40%off
CISSP-ISSMP Premium Bundle
Latest CISSP-ISSMP Exam Premium Dumps provide by TrainingDump.com to help you Passing CISSP-ISSMP Exam! TrainingDump.com offers the updated CISSP-ISSMP exam dumps, the TrainingDump.com CISSP-ISSMP exam questions has been updated to correct Answer. Get the latest TrainingDump.com CISSP-ISSMP pdf dumps with Exam Engine here:
(447 Q&As Dumps, 40%OFF Special Discount: DumpsFiles)
Join the discussion
Question 166/228
Which of the following issues are addressed by the change control phase in the maintenance phase of the life cycle models? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,C,D
Add Comments
- Other Question (228q)
- Q1. Peter works as a Computer Hacking Forensic Investigator. He has been called by an organiza...
- Q2. Which of the following BEST describes "attack surface reduction" as a strategic security o...
- Q3. Which of the following are the goals of risk management? Each correct answer represents a ...
- Q4. You are the project manager of the NGQQ Project for your company. To help you communicate ...
- Q5. Which of the following BEST describes the concept of "security debt," analogous to "techni...
- Q6. Which of the following contract types is described in the statement below? "This contract ...
- Q7. Sarah has created a site on which she publishes a copyrighted material. She is ignorant th...
- Q8. Which of the following statements about Due Care policy is true?...
- Q9. Which of the following BEST describes why "operational threat intelligence" is particularl...
- Q10. Rachael is the project manager for a large project in her organization. A new change reque...
- Q11. Which of the following test methods has the objective to test the IT system from the viewp...
- Q12. Which of the following protocols is used with a tunneling protocol to provide security?...
- Q13. You work as a Senior Marketing Manger for Umbrella Inc. You find out that some of the soft...
- Q14. You work as a security manager for SoftTech Inc. You along with your team are doing the di...
- Q15. You are a project manager of a large construction project. Within the project you are work...
- Q16. Which of the following relies on a physical characteristic of the user to verify his ident...
- Q17. Which of the following are the goals of risk management? Each correct answer represents a ...
- Q18. You are responsible for network and information security at a metropolitan police station....
- Q19. Which of the following is the BEST justification for implementing "network segmentation" b...
- Q20. Which of the following BEST describes why "single sign-on (SSO)" implementations require c...
- Q21. Which of the following is the PRIMARY reason for maintaining an updated asset inventory as...
- Q22. You are the project manager of the GHE Project. You have identified the following risks wi...
- Q23. Which of the following steps are generally followed in computer forensic examinations? Eac...
- Q24. Which of the following is the BEST approach when a critical vulnerability is identified in...
- Q25. Which of the following contract types is described in the statement below? "This contract ...
- Q26. You work as a Network Administrator for ABC Inc. The company uses a secure wireless networ...
- Q27. Which of the following BEST describes why "geographic diversity" between primary and backu...
- Q28. Which of the following is the correct order of digital investigations Standard Operating P...
- Q29. In which of the following mechanisms does an authority, within limitations, specify what o...
- Q30. DIACAP applies to the acquisition, operation, and sustainment of any DoD system that colle...
- Q31. Which of the following security models dictates that subjects can only access objects thro...
- Q32. SIMULATION Fill in the blank with the appropriate phrase. ____________ is the ability to r...
- Q33. Which of the following BEST describes why security managers should track "control effectiv...
- Q34. Which of the following refers to an information security document that is used in the Unit...
- Q35. Which of the following processes is used by remote users to make a secure connection to in...
- Q36. You work as a Senior Marketing Manger for Umbrella Inc. You find out that some of the soft...
- Q37. Which of the following is the PRIMARY reason to conduct a lessons-learned session after a ...
- Q38. Which of the following access control models uses a predefined set of access privileges fo...
- Q39. Which of the following BEST describes the purpose of a Memorandum of Understanding (MOU) i...
- Q40. Which of the following BEST describes why "communication redundancy" (multiple channels) i...
- Q41. Which of the following are the goals of risk management? Each correct answer represents a ...
- Q42. Which of the following access control models are used in the commercial sector? Each corre...
- Q43. Tomas is the project manager of the QWS Project and is worried that the project stakeholde...
- Q44. Sarah, a CISO, wants to measure how quickly her SOC detects and responds to incidents. Whi...
- Q45. Which of the following 'Code of Ethics Canons' of the '(ISC)2 Code of Ethics' states to ac...
- Q46. Which of the following BEST describes why "tabletop exercises should include realistic con...
- Q47. Which of the following evidences are the collection of facts that, when considered togethe...
- Q48. Which of the following issues are addressed by the change control phase in the maintenance...
- Q49. Which of the following recovery plans includes specific strategies and actions to deal wit...
- Q50. Which of the following is a formula, practice, process, design, instrument, pattern, or co...
- Q51. Which of the following options is an approach to restricting system access to authorized u...
- Q52. Which of the following can be done over telephone lines, e-mail, instant messaging, and an...
- Q53. Which of the following BEST describes the purpose of an "escalation matrix" within an inci...
- Q54. Which of the following protocols are used to provide secure communication between a client...
- Q55. Drop the appropriate value to complete the formula. (Exhibit)...
- Q56. Which of the following response teams aims to foster cooperation and coordination in incid...
- Q57. Which of the following protocols are used to provide secure communication between a client...
- Q58. During an incident, which role is typically responsible for making the final decision to i...
- Q59. Which of the following is used to back up forensic evidences or data folders from the netw...
- Q60. Which of the following is a process that identifies critical information to determine if f...
- Q61. Which of the following is the BEST description of "impact tolerance" as distinguished from...
- Q62. You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extens...
- Q63. Which of the following 'Code of Ethics Canons' of the '(ISC)2 Code of Ethics' states to ac...
- Q64. You work as a Network Administrator for ABC Inc. The company uses a secure wireless networ...
- Q65. You work as a Forensic Investigator. Which of the following rules will you follow while wo...
- Q66. Which of the following plans provides procedures for recovering business operations immedi...
- Q67. Which of the following roles typically has ultimate accountability for an organization's o...
- Q68. Which of the following terms related to risk management represents the estimated frequency...
- Q69. Which of the following roles is responsible for review and risk analysis of all contracts ...
- Q70. You are documenting your organization's change control procedures for project management. ...
- Q71. You work as a security manager for SoftTech Inc. You are conducting a security awareness c...
- Q72. Mark works as a security manager for SofTech Inc. He is working in a partially equipped of...
- Q73. Peter works as a Computer Hacking Forensic Investigator. He has been called by an organiza...
- Q74. Which of the following BEST describes "safe harbor" provisions in the context of data brea...
- Q75. Which of the following is the PRIMARY purpose of an "Acceptable Use Policy (AUP)"?...
- Q76. Which of the following BEST describes the purpose of "alternate work-site strategies" (e.g...
- Q77. Which of the following fields of management focuses on establishing and maintaining consis...
- Q78. You are the project manager of the HJK Project for your organization. You and the project ...
- Q79. Which of the following types of cyber stalking damage the reputation of their victim and t...
- Q80. Which of the following statements reflect the 'Code of Ethics Preamble' in the '(ISC)2 Cod...
- Q81. Which of the following steps are generally followed in computer forensic examinations? Eac...
- Q82. Which of the following BEST describes the relationship between "compliance" and "security"...
- Q83. Which of the following authentication protocols provides support for a wide range of authe...
- Q84. Which of the following is a variant with regard to Configuration Management?...
- Q85. Which of the following BEST captures the ISSMP's overarching emphasis when synthesizing ac...
- Q86. Which of the following are the process steps of OPSEC? Each correct answer represents a pa...
- Q87. Which of the following enables an inventor to legally enforce his right to exclude others ...
- Q88. Which of the following BEST describes the concept of "security champions" embedded within ...
- Q89. Fill in the blank with an appropriate phrase. _______is a branch of forensic science perta...
- Q90. Which of the following authentication protocols provides support for a wide range of authe...
- Q91. Which of the following BEST describes why "third-party breach notification clauses" are im...
- Q92. Which of the following governance bodies provides management, operational and technical co...
- Q93. Which of the following U.S. Federal laws addresses computer crime activities in communicat...
- Q94. Which of the following laws is defined as the Law of Nations or the legal norms that has d...
- Q95. Which of the following BEST describes the purpose of "segregation of duties" combined with...
- Q96. John works as a security manager for Soft Tech Inc. He is working with his team on the dis...
- Q97. Management has asked you to perform a risk audit and report back on the results. Bonny, a ...
- Q98. Which of the following U.S. Federal laws addresses computer crime activities in communicat...
- Q99. Which of the following types of agreement creates a confidential relationship between the ...
- Q100. You are responsible for network and information security at a metropolitan police station....
- Q101. Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC...
- Q102. Which of the following types of activities can be audited for security? Each correct answe...
- Q103. Which of the following BEST reflects the concept of "management commitment" as a critical ...
- Q104. Sarah has created a site on which she publishes a copyrighted material. She is ignorant th...
- Q105. Which of the following strategies is used to minimize the effects of a disruptive event on...
- Q106. Which of the following signatures watches for the connection attempts to well-known, frequ...
- Q107. You are the Network Administrator for a software company. Due to the nature of your compan...
- Q108. Which of the following security models focuses on data confidentiality and controlled acce...
- Q109. Which of the following BEST describes the PRIMARY value of scenario-based planning (e.g., ...
- Q110. Which of the following BEST describes why an organization should maintain a documented "in...
- Q111. Shoulder surfing is a type of in-person attack in which the attacker gathers information a...
- Q112. Which of the following is generally considered the WEAKEST basis for making a risk accepta...
- Q113. Which of the following 'Code of Ethics Canons' of the '(ISC)2 Code of Ethics' states to ac...
- Q114. Which of the following roles is used to ensure that the confidentiality, integrity, and av...
- Q115. Rick is the project manager for TTM project. He is in the process of procuring services fr...
- Q116. Which of the following BEST describes a "false positive" in the context of security monito...
- Q117. Which of the following can be done over telephone lines, e-mail, instant messaging, and an...
- Q118. Which of the following issues are addressed by the change control phase in the maintenance...
- Q119. Which of the following BEST describes why security program budgets should be justified usi...
- Q120. Configuration Management (CM) is an Information Technology Infrastructure Library (ITIL) I...
- Q121. Which of the following BEST illustrates the difference between a "Standard Operating Proce...
- Q122. Which of the following plans is designed to protect critical business processes from natur...
- Q123. Which of the following BEST summarizes the ISSMP view on the CISO's relationship with othe...
- Q124. Which of the following is the PRIMARY purpose of a security metrics dashboard presented to...
- Q125. Which of the following BEST describes why "third-party dependency documentation" should be...
- Q126. Which of the following is the PRIMARY goal of a post-incident review meeting involving leg...
- Q127. Which of the following attacks can be mitigated by providing proper training to the employ...
- Q128. Which of the following are the major tasks of risk management? Each correct answer represe...
- Q129. Which of the following BEST describes "impact analysis" as distinct from "likelihood analy...
- Q130. A security governance framework primarily helps ensure which of the following?...
- Q131. In which of the following mechanisms does an authority, within limitations, specify what o...
- Q132. You work as a project manager for SoftTech Inc. A threat with a dollar value of $150,000 i...
- Q133. Which of the following is the PRIMARY objective of conducting a "privacy impact assessment...
- Q134. Which of the following evidences are the collection of facts that, when considered togethe...
- Q135. Which of the following is a documentation of guidelines that computer forensics experts us...
- Q136. Which of the following are the common roles with regard to data in an information classifi...
- Q137. Which of the following analysis provides a foundation for measuring investment of time, mo...
- Q138. Which of the following anti-child pornography organizations helps local communities to cre...
- Q139. Which of the following are the common roles with regard to data in an information classifi...
- Q140. Which of the following analysis provides a foundation for measuring investment of time, mo...
- Q141. Which of the following deals is a binding agreement between two or more persons that is en...
- Q142. Your company is covered under a liability insurance policy, which provides various liabili...
- Q143. Which of the following is used to back up forensic evidences or data folders from the netw...
- Q144. During a tabletop exercise, participants discuss their roles and responses to a simulated ...
- Q145. SIMULATION Fill in the blank with an appropriate phrase.______________ is used to provide ...
- Q146. Which of the following roles is responsible for review and risk analysis of all contracts ...
- Q147. Which of the following BEST describes the concept of "residual risk reporting cadence" as ...
- Q148. Which of the following concepts represent the three fundamental principles of information ...
- Q149. Which of the following BEST describes the concept of "graceful degradation" as a resilienc...
- Q150. Which of the following access control models uses a predefined set of access privileges fo...
- Q151. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q152. Which of the following BEST describes why the "second line of defense" (risk/compliance fu...
- Q153. How many change control systems are there in project management?...
- Q154. Which of the following are the examples of administrative controls? Each correct answer re...
- Q155. Which of the following persons is responsible for testing and verifying whether the securi...
- Q156. Which of the following is the correct order of digital investigations Standard Operating P...
- Q157. Which of the following liabilities is a third-party liability in which an individual may b...
- Q158. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q159. You work as the Network Administrator for a defense contractor. Your company works with se...
- Q160. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q161. Which of the following processes provides a standard set of activities, general tasks, and...
- Q162. Mark is the project manager of the NHQ project in Spartech Inc. The project has an asset v...
- Q163. Which of the following characteristics are described by the DIAP Information Readiness Ass...
- Q164. The incident response team has turned the evidence over to the forensic team. Now, it is t...
- Q165. Which of the following BEST describes the concept of "security through the lifecycle" as e...
- Q166. Which of the following issues are addressed by the change control phase in the maintenance...
- Q167. Your project team has identified a project risk that must be responded to. The risk has be...
- Q168. Which of the following is the default port for Simple Network Management Protocol (SNMP)?...
- Q169. You work as a security manager for SoftTech Inc. You are conducting a security awareness c...
- Q170. Which of the following BEST describes the concept of "dwell time" in the context of an adv...
- Q171. Which of the following BEST describes the purpose of a "damage assessment" immediately fol...
- Q172. Which of the following U.S. Federal laws addresses computer crime activities in communicat...
- Q173. Which of the following test methods has the objective to test the IT system from the viewp...
- Q174. Which of the following BEST describes a "single point of failure" in the context of busine...
- Q175. Which of the following statements about system hardening are true? Each correct answer rep...
- Q176. Mark works as a security manager for SoftTech Inc. He is performing a security awareness p...
- Q177. Fill in the blank with an appropriate phrase.___________ is the process of using a strateg...
- Q178. Electronic communication technology refers to technology devices, such as computers and ce...
- Q179. Which of the following are the responsibilities of a custodian with regard to data in an i...
- Q180. Which of the following deals is a binding agreement between two or more persons that is en...
- Q181. Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC...
- Q182. Which of the following BEST describes the concept of "asset criticality tiering" when plan...
- Q183. Which of the following BEST describes the purpose of "security orchestration, automation, ...
- Q184. Drag and drop the Response management plans to match up with their respective purposes. (E...
- Q185. Which of the following BEST describes why "board-level risk reporting" should avoid excess...
- Q186. Electronic communication technology refers to technology devices, such as computers and ce...
- Q187. Which of the following BEST describes why "encryption key management" is considered a crit...
- Q188. Which of the following statements best explains how encryption works on the Internet?...
- Q189. NIST Special Publication 800-50 is a security awareness program. It is designed for those ...
- Q190. Which of the following is the process performed between organizations that have unique har...
- Q191. Which of the following processes will you involve to perform the active analysis of the sy...
- Q192. Which of the following recovery plans includes specific strategies and actions to deal wit...
- Q193. Which of the following statements reflect the 'Code of Ethics Canons' in the '(ISC)2 Code ...
- Q194. Which of the following statements are true about security risks? Each correct answer repre...
- Q195. Which of the following protocols is used with a tunneling protocol to provide security?...
- Q196. What is a stakeholder analysis chart?
- Q197. Which of the following are the responsibilities of a custodian with regard to data in an i...
- Q198. Which of the following BEST describes the purpose of a "war room" during a major incident?...
- Q199. Which of the following statements best explains how encryption works on the Internet?...
- Q200. The incident response team has turned the evidence over to the forensic team. Now, it is t...
- Q201. Which of the following architecturally related vulnerabilities is a hardware or software m...
- Q202. Which of the following BEST describes why "independence" is important for an internal audi...
- Q203. Which of the following statements are true about a hot site? Each correct answer represent...
- Q204. Which of the following involves changing data prior to or during input to a computer in an...
- Q205. Which of the following BEST describes a "Computer Security Incident Response Team (CSIRT)"...
- Q206. You are the project manager of the GHE Project. You have identified the following risks wi...
- Q207. Which of the following roles is typically responsible for developing and maintaining the o...
- Q208. Which of the following documents is described in the statement below? "It is developed alo...
- Q209. Which of the following BEST describes "security by design"?...
- Q210. Which of the following are the levels of public or commercial data classification system? ...
- Q211. Change Management is used to ensure that standardized methods and procedures are used for ...
- Q212. Eric is the project manager of the NQQ Project and has hired the ZAS Corporation to comple...
- Q213. Which of the following are the responsibilities of the owner with regard to data in an inf...
- Q214. How can you calculate the Annualized Loss Expectancy (ALE) that may occur due to a threat?...
- Q215. Which of the following Acts enacted in United States allows the FBI to issue National Secu...
- Q216. Which of the following laws enacted in United States makes it illegal for an Internet Serv...
- Q217. Which of the following plans is documented and organized for emergency response, backup op...
- Q218. Which of the following BEST describes the PRIMARY value of maintaining "offline/air-gapped...
- Q219. Which of the following BEST describes the purpose of a "risk register"?...
- Q220. Which of the following policies helps reduce the potential damage from the actions of one ...
- Q221. Which of the following BEST describes the purpose of "breach simulation exercises" specifi...
- Q222. An organization is deciding between building an in-house SOC versus outsourcing to an MSSP...
- Q223. Which of the following statements is true about auditing?...
- Q224. Which of the following BEST describes why a CISO should maintain relationships with peer o...
- Q225. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q226. Which of the following roles is responsible for formally accepting residual risk on behalf...
- Q227. Which of the following BEST describes "attribution" in the context of threat intelligence,...
- Q228. Which of the following analysis provides a foundation for measuring investment of time, mo...
