
(2026) CISSP-ISSMP Exam Dumps, Practice Test Questions BUNDLE PACK
CISSP Concentrations Certification CISSP-ISSMP Sample Questions Reliable
The CISSP-ISSMP is one of the three concentrations of the Certified Information Systems Security Professional (CISSP) certification, with the other concentrations being the CISSP-ISSAP and CISSP-ISSEP. With this particular certificate, you will gain specialized knowledge and skills in cybersecurity management. In addition, you can verify your abilities about implementing and governing information security programs as a CISSP-ISSMP certified professional. Once accredited, you will acquire advanced management and leadership skills to guide breach mitigation teams. With this article, you will get familiarized with an overview of the CISSP-ISSMP certification exam and why you should get certified. You will also learn about exam-specific details and preparatory materials such as official study guides and training courses.
NEW QUESTION # 16
Mark works as a security manager for SoftTech Inc. He is involved in the BIA phase to create a document to be used to help understand what impact a disruptive event would have on the business. The impact might be financial or operational. Which of the following are the objectives related to the above phase in which Mark is involved? Each correct answer represents a part of the solution. Choose three.
- A. Performing vulnerability assessment
- B. Down-time estimation
- C. Criticality prioritization
- D. Resource requirements identification
Answer: B,C,D
NEW QUESTION # 17
Which of the following rated systems of the Orange book has mandatory protection of the TCB?
- A. D-rated
- B. A-rated
- C. B-rated
- D. C-rated
Answer: C
NEW QUESTION # 18
You are a project manager of a large construction project. Within the project you are working with several vendors to complete different phases of the construction. Your client has asked that you arrange for some of the materials a vendor is to install next week in the project to be changed. According to the change management plan what subsystem will need to manage this change request?
- A. Contract
- B. Resources
- C. Cost
- D. Schedule
Answer: A
NEW QUESTION # 19
Management has asked you to perform a risk audit and report back on the results. Bonny, a project team member asks you what a risk audit is. What do you tell Bonny?
- A. A risk audit is a review of all the risk probability and impact for the risks, which are still present in the project but which have not yet occurred.
- B. A risk audit is an audit of all the risks that have occurred in the project and what their true impact on cost and time has been.
- C. A risk audit is a review of the effectiveness of the risk responses in dealing with identified risks and their root causes, as well as the effectiveness of the risk management process.
- D. A risk audit is a review of all the risks that have yet to occur and what their probability of happening are.
Answer: C
NEW QUESTION # 20
Which of the following terms describes a repudiation of a contract that occurs before the time when performance is due?
- A. Anticipatory breach
- B. Nonperforming breach
- C. Actual breach
- D. Expected breach
Answer: A
Explanation:
The anticipatory breach is also known as an anticipatory repudiation. It is a term in the law of contracts that describes a declaration by the promising party to a contract that he or she does not intend to live up to his or her obligations under the contract. Anticipatory breach is an unequivocal indication that the party will not perform when performance is due, or a situation in which future non-performance is inevitable.
Answer option B is incorrect. An actual breach is an unwarranted failure to perform a contract at the time when the performance is due.
Answer options A and D are incorrect. These are not valid options.
Reference: CISM Review Manual 2010, Contents. "Information security program management"
NEW QUESTION # 21
DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP? Each correct answer represents a complete solution. Choose all that apply.
- A. Accreditation
- B. Identification
- C. Verification
- D. Validation
- E. System Definition
- F. Re-Accreditation
Answer: C,D,E,F
NEW QUESTION # 22
Mark is the project manager of the NHQ project in Spartech Inc. The project has an asset valued at $195,000 and is subjected to an exposure factor of 35 percent. What will be the Single Loss Expectancy of the project?
- A. $92,600
- B. $67,250
- C. $72,650
- D. $68,250
Answer: D
NEW QUESTION # 23
Which of the following security issues does the Bell-La Padula model focus on?
- A. Authentication
- B. Authorization
- C. Confidentiality
- D. Integrity
Answer: C
NEW QUESTION # 24
Which of the following test methods has the objective to test the IT system from the viewpoint of a threat- source and to identify potential failures in the IT system protection schemes?
- A. Penetration testing
- B. On-site interviews
- C. Security Test and Evaluation (ST&E)
- D. Automated vulnerability scanning tool
Answer: A
NEW QUESTION # 25
Change Management is used to ensure that standardized methods and procedures are used for efficient handling of all changes. Who decides the category of a change?
- A. The Change Advisory Board
- B. The Change Manager
- C. The Problem Manager
- D. The Service Desk
- E. The Process Manager
Answer: B
Explanation:
The Change Manager authorizes and documents all changes in the IT Infrastructure and its components (CIs) to maintain a least amount of interruptive effects after the running operation.
The succession of the individual stages is planned and communicated to recognize any overlapping as early as possible. In the case of further-reaching changes, he involves the Change Advisory Board (CAB).
Answer option A is incorrect. The Problem Manager takes on research for the core causes of Incidents, and therefore he ensures the durable elimination of interruptions. If possible, he makes short-term solutions (Workarounds) available to Incident Management. The Problem Manager develops ultimate solutions for Known Errors. He also engages in the prevention of interruptions (Pro-active Problem Management), i.e. via a trend-analysis of vital services or historical Incidents.
Answer option B is incorrect. The Process Manager is responsible for planning and coordinating all Process Management activities. He supports all parties involved in managing and improving processes, in particular the Process Owners. This role will also coordinate all Changes to processes, thereby making sure that all processes cooperate in a seamless way. Answer option D is incorrect. The Service Desk is a primary IT capability called for in IT Service Management (ITSM) as defined by the Information Technology Infrastructure Library (ITIL). It is intended to provide a Single Point of Contact ("SPOC") to meet the communication needs of both Users and IT, and to satisfy both Customer and IT Provider objectives. ("User" refers to the actual user of the service, while
"Customer" refers to the entity that is paying for service) Answer option E is incorrect. The Change Advisory Board (CAB) is a group of people that advises the Change Manager in the assessment, prioritization, and scheduling of Changes. This board is usually made up of representatives from all areas within the IT Service Provider, the Business, and Third Parties such as Suppliers.
Reference: ITIL v3 Study Guide, Published with the permission of the Office of Government Commerce (OGC)
NEW QUESTION # 26
You work as a Senior Marketing Manger for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote desktop session. You suspected that some malicious attack was performed on the network of the company. You immediately called the incident response team to handle the situation who enquired the Network Administrator to acquire all relevant information regarding the malfunctioning. The Network Administrator informed the incident response team that he was reviewing the security of the network which caused all these problems. Incident response team announced that this was a controlled event not an incident. Which of the following steps of an incident handling process was performed by the incident response team?
- A. Eradication
- B. Identification
- C. Containment
- D. Preparation
Answer: B
NEW QUESTION # 27
Which of the following BEST describes "attack surface reduction" as a strategic security objective?
- A. It is achieved solely through employee training
- B. Minimizing the number of potential entry points (services, ports, accounts, code) available to an attacker
- C. Increasing the number of exposed services to improve visibility
- D. Attack surface reduction applies only to network firewalls
Answer: B
Explanation:
Reducing unnecessary services, open ports, excess privileges, and unused code/features shrinks the number of ways an attacker could potentially gain access, a core proactive risk reduction strategy.
NEW QUESTION # 28
Which of the following representatives of incident response team takes forensic backups of the systems that are the focus of the incident?
- A. Information security representative
- B. Technical representative
- C. Legalrepresentative
- D. Lead investigator
Answer: B
NEW QUESTION # 29
Which of the following evidences are the collection of facts that, when considered together, can be used to infer a conclusion about the malicious activity/person?
- A. Direct
- B. Circumstantial
- C. Incontrovertible
- D. Corroborating
Answer: B
NEW QUESTION # 30
Management has asked you to perform a risk audit and report back on the results. Bonny, a project team member asks you what a risk audit is. What do you tell Bonny?
- A. A risk audit is a review of all the risk probability and impact for the risks, which are still present in the project but which have not yet occurred.
- B. A risk audit is an audit of all the risks that have occurred in the project and what their true impact on cost and time has been.
- C. A risk audit is a review of the effectiveness of the risk responses in dealing with identified risks and their root causes, as well as the effectiveness of the risk management process.
- D. A risk audit is a review of all the risks that have yet to occur and what their probability of happening are.
Answer: C
Explanation:
Risk audit is a method to test the overall risk management process and the planned risk responses. A risk audit is a review of the effectiveness of the risk responses in dealing with identified risks and their root causes, as well as the effectiveness of the risk management process. Answer option D is incorrect. This defines quantitative analysis of the risk events have occurred. Answer options A and C are incorrect. These define risk analysis, part of project risk management planning.
Reference: PMP Chapter 11. A Guide to the Project Management Body of Knowledge, (PMBOK Guide), Fourth Edition, ISBN.9781933890517, Section 11.6.2.2.
NEW QUESTION # 31
Which of the following administrative policy controls is usually associated with government classifications of materials and the clearances of individuals to access those materials?
- A. Due Care
- B. Acceptable Use
- C. Need to Know
- D. Separation of Duties
Answer: C
Explanation:
It is the concept of need to know, which is generally associated with government classifications of materials and the clearances of individuals to access those materials. It is similar to the least privilege principle.
Answer option C is incorrect. An acceptable or appropriate user policy details the conditions that a user must agree to in order to use an account on an information system. Answer option B is incorrect. Due Care policy identifies the level of confidentiality of information on a computer. It specifies how the information is to be handled. The objective of this policy is to protect confidential records, the unauthorized disclosure of which creates a strong potential for liability.
Answer option A is incorrect. Separation of duties (SoD) is the concept of having more than one person required to complete a task. It is alternatively called segregation of duties or, in the political realm, separation of powers. Segregation of duties helps reduce the potential damage from the actions of one person. IS or end-user department should be organized in a way to achieve adequate separation of duties.
According to ISACA's Segregation of Duties Control matrix, some duties should not be combined into one position. This matrix is not an industry standard, just a general guideline suggesting which positions should be separated and which require compensating controls when combined.
Reference: CISM Review Manual 2010, Contents: "Information security governance"
NEW QUESTION # 32
Which of the following BEST describes the concept of "crisis leadership" as distinct from routine management during a disaster?
- A. Crisis leadership requires rapid decision-making under uncertainty, clear communication, and calm authority, often with incomplete information
- B. Crisis leadership is solely a technical IT function
- C. Crisis leadership should always defer entirely to external consultants
- D. Crisis leadership requires no different skills than day-to-day management
Answer: A
Explanation:
Crisis situations demand different leadership skills than routine operations - the ability to make timely decisions despite ambiguity, communicate confidently, and maintain organizational stability under pressure.
NEW QUESTION # 33
The incident response team has turned the evidence over to the forensic team. Now, it is the time to begin looking for the ways to improve the incident response process for next time. What are the typical areas for improvement?
Each correct answer represents a complete solution. Choose all that apply.
- A. Additional personnel security controls
- B. Information dissemination policy
- C. Electronic monitoring statement
- D. Incident response plan
Answer: A,B,C,D
Explanation:
When the incident response team has turned the evidence over to the forensic team, it starts looking for the ways to improve the incident response process. The typical areas for improvement are as follows.
Incident response plan
Information dissemination policy
Incident reporting policy
Electronic monitoring statement
Audit trail policy
Additional personnel security controls
Reference: CHFI Manuals, Contents. "Incident Response"
NEW QUESTION # 34
Which of the following laws is the first to implement penalties for the creator of viruses, worms, and other types of malicious code that causes harm to the computer systems?
- A. Gramm-Leach-Bliley Act
- B. Computer Security Act
- C. Computer Fraud and Abuse Act
- D. Digital Millennium Copyright Act
Answer: C
NEW QUESTION # 35
Which of the following contract types is described in the statement below? "This contract type provides no incentive for the contractor to control costs and hence is rarely utilized."
- A. Cost Plus Percentage of Cost
- B. Cost Plus Incentive Fee
- C. Cost Plus Fixed Fee
- D. Cost Plus Award Fee
Answer: A
NEW QUESTION # 36
Which of the following protocols is used with a tunneling protocol to provide security?
- A. IPX/SPX
- B. IPSec
- C. FTP
- D. EAP
Answer: B
Explanation:
Internet Protocol Security (IPSec) is used with Layer 2 Tunneling Protocol (L2TP). It is a standard- based protocol that provides the highest level of virtual private network (VPN) security.
IPSec can encrypt virtually everything above the networking layer. It secures both data and password.
NEW QUESTION # 37
Which of the following laws enacted in United States makes it illegal for an Internet Service Provider (ISP) to allow child pornography to exist on Web sites?
- A. USA PATRIOT Act
- B. Child Pornography Prevention Act (CPPA)
- C. Prosecutorial Remedies and Tools Against the Exploitation of Children Today Act (PROTECT Act)
- D. Sexual Predators Act
Answer: D
NEW QUESTION # 38
......
CISSP-ISSMP Exam topics
Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our ISC CISSP-ISSMP exam dumps will include the following topics:
- Risk Management 18%
- Law, Ethics, and Security Compliance Management 14%
- Contingency Management 10%
How to book the CISSP-ISSMP Exam
These are following steps for registering the ISC CISSP-ISSMP exam. Step 1: Visit to Pearson VUE Exam Registration Step 2: Signup/Login to Pearson VUE account Step 3: Search for ISC CISSP-ISSMP Exam Certifications Exam Step 4: Select Date, time and confirm with payment method
Prepare for the Actual CISSP Concentrations CISSP-ISSMP Exam Practice Materials Collection: https://practicetorrent.exam4pdf.com/CISSP-ISSMP-dumps-torrent.html

