Which term describes a vulnerability that is unknown and therefore has no mitigating control which is immediately and generally available?
A. Advanced Persistent Threat.
B. Trojan.
C. Stealthware.
D. Zero-day.
Which of the following is LEASTLIKELY to be the result of a global pandemic impacting on information security?
A. A large increase in remote workers operating in insecure premises.
B. Additional physical security requirements at data centres and corporate headquarters.
C. Increased demand on service desks as users need additional tools such as VPNs.
D. An upsurge in activity by attackers seeking vulnerabilities caused by operational changes.
Which of the following types of organisation could be considered the MOST at risk from the theft of electronic based credit card data?
A. Online retailer.
B. Traditional market trader.
C. Mail delivery business.
D. Agricultural producer.
Which types of organisations are likely to be the target of DDoS attacks?
A. Cloud service providers.
B. Any financial sector organisations.
C. Online retail based organisations.
D. Any organisation with an online presence.
In a security governance framework, which of the following publications would be at the HIGHEST level?
A. Procedures.
B. Standards
C. Policy.
D. Guidelines
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?
A. System Integrity.
B. Sandboxing.
C. Intrusion Prevention System.
D. Defence in depth.
Which term describes the acknowledgement and acceptance of ownership of actions, decisions, policies and deliverables?
A. Accountability.
B. Responsibility.
C. Credibility.
D. Confidentiality.
According to ISO/IEC 27000, which of the following is the definition of a vulnerability?
A. A weakness of an asset or group of assets that can be exploited by one or more threats.
B. The impact of a cyber attack on an asset or group of assets.
C. The threat that an asset or group of assets may be damaged by an exploit.
D. The damage that has been caused by a weakness iin a system.
Which of the following is NOT an accepted classification of security controls?
A. Nominative.
B. Preventive.
C. Detective.
D. Corrective.
Which three of the following characteristics form the AAA Triad in Information Security?
1.
Authentication
2.
Availability
3.
Accounting
4.
Asymmetry
5.
Authorisation
A. 1, 2 and 3.
B. 2, 4, and 5.
C. 1, 3 and 4.
D. 1, 3 and 5.
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only BCS exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISMP-V9 exam preparations and BCS certification application, do not hesitate to visit our Vcedump.com to find your solutions here.