Free ISMP sample questions
Real questions from the Ismp practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
When a healthcare provider outsources its patient portal to a cloud vendor, what is the most critical aspect of information governance from the customer's (the healthcare provider's) perspective to ensure regulatory compliance?
An e-commerce company integrates a third-party payment gateway into its platform. To gain security assurance, which TWO of the following artifacts are most crucial for the supplier to provide and maintain? (Select TWO)
A risk analyst is conducting a qualitative risk assessment for a new mobile application. The analyst has identified a threat of "unauthorized access to user data" and a vulnerability of "weak session management." What is the next logical step in the risk analysis process?
FinSecure Bank's online banking platform processes millions of dollars in transactions daily. The Chief Risk Officer (CRO) has tasked a team with performing a quantitative risk analysis on a specific threat: a sophisticated phishing attack leading to fraudulent wire transfers. The team has determined that the value of an average fraudulent wire transfer (Single Loss Expectancy - SLE) is $10,000. Historical data and industry threat intelligence suggest that a major phishing campaign targeting the bank's customers occurs approximately four times per year. The bank's current security controls, including email filtering and user awareness training, are estimated to be 75% effective at preventing these attacks from succeeding. The CRO wants to know the residual risk to decide if a new, more advanced anti-phishing solution is justified. The proposed new solution costs $5,000 per year but claims to increase the effectiveness of controls to 95%. The CRO needs a clear financial justification based on risk reduction. Which of the following statements accurately represents the current financial risk and the justification for the new control?
A security architect is selecting controls for a critical customer database. To address the "Detection" stage of the incident response cycle, which control would be most appropriate?
True or False: After implementing a set of security controls, the goal of risk management is to completely eliminate all residual risk.
An organization is mapping its incident handling process to align with industry best practices. A security analyst has proposed the following high-level workflow. At which stage should the "Lessons Learned" activity be formally conducted? ``` [ A ] [ B ] [ C ] [ D ] Event --> Triage & --> Containment & --> Post-Incident Detected Analysis Eradication Activity ```
A fast-growing tech startup is transitioning its monolithic application to a microservices architecture hosted in a public cloud. A security architect advises implementing a "Zero Trust" security model. What is the primary purpose of adopting this architecture?
A company is designing the physical security for its new data center. Which of the following controls is a detective physical security control?
10 more free samples are waiting
Create a free account to unlock the whole ISMP sample bank, or get full access to all 162 practice questions in the simulator.