최신EXIN Information Security Management Professional based on ISO/IEC 27001 - ISMP무료샘플문제
문제1
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?
The handling of security incidents is done by the incident management process under guidelines of information security management. These guidelines call for several types of mitigation plans.
Which mitigation plan covers short-term recovery after a security incident has occurred?
정답: D
문제2
What is a risk treatment strategy?
What is a risk treatment strategy?
정답: A
문제3
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do- Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
정답: D
문제4
Who should be asked to check compliance with the information security policy throughout the company?
Who should be asked to check compliance with the information security policy throughout the company?
정답: A