
2021 Updated Verified CISM dumps Q&As - Pass Guarantee or Full Refund
CISM PDF Questions and Testing Engine With 1340 Questions
NEW QUESTION 726
Which of the following would BEST help to identify vulnerabilities introduced by changes to an organization's technical infrastructure?
- A. An intrusion detection system
- B. Penetration testing
- C. Established security baselines
- D. Log aggregation and correlation
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 727
When building a corporate-wide business continuity plan {BCP), it is discovered there are two separate lines of business systems that could be impacted by the same threat. Which of the following is the BEST method to determine the priority of system recovery in the event of a disaster?
- A. Reviewing each system's key performance indicators (KPIs)
- B. Evaluating the cost associated with each system's outage
- C. Reviewing the business plans of each department
- D. Comparing the recovery point objectives (RPOs)
Answer: D
NEW QUESTION 728
Which of the following is the BEST method to determine whether an information security program meets an organization's business objectives?
- A. Perform a business impact analysis (BIA).
- B. Implement performance measures.
- C. Review against international security standards.
- D. Conduct an annual enterprise-wide security evaluation.
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 729
Who can BEST approve plans to implement an information security governance framework?
- A. Steering committee
- B. Internal auditor
- C. Infrastructure management
- D. Information security management
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Senior management that is part of the security steering committee is in the best position to approve plans to implement an information security governance framework. An internal auditor is secondary' to the authority and influence of senior management. Information security management should not have the authority to approve the security governance framework. Infrastructure management will not be in the best position since it focuses more on the technologies than on the business.
NEW QUESTION 730
Executive leadership has decided to engage a consulting firm to develop and implement a comprehensive security framework for the organization to allow senior management to remain focused on business priorities. Which of the following poses the GREATEST challenge to the successful implementation of the new security governance framework?
- A. Information security staff has little or no experience with the practice of information security governance.
- B. Information Security management does not fully accept the responsibility for information security governance.
- C. Executive leadership views information security governance primarily as a concern of the information security management team.
- D. Executive leadership becomes involved in decisions about information security governance
Answer: C
NEW QUESTION 731
The MOST important factor in ensuring the success of an information security program is effective:
- A. communication of information security requirements to all users in the organization.
- B. formulation of policies and procedures for information security.
- C. alignment with organizational goals and objectives.
- D. monitoring compliance with information security policies and procedures.
Answer: C
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The success of security programs is dependent upon alignment with organizational goals and objectives.
Communication is a secondary step. Effective communication and education of users is a critical determinant of success but alignment with organizational goals and objectives is the most important factor for success.
Mere formulation of policies without effective communication to users will not ensure success. Monitoring compliance with information security policies and procedures can be, at best, a detective mechanism that will not lead to success in the midst of uninformed users.
NEW QUESTION 732
Which of the following is the MOST effective method to help ensure information security incidents are reported?
- A. Implementing an incident management system
- B. Integrating information security language in conditions of employment
- C. Integrating information security language in corporate compliance rules
- D. Providing information security awareness training to employees
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 733
When outsourcing sensitive data to a cloud service provider, which of the following should be the information security manager's MOST important.....
- A. Data stored at the cloud service provider is not co-hosted.
- B. Access authorization includes biometric security verification.
- C. Roles and responsibilities have been defined for the service provider.
- D. The cloud service provider contract includes right to audit.
Answer: D
NEW QUESTION 734
When an organization is implementing an information security governance program, its board of directors should be responsible for:
- A. setting the strategic direction of the program.
- B. auditing for compliance.
- C. reviewing training and awareness programs.
- D. drafting information security policies.
Answer: A
Explanation:
A board of directors should establish the strategic direction of the program to ensure that it is in sync with the company's vision and business goals. The board must incorporate the governance program into the overall corporate business strategy. Drafting information security policies is best fulfilled by someone such as a security manager with the expertise to bring balance, scope and focus to the policies. Reviewing training and awareness programs may best be handled by security management and training staff to ensure that the training is on point and follows best practices. Auditing for compliance is best left to the internal and external auditors to provide an objective review of the program and how it meets regulatory and statutory compliance.
NEW QUESTION 735
Which of the following circumstances would MOST likely require a review and update to an organization's information security incident response plan?
- A. A new business strategy has been developed.
- B. The organizational structure has changed.
- C. A new business application has been implemented.
- D. A high-risk vulnerability has been detected.
Answer: C
NEW QUESTION 736
Which of the following has the GREATEST impact on efforts to improve an organization's security posture?
- A. Automation of security controls
- B. Well-documented security policies and procedures
- C. Supportive tone at the top management regarding security
- D. Regular reporting to senior management
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 737
The BEST reason for an organization to have two discrete firewalls connected directly to the Internet and to the same DMZ would be to:
- A. prevent a denial-of-service attack.
- B. provide in-depth defense.
- C. separate test and production.
- D. permit traffic load balancing.
Answer: D
Explanation:
Explanation
Having two entry points, each guarded by a separate firewall, is desirable to permit traffic load balancing. As they both connect to the Internet and to the same demilitarized zone (DMZ), such an arrangement is not practical for separating test from production or preventing a denial-of-service attack.
NEW QUESTION 738
A benefit of using a full disclosure (white box) approach as compared to a blind (black box) approach to penetration testing is that:
- A. critical infrastructure information is not revealed to the tester.
- B. less time is spent on reconnaissance and information gathering.
- C. human intervention is not required for this type of test.
- D. it simulates the real-life situation of an external security attack.
Answer: B
Explanation:
Explanation
Data and information required for penetration are shared with the testers, thus eliminating time that would otherwise have been spent on reconnaissance and gathering of information. Blind (black box) penetration testing is closer to real life than full disclosure (white box) testing. There is no evidence to support that human intervention is not required for this type of test. A full disclosure (white box) methodology requires the knowledge of the subject being tested.
NEW QUESTION 739
The GREATEST benefit of choosing a private cloud over a public cloud would be:
- A. server protection.
- B. online service availability.
- C. containment of customer data.
- D. collection of data forensics.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 740
Which of the following reports would provide the BEST overview of the progress of an information security program to senior management?
- A. Key performance indicators (KPIs) related to security initiatives
- B. Heat map of the current risk landscape
- C. Results of the last penetration test
- D. Inventory of information technology security controls
Answer: B
NEW QUESTION 741
Which of the following BEST demonstrates that an organization supports information security governance?
- A. Information security steering committee meetings are held regularly.
- B. Employees attend annual organization-wide security training.
- C. The incident response plan is documented and tested regularly.
- D. Information security policies are readily available to employees.
Answer: A
NEW QUESTION 742
A contract bid is digitally signed and electronically mailed. The PRIMARY advantage to using a digital signature is that:
- A. any alteration of the bid will invalidate the signature
- B. the bid and the signature can be copied from one document to another
- C. the signature can be authenticated even if no encryption is used
- D. the bid cannot be forged even if the keys are compromised
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 743
At what stage of the applications development process would encryption key management initially be addressed?
- A. Systems testing
- B. Deployment
- C. Requirements development
- D. Code reviews
Answer: C
Explanation:
Explanation
Encryption key management has to be integrated into the requirements of the application's design. During systems testing and deployment would be too late since the requirements have already been agreed upon. Code reviews are part of the final quality assurance (QA) process and would also be too late in the process.
NEW QUESTION 744
Which of the following MOST effectively helps an organization to align information security governance with corporate governance?
- A. Adopting global security standards to achieve business goals
- B. Developing security performance metrics
- C. Prioritizing security initiatives based on IT strategy
- D. Promoting security as enabler 10 achieve business objectives
Answer: D
NEW QUESTION 745
When a proposed system change violates an existing security standard, the conflict would be BEST resolved by:
- A. implementing mitigating controls.
- B. enforcing the security standard.
- C. calculating the residual risk.
- D. redesigning the system change.
Answer: A
NEW QUESTION 746
Acceptable risk is achieved when:
- A. control risk is minimized.
- B. inherent risk is minimized.
- C. transferred risk is minimized.
- D. residual risk is minimized.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Residual risk is the risk that remains after putting into place an effective risk management program; therefore, acceptable risk is achieved when this amount is minimized. Transferred risk is risk that has been assumed by a third party and may not necessarily be equal to the minimal form of residual risk. Control risk is the risk that controls may not prevent/detect an incident with a measure of control effectiveness.
Inherent risk cannot be minimized.
NEW QUESTION 747
Which of the following is the PRIMARY benefit to an organization using an automated event monitoring solution?
- A. Reduced need for manual analysis
- B. Improved response time to incidents
- C. Enhanced forensic analysis
- D. Improved network protection
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation
NEW QUESTION 748
When performing a quantitative risk analysis, which of the following is MOST important to estimate the potential loss?
- A. Evaluate productivity losses
- B. Calculate the value of the information or asset
- C. Assess the impact of confidential data disclosure
- D. Measure the probability of occurrence of each threat
Answer: B
Explanation:
Explanation
Calculating the value of the information or asset is the first step in a risk analysis process to determine the impact to the organization, which is the ultimate goal. Determining how much productivity could be lost and how much it would cost is a step in the estimation of potential risk process. Knowing the impact if confidential information is disclosed is also a step in the estimation of potential risk. Measuring the probability of occurrence for each threat identified is a step in performing a threat analysis and therefore a partial answer.
NEW QUESTION 749
Which of the following sites would be MOST appropriate in the case of a very short recovery time objective (RTO)?
- A. Warm
- B. Mobile
- C. Shared
- D. Redundant
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference: https://searchdisasterrecovery.techtarget.com/answer/Whats-the-difference-between-a-hot-site- and-cold-site-for-disaster-recovery
NEW QUESTION 750
......
Exam Engine for CISM Exam Free Demo & 365 Day Updates: https://www.actualcollection.com/CISM-exam-questions.html
Test Engine to Practice Test for CISM Valid and Updated Dumps: https://drive.google.com/open?id=1T3IhDx0vcQV7QtRVgjV9MKYqZXr4c92A