BCS Foundation Certificate in Information Security Management Principles V9.0 CISMP-V9 Exam Questions
Preparing for the CISMP-V9 exam is simple with Certs Vault. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.
At Certs Vault, we keep our CISMP-V9 practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.
Which three of the following characteristics form the AAA Triad in Information Security?
1. Authentication
2. Availability
3. Accounting
4. Asymmetry
5. Authorisation
Correct Answer: D
The AAA Triad in Information Security stands for Authentication, Authorization (also known as
Authorisation), and Accounting. These three components are fundamental to ensuring that access to
systems is controlled and monitored:
Authentication is the process of verifying the identity of a user or entity. It ensures that individuals
are who they claim to be. This can involve methods such as passwords, biometrics, or tokens.
Authorization determines what an authenticated user is allowed to do. It involves granting or
denying rights to access resources and perform actions within a system based on the user’s identity.
Accounting keeps track of user activities. This includes logging when users log in and out, what
actions they perform, and what resources they access. It’s essential for auditing purposes and can
also be used for billing or analyzing resource usage.
These principles are designed to protect information by managing potential risks and controlling
access to data. They are part of a broader framework that includes physical, technical, and
procedural controls to safeguard information assets.
Which of the following is NOT an accepted classification of security controls?
Correct Answer: A
Security controls are measures taken to safeguard an information system from attacks or to mitigate
the impact of a breach. They are commonly classified into three main categories: preventive,
detective, and corrective. Preventive controls aim to prevent incidents before they occur, detective
controls are designed to discover and detect security events, and corrective controls are intended to
restore systems to normal operation after an incident. The term “nominative” is not recognized as a
standard classification of security controls within the principles of information security
management.
According to ISO/IEC 27000, which of the following is the definition of a vulnerability?
Correct Answer: A
The term ‘vulnerability’ within the context of ISO/IEC 27000 refers to any weakness present in an
asset or group of assets that could potentially be exploited by one or more threats. This definition
aligns with the concept of vulnerability as a gap in protection efforts that, if not addressed, could
allow a threat to compromise the confidentiality, integrity, or availability of an asset. It is important
to note that vulnerabilities can be identified in various components of an organization’s
infrastructure, including hardware, software, processes, and even personnel. Effective information
security management involves identifying these vulnerabilities through risk assessments and
implementing appropriate controls to mitigate the risk of exploitation.
Which term describes the acknowledgement and acceptance of ownership of actions, decisions,
policies and deliverables?
Correct Answer: A
Accountability is the term that describes the acknowledgement and acceptance of ownership of
actions, decisions, policies, and deliverables. It implies that an individual or organization is willing to
take responsibility for their actions and the outcomes of those actions, and is answerable to the
relevant stakeholders. This concept is fundamental in information security management, as it
ensures that individuals and teams are aware of their roles and the expectations placed upon them,
particularly in relation to the protection of information assets. Accountability cannot be delegated;
while tasks can be assigned to others, the ultimate ownership and obligation to report and justify the
outcomes remain with the accountable party.
Reference: = The BCS Foundation Certificate in Information Security Management Principles outlines
the importance of accountability within the context of information security management.
Which security concept provides redundancy in the event a security control failure or the
exploitation of a vulnerability?
Correct Answer: D
Defence in depth is a security concept that involves implementing multiple layers of security controls
throughout an information system. The idea is that if one control fails or a vulnerability is exploited,
other controls will provide redundancy and continue to protect the system. This approach is
analogous to a physical fortress with multiple walls; if an attacker breaches one wall, additional
barriers exist to stop them from progressing further. In the context of information security, this could
include a combination of firewalls, intrusion detection systems, antivirus software, and strict access
controls, among others. Defence in depth is designed to address security vulnerabilities not only in
technology but also in processes and people, acknowledging that human error or negligence can
often lead to security breaches.
Reference: The concept of defence in depth aligns with the Information Security Management
Principles as outlined by BCS, particularly under the domains of Technical Security Controls and
Disaster Recovery and Business Continuity Management.