affirmed by the fact that ISSMP is aligned with the requirements of ANSI/ISO/IEC Standard 17024. Also, to be eligible for this certification you must be initially CISSP certified and possess two-year cumulative paid work experience in at least one or more of the following 6 CISSP-ISSMP Common Body of Knowledge (CBK) domains:
- Risk Management;
- Systems Lifecycle Management;
- Threat Intelligence and Incident Management;
- Leadership & Business Management;
- Contingency Management;
To obtain the CISSP-ISSMP certification you must pass the ISSMP exam. Once you attain this validation, make sure to recertify every three years by earning 20 Continuing Professional Education (CPE) credits annually. Luckily, there is no Annual Maintenance Fee for maintaining the CISSP-ISSMP concentration.
Pass ISC CISSP-ISSMP exam Dumps 100 Pass Guarantee With Latest Demo: https://pdfpractice.actual4dumps.com/CISSP-ISSMP-study-material.html