CISM Actual Questions Answers PDF 100% Cover Real Exam Questions [Q199-Q215]

Share

CISM Actual Questions Answers PDF 100% Cover Real Exam Questions

CISM Exam questions and answers


ISACA CISM (Certified Information Security Manager) exam is a certification exam that is designed to test the knowledge and skills of individuals who are responsible for developing, managing, and overseeing information security programs within an organization. CISM exam is intended for individuals who have several years of experience in the field of information security and who are looking to advance their career in this area.

 

NEW QUESTION # 199
The MOST likely reason to use qualitative security risk assessments instead of quantitative methods is when:

  • A. a security program requires independent expression of risks.
  • B. an organization provides services instead of hard goods.
  • C. a mature security program is in place.
  • D. available data is too subjective.

Answer: D


NEW QUESTION # 200
A security incident has been reported within an organization When should an information security manager contact the information owner?

  • A. After the incident has been mitigated
  • B. After the incident has been confirmed.
  • C. After the potential incident has been togged
  • D. After the incident has been contained

Answer: B

Explanation:
Explanation
= An information security manager should contact the information owner after the incident has been confirmed, as this is the point when the impact and severity of the incident can be assessed and communicated.
The information owner is responsible for the business value and use of the information and should be involved in the decision making process regarding the incident response. Contacting the information owner after the incident has been mitigated or contained may be too late, as the information owner may have different priorities or expectations than the security team. Contacting the information owner after the potential incident has been logged may be premature, as the incident may turn out to be a false positive or a minor issue that does not require the information owner's attention. References = 1: CISM Review Manual, 16th Edition by Isaca (Author), page 292.


NEW QUESTION # 201
What is the MAIN drawback of e-mailing password-protected zip files across the Internet? They:

  • A. all use weak encryption.
  • B. may be quarantined by mail filters.
  • C. may be corrupted by the receiving mail server.
  • D. are decrypted by the firewall.

Answer: B

Explanation:
Explanation
Often, mail filters will quarantine zip files that are password-protected since the filter (or the firewall) is unable to determine if the file contains malicious code. Many zip file products are capable of using strong encryption. Such files are not normally corrupted by the sending mail server.


NEW QUESTION # 202
An intrusion has been detected and contained. Which of the following steps represents the BEST practice for ensuring the system?

  • A. Restore the OS, patches, and application from a backup.
  • B. Remove all signs of the intrusion from the OS and application.
  • C. Install the OS, patches, and application from the original source.
  • D. Restore the application and data from a forensic copy.

Answer: C


NEW QUESTION # 203
Which of the following is the MOST likely outcome of a well-designed information security awareness course?

  • A. Decrease in the number of password resets
  • B. Increased reporting of security incidents to the incident response function
  • C. Increase in the number of identified system vulnerabilities
  • D. Decreased reporting of security incidents to the incident response function

Answer: B

Explanation:
Explanation
A well-organized information security awareness course informs all employees of existing security policies, the importance of following safe practices for data security anil the need to report any possible security incidents to the appropriate individuals in the organization. The other choices would not be the likely outcomes.


NEW QUESTION # 204
When considering the value of assets, which of the following would give the information security manager the MOST objective basis for measurement of value delivery in information security governance?

  • A. Test results of controls
  • B. Number of controls
  • C. Cost of achieving control objectives
  • D. Effectiveness of controls

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Comparison of cost of achievement of control objectives and corresponding value of assets sought to be protected would provide a sound basis for the information security manager to measure value delivery. Number of controls has no correlation with the value of assets unless the effectiveness of the controls and their cost are also evaluated. Effectiveness of controls has no correlation with the value of assets unless their costs are also evaluated. Test results of controls have no correlation with the value of assets unless the effectiveness of the controls and their cost are also evaluated.


NEW QUESTION # 205
After logging in to a web application, further password credentials are required at various application points.
Which of the following is the PRIMARY reason for such an approach?

  • A. To implement single sign-on
  • B. To ensure access is granted to the authorized person
  • C. To enforce strong two-factor authentication
  • D. To ensure session management variables are secure

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 206
Which of the following would BEST guide the development and maintenance of an information security program?

  • A. A comprehensive risk register
  • B. A business impact assessment
  • C. An established risk assessment process
  • D. The organization's risk appetite

Answer: D

Explanation:
Explanation
According to the CISM Manual, the organization's risk appetite is the amount and type of risk that the organization is willing to accept in order to achieve its objectives1. The organization's risk appetite should guide the development and maintenance of an information security program, as it determines the level of security controls, resources, and activities that are needed to protect the organization's assets and operations1.
The CISM Manual states that "the information security program should be aligned with the organization's risk appetite, which reflects its tolerance for risk and its strategic objectives" (IR 8288A)1. The information security program should also consider other factors that influence the organization's risk appetite, such as its mission, vision, values, culture, stakeholders, regulations, standards, guidelines, and best practices1.
The CISM Manual also provides guidance on how to develop and maintain an information security program based on the organization's risk appetite. It recommends using a process that involves identifying, analyzing, evaluating, treating, monitoring, and reviewing risks that affect the organization's information assets1. It also suggests using a framework or model that supports the development of an information security program based on the organization's risk appetite (e.g., ISO/IEC 27001)1.
References: 1: IR 8288A - Information Security Program Development | CSRC NIST


NEW QUESTION # 207
The MOST important factors in determining the scope and timing for testing a business continuity plan are:

  • A. the experience level of personnel and the function location.
  • B. prior testing results and the degree of detail of the business continuity plan
  • C. the importance of the function to be tested and the cost of testing,
  • D. manual processing capabilities and the test location

Answer: C


NEW QUESTION # 208
Which of the following provides the BEST evidence that the information security program is aligned to the business strategy?

  • A. Business senior management supports the information security policies.
  • B. The information security team is able to provide key performance indicators (KPIs) to senior management.
  • C. Information security initiatives are directly correlated to business processes.
  • D. The information security program manages risk within the business1* risk tolerance.

Answer: A


NEW QUESTION # 209
An organization is the victim of a targeted attack, and is unaware of the compromise until a security analyst notices an additional user account on the firewall. The implementation of which of the following would have detected the incident?

  • A. Data leakage prevention (OLP)
  • B. Network access control (NAC)
  • C. Security information event management (SIEM)
  • D. Web-application firewall (WAF)

Answer: A


NEW QUESTION # 210
Which of the following security characteristics is MOST important to the protection of customer data in an online transaction system?

  • A. Authentication
  • B. Availability
  • C. Data segregation
  • D. Audit monitoring

Answer: A

Explanation:
Section: MIXED QUESTIONS


NEW QUESTION # 211
Which of the following BEST enables the assignment of risk and control ownership?

  • A. Obtaining senior management buy-in
  • B. Aligning to an industry-recognized control framework
  • C. Adopting a risk management framework
  • D. Developing an information security strategy

Answer: A

Explanation:
Explanation
Obtaining senior management buy-in is the best way to enable the assignment of risk and control ownership because it helps to establish the authority and accountability of the risk and control owners, as well as to provide them with the necessary resources and support to perform their roles. Risk and control ownership refers to the assignment of specific responsibilities and accountabilities for managing risks and controls to individuals or groups within the organization. Obtaining senior management buy-in helps to ensure that risk and control ownership is aligned with the organizational objectives, structure, and culture, as well as to communicate the expectations and benefits of risk and control ownership to all stakeholders. Therefore, obtaining senior management buy-in is the correct answer.
References:
* https://www.protechtgroup.com/en-au/blog/risk-control-management
* https://www.mckinsey.com/~/media/mckinsey/dotcom/client_service/risk/working%20papers/23_getting_
* https://www.linkedin.com/pulse/risk-controls-who-owns-them-david-tattam


NEW QUESTION # 212
Risk acceptance is a component of which of the following?

  • A. Assessment
  • B. Evaluation
  • C. Mitigation
  • D. Monitoring

Answer: C

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Risk acceptance is one of the alternatives to be considered in the risk mitigation process. Assessment and evaluation are components of the risk analysis process. Risk acceptance is not a component of monitoring.


NEW QUESTION # 213
When an organization is implementing an information security governance program, its board of directors should be responsible for:

  • A. drafting information security policies.
  • B. reviewing training and awareness programs.
  • C. setting the strategic direction of the program.
  • D. auditing for compliance.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A board of directors should establish the strategic direction of the program to ensure that it is in sync with the company's vision and business goals. The board must incorporate the governance program into the overall corporate business strategy. Drafting information security policies is best fulfilled by someone such as a security manager with the expertise to bring balance, scope and focus to the policies. Reviewing training and awareness programs may best be handled by security management and training staff to ensure that the training is on point and follows best practices. Auditing for compliance is best left to the internal and external auditors to provide an objective review of the program and how it meets regulatory and statutory compliance.


NEW QUESTION # 214
An organization's board of directors has learned of recent legislation requiring organizations within the industry to enact specific safeguards to protect confidential customer information. What actions should the board take next?

  • A. Direct information security on what they need to do
  • B. Require management to report on compliance
  • C. Research solutions to determine the proper solutions
  • D. Nothing; information security does not report to the board

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Information security governance is the responsibility of the board of directors and executive management.
In this instance, the appropriate action is to ensure that a plan is in place for implementation of needed safeguards and to require updates on that implementation.


NEW QUESTION # 215
......

GetValidTest CISM Exam Practice Test Questions: https://troytec.getvalidtest.com/CISM-brain-dumps.html