CramPDF Co., ltd provides valid exam cram PDF & dumps PDF materials to help candidates pass exam certainly. If you want to get certifications in the short time please choose CramPDF exam cram or dumps PDF file.

ISACA CISM Dumps - 100% Cover Real Exam Questions (Updated 417 Questions) [Q116-Q131]

Share

ISACA CISM Dumps - 100% Cover Real Exam Questions (Updated 417 Questions)

Real CISM dumps - Real ISACA dumps PDF


3. Information Security Program Development and Management – 27%

The next area that you should learn will evaluate your knowledge base whether it contains the following or not:

  • Knowledge of the techniques to communicate this program to the stakeholders.
  • Knowledge of the certifications, training, and skills required for information security;
  • Knowledge and ability to implement the proper effectiveness and procedures of information security along with its policies;
  • Knowledge and skills in managing, identifying, and defining the necessary requirements for internal and external resources;
  • Knowledge and skills in implementing the rules into contracts, agreements, and third-party management processes;

As for the practical skills, you should be able to perform the following tasks:

  • Maintain the integration of a incident response plan and a disaster recovery plan.
  • Make sure to carry out reviews of incidents afterwards to know the exact cause of certain situations to avoid its probability in the future;
  • Establish proper information security incidents to allow the accuracy in responding to incidents;
  • Make sure to test, review, and revise the incident response to ensure the effectiveness and improve response capabilities;

 

NEW QUESTION # 116
An organization is already certified to an international security standard. Which mechanism would BEST help to further align the organization with other data security regulatory requirements as per new business needs?

  • A. Gap analysis
  • B. Business impact analysis (BIA)
  • C. Key performance indicators (KPIs)
  • D. Technical vulnerability assessment

Answer: A

Explanation:
Explanation
Gap analysis would help identify the actual gaps between the desired state and the current implementation of information security management. BIA is primarily used for business continuity planning. Technical vulnerability assessment is used for detailed assessment of technical controls, which would come later in the process and would not provide complete information in order to identify gaps.


NEW QUESTION # 117
Which of the following BEST demonstrates the added value of an information security program?

  • A. A balanced scorecard
  • B. Security baselines
  • C. A SWOT analysis
  • D. A gap analysis

Answer: C


NEW QUESTION # 118
Investments in information security technologies should be based on:

  • A. business climate.
  • B. value analysis.
  • C. vulnerability assessments.
  • D. audit recommendations.

Answer: B

Explanation:
Investments in security technologies should be based on a value analysis and a sound business case. Demonstrated value takes precedence over the current business climate because it is ever changing. Basing decisions on audit recommendations would be reactive in nature and might not address the key business needs comprehensively. Vulnerability assessments are useful, but they do not determine whether the cost is justified.


NEW QUESTION # 119
The FIRST step in establishing a security governance program is to:

  • A. conduct a workshop for all end users.
  • B. conduct a risk assessment.
  • C. obtain high-level sponsorship.
  • D. prepare a security budget.

Answer: C

Explanation:
The establishment of a security governance program is possible only with the support and sponsorship of top management since security governance projects are enterprise wide and integrated into business processes. Conducting a risk assessment, conducting a workshop for all end users and preparing a security budget all follow once high-level sponsorship is obtained.


NEW QUESTION # 120
Which of the following is an information security manager's MOST important consideration during the investigative process of analyzing the hard drive of 3 compromises..

  • A. Determining the classification of stored data
  • B. Maintaining chain of custody
  • C. Notifying the relevant stakeholders
  • D. Identifying the relevant strain of malware

Answer: A


NEW QUESTION # 121
Which of the following would be the BEST way for a company to reduce the risk of data loss resulting from employee-owned devices accessing the corporate email system?

  • A. Require employees to undergo training before permitting access to the corporate email service
  • B. Use a mobile device management (MDM) solution to isolate the local corporate email storage.
  • C. Require employees to install a reputable mobile anti-virus solution on their personal devices.
  • D. Link the bring-your-own-device (BYOD) policy to the existing staff disciplinary policy.

Answer: B


NEW QUESTION # 122
Which is the BEST way to measure and prioritize aggregate risk deriving from a chain of linked system vulnerabilities?

  • A. Penetration tests
  • B. Vulnerability scans
  • C. Security audits
  • D. Code reviews

Answer: A

Explanation:
Explanation
A penetration test is normally the only security assessment that can link vulnerabilities together by exploiting them sequentially. This gives a good measurement and prioritization of risks. Other security assessments such as vulnerability scans, code reviews and security audits can help give an extensive and thorough risk and vulnerability overview', but will not be able to test or demonstrate the final consequence of having several vulnerabilities linked together. Penetration testing can give risk a new perspective and prioritize based on the end result of a sequence of security problems.


NEW QUESTION # 123
The MOST likely reason to use qualitative security risk assessments instead of quantitative methods is when:

  • A. an organization provides services instead of hard goods.
  • B. a security program requires independent expression of risks.
  • C. available data is too subjective.
  • D. a mature security program is in place.

Answer: C


NEW QUESTION # 124
When an operating system is being hardened, it is MOST important for an information security manager to ensure that

  • A. file access is restricted
  • B. system logs are activated.
  • C. default passwords are changed,
  • D. anonymous access is removed.

Answer: C


NEW QUESTION # 125
To determine how a security breach occurred on the corporate network, a security manager looks at the logs of various devices. Which of the following BEST facilitates the correlation and review of these logs?

  • A. Domain name server (DNS)
  • B. Database server
  • C. Time server
  • D. Proxy server

Answer: C

Explanation:
Explanation
To accurately reconstruct the course of events, a time reference is needed and that is provided by the time server. The other choices would not assist in the correlation and review of these logs.


NEW QUESTION # 126
Which of the following would provide the justification for a new information security investment?

  • A. Defined key performance indicators (KPIs)
  • B. Projected reduction in risk.
  • C. Results of a comprehensive threat analysis.
  • D. Senior management involvement in project prioritization.

Answer: C


NEW QUESTION # 127
Which of the following is MOST effective in preventing security weaknesses in operating systems?

  • A. Security baselines
  • B. Change management
  • C. Patch management
  • D. Configuration management

Answer: C

Explanation:
Patch management corrects discovered weaknesses by applying a correction (a patch) to the original program code. Change management controls the process of introducing changes to systems. Security baselines provide minimum recommended settings. Configuration management controls the updates to the production environment.


NEW QUESTION # 128
The MOST effective approach to address issues that arise between IT management, business units and security management when implementing a new security strategy is for the information security manager to:

  • A. ensure that senior management provides authority for security to address the issues.
  • B. insist that managers or units not in agreement with the security solution accept the risk.
  • C. refer the issues to senior management along with any security recommendations.
  • D. escalate issues to an external third party for resolution.

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Senior management is in the best position to arbitrate since they will look at the overall needs of the business in reaching a decision. The authority may be delegated to others by senior management after their review of the issues and security recommendations. Units should not be asked to accept the risk without first receiving input from senior management.


NEW QUESTION # 129
Which of the following is the MOST effective way for an organization to ensure its third-party service providers are aware of information security requirements and expectations?

  • A. Providing information security training to third-party personnel
  • B. Inducting information security clauses within contracts
  • C. Requiring third parties to sign confidentiality agreements
  • D. Auditing the service delivery of third-party providers

Answer: B


NEW QUESTION # 130
Which of the following steps should be performed FIRST in the risk assessment process?

  • A. Threat identification
  • B. Asset identification and valuation
  • C. Staff interviews
  • D. Determination of the likelihood of identified risks

Answer: B

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
The first step in the risk assessment methodology is a system characterization, or identification and valuation, of all of the enterprise's assets to define the boundaries of the assessment. Interviewing is a valuable tool to determine qualitative information about an organization's objectives and tolerance for risk. Interviews are used in subsequent steps. Identification of threats comes later in the process and should not be performed prior to an inventory since many possible threats will not be applicable if there is no asset at risk. Determination of likelihood comes later in the risk assessment process.


NEW QUESTION # 131
......


The CISM certification exam consists of 150 multiple-choice questions, which must be completed within a four-hour time limit. CISM exam covers four domains: Information Security Governance, Information Risk Management and Compliance, Information Security Program Development and Management, and Information Security Incident Management. Candidates who pass the exam are awarded the CISM certification, which is valid for three years.

 

Realistic CramPDF CISM Dumps PDF - 100% Passing Guarantee: https://www.crampdf.com/CISM-exam-prep-dumps.html

Free ISACA CISM Exam Questions and Answer: https://drive.google.com/open?id=1ScVE8hyRLpn7muF5irNAKnGrv3QEQmEq