ExamDumpster

Free ISMP sample questions

Real questions from the Ismp practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial services firm is classifying its information assets. The CISO needs to explain to the board why the customer transaction database has a higher business value than the internal marketing materials. Which characteristic most directly determines the high business value of the customer transaction database compared to internal marketing collateral?

Question 2Choose one

When a healthcare provider outsources its patient portal to a cloud vendor, what is the most critical aspect of information governance from the customer's (the healthcare provider's) perspective to ensure regulatory compliance?

Question 3Choose 2

An e-commerce company integrates a third-party payment gateway into its platform. To gain security assurance, which TWO of the following artifacts are most crucial for the supplier to provide and maintain? (Select TWO)

Question 4Choose one

A risk analyst is conducting a qualitative risk assessment for a new mobile application. The analyst has identified a threat of "unauthorized access to user data" and a vulnerability of "weak session management." What is the next logical step in the risk analysis process?

Question 5Choose one

FinSecure Bank's online banking platform processes millions of dollars in transactions daily. The Chief Risk Officer (CRO) has tasked a team with performing a quantitative risk analysis on a specific threat: a sophisticated phishing attack leading to fraudulent wire transfers. The team has determined that the value of an average fraudulent wire transfer (Single Loss Expectancy - SLE) is $10,000. Historical data and industry threat intelligence suggest that a major phishing campaign targeting the bank's customers occurs approximately four times per year. The bank's current security controls, including email filtering and user awareness training, are estimated to be 75% effective at preventing these attacks from succeeding. The CRO wants to know the residual risk to decide if a new, more advanced anti-phishing solution is justified. The proposed new solution costs $5,000 per year but claims to increase the effectiveness of controls to 95%. The CRO needs a clear financial justification based on risk reduction. Which of the following statements accurately represents the current financial risk and the justification for the new control?

Question 6Choose one

A security architect is selecting controls for a critical customer database. To address the "Detection" stage of the incident response cycle, which control would be most appropriate?

Question 7Choose one

True or False: After implementing a set of security controls, the goal of risk management is to completely eliminate all residual risk.

Question 8Choose one

An organization is mapping its incident handling process to align with industry best practices. A security analyst has proposed the following high-level workflow. At which stage should the "Lessons Learned" activity be formally conducted? ``` [ A ] [ B ] [ C ] [ D ] Event --> Triage & --> Containment & --> Post-Incident Detected Analysis Eradication Activity ```

Question 9Choose one

A fast-growing tech startup is transitioning its monolithic application to a microservices architecture hosted in a public cloud. A security architect advises implementing a "Zero Trust" security model. What is the primary purpose of adopting this architecture?

Question 10Choose one

A company is designing the physical security for its new data center. Which of the following controls is a detective physical security control?

10 more free samples are waiting

Create a free account to unlock the whole ISMP sample bank, or get full access to all 162 practice questions in the simulator.

Create account