Download Free ISACA CISM Exam Questions & Answer [Q112-Q133]

Share

Download Free ISACA CISM Exam Questions & Answer 

Online VALID CISM Exam Dumps File Instantly


What Are the Primary Sections Featured in the Isaca CISM Exam?

Adding this certification into your profile verifies that you have a broad set of skills that you can apply for solving different issues in the workplace. And these are covered in the domains of the the CISM exam. Let's go into these one by one.

  • Information risk management

    CISM ensures that you get the right skills essential for risk management. Mastering the tools and techniques related to this particular process helps you easily distinguish, evaluate, and control possible threats that may affect the business' operations and financial flow. Another thing that makes this area more challenging is the extensive sources of threats, which may include management errors, legal liabilities, and even natural disasters. As a result, it's important to know the entire risk management frameworks, along with related functionalities such as security control selection, risk visibility, reporting, and actions.

  • Information security program development and management

    For the third section, it's all about program development and administration. At this point, one becomes more competent in the scope of an information security program as well as the entire management framework. Additionally, there will be a comprehensive elaboration of the list of operational and administrative activities, together with typical program challenges, controls, and countermeasures. The general security infrastructure and architecture are also vital topics.

  • Information security incident management

    Now, we're down to the last part of the exam and that is IS incident management. This domain requires candidates to know critical information about incident management as a whole. From there, it underscores one's skills in dealing with incident metrics, indicators, response methodologies, response plans, and management resources. Other areas that need your attention are business continuity, disaster recovery procedures, and post-incident activities. Being able to expound on the present situation of incident response is substantial too.

  • Information security governance

    Information security governance, in general, is the way you utilize and lead the company's methodology to security. Proper handling of this crucial aspect greatly affects the core security activities of the business. In addition, it allows a smooth-sailing flow of security details within the organization. Aside from aligning the security with the key objectives, it's also significant to have a profound comprehension of the structural processes, security roles, and control frameworks.

 

NEW QUESTION 112
Which of the following is the BEST way to facilitate the alignment between an organization's information security program and business objectives?

  • A. Information security is considered at the feasibility stage of all IT projects.
  • B. The chief executive officer reviews and approves the information security program.
  • C. The information security program is audited by the internal audit department.
  • D. The information security governance committee includes representation from key business areas.

Answer: D

 

NEW QUESTION 113
Investments in information security technologies should be based on:

  • A. business climate.
  • B. vulnerability assessments.
  • C. audit recommendations.
  • D. value analysis.

Answer: D

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Investments in security technologies should be based on a value analysis and a sound business case.
Demonstrated value takes precedence over the current business climate because it is ever changing. Basing decisions on audit recommendations would be reactive in nature and might not address the key business needs comprehensively. Vulnerability assessments are useful, but they do not determine whether the cost is justified.

 

NEW QUESTION 114
To justify the need to invest in a forensic analysis tool, an information security manager should FIRST:

  • A. review comparison reports of tool implementation in peer companies.
  • B. substantiate the investment in meeting organizational needs.
  • C. provide examples of situations where such a tool would be useful.
  • D. review the functionalities and implementation requirements of the solution.

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Any investment must be reviewed to determine whether it is cost effective and supports the organizational strategy. It is important to review the features and functionalities provided by such a tool, and to provide examples of situations where the tool would be useful, but that comes after substantiating the investment and return on investment to the organization.

 

NEW QUESTION 115
Which of the following techniques MOST clearly indicates whether specific risk-reduction controls should be implemented?

  • A. Penetration testing
  • B. Annual loss expectancy (ALE) calculation
  • C. Frequent risk assessment programs
  • D. Countermeasure cost-benefit analysis

Answer: D

Explanation:
Explanation
In a countermeasure cost-benefit analysis, the annual cost of safeguards is compared with the expected cost of loss. This can then be used to justify a specific control measure. Penetration testing may indicate the extent of a weakness but, by itself, will not establish the cost/benefit of a control. Frequent risk assessment programs will certainly establish what risk exists but will not determine the maximum cost of controls. Annual loss expectancy (ALE) is a measure which will contribute to the value of the risk but. alone, will not justify a control.

 

NEW QUESTION 116
An organization has concerns regarding a potential advanced persistent threat (APT). To ensure that the risk associated with this threat is appropriately managed, what should be the organization's FIRST action?

  • A. Implement additional controls.
  • B. Initiate incident response processes.
  • C. Report to senior management.
  • D. Conduct an impact analysis.

Answer: D

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 117
If the inherent risk of a business activity is higher than the acceptable risk level, the information security manager should FIRST

  • A. transfer risk to a third party to avoid cost of impact
  • B. recommend that management avoids the business activity
  • C. implement controls to mitigate the risk to an acceptable level
  • D. assess the gap between current and acceptable level of risk

Answer: C

 

NEW QUESTION 118
The PRIMARY goal of a post-incident review should be to:

  • A. determine how to improve the incident handling process.
  • B. determine why the incident occurred.
  • C. identify policy changes to prevent a recurrence.
  • D. establish the cost of the incident to the business.

Answer: C

 

NEW QUESTION 119
Which of the following is the MOST important reason to have documented security procedures and guidelines?

  • A. To enable standard security practices
  • B. To meet regulatory compliance requirements
  • C. To allocate security responsibilities to staff
  • D. To facilitate collection of security metrics

Answer: A

 

NEW QUESTION 120
A project manager is developing a developer portal and requests that the security manager assign a public IP address so that it can be accessed by in-house staff and by external consultants outside the organization's local area network (LAN). What should the security manager do FIRST?

  • A. Understand the business requirements of the developer portal
  • B. Install an intrusion detection system (IDS)
  • C. Obtain a signed nondisclosure agreement (NDA) from the external consultants before allowing external access to the server
  • D. Perform a vulnerability assessment of the developer portal

Answer: A

Explanation:
The information security manager cannot make an informed decision about the request without first understanding the business requirements of the developer portal. Performing a vulnerability assessment of developer portal and installing an intrusion detection system (IDS) are best practices but are subsequent to understanding the requirements. Obtaining a signed nondisclosure agreement will not take care of the risks inherent in the organization's application.

 

NEW QUESTION 121
Which of the following mechanisms is the MOST secure way to implement a secure wireless network?

  • A. Filter media access control (MAC) addresses
  • B. Web-based authentication
  • C. Use a Wired Equivalent Privacy (WEP) key
  • D. Use a Wi-Fi Protected Access (WPA2) protocol

Answer: D

Explanation:
Explanation/Reference:
Explanation:
WPA2 is currently one of the most secure authentication and encryption protocols for mainstream wireless products. MAC address filtering by itself is not a good security mechanism since allowed MAC addresses can be easily sniffed and then spoofed to get into the network. WEP is no longer a secure encryption mechanism for wireless communications. The WEP key can be easily broken within minutes using widely available software. And once the WEP key is obtained, all communications of every other wireless client are exposed. Finally, a web-based authentication mechanism can be used to prevent unauthorized user access to a network, but it will not solve the wireless network's main security issues, such as preventing network sniffing.

 

NEW QUESTION 122
An information security manager has developed a strategy to address new information security risks resulting from recent change the business. Which of the following would be MOST important to include when presenting the strategy to senior management?

  • A. Results of benchmarking against industry peers
  • B. The costs associated with business process changes
  • C. Security controls needed for risk mitigation
  • D. The impact of organizational changes on the security risk profile

Answer: D

 

NEW QUESTION 123
Which of the following information security metrics would be MOST meaningful to executive management in assessing the effectiveness of the information security strategy?

  • A. Monthly cost of maintaining information security controls
  • B. Number of information security policy violations reported quarterly
  • C. Monthly cost of interruptions in core processes due to security incidents
  • D. Percentage of systems that are patched within the required time period

Answer: C

 

NEW QUESTION 124
Which of the following is MOST important to understand when developing a meaningful information security strategy?

  • A. International security standards
  • B. Regulatory environment
  • C. Organizational risks
  • D. Organizational goals

Answer: D

Explanation:
Alignment of security with business objectives requires an understanding of what an organization is trying to accomplish. The other choices are all elements that must be considered, but their importance is secondary and will vary depending on organizational goals.

 

NEW QUESTION 125
When designing security controls, it is

  • A. evaluate the costs associated with the controls.
  • B. apply controls to confidential information.
  • C. apply a risk-based approach.
  • D. focus on preventive controls.

Answer: C

 

NEW QUESTION 126
The PRIMARY goal of a security infrastructure design is the:

  • A. protection of corporate assets.
  • B. elimination of risk exposures.
  • C. reduction of security incidents.
  • D. optimization of IT resources.

Answer: A

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 127
Before engaging outsourced providers, an information security manager should ensure that the organization's data classification requirements:

  • A. exceed those of the outsourcer.
  • B. are communicated to the provider.
  • C. are compatible with the provider's own classification.
  • D. are stated in the contract.

Answer: D

Explanation:
The most effective mechanism to ensure that the organization's security standards are met by a third party, would be a legal agreement. Choices A. B and C are acceptable options, but not as comprehensive or as binding as a legal contract.

 

NEW QUESTION 128
For an organization with a large and complex IT infrastructure, which of the following elements of a disaster recovery hot site service will require the closest monitoring?

  • A. Audit tights
  • B. Systems configurations
  • C. Employee access
  • D. Number of subscribers

Answer: B

 

NEW QUESTION 129
Which of the following BEST enables the integration of information security governance into corporate governance?

  • A. An information security steering committee with business representation
  • B. Clear lines of authority across the organization
  • C. Senior management approval of the information security strategy
  • D. Well-decumented information security policies and standards

Answer: A

 

NEW QUESTION 130
Which of the following metrics provides the BEST indication of the effectiveness of a security awareness campaign?

  • A. Percentage of users who have taken the courses
  • B. The number of reported security events
  • C. User approval rating of security awareness classes
  • D. Quiz scores for users who took security awareness classes

Answer: B

 

NEW QUESTION 131
The criticality and sensitivity of information assets is determined on the basis of:

  • A. threat assessment.
  • B. vulnerability assessment.
  • C. resource dependency assessment.
  • D. impact assessment.

Answer: D

Explanation:
Explanation
The criticality and sensitivity of information assets depends on the impact of the probability of the threats exploiting vulnerabilities in the asset, and takes into consideration the value of the assets and the impairment of the value. Threat assessment lists only the threats that the information asset is exposed to. It does not consider the value of the asset and impact of the threat on the value. Vulnerability assessment lists only the vulnerabilities inherent in the information asset that can attract threats. It does not consider the value of the asset and the impact of perceived threats on the value. Resource dependency assessment provides process needs but not impact.

 

NEW QUESTION 132
In a business proposal, a potential vendor promotes being certified for international security standards as a measure of its security capability.
Before relying on this certification, it is MOST important that the information security manager confirms that the:

  • A. current international standard was used to assess security processes.
  • B. certification scope is relevant to the service being offered.
  • C. certification will remain current through the life of the contract.
  • D. certification can be extended to cover the client's business.

Answer: B

 

NEW QUESTION 133
......

CISM Exam Dumps For Certification Exam Preparation: https://prep4sure.real4dumps.com/CISM-prep4sure-exam.html