ISC CISSP-ISSMP - ISSMPĀ®: Information Systems Security Management Professional Exam

Question #11 (Topic: )
Which of the following steps is the initial step in developing an information security
strategy?
A. Perform a technical vulnerabilities assessment. B. Assess the current levels of security awareness. C. Perform a business impact analysis. D. Analyze the current business strategy.
Answer: D
Question #12 (Topic: )
Which of the following test methods has the objective to test the IT system from the
viewpoint of a threat-source and to identify potential failures in the IT system protection
schemes?
A. Penetration testing B. On-site interviews C. Security Test and Evaluation (ST&E) D. Automated vulnerability scanning tool
Answer: A
Question #13 (Topic: )
How can you calculate the Annualized Loss Expectancy (ALE) that may occur due to a
threat?
A. Single Loss Expectancy (SLE)/ Exposure Factor (EF) B. Asset Value X Exposure Factor (EF) C. Exposure Factor (EF)/Single Loss Expectancy (SLE) D. Single Loss Expectancy (SLE) X Annualized Rate of Occurrence (ARO)
Answer: D
Question #14 (Topic: )
NIST Special Publication 800-50 is a security awareness program. It is designed for those
people who are currently working in the information technology field and want information
on security policies. Which of the following are some of its critical steps? Each correct
answer represents a complete solution. Choose two.
A. Awareness and Training Material Effectiveness B. Awareness and Training Material Development C. Awareness and Training Material Implementation D. Awareness and Training Program Design
Answer: B,D
Question #15 (Topic: )
Which of the following processes is a structured approach to transitioning individuals,
teams, and organizations from a current state to a desired future state?
A. Risk management B. Configuration management C. Change management D. Procurement management
Answer: C
Download Exam
Page: 3 / 44
Total 218 questions