[Q99-Q124] Ensure Success With Updated Verified CISM Exam Dumps [2023]

Share

Ensure Success With Updated Verified CISM Exam Dumps [2023]

Exam Materials for You to Prepare & Pass CISM Exam.

NEW QUESTION # 99
Which of the following measures is the MOST effective deterrent against disgruntled stall abusing their privileges?

  • A. Signed acceptable use policy
  • B. System audit log monitoring
  • C. High-availability systems
  • D. Layered defense strategy

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
A layered defense strategy would only prevent those activities that are outside of the user's privileges. A signed acceptable use policy is often an effective deterrent against malicious activities because of the potential for termination of employment and/or legal actions being taken against the individual. System audit log monitoring is after the fact and may not be effective. High-availability systems have high costs and are not always feasible for all devices and components or systems.


NEW QUESTION # 100
The MOST important function of a risk management program is to:

  • A. eliminate inherent risk.
  • B. maximize the sum of all annualized loss expectancies (ALEs).
  • C. quantify overall risk.
  • D. minimize residual risk.

Answer: D

Explanation:
A risk management program should minimize the amount of risk that cannot be otherwise eliminated or transferred; this is the residual risk to the organization. Quantifying overall risk is important but not as critical as the end result. Eliminating inherent risk is virtually impossible. Maximizing the sum of all ALEs is actually the opposite of what is desirable.


NEW QUESTION # 101
Which of the following would provide the BEST evidence to senior management that security control performance has improved?

  • A. Demonstrated return on security investment
  • B. Results of an emerging threat analysis
  • C. Review of security metrics trends
  • D. Reduction in inherent risk

Answer: C


NEW QUESTION # 102
Which of the following would be MOST important to include in a bring your own device (BYOD) policy with regard to lost or stolen devices? The need for employees to:

  • A. notify local law enforcement.
  • B. request a remote wipe of the device
  • C. seek advice from the mobile service provider
  • D. initiate the company's incident reporting process

Answer: D


NEW QUESTION # 103
An executive's personal mobile device used for business purposes is reported lost. The information security manager should respond based on:

  • A. the business impact analysis (BIA),
  • B. incident classification.
  • C. asset management guidelines.
  • D. the acceptable use policy.

Answer: B


NEW QUESTION # 104
Primary direction on the impact of compliance with new regulatory requirements that may lead to major application system changes should be obtained from the:

  • A. key business process owners.
  • B. corporate internal auditor.
  • C. System developers/analysts.
  • D. corporate legal counsel.

Answer: A

Explanation:
Business process owners are in the best position to understand how new regulatory requirements may affect their systems. Legal counsel and infrastructure management, as well as internal auditors, would not be in as good a position to fully understand all ramifications.


NEW QUESTION # 105
Which of the following is the MAIN reason for performing risk assessment on a continuous basis'?

  • A. Justification of the security budget must be continually made.
  • B. New vulnerabilities are discovered every day.
  • C. The risk environment is constantly changing.
  • D. Management needs to be continually informed about emerging risks.

Answer: C

Explanation:
Explanation
The risk environment is impacted by factors such as changes in technology, and business strategy. These changes introduce new threats and vulnerabilities to the organization. As a result, risk assessment should be performed continuously. Justification of a budget should never be the main reason for performing a risk assessment. New vulnerabilities should be managed through a patch management process. Informing management about emerging risks is important, but is not the main driver for determining when a risk assessment should be performed.


NEW QUESTION # 106
An organization that outsourced its payroll processing performed an independent assessment of the security controls of the third party, per policy requirements. Which of the following is the MOST useful requirement to include in the contract?

  • A. Dedicated security manager for monitoring compliance
  • B. Right to audit
  • C. Nondisclosure agreement
  • D. Proper firewall implementation

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Right to audit would be the most useful requirement since this would provide the company the ability to perform a security audit/assessment whenever there is a business need to examine whether the controls are working effectively at the third party. Options B, C and D are important requirements and can be examined during the audit. A dedicated security manager would be a costly solution and not always feasible for most situations.


NEW QUESTION # 107
The effectiveness of an information security governance framework will BEST be enhanced if:

  • A. risk management is built into operational and strategic activities
  • B. a culture of legal and regulatory compliance is promoted by management
  • C. consultants review the information security governance framework
  • D. IS auditors are empowered to evaluate governance activities

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE


NEW QUESTION # 108
Which of the following would help management determine the resources needed to mitigate a risk to the organization?

  • A. Business impact analysis (BIA)
  • B. Risk-based audit program
  • C. Risk analysis process
  • D. Risk management balanced scorecard

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The business impact analysis (BIA) determines the possible outcome of a risk and is essential to determine the appropriate cost of control. The risk analysis process provides comprehensive data, but does not determine definite resources to mitigate the risk as does the BIA. The risk management balanced scorecard is a measuring tool for goal attainment. A risk-based audit program is used to focus the audit process on the areas of greatest importance to the organization.


NEW QUESTION # 109
The PRIMARY benefit of a centralized time server is that it

  • A. decreases the likelihood of an unrecoverable systems failure.
  • B. reduces individual time-of-day requests by client applications,
  • C. allows decentralized logs to be kept in synchronization.
  • D. Is required by password synchronization programs.

Answer: C


NEW QUESTION # 110
Which of the following is the MOST important factor when designing information security architecture?

  • A. Stakeholder requirements
  • B. Technical platform interfaces
  • C. Scalability of the network
  • D. Development methodologies

Answer: A

Explanation:
Explanation
The most important factor for information security is that it advances the interests of the business, as defined by stakeholder requirements. Interoperability and scalability, as well as development methodologies, are all important but are without merit if a technologically-elegant solution is achieved that does not meet the needs of the business.


NEW QUESTION # 111
Which of the following is an information security manager's BEST course of action when a threat intelligence report indicates a large number of ransomware attacks targeting the industry?

  • A. Review the mitigating security controls
  • B. Increase the frequency of system backups
  • C. Notify staff members of the threat
  • D. Assess the risk to the organization

Answer: C


NEW QUESTION # 112
Obtaining senior management support for establishing a warm site can BEST be accomplished by:

  • A. developing effective metrics.
  • B. establishing a periodic risk assessment.
  • C. promoting regulatory requirements.
  • D. developing a business case.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Business case development, including a cost-benefit analysis, will be most persuasive to management. A risk assessment may be included in the business ease, but by itself will not be as effective in gaining management support. Informing management of regulatory requirements may help gain support for initiatives, but given that more than half of all organizations are not in compliance with regulations, it is unlikely to be sufficient in many cases. Good metrics which provide assurance that initiatives are meeting organizational goals will also be useful, but are insufficient in gaining management support.


NEW QUESTION # 113
Which of the following is BEST to include in a business case when the return on investment (RIO) for an information security initiative is difficult to calculate?

  • A. Projected increase in maturity level
  • B. Estimated reduction in risk
  • C. Estimated increase in efficiency
  • D. Projected costs over time

Answer: C


NEW QUESTION # 114
While implementing information security governance an organization should FIRST:

  • A. determine security baselines.
  • B. adopt security standards.
  • C. establish security policies.
  • D. define the security strategy.

Answer: D

Explanation:
Explanation
The first step in implementing information security governance is to define the security strategy based on which security baselines are determined. Adopting suitable security- standards, performing risk assessment and implementing security policy are steps that follow the definition of the security strategy.


NEW QUESTION # 115
Which of the following would BEST mitigate identified vulnerabilities in a timely manner?

  • A. Continuous vulnerability monitoring tool
  • B. Monitoring of key risk indicators (KRIs)
  • C. Action plan with responsibilities and deadlines
  • D. Categorization of the vulnerabilities based on system's criticality

Answer: B

Explanation:
Explanation/Reference:
Explanations
One approach seeing increasing use is to report and monitor risk through the use of key risk indicators (KRIs). KRIs can be defined as measures that, in some manner, indicate when an enterprise is subject to risk that exceeds a defined risk level. Typically, these indicators are trends in factors known to increase risk and are generally developed based on experience. They can be as diverse as increasing absenteeism or increased turnover in key employees to rising levels of security events or incidents.


NEW QUESTION # 116
Which of the following needs to be established between an IT service provider and its clients to BEST enable adequate continuity of service in preparation for an outage?

  • A. Reciprocal site agreement
  • B. Data retention policies
  • C. Server maintenance plans
  • D. Recovery time objectives (RTOs)

Answer: D


NEW QUESTION # 117
A benefit of using a full disclosure (white box) approach as compared to a blind (black box) approach to penetration testing is that:

  • A. human intervention is not required for this type of test.
  • B. it simulates the real-life situation of an external security attack.
  • C. critical infrastructure information is not revealed to the tester.
  • D. less time is spent on reconnaissance and information gathering.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Data and information required for penetration are shared with the testers, thus eliminating time that would otherwise have been spent on reconnaissance and gathering of information. Blind (black box) penetration testing is closer to real life than full disclosure (white box) testing. There is no evidence to support that human intervention is not required for this type of test. A full disclosure (white box) methodology requires the knowledge of the subject being tested.


NEW QUESTION # 118
What should an information security manager do FIRST after a number of security gaps have been identified that need to be resolved?

  • A. Develop and implement incident response strategies.
  • B. Consolidate overlapping controls.
  • C. Perform a cost-benefit analysis.
  • D. Prioritize responses based on likelihood and impact.

Answer: D


NEW QUESTION # 119
Which of the following analyses will BEST identify the external influences to an organization's information security?

  • A. Gap analysis
  • B. Threat analysis
  • C. Business impact analysis (BIA)
  • D. Vulnerability analysis

Answer: B

Explanation:
Explanation
Threat analysis is a process that is used to identify and assess the external influences or threats that could potentially affect an organization's information security. It is used to identify potential risks and develop strategies to mitigate or reduce those risks. Threat analysis involves analyzing the environment, identifying potential threats and their potential impacts, and then evaluating the organization's current security measures and developing strategies to address any deficiencies.


NEW QUESTION # 120
Which of the following practices BEST supports the achievement of information security program objectives in the IT function?

  • A. IT management sign-off on information security policies
  • B. Participation of IT stakeholders in the security program steering committee
  • C. Review and approval of IT projects by the information security manager
  • D. Continuous security auditing of IT service processes

Answer: B


NEW QUESTION # 121
An organization's IT department needs to implement security patches. Recent reports indicate these patches could result in stability issues. Which of the following is the information security manager's BEST recommendation?

  • A. Research compensating security controls.
  • B. Research alternative software solutions,
  • C. Evaluate the patches in a test environment.
  • D. Increase monitoring after patch implementation.

Answer: C


NEW QUESTION # 122
Which of the following provides the BEST evidence that a recently established infofmation security program is effective?

  • A. The number of reported incidents has increased
  • B. Senior management has reported fewer junk emails.
  • C. The number of tickets associated with IT incidents have stayed consistent
  • D. Regular IT balanced scorecards are communicated.

Answer: A

Explanation:
The number of reported incidents has increased is the best evidence that a recently established information security program is effective because it indicates that the organization has improved its detection and reporting capabilities and has raised awareness among employees about security issues. Regular IT balanced scorecards are communicated is not a good evidence because it does not measure the actual performance or outcomes of the security program. Senior management has reported fewer junk emails is not a good evidence because it does not reflect the overall security posture or maturity of the organization. The number of tickets associated with IT incidents have stayed consistent is not a good evidence because it does not show any improvement or reduction in security incidents or risks. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-6/how-to-measure-the-effectiveness-of-information-security-using-iso-27004 https://www.isaca.org/resources/isaca-journal/issues/2014/volume-6/how-to-measure-the-effectiveness-of-your-information-security-management-system


NEW QUESTION # 123
Which of the following would raise security awareness among an organization's employees?

  • A. Distributing industry statistics about security incidents
  • B. Encouraging employees to behave in a more conscious manner
  • C. Continually reinforcing the security policy
  • D. Monitoring the magnitude of incidents

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Employees must be continually made aware of the policy and expectations of their behavior. Choice A would have little relevant bearing on the employee's behavior. Choice B does not involve the employees.
Choice C could be an aspect of continual reinforcement of the security policy.


NEW QUESTION # 124
......


The Certified Information Security Manager (CISM) exam is a certification program designed and offered by the Information Systems Audit and Control Association (ISACA). CISM exam is designed for professionals who are responsible for managing, designing, and overseeing an organization's information security program. It is a globally recognized certification that validates the skills and knowledge required for managing, designing, and assessing an enterprise's information security program.

 

Updated CISM Certification Exam Sample Questions: https://testinsides.dumps4pdf.com/CISM-valid-braindumps.html