
Steps Necessary To Pass The CISM Exam from Training Expert CramPDF
Valid Way To Pass Isaca Certification's CISM Exam
NEW QUESTION 149
A major trading partner with access to the internal network is unwilling or unable to remediate serious information security exposures within its environment. Which of the following is the BEST recommendation?
- A. Set up firewall rules restricting network traffic from that location
- B. Send periodic reminders advising them of their noncompliance
- C. Sign a legal agreement assigning them all liability for any breach
- D. Remove all trading partner access until the situation improves
Answer: A
Explanation:
It is incumbent on an information security manager to see to the protection of their organization's network, but to do so in a manner that does not adversely affect the conduct of business. This can be accomplished by adding specific traffic restrictions for that particular location. Removing all access will likely result in lost business. Agreements and reminders do not protect the integrity of the network.
NEW QUESTION 150
Which of the following enables compliance with a nonrepudiation policy requirement for electronic transactions?
- A. Digital signatures
- B. Digital certificates
- C. One-time passwords
- D. Encrypted passwords
Answer: A
NEW QUESTION 151
Risk scenarios simplify the risk assessment process by:
- A. reducing the need for subsequent risk evaluation.
- B. ensuring business risk is mitigated.
- C. covering the full range of possible risk.
- D. focusing on important and relevant risk.
Answer: D
NEW QUESTION 152
Which of the following is MOST critical for prioritizing actions in a business continuity plan (BCP)?
- A. Business process mapping
- B. Business impact analysis (BIA)
- C. Asset classification
- D. Risk assessment
Answer: B
NEW QUESTION 153
The cost of implementing a security control should not exceed the:
- A. implementation opportunity costs.
- B. asset value.
- C. cost of an incident.
- D. annualized loss expectancy.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The cost of implementing security controls should not exceed the worth of the asset. Annualized loss expectancy represents the losses drat are expected to happen during a single calendar year. A security mechanism may cost more than this amount (or the cost of a single incident) and still be considered cost effective. Opportunity costs relate to revenue lost by forgoing the acquisition of an item or the making of a business decision.
NEW QUESTION 154
Which of the following BEST enables a more efficient incident reporting process?
- A. Training executive management for communication with external entities
- B. Training end users to identify abnormal events
- C. Educating the incident response team on escalation procedures
- D. Educating IT teams on compliance requirements
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation
NEW QUESTION 155
Which of the following is MOST essential for a risk management program to be effective?
- A. Flexible security budget
- B. Accurate risk reporting
- C. New risks detection
- D. Sound risk baseline
Answer: C
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
All of these procedures are essential for implementing risk management. However, without identifying new risks, other procedures will only be useful for a limited period.
NEW QUESTION 156
Which of the following is a MAIN security challenge when conducting a post-incident review related to bring your own device (BYOD) in a mature, diverse organization?
- A. Lack of mobile forensics expertise
- B. Ability to obtain possession of devices
- C. Diversity of operating systems
- D. Ability to access devices remotely
Answer: B
NEW QUESTION 157
Which of the following is the BEST metric for evaluating the effectiveness of an intrusion detection mechanism?
- A. Ratio of successful to unsuccessful attacks
- B. Number of attacks detected
- C. Number of successful attacks
- D. Ratio of false positives to false negatives
Answer: D
Explanation:
Explanation
The ratio of false positives to false negatives will indicate whether an intrusion detection system (IDS) is properly tuned to minimize the number of false alarms while, at the same time, minimizing the number of omissions. The number of attacks detected, successful attacks or the ratio of successful to unsuccessful attacks would not indicate whether the IDS is properly configured.
NEW QUESTION 158
Senior management commitment and support for information security can BEST be obtained through presentations that:
- A. evaluate the organization against best security practices.
- B. use illustrative examples of successful attacks.
- C. tie security risks to key business objectives.
- D. explain the technical risks to the organization.
Answer: C
Explanation:
Senior management seeks to understand the business justification for investing in security. This can best be accomplished by tying security to key business objectives. Senior management will not be as interested in technical risks or examples of successful attacks if they are not tied to the impact on business environment and objectives. Industry best practices are important to senior management but, again, senior management will give them the right level of importance when they are presented in terms of key business objectives.
NEW QUESTION 159
An organization is already certified to an international security standard. Which mechanism would BEST help to further align the organization with other data security regulatory requirements as per new business needs?
- A. Technical vulnerability assessment
- B. Gap analysis
- C. Business impact analysis (BIA)
- D. Key performance indicators (KPIs)
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Gap analysis would help identify the actual gaps between the desired state and the current implementation of information security management. BIA is primarily used for business continuity planning. Technical vulnerability assessment is used for detailed assessment of technical controls, which would come later in the process and would not provide complete information in order to identify gaps.
NEW QUESTION 160
Relationships among security technologies are BEST defined through which of the following?
- A. Security architecture
- B. Security metrics
- C. Network topology
- D. Process improvement models
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Security architecture explains the use and relationships of security mechanisms. Security metrics measure improvement within the security practice but do not explain the use and relationships of security technologies.
Process improvement models and network topology diagrams also do not describe the use and relationships of these technologies.
NEW QUESTION 161
Which of the following is the MOST effective way of ensuring that business units comply with an information security governance framework?
- A. Integrating security requirements with processes
- B. Conducting a business impact analysis (BIA)
- C. Performing security assessments and gap analyses
- D. Conducting information security awareness training
Answer: D
NEW QUESTION 162
Who should be responsible for determining the classification of data within a database used in conjunction with an enterprise application?
- A. Data owner
- B. Database architect
- C. Information security manager
- D. Database administrator
Answer: A
NEW QUESTION 163
Which of the following is the MOST effective method to help ensure information security incidents are reported?
- A. Integrating information security language in conditions of employment
- B. Integrating information security language in corporate compliance rules
- C. Providing information security awareness training to employees
- D. Implementing an incident management system
Answer: C
NEW QUESTION 164
Who should decide the extent to which an organization will comply with new cybersecurity regulatory requirements?
- A. Senior management
- B. IT steering committee
- C. Information security manager
- D. Legal counsel
Answer: A
Explanation:
Section: MIXED QUESTIONS
NEW QUESTION 165
Which of the following practices BEST supports the achievement of information security program objectives in the IT function?
- A. Review and approval of IT projects by the information security manager
- B. Participation of IT stakeholders in the security program steering committee
- C. Continuous security auditing of IT service processes
- D. IT management sign-off on information security policies
Answer: B
NEW QUESTION 166
An information security manager has discovered a potential security breach in a server that supports a critical business process. Which of the following should be the information security manager's FIRST course of action?
- A. Shut down the server in an organized manner.
- B. Validate that there has been an incident.
- C. Notify the business process owner.
- D. Inform senior management of the incident.
Answer: B
Explanation:
Section: MIXED QUESTIONS
NEW QUESTION 167
Which of the following attacks is BEST mitigated by utilizing strong passwords?
- A. Brute force attack
- B. Root kit
- C. Remote buffer overflow
- D. Man-in-the-middle attack
Answer: A
Explanation:
Explanation/Reference:
Explanation:
A brute force attack is normally successful against weak passwords, whereas strong passwords would not prevent any of the other attacks. Man-in-the-middle attacks intercept network traffic, which could contain passwords, but is not naturally password-protected. Remote buffer overflows rarely require a password to exploit a remote host. Root kits hook into the operating system's kernel and, therefore, operate underneath any authentication mechanism.
NEW QUESTION 168
Which of the following is the PRIMARY role of the information security manager in application development? To ensure:
- A. compliance with industry best practice.
- B. security is integrated into the system development life cycle (SDLC).
- C. enterprise security controls are implemented.
- D. control procedures address business risk.
Answer: B
NEW QUESTION 169
The MAIN goal of an information security strategic plan is to:
- A. establish security governance.
- B. protect information assets and resources.
- C. develop a data protection plan.
- D. develop a risk assessment plan.
Answer: B
Explanation:
Explanation
The main goal of an information security strategic plan is to protect information assets and resources.
Developing a risk assessment plan and H data protection plan, and establishing security governance refer to tools utilized in the security strategic plan that achieve the protection of information assets and resources.
NEW QUESTION 170
Which of the following would be the MOST important factor to be considered in the loss of mobile equipment with unencrypted data?
- A. Replacement cost of the equipment
- B. Sufficient coverage of the insurance policy for accidental losses
- C. Disclosure of personal information
- D. Intrinsic value of the data stored on the equipment
Answer: D
Explanation:
Explanation
When mobile equipment is lost or stolen, the information contained on the equipment matters most in determining the impact of the loss. The more sensitive the information, the greater the liability. If staff carries mobile equipment for business purposes, an organization must develop a clear policy as to what information should be kept on the equipment and for what purpose. Personal information is not defined in the question as the data that were lost. Insurance may be a relatively smaller issue as compared with information theft or opportunity loss, although insurance is also an important factor for a successful business. Cost of equipment would be a less important issue as compared with other choices.
NEW QUESTION 171
Which of the following recovery strategies has the GREATEST chance of failure?
- A. Reciprocal arrangement
- B. Redundant site
- C. Hot site
- D. Cold site
Answer: A
Explanation:
Explanation
A reciprocal arrangement is an agreement that allows two organizations to back up each other during a disaster. This approach sounds desirable, but has the greatest chance of failure due to problems in keeping agreements and plans up to date. A hot site is incorrect because it is a site kept fully equipped with processing capabilities and other services by the vendor. A redundant site is incorrect because it is a site equipped and configured exactly like the primary site. A cold site is incorrect because it is a building having a basic environment such as electrical wiring, air conditioning, flooring, etc. and is ready to receive equipment in order to operate.
NEW QUESTION 172
......
All CISM Dumps and Certified Information Security Manager Training Courses: https://www.crampdf.com/CISM-exam-prep-dumps.html
Free Test Engine For Certified Information Security Manager Certification Exams: https://drive.google.com/open?id=1q9xZX0UljW_mlgXlL1Efnoy3xPt9qlxU