ISMP Sample Questions

ISMP Sample Questions & Answers

Free Ismp practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full ISMP simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Risk management · Control risks

    A security architect is selecting controls for a critical customer database. To address the "Detection" stage of the incident response cycle, which control would be most appropriate?

    Show answer & explanation

    Correct answer: C

    The incident response cycle includes stages like Prevention, Detection, Response, and Recovery. Firewalls and encryption are primarily preventive controls. A disaster recovery plan is a recovery/responsive control. A Database Activity Monitoring (DAM) tool is a classic detective control, as its main purpose is to monitor for and alert on suspicious activities that could indicate an ongoing incident, fitting squarely into the Detection stage.

  2. Question 2Beginner

    Risk management · Deal with residual risks

    True or False: After implementing a set of security controls, the goal of risk management is to completely eliminate all residual risk.

    Show answer & explanation

    Correct answer: B

    It is practically impossible and financially prohibitive to eliminate all risk. The goal of risk management is to reduce risk to an acceptable level, known as the organization's risk appetite. Residual risk is the risk that remains after controls have been implemented, and some level of residual risk must always be formally accepted by management.

  3. Question 3Intermediate

    Information security controls · Organizational controls

    An organization is mapping its incident handling process to align with industry best practices. A security analyst has proposed the following high-level workflow. At which stage should the "Lessons Learned" activity be formally conducted?

    [ A ] [ B ] [ C ] [ D ]
    Event --> Triage & --> Containment & --> Post-Incident
    Detected Analysis Eradication Activity
    
    Show answer & explanation

    Correct answer: D

    The "Lessons Learned" or post-mortem review is a critical part of the Post-Incident Activity stage. This activity is conducted after the incident has been fully contained, eradicated, and normal operations have been restored. Its purpose is to analyze the incident and the response effort to identify weaknesses and make improvements to prevent future occurrences and enhance future responses. Conducting it earlier would be premature.

  4. Question 4Intermediate

    Information security controls · Technological controls

    A fast-growing tech startup is transitioning its monolithic application to a microservices architecture hosted in a public cloud. A security architect advises implementing a "Zero Trust" security model. What is the primary purpose of adopting this architecture?

    Show answer & explanation

    Correct answer: C

    The core principle of a Zero Trust architecture is "never trust, always verify." It assumes that threats exist both inside and outside the traditional network perimeter. Therefore, it requires that every request to access a resource is authenticated and authorized based on identity and context, regardless of whether it originates from a supposedly 'trusted' internal network or an external one.

  5. Question 5Beginner

    Information security controls · Physical controls and people controls

    A company is designing the physical security for its new data center. Which of the following controls is a detective physical security control?

    Show answer & explanation

    Correct answer: C

    Physical controls can be categorized as preventive, detective, or corrective. A mantrap, biometric scanner, and reinforced door are all preventive controls designed to stop unauthorized access. A motion-activated security camera is a detective control; it does not prevent entry but records the event and can trigger an alert, allowing security personnel to detect and respond to an intrusion.

  6. Question 6Advanced

    Information security controls · Organizational controls

    "Global Logistics Inc." is a shipping company that relies heavily on its custom-built "ShipTrack" logistics management system. This system handles all scheduling, tracking, and billing operations. A recent risk assessment identified a high risk of a prolonged system outage due to a natural disaster impacting their primary data center, located in a hurricane-prone region. The business impact analysis (BIA) concluded that the company could only tolerate a maximum of 4 hours of downtime for ShipTrack (RTO) and could afford to lose no more than 15 minutes of transaction data (RPO).

    The company's current disaster recovery plan involves restoring data from nightly backups to a cold site, a process that takes over 48 hours. The CIO has been tasked with proposing a new solution that meets the BIA requirements while being cost-conscious. The IT team has presented two potential solutions.

    Solution 1 involves establishing a hot site in a different geographic region with real-time, synchronous data replication. This provides near-zero RPO and an RTO of under 1 hour but has a very high annual operating cost.

    Solution 2 involves using a cloud-based disaster recovery service (DRaaS) with asynchronous replication. This solution provides an RPO of approximately 15 minutes and a tested RTO of 3-4 hours. The cost is significantly lower than the hot site.

    Given the stated requirements and constraints, which action should the CIO recommend to the board?

    Show answer & explanation

    Correct answer: B

    The core principle of business continuity planning is to align disaster recovery solutions with the specific requirements defined in the Business Impact Analysis (BIA). The BIA states an RTO of 4 hours and an RPO of 15 minutes. Solution 2 (DRaaS) meets these requirements (RTO 3-4 hours, RPO ~15 minutes) and is noted as being more cost-effective. While Solution 1 (hot site) exceeds the requirements, its very high cost is not justified when a cheaper option that still meets the defined business needs is available.

  7. Question 7AdvancedSelect 3

    Information security controls · Technological controls

    A security architect has designed a network with a Demilitarized Zone (DMZ) to protect the internal network. The following diagram shows the proposed firewall rules.

    ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐
    │ Internet │ │ Firewall │ │ DMZ Zone │ │ Internal │
    │ (Any IP) │ │ │ │ Web Srv │ │ LAN │
    └──────────┘ └──────────┘ └──────────┘ └──────────┘
    | | | |
    | | | |
    | | | |
    | | | |
    | | |
    | |<----Rule 5------|<-----------------|
    

    To adhere to security best practices for a DMZ architecture, which THREE rules should be implemented? (Select THREE)

    Show answer & explanation

    Correct answers: B, C, F

    This is a standard best practice. The purpose of the DMZ is to expose only necessary services (like a web server) to the internet on their specific ports.

    It is a common and acceptable practice for a web server in the DMZ to initiate connections to a database server on the more secure internal network. The rule should be specific to the required port (e.g., 1433 for MSSQL).

    Administrators on the internal network need to manage the servers in the DMZ. Allowing specific, secured management traffic (like SSH or RDP) initiated from the trusted internal zone is a necessary operational rule.

  8. Question 8Beginner

    Information security controls · Organizational controls

    A manufacturing company is implementing an ISMS based on ISO/IEC 27001. During an employee onboarding session, a new hire asks about the difference between a 'policy' and a 'standard'. How should the security manager respond?

    Show answer & explanation

    Correct answer: B

    In a typical ISMS documentation hierarchy, a policy is a high-level statement of intent and direction from management (the 'what'). A standard provides the mandatory, specific requirements for how to comply with the policy. For example, a policy might state 'All data must be encrypted', and a standard would specify 'AES-256 must be used for all data-at-rest encryption'. Procedures then detail the step-by-step instructions, and guidelines offer recommendations.

  9. Question 9Intermediate

    Risk management · Deal with residual risks

    A university has decided to accept the risk of data loss from student-owned, unmanaged laptops accessing campus Wi-Fi. What is the most important action the university's risk committee must perform after making this decision?

    Show answer & explanation

    Correct answer: B

    Risk acceptance is a formal risk treatment strategy. For due diligence and governance, it is critical that any decision to accept a known risk is formally documented. This documentation should include a description of the risk, the reasons for accepting it (e.g., cost of mitigation is too high), and clear identification of the management level or authority that approved the decision. This creates an audit trail and ensures accountability.

  10. Question 10Intermediate

    Risk management · Principles of analyzing risks

    During a security audit, an organization is found to be using an outdated version of the TLS protocol (TLS 1.1) on its public-facing web servers. An attacker could potentially exploit this to downgrade the encryption and intercept sensitive data. In the context of risk assessment, how would this situation be best described?

    Show answer & explanation

    Correct answer: B

    This option correctly defines the terms. A vulnerability is a weakness in a system or control (outdated TLS 1.1). A threat is an agent or action that could exploit the vulnerability (the attacker). Risk is the combination of the likelihood of the threat exploiting the vulnerability and the resulting impact (interception of sensitive data).

Ready for the real thing?

The full ISMP simulator has every exam-style question, timed mode, and instant scoring.

Go to the ISMP simulator →