
[Nov 07, 2021] Get Free Updates Up to 365 days On Developing CISM Braindumps
Best Quality ISACA CISM Exam Questions
How much CISM Exam Cost
- The early Registration fee for the CISA exam is $415 for Members and $545 for Non-Members.
- The final Registration fee for the CISA is $465 USD for members and $595 for Non-Members.
NEW QUESTION 315
What is the MOST important reason for conducting security awareness programs throughout an organization?
- A. Reducing the human risk
- B. Training personnel in security incident response
- C. Informing business units about the security strategy
- D. Maintaining evidence of training records to ensure compliance
Answer: A
Explanation:
Explanation
People are the weakest link in security implementation, and awareness would reduce this risk. Through security awareness and training programs, individual employees can be informed and sensitized on various security policies and other security topics, thus ensuring compliance from each individual. Laws and regulations also aim to reduce human risk. Informing business units about the security strategy is best done through steering committee meetings or other forums.
NEW QUESTION 316
Which of the following will BEST prevent external security attacks?
- A. Securing and analyzing system access logs
- B. Background checks for temporary employees
- C. Network address translation
- D. Static IP addressing
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Network address translation is helpful by having internal addresses that are nonroutable. Background checks of temporary employees are more likely to prevent an attack launched from within the enterprise.
Static IP addressing does little to prevent an attack. Writing all computer logs to removable media does not help in preventing an attack.
NEW QUESTION 317
When implementing security architecture, an information security manager MUST ensure that security controls:
- A. form multiple barriers against threats.
- B. are the least expensive.
- C. are communicated through security policies.
- D. are transparent.
Answer: A
NEW QUESTION 318
When supporting an organization's privacy officer, which of the following is the information security manager's PRIMARY role regarding primacy requirements?
- A. Ensuring appropriate controls are in place
- B. Determining data classification
- C. Monitoring the transfer of private data
- D. Conducting privacy awareness programs
Answer: A
NEW QUESTION 319
The criticality and sensitivity of information assets is determined on the basis of:
- A. resource dependency assessment.
- B. vulnerability assessment.
- C. impact assessment.
- D. threat assessment.
Answer: C
Explanation:
The criticality and sensitivity of information assets depends on the impact of the probability of the threats exploiting vulnerabilities in the asset, and takes into consideration the value of the assets and the impairment of the value. Threat assessment lists only the threats that the information asset is exposed to. It does not consider the value of the asset and impact of the threat on the value. Vulnerability assessment lists only the vulnerabilities inherent in the information asset that can attract threats. It does not consider the value of the asset and the impact of perceived threats on the value. Resource dependency assessment provides process needs but not impact.
NEW QUESTION 320
When considering whether to adopt a new information security framework, an organization's information security manager should FIRST:
- A. perform a financial viability study
- B. analyze the framework's legal implications and business impact
- C. perform a technical feasibility analysis
- D. compare the framework with the current business strategy
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 321
Which of the following is MOST appropriate for inclusion in an information security strategy?
- A. Budget estimates to acquire specific security tools
- B. Security processes, methods, tools and techniques
- C. Business controls designated as key controls
- D. Firewall rule sets, network defaults and intrusion detection system (IDS) settings
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
A set of security objectives, processes, methods, tools and techniques together constitute a security strategy.
Although IT and business governance are intertwined, business controls may not be included in a security strategy. Budgets will generally not be included in an information security strategy. Additionally, until information security strategy is formulated and implemented, specific tools will not be identified and specific cost estimates will not be available. Firewall rule sets, network defaults and intrusion detection system (IDS) settings are technical details subject to periodic change, and are not appropriate content for a strategy document.
NEW QUESTION 322
A major trading partner with access to the internal network is unwilling or unable to remediate serious information security exposures within its environment. Which of the following is the BEST recommendation?
- A. Remove all trading partner access until the situation improves
- B. Send periodic reminders advising them of their noncompliance
- C. Sign a legal agreement assigning them all liability for any breach
- D. Set up firewall rules restricting network traffic from that location
Answer: D
Explanation:
Explanation
It is incumbent on an information security manager to see to the protection of their organization's network, but to do so in a manner that does not adversely affect the conduct of business. This can be accomplished by adding specific traffic restrictions for that particular location. Removing all access will likely result in lost business. Agreements and reminders do not protect the integrity of the network.
NEW QUESTION 323
Which of the following is MOST important for the alignment of an information security program with the information security strategy?
- A. Benchmarking against industry peers
- B. Identification of business-specific risk factors
- C. Adoption of an industry recognized framework
- D. Input from senior management
Answer: D
NEW QUESTION 324
Which of the following should be determined while defining risk management strategies?
- A. Enterprise disaster recovery plans
- B. IT architecture complexity
- C. Risk assessment criteria
- D. Organizational objectives and risk appetite
Answer: D
Explanation:
While defining risk management strategies, one needs to analyze the organization's objectives and risk appetite and define a risk management framework based on this analysis. Some organizations may accept known risks, while others may invest in and apply mitigation controls to reduce risks. Risk assessment criteria would become part of this framework, but only after proper analysis. IT architecture complexity and enterprise disaster recovery plans are more directly related to assessing risks than defining strategies.
NEW QUESTION 325
Which of the following is characteristic of centralized information security management?
- A. Better adherence to policies
- B. More aligned with business unit needs
- C. More expensive to administer
- D. Faster turnaround of requests
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Centralization of information security management results in greater uniformity and better adherence to security policies. It is generally less expensive to administer due to the economics of scale. However, turnaround can be slower due to the lack of alignment with business units.
NEW QUESTION 326
Which of the following is the MOST usable deliverable of an information security risk analysis?
- A. List of action items to mitigate risk
- B. Quantification of organizational risk
- C. Business impact analysis (BIA) report
- D. Assignment of risks to process owners
Answer: A
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Although all of these are important, the list of action items is used to reduce or transfer the current level of risk. The other options materially contribute to the way the actions are implemented.
NEW QUESTION 327
The MOST important reason to have a well-documented and tested incident response plan in place is to:
- A. facilitate the escalation process
- B. standardize the chain of custody procedure
- C. promote a coordinated effort.
- D. outline external communications
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION 328
Which of the following will MOST effectively minimize the chance of inadvertent disclosure of confidential information?
- A. Following the principle of least privilege
- B. Applying data classification rules
- C. Enforcing penalties for security policy violations
- D. Restricting the use of removable media
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 329
The MAIN reason for an information security manager to monitor industry level changes in the business and FT is to:
- A. update information security policies in accordance with the changes
- B. evaluate the effect of the changes on the levels of residual risk.
- C. change business objectives based on potential impact
- D. identify changes in the risk environment
Answer: D
NEW QUESTION 330
When an organization is using an automated tool to manage and house its business continuity plans, which of the following is the PRIMARY concern?
- A. Versioning control as plans are modified
- B. Broken hyperlinks to resources stored elsewhere
- C. Ensuring accessibility should a disaster occur
- D. Tracking changes in personnel and plan assets
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
If all of the plans exist only in electronic form, this presents a serious weakness if the electronic version is dependent on restoration of the intranet or other systems that are no longer available. Versioning control and tracking changes in personnel and plan assets is actually easier with an automated system. Broken hyperlinks are a concern, but less serious than plan accessibility.
NEW QUESTION 331
A CIO has asked the organization's information security manager to provide both one-year and five-year plans for the information security program. What is the purpose for the long-term plan?
- A. To create and document a consistent progression of security capabilities
- B. To prioritize risks on a longer scale than the one-year plan
- C. To create formal requirements to meet projected security needs for the future
- D. To facilitate the continuous improvement of the IT organization
Answer: D
NEW QUESTION 332
An organization has decided to implement a security information and event management (SIEM) system. It is MOST important for the organization to consider:
- A. log sources.
- B. threat assessments.
- C. data ownership.
- D. industry best practices.
Answer: A
NEW QUESTION 333
Recovery point objectives (RPOs) can be used to determine which of the following?
- A. Maximum tolerable downtime
- B. Maximum tolerable period of data loss
- C. Baseline for operational resiliency
- D. Time to restore backups
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The RPO is determined based on the acceptable data loss in the case of disruption of operations. It indicates the farthest point in time prior to the incident to which it is acceptable to recover the data. RPO effectively quantifies the permissible amount of data loss in the case of interruption. It also dictates the frequency of backups required for a given data set since the smaller the allowable gap in data, the more frequent that backups must occur.
NEW QUESTION 334
To justify the establishment of an incident management team, an information security manager would find which of the following to be the MOST effective?
- A. Need of an independent review of incident causes
- B. Possible business benefits from incident impact reduction
- C. Assessment of business impact of past incidents
- D. Need for constant improvement on the security level
Answer: B
Explanation:
Business benefits from incident impact reduction would be the most important goal for establishing an incident management team. The assessment of business impact of past incidents would need to be completed to articulate the benefits. Having an independent review benefits the incident management process. The need for constant improvement on the security level is a benefit to the organization.
NEW QUESTION 335
Which of the following would BEST help an information security manager prioritize remediation activities to meet regulatory requirements?
- A. Cost of associated controls
- B. Annual toss expectancy (ALE) of noncompliance
- C. A capability maturity model matrix
- D. Alignment with the IT strategy
Answer: B
NEW QUESTION 336
......
ISACA Exam Practice Test To Gain Brilliante Result: https://www.examcollectionpass.com/ISACA/CISM-practice-exam-dumps.html
Tested Material Used To CISM: https://drive.google.com/open?id=1NHitoYPAgY2zHGwhbWdbEnaRJ9mN6w1h