
Best ISACA CISM-CN Exam Practice Material Updated on Nov 11, 2023
New CISM-CN Actual Exam Dumps, ISACA Practice Test
NEW QUESTION # 174
以下哪項是信息安全治理的預期結果?
- A. 改進風險管理
- B. 成熟度模型
- C. 業務敏捷性
- D. 滲透測試
Answer: A
NEW QUESTION # 175
與白盒控制測試相比,執行黑盒控制測試的主要優點是:
- A. 需要較少的IT人員準備。
- B. 模擬現實世界的攻擊。
- C. 識別更多威脅。
- D. 減少潛在的生產問題。
Answer: B
Explanation:
The primary advantage of performing black-box control tests as opposed to white-box control tests is that they simulate real-world attacks. Black-box control tests are a software testing methodology in which the tester analyzes the functionality of an application without a thorough knowledge of its internal design. Conversely, in white-box control tests, the tester is knowledgeable of the internal design of the application and analyzes it during testing. By performing black-box control tests, the tester can mimic the perspective and behavior of an external attacker who does not have access to the source code or the implementation details of the application. This way, the tester can evaluate how the application responds to different inputs and scenarios, and identify any vulnerabilities or errors that may affect its functionality or security. The other options are not the primary advantage of performing black-box control tests, although they may be some benefits or drawbacks depending on the context. Causing fewer potential production issues is not necessarily true, as black-box control tests may still introduce errors or disruptions to the application if not performed carefully. Requiring less IT staff preparation is not always true, as black-box control tests may still require a lot of planning and documentation to ensure adequate test coverage and quality. Identifying more threats is not necessarily true, as black-box control tests may miss some threats that are hidden in the internal logic or structure of the application.
NEW QUESTION # 176
以下哪一方应负责确定处理客户信息的应用程序的访问级别?
- A. 业务单元管理
- B. 信息安全撕裂
- C. 身份和访问管理团队
- D. 商业客户
Answer: A
NEW QUESTION # 177
以下哪一项最有效地防止引入可能破坏关键业务应用程序可用性的漏洞?
- A. 版本控制
- B. 变更管理控制
- C. 逻辑访问控制
- D. 补丁管理进程
Answer: D
NEW QUESTION # 178
如果民事訴訟是組織響應安全事件的目標,則主要步驟應該是:
- A. 聯繫執法部門。
- B. 在安全區域重新啟動受影響的計算機以搜索證據。
- C. 記錄監管鏈。
- D. 使用標準服務器備份實用程序捕獲證據。
Answer: C
NEW QUESTION # 179
以下哪一项最能保证安全策略适用于整个业务运营?
- A. 组织标准记录在操作程序中。
- B. 组织标准由技术控制强制执行。
- C. 组织标准包含在意识培训中。
- D. 组织标准需要被正式接受。
Answer: A
NEW QUESTION # 180
以下哪項最能確保應用程序開發過程中集成安全性?
- A. 在啟動階段引入安全要求
- B. 在驗收測試期間執行應用程序安全測試
- C. 為程序員提供安全開發實踐培訓
- D. 在開發過程中採用全球安全標準
Answer: C
NEW QUESTION # 181
以下哪項最能幫助組織持續保證滿足法律和法規合規性要求?
- A. 分配運營經理滿足合規性要求的責任
- B. 定期審核以確保遵守法律和監管要求
- C. 聘請外部專家就合規要求的變化提供指導
- D. 將合規性要求嵌入運營流程中
Answer: D
Explanation:
Embedding compliance requirements within operational processes ensures that they are consistently followed and monitored as part of normal business activities. This provides ongoing assurance that legal and regulatory compliance requirements can be met. The other choices are not as effective as embedding compliance requirements within operational processes.
Regulatory compliance involves following external legal mandates set forth by state, federal, or international government2. Compliance requirements may vary depending on the industry, location, and nature of the organization2. Compliance helps organizations avoid legal penalties, protect their reputation, and ensure ethical conduct2.
NEW QUESTION # 182
威胁和脆弱性评估很重要,主要是因为它们是:
- A. 组织安全态势的要素。
- B. 需要评估风险。
- C. 用于建立安全投资
- D. 设定控制目标的依据。
Answer: D
Explanation:
Threat and vulnerability assessments are important PRIMARILY because they are the basis for setting control objectives. Control objectives are the desired outcomes or goals of implementing security controls in an information system. They are derived from the risk assessment process, which identifies and evaluates the threats and vulnerabilities that could affect the system's confidentiality, integrity and availability. By conducting threat and vulnerability assessments, an organization can determine the level of risk it faces and establish the appropriate control objectives to mitigate those risks.
NEW QUESTION # 183
在哪種雲模型中,雲服務購買者承擔最多的安全責任?
- A. 平台即服務 (PaaS)
- B. 基礎設施即服務 (laaS)
- C. 軟件即服務 (SaaS)
- D. 災難恢復即服務 (DRaaS)
Answer: B
NEW QUESTION # 184
以下哪项对于信息安全治理计划的有效实施最为重要?
- A. 员工接受定制的信息安全培训
- B. 记录信息安全角色和职责。
- C. 项目目标已被组织传达和理解。
- D. 项目预算由高级管理层批准和监督
Answer: C
Explanation:
The program goals are communicated and understood by the organization is the most important factor for the effective implementation of an information security governance program because it ensures that the program is aligned with the business objectives and supported by the stakeholders. Employees receive customized information security training is not the most important factor, but rather a means to achieve the program goals and raise awareness among the staff. The program budget is approved and monitored by senior management is not the most important factor, but rather a resource to enable the program activities and measure its performance. Information security roles and responsibilities are documented is not the most important factor, but rather a way to define and assign the program tasks and accountabilities. Reference: https://www.isaca.org/resources/isaca-journal/issues/2015/volume-1/how-to-measure-the-effectiveness-of-information-security-governance https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/how-to-align-security-initiatives-with-business-goals-and-objectives
NEW QUESTION # 185
當需要連續正常運行時間時,哪種方法是評估備用處理站點有效性的最佳方法?
- A. 並行測試
- B. 桌面測試
- C. 全中斷測試
- D. 模擬測試
Answer: A
NEW QUESTION # 186
以下哪项最重要,应包含在向主要利益相关者提交的有关信息安全计划有效性的报告中?
- A. 安全事件详细信息
- B. 安全指标
- C. 安全风险暴露
- D. 安全基线
Answer: B
Explanation:
Security metrics are the most important to include in a report to key stakeholders regarding the effectiveness of an information security program because they provide objective and measurable evidence of security performance and progress. Security metrics can include measures such as the number and severity of security incidents, the level of compliance with security policies and standards, the effectiveness of security controls, and the return on investment (ROI) of security initiatives. The other choices may also be included in a security report, but security metrics are the most important.
An information security program is a set of policies, procedures, standards, guidelines, and tools that aim to protect an organization's information assets from threats and ensure compliance with laws and regulations. The effectiveness of an information security program depends on various factors, such as the organization's risk appetite, business objectives, resources, culture, and external environment. Regular reporting to key stakeholders, such as senior management, the board of directors, and business partners, is critical to maintaining their support and buy-in for the program. The report should provide clear and concise information on the program's status, achievements, challenges, and future plans, and it should be tailored to the audience's needs and expectations.
NEW QUESTION # 187
以下哪项应该是信息安全事件分类严重性等级的主要基础?
- A. 对业务的不利影响
- B. 根本原因分析结果
- C. 法律法规要求
- D. 资源的可用性
Answer: A
Explanation:
The severity hierarchy for information security incident classification should be based on the potential or actual impact of the incident on the business objectives, operations, reputation, and stakeholders. The adverse effects on the business can be measured by criteria such as financial loss, operational disruption, legal liability, regulatory compliance, customer satisfaction, and public confidence. The other options are not the primary basis for a severity hierarchy, although they may be considered as secondary factors or consequences of an incident
NEW QUESTION # 188
識別與社會工程攻擊相關的風險的最佳方法是:
- A. 對電子郵件過濾系統進行業務風險評估。
- B. 監控入侵檢測系統(IDS),
- C. 測試用戶對信息安全實踐的了解。
- D. 檢查單點登錄 (SSO) 身份驗證滯後。
Answer: C
NEW QUESTION # 189
席位托管组织的数据中心设有服务器、应用程序
为组织制定物理访问控制策略的最佳方法?
- A. 设计单点登录 (SSO) 或联合访问。
- B. 进行风险评估以确定安全风险和缓解控制措施。
- C. 审查客户的安全政策。
- D. 为每个系统和应用制定访问控制要求。
Answer: B
NEW QUESTION # 190
一个组织最近外包了一个任务关键型业务应用程序的开发。以下哪项是测试后门是否存在的最佳方法?
- A. 从测试系统上的高权限帐户运行应用程序。
- B. 使用漏洞扫描工具扫描整个应用程序。
- C. 监控互联网流量是否有敏感信息泄露。
- D. 对整个应用程序执行安全代码审查。
Answer: D
NEW QUESTION # 191
一个组织正计划外包其灾难恢复活动的执行。外包协议中应包含以下哪项最重要?
- A. 恢复时间目标 (RTO)
- B. 定义何时应宣布灾难
- C. 定期测试备份的要求
- D. 灾难恢复沟通计划
Answer: D
NEW QUESTION # 192
一个组织正在制定一项风险缓解计划,该计划考虑冗余电源以降低与关键系统中断相关的业务风险。正在考虑哪种类型的控制?
- A. 纠正
- B. 侦探
- C. 威慑
- D. 预防
Answer: D
NEW QUESTION # 193
信息安全经理了解到 IT 人员没有遵守信息安全策略,因为这导致流程效率低下。信息安全经理应该首先做什么?
- A. 建议 IT 更新信息安全政策和程序。
- B. 在 IT 职能部门内进行用户意识培训。
- C. 要求内部审计对政策制定过程进行审查,
- D. 确定与不遵守政策相关的风险。
Answer: D
NEW QUESTION # 194
每日監控報告顯示,一名 IT 員工在變更控制流程之外對防火牆規則進行了更改。信息安全經理解決該問題的第一步應該是:
- A. 審查變更管理流程
- B. 要求撤銷更改
- C. 向高級管理層報告事件
- D. 執行變更分析
Answer: D
Explanation:
Performing an analysis of the change is the first step in addressing the issue of an IT employee making a change to a firewall rule outside of the change control process because it helps to understand the reason, impact, and risk of the change and to decide whether to approve, reject, or reverse it. Requiring that the change be reversed is not the first step because it may cause more disruption or damage without proper analysis and testing. Reviewing the change management process is not the first step because it does not address the specific issue or incident at hand, but rather focuses on improving the process for future changes. Reporting the event to senior management is not the first step because it does not resolve the issue or incident, but rather escalates it without sufficient information or recommendation. Reference: https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/change-management-in-the-age-of-digital-transformation https://www.isaca.org/resources/isaca-journal/issues/
NEW QUESTION # 195
ACISO 了解到,第三方服務提供商沒有向該組織通報影響該服務提供商數據中心的數據洩露事件。CISO 應首先執行以下哪項操作?
- A. 確定對組織的影響程度。
- B. 通知受影響的客戶數據洩露。
- C. 建議取消外包合同。
- D. 請求對提供商的數據中心進行獨立審查。
Answer: A
NEW QUESTION # 196
一个组织的质量过程可以通过提供以下内容来最好地支持安全管理:
- A. 安全策略指导。
- B. 确保满足安全要求。
- C. 安全配置控件。
- D. 安全系统文档的存储库。
Answer: B
Explanation:
An organization's quality process can BEST support security management by providing assurance that security requirements are met. This means that the quality process can be used to ensure that security controls are being implemented as intended and that they are achieving the desired results. This helps to ensure that the organization is properly protected and that it is in compliance with security regulations and standards.
NEW QUESTION # 197
以下哪項是減少不必要的合規活動重複的最佳方法?
- A. 合規要求標準化
- B. 控製程序的文檔
- C. 保障工作的整合
- D. 控制自動化
Answer: A
NEW QUESTION # 198
以下哪项是在实施控制时征求风险负责人意见的最重要原因?
- A. 解决企业架构(EA)中的漏洞
- B. 消除影响业务的威胁
- C. 将风险控制在可接受的水平
- D. 降低风险缓解成本
Answer: C
Explanation:
According to the Certified Information Security Manager (CISM) Study Manual, risk owners are responsible for managing a risk, including taking corrective action to reduce the risk to an acceptable level. When implementing controls, it is essential to obtain input from risk owners to ensure that the controls are effective in managing the risk to an acceptable level.
By obtaining input from risk owners, the organization can ensure that the controls are tailored to the specific risks and are effective in reducing the risk to an acceptable level. This can help to minimize the impact of the risk on the organization and reduce the potential for financial or reputational damage.
NEW QUESTION # 199
......
Study HIGH Quality CISM-CN Free Study Guides and Exams Tutorials: https://www.pass4surequiz.com/CISM-CN-exam-quiz.html
Download ISACA CISM-CN Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1MKn0GiF__NNXREqCQxgWZfDEBncKaxM6