Exin Information Security Management Professional based on ISO/IEC 27001 ISMP Exam Questions

Page: 1 / 14
Total 30 questions
Question 1

An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.

When has the risk assessment program accomplished its primary goal?



Answer : C


Question 2

Who should be asked to check compliance with the information security policy throughout the company?



Answer : B


Question 3

Which security item is designed to take collections of data from multiple computers?



Answer : C


Question 4

The information security architect of a large service provider advocates an open design of the security architecture, as opposed to a secret design.

What is her main argument for this choice?



Answer : C


Question 5

An experienced security manager is well aware of the risks related to communication over the internet. She also knows that Public Key Infrastructure (PKI) can be used to keep e-mails between employees confidential.

Which is the main risk of PKI?



Answer : A


Question 6

What is a risk treatment strategy?



Answer : B


Question 7

A security manager for a large company has the task to achieve physical protection for corporate data stores.

Through which control can physical protection be achieved?



Answer : D


Page:    1 / 14   
Total 30 questions