[Q230-Q254] Valid CISSP-ISSMP Practice Test Dumps with 100% Passing Guarantee [Sep-2026]

Share

Valid CISSP-ISSMP Practice Test Dumps with 100% Passing Guarantee [Sep-2026]

CISSP-ISSMP PDF Dumps Are Helpful To produce Your Dreams Correct QA's

NEW QUESTION # 230
Which of the following plans is designed to protect critical business processes from natural or man- made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes?

  • A. Crisis communication plan
  • B. Contingency plan
  • C. Business continuity plan
  • D. Disaster recovery plan

Answer: C

Explanation:
The business continuity plan is designed to protect critical business processes from natural or man- made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes.
Business Continuity Planning (BCP) is the creation and validation of a practiced logistical plan for how an organization will recover and restore partially or completely interrupted critical (urgent) functions within a predetermined time after a disaster or extended disruption. The logistical plan is called a business continuity plan.
Answer option B is incorrect. The crisis communication plan can be broadly defined as the plan for the exchange of information before, during, or after a crisis event. It is considered as a sub- specialty of the public relations profession that is designed to protect and defend an individual, company, or organization facing a public challenge to its reputation. The aim of crisis communication plan is to assist organizations to achieve continuity of critical business processes and information flows under crisis, disaster or event driven circumstances. Answer option C is incorrect. A contingency plan is a plan devised for a specific situation when things could go wrong. Contingency plans are often devised by governments or businesses who want to be prepared for anything that could happen. Contingency plans include specific strategies and actions to deal with specific variances to assumptions resulting in a particular problem, emergency, or state of affairs. They also include a monitoring process and "triggers" for initiating planned actions. They are required to help governments, businesses, or individuals to recover from serious incidents in the minimum time with minimum cost and disruption.
Answer option D is incorrect. A disaster recovery plan should contain data, hardware, and software that can be critical for a business. It should also include the plan for sudden loss such as hard disc crash. The business should use backup and data recovery utilities to limit the loss of data.
Reference: CISM Review Manual 2010, Contents. "Incident Management and Response"


NEW QUESTION # 231
Which of the following is the BEST reason to involve Legal counsel EARLY in incident response planning, rather than only after an incident occurs?

  • A. Legal has no role in incident response
  • B. To ensure response actions preserve evidence, meet notification obligations, and protect privilege where applicable
  • C. To delay the response process for review
  • D. Legal should only be involved in contract negotiations

Answer: B

Explanation:
Early legal involvement ensures response procedures account for regulatory notification deadlines, evidence handling for potential litigation, and attorney-client privilege considerations - waiting until after an incident risks missteps.


NEW QUESTION # 232
Which of the following roles typically has ultimate accountability for an organization's overall risk management program, even though day-to-day execution is delegated?

  • A. External auditor
  • B. Board of Directors / senior executive management
  • C. Help desk manager
  • D. Security analyst

Answer: B

Explanation:
While execution is delegated to risk and security teams, ultimate accountability for organizational risk oversight rests with the board and senior executive leadership under corporate governance principles.


NEW QUESTION # 233
Which of the following BEST describes a "litigation hold" (legal hold) and when it should be issued?

  • A. A notice requiring preservation of potentially relevant information once litigation is reasonably anticipated, issued as early as possible
  • B. A hold applicable only to paper documents
  • C. A hold that only applies after a lawsuit is formally filed
  • D. A hold placed on all company communications permanently

Answer: A

Explanation:
A legal hold must be issued proactively - as soon as litigation is reasonably foreseeable, not only after a suit is filed - instructing custodians to preserve relevant data and suspending routine destruction/retention schedules for that data.


NEW QUESTION # 234
NIST Special Publication 800-50 is a security awareness program. It is designed for those people who are currently working in the information technology field and want information on security policies. Which of the following are some of its critical steps? Each correct answer represents a complete solution. Choose two.

  • A. Awareness and Training Material Implementation
  • B. Awareness and Training Material Effectiveness
  • C. Awareness and Training Program Design
  • D. Awareness and Training Material Development

Answer: C,D


NEW QUESTION # 235
Which of the following tools works by using standard set of MS-DOS commands and can create an MD5 hash of an entire drive, partition, or selected files?

  • A. Device Seizure
  • B. Forensic Sorter
  • C. DriveSpy
  • D. Ontrack

Answer: C

Explanation:
DriveSpy is a modified MS-DOS shell, which is designed to use standard commands of MS-DOS for forensic purposes. It uses a set of standard MS-DOS commands followed by commands specific to process the computer during investigations. It can clean an entire drive or partition, unallocated space, or slack space. DriveSpy can also create an MD5 hash of an entire drive, partition, or selected files. It saves and restores compressed images of a partition for forensic use. Answer options B, A, and D are incorrect. All these tools are not used for creating an MD5 hash of an entire drive, partition, or selected files. Ontrack is a data recovery tool, which is used to recover lost and deleted data. It provides file repair capability for files in Microsoft Word and Zip format. Ontrack also recovers deleted files, folders, and entire partitions. It uses an emergency boot disks to collect data from systems that cannot boot Windows operating system. The user can configure the filter of the file for a full scan. Ontrack can also filter data according to the different file parameters, such as date, time, name, size, etc.
Device Seizure is a software, which is used in forensic analysis and recovery of mobile phone and PDA data. It is used for data recovery, full data dumps of certain cell phone models, logical and physical acquisitions of PDAs, data cable access, and advanced reporting. Device Seizure also provides feature of GSM SIM card acquisition and deleted data recovery using SIMCon technology. Forensic Sorter is software, which is used to organize the contents of a hard drive. It sorts files of hard drive into different categories, such as video, audio, spreadsheets etc. Forensic Sorter also recovers deleted files, or file fragments in slack. It supports drive image in RAW, PFR, safeback, and Encase image file formats. Forensic Sorter sorts file on the basis of their header for more accuracy.
Reference: CHFI Course Manual, Contents: "Forensic software"


NEW QUESTION # 236
Which of the following BEST describes why "third-party breach notification clauses" are important in vendor contracts?

  • A. They eliminate the need for a vendor risk assessment
  • B. They obligate the vendor to promptly inform the organization of a breach affecting shared/processed data, enabling timely response and regulatory compliance
  • C. They are irrelevant since vendors are solely liable for their own breaches
  • D. They only apply to cloud vendors

Answer: B

Explanation:
Since the client organization often retains regulatory notification obligations (e.g., under GDPR) even when a vendor is breached, contracts must require prompt vendor notification to enable the client to meet its own compliance timelines.


NEW QUESTION # 237
Which of the following is generally practiced by the police or any other recognized governmental authority?

  • A. Spoofing
  • B. Wiretapping
  • C. SMB signing
  • D. Phishing

Answer: B


NEW QUESTION # 238
Which of the following are examples of physical controls used to prevent unauthorized access to sensitive materials?

  • A. Encryption
  • B. Security Guards
  • C. Thermal alarm systems
  • D. Closed circuit cameras

Answer: B,C,D


NEW QUESTION # 239
You work as the project manager for Bluewell Inc. You are working on NGQQ Project for your company. You have completed the risk analysis processes for the risk events. You and the project team have created risk responses for most of the identified project risks. Which of the following risk response planning techniques will you use to shift the impact of a threat to a third party, together with the responses?

  • A. Risk avoidance
  • B. Risk acceptance
  • C. Risk transference
  • D. Risk mitigation

Answer: C


NEW QUESTION # 240
Which of the following BEST describes the concept of "risk-based authentication (RBA)"?

  • A. Authentication requirements are identical regardless of context
  • B. RBA applies only to physical access control systems
  • C. RBA eliminates the need for multi-factor authentication
  • D. Authentication requirements dynamically adjust based on contextual risk factors (location, device, behavior pattern)

Answer: D

Explanation:
Risk-based/adaptive authentication increases friction (e.g., requiring MFA) when contextual signals suggest higher risk (unusual location, new device) while allowing smoother access under normal, low-risk conditions.


NEW QUESTION # 241
Which of the following statements is related with the first law of OPSEC?

  • A. If you don't know about your security resources you could not protect your network.
  • B. If you are not protecting it (the critical and sensitive information), the adversary wins!
  • C. If you don't know what to protect, how do you know you are protecting it?
  • D. If you don't know the threat, how do you know what to protect?

Answer: D

Explanation:
OPSEC is also known as operations security. It has three laws:
The First Law of OPSEC. If you don't know the threat, how do you know what to protect?
Although specific threats may vary from site to site or program to program. Employees must be aware of the actual and postulated threats. In any given situation, there is likely to be more than one adversary, although each may be interested in different information. The Second Law of OPSEC. If you don't know what to protect, how do you know you are protecting it? The "what" is the critical and sensitive, or target, information that adversaries require to meet their objectives.
The Third Law of OPSEC. If you are not protecting it (the critical and sensitive information), the adversary wins! OPSEC vulnerability assessments, (referred to as "OPSEC assessments" - OA's
- or sometimes as Surveys") are conducted to determine whether or not critical information is vulnerable to exploitation. An OA is a critical analysis of "what we do" and "how we do it" from the perspective of an adversary. Internal procedures and information sources are also reviewed to determine whether there is an inadvertent release of sensitive information. Answer option C is incorrect. The statement given in the option is not a valid law of OPSEC.
Reference:
http://www.guardianangelsforsoldierspet.org/index.php?option=com_content&view=article&id=70
&Itemid=153


NEW QUESTION # 242
Mark is the project manager of the NHQ project in Spartech Inc. The project has an asset valued at $195,000 and is subjected to an exposure factor of 35 percent. What will be the Single Loss Expectancy of the project?

  • A. $68,250
  • B. $67,250
  • C. $72,650
  • D. $92,600

Answer: A

Explanation:
Explanation


NEW QUESTION # 243
Which of the following BEST describes the "Daubert standard" as it might relate to digital forensic evidence in U.S. courts?

  • A. A standard for classifying data sensitivity
  • B. A framework for calculating ALE
  • C. A standard exclusive to European courts
  • D. A standard used by courts to evaluate the reliability and admissibility of expert/scientific testimony, including forensic methodology

Answer: D

Explanation:
The Daubert standard is used by U.S. federal courts to assess whether expert testimony (including forensic analysis methods) is based on reliable, scientifically valid methodology before it can be admitted as evidence.


NEW QUESTION # 244
You are the Network Administrator for a software company. Due to the nature of your company's business, you have a significant number of highly computer savvy users. However, you have still decided to limit each user access to only those resources required for their job, rather than give wider access to the technical users (such as tech support and software engineering personnel). What is this an example of?

  • A. Proper use of an ACL.
  • B. The principle of least privileges.
  • C. Poor resource management.
  • D. The principle of maximum control.

Answer: B


NEW QUESTION # 245
Which of the following BEST describes why "dependency mapping" is a critical input to contingency planning?

  • A. Dependency mapping replaces the need for an RTO
  • B. Dependency mapping is only relevant to network diagrams
  • C. Dependencies rarely change and require no periodic updates
  • D. Understanding upstream/downstream dependencies between systems and processes ensures recovery sequencing avoids restoring a system before its prerequisites are available

Answer: D

Explanation:
Restoring an application before its database or authentication service is available wastes effort and delays recovery; dependency mapping ensures the recovery sequence follows the correct technical and business order.


NEW QUESTION # 246
Your project team has identified a project risk that must be responded to. The risk has been recorded in the risk register and the project team has been discussing potential risk responses for the risk event. The event is not likely to happen for several months but the probability of the event is high. Which one of the following is a valid response to the identified risk event?

  • A. Technical performance measurement
  • B. Earned value management
  • C. Risk audit
  • D. Corrective action

Answer: D


NEW QUESTION # 247
Drag and drop the Response management plans to match up with their respective purposes.

Answer:

Explanation:

Explanation:
The response management plans are shown in the table below:
Business continuity planIt provides measures for sustaining essential business operations while recovering from a significant disruption.
Business recovery planIt provides measures for recovering business operations immediately following a disaster.
Continuity of operation It provides measures and capabilities to maintain organizational essential, strategic functions at an alternate site planfor upto 30 days.
Contingency planIt provides measures and capabilities for recovering a major application or general support system.
Crisis communication plan It provides measures for disseminating status report to personnel and the public.
Disaster recovery planIt provides detailed measures to facilitate recovery of capabilities at an alternate site.
Reference: CISM Review Manual 2010, Contents: "Incident management and response"


NEW QUESTION # 248
Which of the following statements are true about a hot site? Each correct answer represents a complete solution. Choose all that apply.

  • A. It can be used within an hour for data recovery.
  • B. It is cheaper than a cold site but more expensive than a worm site.
  • C. It is a duplicate of the original site of the organization, with full computer systems as well as near-complete backups of user data.
  • D. It is the most inexpensive backup site.

Answer: A,C


NEW QUESTION # 249
What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.

  • A. Baseline the Environment
  • B. Define Policy
  • C. Organization Vulnerability
  • D. Maintain and Monitor

Answer: A,B,D


NEW QUESTION # 250
John works as a security manager for Soft Tech Inc. He is working with his team on the disaster recovery management plan. One of his team members has a doubt related to the most cost effective DRP testing plan. According to you, which of the following disaster recovery testing plans is the most cost-effective and efficient way to identify areas of overlap in the plan before conducting more demanding training exercises?

  • A. Walk-through drill
  • B. Structured walk-through test
  • C. Evacuation drill
  • D. Full-scale exercise

Answer: B

Explanation:
The structured walk-through test is also known as the table-top exercise. In structured walk- through test, the team members walkthrough the plan to identify and correct weaknesses and how they will respond to the emergency scenarios by stepping in the course of the plan. It is the most effective and competent way to identify the areas of overlap in the plan before conducting more challenging training exercises.
Answer option A is incorrect. In full-scale exercise, the critical systems run at an alternate site.
Answer option B is incorrect. The emergency management group and response teams actually perform their emergency response functions by walking through the test, without actually initiating recovery procedures. But it is not much cost effective. Answer option C is incorrect. It is a test performed when personnel walks through the evacuation route to a designated area where procedures for accounting for the personnel are tested.
Reference: CISM Review Manual 2010, Chapter. "Incident Management and Response"


NEW QUESTION # 251
You work as a security manager for SoftTech Inc. You are conducting a security awareness campaign for your employees. One of the employees of your organization asks you the purpose of the security awareness, training and education program. What will be your answer?

  • A. It improves awareness of the need to protect system resources.
  • B. It improves the security of vendor relations.
  • C. It improves the performance of a company's intranet.
  • D. It improves the possibility for career advancement of the IT staff.

Answer: A


NEW QUESTION # 252
A Web-based credit card company had collected financial and personal details of Mark before issuing him a credit card. The company has now provided Mark's financial and personal details to another company. Which of the following Internet laws has the credit card issuing company violated?

  • A. Copyright law
  • B. Privacy law
  • C. Security law
  • D. Trademark law

Answer: B

Explanation:
The credit card issuing company has violated the Privacy law. According to the Internet Privacy law, a company cannot provide their customer's financial and personal details to other companies. Answer option B is incorrect. Trademark laws facilitate the protection of trademarks around the world.
Answer option D is incorrect. There is no law such as Security law. Answer option A is incorrect.
The Copyright law protects original works or creations of authorship including literary, dramatic, musical, artistic, and certain other intellectual works.


NEW QUESTION # 253
Which of the following laws enacted in United States makes it illegal for an Internet Service Provider (ISP) to allow child pornography to exist on Web sites?

  • A. USA PATRIOT Act
  • B. Prosecutorial Remedies and Tools Against the Exploitation of Children Today Act (PROTECT Act)
  • C. Child Pornography Prevention Act (CPPA)
  • D. Sexual Predators Act

Answer: D


NEW QUESTION # 254
......

Cover CISSP-ISSMP Exam Questions Make Sure You 100% Pass: https://www.vce4plus.com/ISC/CISSP-ISSMP-valid-vce-dumps.html