Free BCS CISMP-V9 Exam Actual Questions

The questions for CISMP-V9 were last updated On Jan 18, 2025

Question No. 1

What advantage does the delivery of online security training material have over the distribution of printed media?

Show Answer Hide Answer
Correct Answer: A
Question No. 2

What Is the KEY purpose of appending security classification labels to information?

Show Answer Hide Answer
Correct Answer: A

The primary purpose of appending security classification labels to information is to guide the implementation of appropriate security controls. These labels indicate the level of sensitivity of the information and determine the extent and nature of the controls that need to be applied to protect it. For example, information classified as 'Confidential' will require stricter access controls compared to information classified as 'Public'. The classification labels help in ensuring that information is handled and protected in accordance with its importance to the organization, and in compliance with relevant legal and regulatory requirements.


Question No. 3

What Is the root cause as to why SMS messages are open to attackers and abuse?

Show Answer Hide Answer
Question No. 5

Which of the following compliance legal requirements are covered by the ISO/IEC 27000 series?

1. Intellectual Property Rights.

2. Protection of Organisational Records

3. Forensic recovery of data.

4. Data Deduplication.

5. Data Protection & Privacy.

Show Answer Hide Answer
Correct Answer: D

The ISO/IEC 27000 series, particularly ISO/IEC 27001, provides a framework for information security management systems (ISMS) that helps organizations secure their information assets. This series covers various aspects of information security, including the protection of organizational records and data protection & privacy, which are legal compliance requirements in many jurisdictions. Intellectual Property Rights (IPR) are also considered within the scope of information security as they pertain to the protection of proprietary information and assets. Forensic recovery of data and data deduplication are technical and operational considerations but are not directly addressed as compliance legal requirements within the ISO/IEC 27000 series.