Skip to content

CISMP BCS Foundation Certificate in Information Security Management Principles Practice Questions

Prepare for CISMP with more than an answer.

111 questions in the full set12 sample questionsUpdated Mar 12, 2026
Time limit
60 minutes
Questions on the exam
40
Level
Foundation
Valid for
Does not expire
Domains covered on the exam 9
  1. Information Security Principles10%
  2. Information Risk15%
  3. Information Security Frameworks15%
  4. Security Operations15%
  5. The Security Lifecycle and DevSecOps10%
  6. Technical Security15%
  7. Physical and Environmental Security5%
  8. Disaster Recovery and Digital Forensics10%
  9. Emerging and Growing Technologies5%
  1. 1

    A UK-based SME is looking to bid on a government contract and must demonstrate basic cybersecurity hygiene. They are considering the UK government-backed Cyber Essentials scheme. What is the primary difference between the standard 'Cyber Essentials' certification and 'Cyber Essentials Plus'?

    Show answer details

    Correct answer: B

    The standard Cyber Essentials certification is achieved through a verified self-assessment questionnaire. Cyber Essentials Plus requires the same controls but includes a hands-on technical verification (vulnerability assessment) carried out by an independent certification body.

  2. 2

    The UK legislation that specifically criminalises unauthorised access to computer material, and unauthorised acts with intent to impair the operation of a computer, is the _____ Act 1990.

    Show answer details

    Correct answer: B

    The Computer Misuse Act 1990 is the primary piece of UK legislation that deals with cybercrime, specifically making unauthorized access to computer systems (hacking) and intentional impairment of computer operations (like deploying malware) illegal.

  3. 3

    During a threat modelling exercise for a new API, the security team identifies a risk where an attacker could intercept network traffic and alter the payload before it reaches the server. According to the STRIDE threat modelling framework, which specific category does this threat fall under?

    Show answer details

    Correct answer: B

    In the STRIDE framework (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), 'Tampering' involves the malicious modification of data, such as altering a payload in transit or modifying data at rest.

  4. 4

    A customer disputes an online transaction, claiming they never placed the order. The e-commerce company provides cryptographic logs showing the customer's unique digital signature was used to authorise the purchase. Which core principle of information assurance is the company relying on to defend against the customer's claim?

    Show answer details

    Correct answer: D

    Non-repudiation ensures that a party to a transaction cannot later deny having performed the action. By using digital signatures, the e-commerce company can cryptographically prove the customer's involvement, fulfilling the non-repudiation requirement.

  5. 5

    A UK-based healthcare provider (HealthTrust) collects patient data to provide medical services. To improve efficiency, HealthTrust subscribes to a cloud-based Software-as-a-Service (SaaS) platform provided by CloudMed Inc. to store and manage this patient data.

    CloudMed Inc. strictly follows the instructions provided by HealthTrust and does not use the patient data for its own purposes. However, to ensure high availability, CloudMed Inc. subcontracts data hosting to a third-party infrastructure provider, InfraHost.

    Under the UK GDPR and Data Protection Act 2018, how are the roles of HealthTrust and CloudMed Inc. legally defined in this scenario?

    flowchart LR A[Patients] -->|Provide Data| B(HealthTrust) B -->|Determines Purpose| C{Data Controller} B -->|Uploads Data| D(CloudMed Inc.) D -->|Follows Instructions| E{Data Processor} D -->|Subcontracts| F[InfraHost]
    Show answer details

    Correct answer: C

    Under GDPR, the Data Controller (HealthTrust) determines the purposes and means of processing personal data. The Data Processor (CloudMed Inc.) processes personal data only on behalf of the controller and strictly according to their instructions. InfraHost would be considered a sub-processor.

  6. 6

    Risk tolerance refers to the broad, high-level amount of risk an organisation is willing to accept in pursuit of its strategic objectives, whereas risk appetite is the specific, acceptable variance around a specific objective.

    Show answer details

    Correct answer: B

    The statement has the definitions reversed. Risk APPETITE is the broad, high-level amount of risk an organisation is willing to accept. Risk TOLERANCE is the specific, acceptable variance around a particular objective or initiative.

Create an account to continue.