ISMP Practice Questions
Prepare for ISMP with more than an answer.
- 1
A university has decided to accept the risk of data loss from student-owned, unmanaged laptops accessing campus Wi-Fi. What is the most important action the university's risk committee must perform after making this decision?
Show answer details
Correct answer: B
Risk acceptance is a formal risk treatment strategy. For due diligence and governance, it is critical that any decision to accept a known risk is formally documented. This documentation should include a description of the risk, the reasons for accepting it (e.g., cost of mitigation is too high), and clear identification of the management level or authority that approved the decision. This creates an audit trail and ensures accountability.
- 2
During a security audit, an organization is found to be using an outdated version of the TLS protocol (TLS 1.1) on its public-facing web servers. An attacker could potentially exploit this to downgrade the encryption and intercept sensitive data. In the context of risk assessment, how would this situation be best described?
Show answer details
Correct answer: B
This option correctly defines the terms. A vulnerability is a weakness in a system or control (outdated TLS 1.1). A threat is an agent or action that could exploit the vulnerability (the attacker). Risk is the combination of the likelihood of the threat exploiting the vulnerability and the resulting impact (interception of sensitive data).
- 3
A project manager for a new software development project wants to incorporate security into the lifecycle but is concerned about budget overruns. The Information Security Manager (ISM) recommends adopting a Secure Software Development Lifecycle (SSDLC). What is the primary benefit the ISM should emphasize to the project manager?
Show answer details
Correct answer: B
The cost to fix a security vulnerability increases exponentially the later it is found in the development lifecycle. Finding and fixing a flaw during the design or coding phase is far cheaper than fixing it after the product has been deployed to production. This reduction in remediation cost is the most compelling financial argument for adopting an SSDLC.
- 4
A retail company's security policy requires all terminated employees to have their system access revoked within one hour of notification from HR. This is an example of what type of control?
Show answer details
Correct answer: C
This control is designed to prevent a potential security incident (unauthorized access by a former employee) before it can happen. By revoking access promptly upon termination, the organization is proactively stopping a known threat. Therefore, it is a preventive control.
- 5
True or False: In a well-structured ISMS, the 'Statement of Applicability' (SoA) primarily serves as a public declaration of the organization's commitment to information security.
Show answer details
Correct answer: B
The Statement of Applicability (SoA) is a core document in an ISO/IEC 27001 ISMS, but it is primarily an internal governance and audit tool, not a public declaration. Its purpose is to list all the controls from Annex A, state whether each is applicable to the organization, justify any exclusions, and reference how the applicable controls are implemented. It links the risk assessment to the control implementation.
- 6
A marketing firm outsources its IT help desk to a Managed Service Provider (MSP). The contract requires the MSP to handle all security incidents related to end-user devices. When an employee's laptop is infected with ransomware, who holds the ultimate accountability for ensuring the incident is managed in compliance with the firm's policies and legal obligations?
Show answer details
Correct answer: B
A fundamental principle of governance and risk management is that an organization can outsource responsibility for a task, but it cannot outsource accountability. The marketing firm is ultimately accountable to its clients, regulators, and stakeholders for the security of its data and systems. While the MSP is responsible for performing the incident response tasks, the marketing firm's management is accountable for ensuring those tasks are done correctly and meet all compliance obligations.
- 7
A pharmaceutical company is conducting a business impact analysis (BIA) for its research and development (R&D) data. The analysis determined that the Maximum Tolerable Downtime (MTD) for the primary R&D database is 24 hours. How should this MTD value be used?
Show answer details
Correct answer: C
The Maximum Tolerable Downtime (MTD) is the absolute longest period a business function can be unavailable before causing irreparable harm to the organization. This business requirement is used to derive the technical requirement, the Recovery Time Objective (RTO). The RTO is the targeted time within which a business process must be restored after a disaster to avoid unacceptable consequences. Therefore, the RTO must always be less than or equal to the MTD.
- 8
A financial services firm is classifying its information assets. The CISO needs to explain to the board why the customer transaction database has a higher business value than the internal marketing materials. Which characteristic most directly determines the high business value of the customer transaction database compared to internal marketing collateral?
Show answer details
Correct answer: B
The business value of information is heavily influenced by the consequences of its compromise. For a financial firm, the compromise of a customer transaction database can lead to severe regulatory fines (e.g., under GDPR), significant reputational damage, and loss of customer trust. This direct financial and reputational impact makes its confidentiality and integrity critical and gives it a higher business value than internal materials.
- 9
When a healthcare provider outsources its patient portal to a cloud vendor, what is the most critical aspect of information governance from the customer's (the healthcare provider's) perspective to ensure regulatory compliance?
Show answer details
Correct answer: B
From a governance standpoint, the healthcare provider (data controller) remains ultimately responsible for protecting patient data under regulations like HIPAA. A critical governance requirement is to ensure the vendor (data processor) has robust, compliant processes for handling security incidents, especially data breaches. The vendor's breach notification process directly impacts the provider's legal and regulatory obligations to patients and authorities.
- 10
An e-commerce company integrates a third-party payment gateway into its platform. To gain security assurance, which TWO of the following artifacts are most crucial for the supplier to provide and maintain? (Select TWO)
Show answer details
Correct answer: B, E
A PCI DSS AoC is mandatory proof that a service provider securely handles cardholder data. This is a primary document for security assurance in any payment processing context.
A SOC 2 Type II report provides detailed, independent assurance over a period of time about the effectiveness of a vendor's security controls. It is a standard and crucial document for third-party risk management.
