Get CISM Braindumps & CISM Real Exam Questions [Q323-Q343]

Share

Get CISM Braindumps & CISM Real Exam Questions

ISACA CISM Actual Questions and Braindumps

NEW QUESTION # 323
Which of the following BEST demonstrates that the objectives of an information security governance framework are being met?

  • A. Balanced scorecard
  • B. Risk dashboard
  • C. Penetration test results
  • D. Key performance indicators (KPIs)

Answer: D


NEW QUESTION # 324
Which of the following would a security manager establish to determine the target for restoration of normal processing?

  • A. Recover)' time objective (RTO)
  • B. Services delivery objectives (SDOs)
  • C. Recovery point objectives (RPOs)
  • D. Maximum tolerable outage (MTO)

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Recovery time objective (RTO) is the length of time from the moment of an interruption until the time the process must be functioning at a service level sufficient to limit financial and operational impacts to an acceptable level. Maximum tolerable outage (MTO) is the maximum time for which an organization can operate in a reduced mode. Recovery point objectives (RPOs) relate to the age of the data required for recovery. Services delivery objectives (SDOs) are the levels of service required in reduced mode.


NEW QUESTION # 325
An organization has verified that its customer information was recently exposed. Which of the following is the FIRST step a security manager should take in this situation?

  • A. Report the incident to the authorities.
  • B. Inform senior management.
  • C. Determine the extent of the compromise.
  • D. Communicate with the affected customers.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Before reporting to senior management, affected customers or the authorities, the extent of the exposure needs to be assessed.


NEW QUESTION # 326
An intrusion detection system (IDS) should:

  • A. run continuously
  • B. be located on the network
  • C. require a stable, rarely changed environment
  • D. ignore anomalies

Answer: A

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
If an intrusion detection system (IDS) does not run continuously the business remains vulnerable. An IDS should detect, not ignore anomalies. An IDS should be flexible enough to cope with a changing environment. Both host and network based IDS are recommended for adequate detection.


NEW QUESTION # 327
A project manager is developing a developer portal and requests that the security manager assign a public IP address so that it can be accessed by in-house staff and by external consultants outside the organization's local area network (LAN). What should the security manager do FIRST?

  • A. Understand the business requirements of the developer portal
  • B. Obtain a signed nondisclosure agreement (NDA) from the external consultants before allowing external access to the server
  • C. Install an intrusion detection system (IDS)
  • D. Perform a vulnerability assessment of the developer portal

Answer: A

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
The information security manager cannot make an informed decision about the request without first understanding the business requirements of the developer portal. Performing a vulnerability assessment of developer portal and installing an intrusion detection system (IDS) are best practices but are subsequent to understanding the requirements. Obtaining a signed nondisclosure agreement will not take care of the risks inherent in the organization's application.


NEW QUESTION # 328
To mitigate a situation where one of the programmers of an application requires access to production data, the information security manager could BEST recommend to.

  • A. have the programmer sign a letter accepting full responsibility.
  • B. perform regular audits of the application.
  • C. create a separate account for the programmer as a power user.
  • D. log all of the programmers' activity for review by supervisor.

Answer: D

Explanation:
Explanation
It is not always possible to provide adequate segregation of duties between programming and operations in order to meet certain business requirements. A mitigating control is to record all of the programmers' actions for later review by their supervisor, which would reduce the likelihood of any inappropriate action on the part of the programmer. Choices A, C and D do not solve the problem.


NEW QUESTION # 329
What is the MOST important factor in the successful implementation of an enterprise wide information security program?

  • A. Support of senior management
  • B. Realistic budget estimates
  • C. Recalculation of the work factor
  • D. Security awareness

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Without the support of senior management, an information security program has little chance of survival. A company's leadership group, more than any other group, will more successfully drive the program. Their authoritative position in the company is a key factor. Budget approval, resource commitments, and companywide participation also require the buy-in from senior management. Senior management is responsible for providing an adequate budget and the necessary resources. Security awareness is important, but not the most important factor. Recalculation of the work factor is a part of risk management.


NEW QUESTION # 330
What is the BEST course of action when an information security manager finds an external service provider has not implemented adequate controls for safeguarding the organization's critical data?

  • A. Initiate contract renegotiations.
  • B. Assess the impact of the control gap.
  • C. Purchase additional insurance.
  • D. Conduct a controls audit of the provider.

Answer: B


NEW QUESTION # 331
Which of the following is the MOST important item to include when developing web hosting agreements with third-party providers?

  • A. Privacy restrictions
  • B. Termination conditions
  • C. Service levels
  • D. Liability limits

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Service levels are key to holding third parties accountable for adequate delivery of services. This is more important than termination conditions, privacy restrictions or liability limitations.


NEW QUESTION # 332
The PRIMARY concern of an information security manager documenting a formal data retention policy would be:

  • A. business requirements.
  • B. storage availability.
  • C. legislative and regulatory requirements.
  • D. generally accepted industry best practices.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The primary concern will be to comply with legislation and regulation but only if this is a genuine business requirement. Best practices may be a useful guide but not a primary concern. Legislative and regulatory requirements are only relevant if compliance is a business need. Storage is irrelevant since whatever is needed must be provided


NEW QUESTION # 333
Which of the following is the MOST important factor to consider when establishing a severity hierarchy for information security incidents?

  • A. Residual risk
  • B. Management support
  • C. Regulatory compliance
  • D. Business impact

Answer: D


NEW QUESTION # 334
Which of the following BEST contributes to the development of a security governance framework that supports the maturity model concept?

  • A. Continuous risk reduction
  • B. Continuous analysis, monitoring and feedback
  • C. Key risk indicator (KRD setup to security management processes
  • D. Continuous monitoring of the return on security investment (ROSD

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
To improve the governance framework and achieve a higher level of maturity, an organization needs to conduct continuous analysis, monitoring and feedback compared to the current state of maturity. Return on security investment (ROSD may show the performance result of the security-related activities; however, the result is interpreted in terms of money and extends to multiple facets of security initiatives. Thus, it may not be an adequate option. Continuous risk reduction would demonstrate the effectiveness of the security governance framework, but does not indicate a higher level of maturity. Key risk indicator (KRD setup is a tool to be used in internal control assessment. KRI setup presents a threshold to alert management when controls are being compromised in business processes. This is a control tool rather than a maturity model support tool.


NEW QUESTION # 335
An information security manager has been tasked with developing materials to update the board, regulatory agencies, and the media about a security incident. Which of the following should the information security manager do FIRST?

  • A. Set up communication channels for the target audience.
  • B. Determine the needs and requirements of each audience.
  • C. Create a comprehensive singular communication.
  • D. Invoke the organization's incident response plan.

Answer: A


NEW QUESTION # 336
When developing an incident escalation process, the BEST approach is to classify incidents based on:

  • A. estimated time to recover.
  • B. information assets affected.
  • C. their root causes.
  • D. recovery point objectives (RPOs).

Answer: D


NEW QUESTION # 337
Which of the following devices should be placed within a DMZ?

  • A. Data warehouse server
  • B. Application server
  • C. Proxy server
  • D. Departmental server

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:
Explanation:
An application server should normally be placed within a demilitarized zone (DMZ) to shield the internal network. Data warehouse and departmental servers may contain confidential or valuable data and should always be placed on the internal network, never on a DMZ that is subject to compromise. A proxy server forms the inner boundary of the DMZ but is not placed within it.


NEW QUESTION # 338
Which of the following is the PRIMARY objective of reporting security metrics to stakeholders?

  • A. To identify key controls within the organization
  • B. To provide support for security audit activities
  • C. To demonstrate alignment to the business strategy
  • D. To communicate the effectiveness of the security program

Answer: D


NEW QUESTION # 339
Which of the following devices should be placed within a demilitarized zone (DMZ )?

  • A. File/print server
  • B. Network switch
  • C. Database server
  • D. Web server

Answer: D

Explanation:
Explanation/Reference:
Explanation:
A web server should normally be placed within a demilitarized zone (DMZ) to shield the internal network.
Database and file/print servers may contain confidential or valuable data and should always be placed on the internal network, never on a DMZ that is subject to compromise. Switches may bridge a DMZ to another network but do not technically reside within the DMZ network segment.


NEW QUESTION # 340
Nonrepudiation can BEST be ensured by using:

  • A. symmetric encryption.
  • B. a digital hash.
  • C. digital signatures.
  • D. strong passwords.

Answer: C

Explanation:
Digital signatures use a private and public key pair, authenticating both parties. The integrity of the contents exchanged is controlled through the hashing mechanism that is signed by the private key of the exchanging party. A digital hash in itself helps in ensuring integrity of the contents, but not nonrepudiation. Symmetric encryption wouldn't help in nonrepudiation since the keys are always shared between parties. Strong passwords only ensure authentication to the system and cannot be used for nonrepudiation involving two or more parties.
Topic 4, INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 341
Identification and prioritization of business risk enables project managers to:

  • A. reduce the overall amount of slack time.
  • B. establish implementation milestones.
  • C. accelerate completion of critical paths.
  • D. address areas with most significance.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Identification and prioritization of risk allows project managers to focus more attention on areas of greater importance and impact. It will not reduce the overall amount of slack time, facilitate establishing implementation milestones or allow a critical path to be completed any sooner.


NEW QUESTION # 342
To improve the efficiency of the development of a new software application, security requirements should be defined:

  • A. concurrently with other requirements.
  • B. based on available security assessment tools.
  • C. based on code review.
  • D. after functional requirements.

Answer: A


NEW QUESTION # 343
......


The CISM exam is considered one of the most prestigious certifications in the field of information security. It is recognized globally and is highly valued by employers in various industries. CISM exam covers a wide range of topics, including information security governance, risk management, incident management, and program development and management.

 

CISM Dumps To Pass ISACA Exam in 24 Hours - ExamcollectionPass: https://www.examcollectionpass.com/ISACA/CISM-practice-exam-dumps.html

Buy Latest CISM Exam Q&A PDF - One Year Free Update: https://drive.google.com/open?id=1NHitoYPAgY2zHGwhbWdbEnaRJ9mN6w1h