
[Dec-2024] Pass ISACA CISM Exam in First Attempt Guaranteed!
Full CISM Practice Test and 1180 unique questions with explanations waiting just for you, get it now!
NEW QUESTION # 508
The MOST important characteristic of good security policies is that they:
- A. state only one general security mandate.
- B. govern the creation of procedures and guidelines.
- C. state expectations of IT management.
- D. are aligned with organizational goals.
Answer: D
Explanation:
Explanation
The most important characteristic of good security policies is that they be aligned with organizational goals.
Failure to align policies and goals significantly reduces the value provided by the policies. Stating expectations of IT management omits addressing overall organizational goals and objectives. Stating only one general security mandate is the next best option since policies should be clear; otherwise, policies may be confusing and difficult to understand. Governing the creation of procedures and guidelines is most relevant to information security standards.
NEW QUESTION # 509
In an organization, the responsibilities for IT security are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed. This represents which level of ranking in the information security governance maturity model?
- A. Defined
- B. Managed
- C. Repeatable
- D. Optimized
Answer: B
Explanation:
Explanation
Boards of directors and executive management can use the information security governance maturity model to establish rankings for security in their organizations. The ranks are nonexistent, initial, repeatable, defined, managed and optimized. When the responsibilities for IT security in an organization are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed, it is said to be 'managed and measurable.'
NEW QUESTION # 510
Which of the following is MOST important to the successful implementation of an information security program?
- A. Key performance indicators (KPIs) are defined.
- B. A balanced scorecard is approved by the steering committee.
- C. The program is developed using global security standards.
- D. Adequate security resources are allocated to the program.
Answer: D
NEW QUESTION # 511
Which of the following should be the PRIMARY goal of an Information security manager when designing Information security policies?
- A. Improving the protection of information
- B. Achieving organizational objectives
- C. Reducing organizational security risk
- D. Minimizing the cost of security controls
Answer: C
NEW QUESTION # 512
The advantage of sending messages using steganographic techniques, as opposed to utilizing encryption, is that:
- A. the existence of messages is unknown.
- B. required key sizes are smaller.
- C. reliability of the data is higher in transit.
- D. traffic cannot be sniffed.
Answer: A
Explanation:
The existence of messages is hidden when using steganography. This is the greatest risk. Keys are relevant for encryption and not for steganography. Sniffing of steganographic traffic is also possible. Option D is not relevant.
NEW QUESTION # 513
A mission-critical system has been identified as having an administrative system account with attributes that prevent locking and change of privileges and name. Which would be the BEST approach to prevent successful brute forcing of the account?
- A. Ask for a vendor patch
- B. Prevent the system from being accessed remotely
- C. Create a strong random password
- D. Track usage of the account by audit trails
Answer: C
Explanation:
Creating a strong random password reduces the risk of a successful brute force attack by exponentially increasing the time required. Preventing the system from being accessed remotely is not always an option in mission-critical systems and still leaves local access risks. Vendor patches are not always available, tracking usage is a detective control and will not prevent an attack.
NEW QUESTION # 514
Key systems necessary for branch operations reside at corporate headquarters. Branch A is negotiating with a third party to provide disaster recovery facilities.
Which of the following contract terms would be the MOST significant concern?
- A. Penalty clauses for nonperformance are not included in contract.
- B. The right to audit the hot site is not provided in the contract.
- C. Connectivity is not provided from the hot site to corporate headquarters.
- D. The hot site for the branch may have to be shared.
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 515
When performing an information risk analysis, an information security manager should FIRST:
- A. establish the ownership of assets.
- B. take an asset inventory.
- C. categorize the assets.
- D. evaluate the risks to the assets.
Answer: B
Explanation:
Assets must be inventoried before any of the other choices can be performed.
NEW QUESTION # 516
A business unit has updated its long-term business plan to include a strategy of upgrading information management system to increase productivity. To support this initiative, with the information security strategy?
- A. The business strategy
- B. It risk assessment results
- C. the information security framework
- D. The IT strategy
Answer: B
NEW QUESTION # 517
Which of the following is the GREATEST benefit of incorporating information security governance into the corporate governance framework?
- A. Promotion of security-by-design principles to the business
- B. Heightened awareness of information security strategies
- C. Management accountability for information security
- D. Improved process resiliency in the event of attacks
Answer: C
Explanation:
Explanation
The greatest benefit of incorporating information security governance into the corporate governance framework is D. Management accountability for information security. This is because management accountability for information security means that the senior management and the board of directors are responsible for defining, overseeing, and supporting the information security strategy, policies, and objectives of the organization, and ensuring that they are aligned with the business goals, stakeholder expectations, and regulatory requirements. Management accountability for information security also means that the senior management and the board of directors are accountable for the performance, value, and effectiveness of the information security program, and for the management and mitigation of the information security risks and incidents. Management accountability for information security can help to foster a culture of security awareness and responsibility, and to enhance the trust and confidence of the customers, partners, and regulators in the organization's information security capabilities.
Management accountability for information security means that the senior management and the board of directors are responsible for defining, overseeing, and supporting the information security strategy, policies, and objectives of the organization, and ensuring that they are aligned with the business goals, stakeholder expectations, and regulatory requirements. (From CISM Manual or related resources) References = CISM Review Manual 15th Edition, Chapter 1, Section 1.2.1, page 181; CISM domain 1:
Information security governance [Updated 2022] | Infosec2; Information Security Governance: Guidance for Boards of Directors and Executive Management, 2nd Edition3
NEW QUESTION # 518
Spoofing should be prevented because it may be used to:
- A. gain illegal entry to a secure system by faking the sender's address.
- B. capture information such as password traveling through the network.
- C. predict which way a program will branch when an option is presented.
- D. assemble information, track traffic, and identify network vulnerabilities.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 519
A risk management approach to information protection is:
- A. managing risks to an acceptable level, commensurate with goals and objectives.
- B. managing risk tools to ensure that they assess all information protection vulnerabilities.
- C. implementing a training program to educate individuals on information protection and risks.
- D. accepting the security posture provided by commercial security products.
Answer: A
Explanation:
Explanation
Risk management is identifying all risks within an organization, establishing an acceptable level of risk and effectively managing risks which may include mitigation or transfer. Accepting the security- posture provided by commercial security products is an approach that would be limited to technology components and may not address all business operations of the organization. Education is a part of the overall risk management process.
Tools may be limited to technology and would not address non-technology risks.
NEW QUESTION # 520
Which of the following is the MOST important reason to involve external forensics experts in evidence collection when responding to a major security breach?
- A. To ensure evidence is handled by qualified resources
- B. To provide the response team with expert training on evidence handling
- C. To validate the incident response process
- D. To prevent evidence from being disclosed to any internal staff members
Answer: A
NEW QUESTION # 521
When an organization is implementing an information security governance program, its board of directors should be responsible for:
- A. setting the strategic direction of the program.
- B. auditing for compliance.
- C. drafting information security policies.
- D. reviewing training and awareness programs.
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation
Explanation:
A board of directors should establish the strategic direction of the program to ensure that it is in sync with the company's vision and business goals. The board must incorporate the governance program into the overall corporate business strategy. Drafting information security policies is best fulfilled by someone such as a security manager with the expertise to bring balance, scope and focus to the policies. Reviewing training and awareness programs may best be handled by security management and training staff to ensure that the training is on point and follows best practices. Auditing for compliance is best left to the internal and external auditors to provide an objective review of the program and how it meets regulatory and statutory compliance.
NEW QUESTION # 522
A multinational organization operating in fifteen countries is considering implementing an information security program. Which factor will MOST influence the design of the Information security program?
- A. Cultures of the different countries
- B. Composition of the board
- C. Representation by regional business leaders
- D. IT security skills
Answer: A
Explanation:
Explanation
Culture has a significant impact on how information security will be implemented. Representation by regional business leaders may not have a major influence unless it concerns cultural issues. Composition of the board may not have a significant impact compared to cultural issues. IT security skills are not as key or high impact in designing a multinational information security program as would be cultural issues.
NEW QUESTION # 523
Which of the following is the BEST indication that the information security strategy is delivering business value?
- A. The information security team analyzes results from end user surveys.
- B. Key risk indicators (KRIs) are regularly reviewed.
- C. There has been a significant reduction in the number of reported incidents.
- D. Stakeholders regularly seek feedback from the information security team
Answer: C
NEW QUESTION # 524
Which of the following is the BEST justification to convince management to invest in an information security program?
- A. Cost reduction
- B. Protection of business assets
- C. Compliance with company policies
- D. Increased business value
Answer: D
Explanation:
Explanation
Investing in an information security program should increase business value and confidence. Cost reduction by itself is rarely the motivator for implementing an information security program. Compliance is secondary to business value. Increasing business value may include protection of business assets.
NEW QUESTION # 525
An organization manages payroll and accounting systems for multiple client companies Which of the following contract terms would indicate a potential weakness for a disaster recovery hot site?
- A. Timestamp of declaration will determine priority of access to facility
- B. Exclusive use of hot site is limited to six weeks (following declaration)
- C. Work-area size Is limited but can be augmented with nearby office space
- D. Servers will be provided at time of disaster (not on floor).
Answer: D
NEW QUESTION # 526
In an organization implementing a data classification program, ultimate responsibility for the data on the database server lies with the:
- A. database administrator
- B. business unit manager
- C. information security manager.
- D. information technology manager.
Answer: B
NEW QUESTION # 527
......
Prepare for your ISACA certification with the updated CramPDF CISM exam questions: https://drive.google.com/open?id=1m0aAWmWrJwoaLjCL0sdEA2UQ8YHjWFXH
Get Latest CISM Dumps Exam Questions in here: https://www.crampdf.com/CISM-exam-prep-dumps.html