EXIN certification preparation
ISMP Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- ISMP
- Provider
- EXIN
- Full set
- 30 questions
- Last Update Check
What needs to be decided prior to considering the treatment of risks?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Zoning is a security control to separate physical areas with different security levels. Zones with higher
security levels can be secured by more controls. The facility manager of a conference center is
responsible for security.
What combination of business functions should be combined into one security zone?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
What is the best way to start setting the information security controls?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company's webshop offers prospects and customers the possibility to search the catalog and place
orders around the clock. In order to satisfy the needs of both customer and business several
requirements
have
to
be met. One of the criteria is data classification.
What is the most important classification aspect of the unit price of an object in a 24h webshop?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
The information security architect of a large service provider advocates an open design of the
security architecture, as opposed to a secret design.
What is her main argument for this choice?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
An employee has worked on the organizational risk assessment. The goal of the assessment is not to
bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A protocol to investigate fraud by employees is being designed.
Which measure can be part of this protocol?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A security manager just finished the final copy of a risk assessment. This assessment contains a list of
identified risks and she has to determine how to treat these risks.
What is the best option for the treatment of risks?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
In a company a personalized smart card is used for both physical and logical access control.
What is the main purpose of the person’s picture on the smart card?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
When should information security controls be considered?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
