Free CISMP sample questions
Real questions from the BCS Foundation Certificate in Information Security Management Principles practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
A UK-based healthcare provider (HealthTrust) collects patient data to provide medical services. To improve efficiency, HealthTrust subscribes to a cloud-based Software-as-a-Service (SaaS) platform provided by CloudMed Inc. to store and manage this patient data. CloudMed Inc. strictly follows the instructions provided by HealthTrust and does not use the patient data for its own purposes. However, to ensure high availability, CloudMed Inc. subcontracts data hosting to a third-party infrastructure provider, InfraHost. Under the UK GDPR and Data Protection Act 2018, how are the roles of HealthTrust and CloudMed Inc. legally defined in this scenario? flowchart LR A[Patients] -->|Provide Data| B(HealthTrust) B -->|Determines Purpose| C{Data Controller} B -->|Uploads Data| D(CloudMed Inc.) D -->|Follows Instructions| E{Data Processor} D -->|Subcontracts| F[InfraHost]
Risk tolerance refers to the broad, high-level amount of risk an organisation is willing to accept in pursuit of its strategic objectives, whereas risk appetite is the specific, acceptable variance around a specific objective.
A financial organisation has implemented a mantrap (security vestibule) at the entrance of its data centre. The mantrap requires a valid smart card to enter the first door, and a biometric retina scan to open the second door, preventing tailgating. How is this control correctly categorised according to the CISMP v10.0 syllabus?
A security manager is performing a quantitative risk analysis on a legacy database server. If the server fails, the business estimates the Single Loss Expectancy (SLE) to be £12,000 in lost revenue and recovery costs. Historical data suggests this type of failure occurs once every three years. What is the Annual Loss Expectancy (ALE) for this risk?
An organisation decides that the cost of implementing encryption and access controls for a low-value, publicly available marketing dataset far exceeds the potential impact of its exposure. Management formally documents this decision and takes no further security action regarding this dataset. Which risk treatment option has been applied?
6 more free samples are waiting
Create a free account to unlock the whole CISMP sample bank, or get full access to all 111 practice questions in the simulator.