
[Dec-2021] Free CISM Exam Dumps to Improve Exam Score
2021 Realistic CISM Dumps Exam Tips Test Pdf Exam Material
The primary goal of every ISACA certification is to deliver you to the highest stages of professional triumph. The CISM or known completely as the Certified Information Security Manager is a transformative certification exam that seals your capability across different work-related aspects of management using your information security command. It is your testament of know-how in juggling risk management, program development alongside management, information security governance, and incident management with a breeze.
To be able to pass the CISM exam with a high result, you have to learn all the required skills. The domains that are covered in this test are the following:
- Information Security Governance (24%)
For this area, you need to know the techniques that are used to develop the IS strategies, methods to plan and implement the IS governance framework, as well as considerations for communicating with the stakeholders and senior leadership. Besides that, you need to have the skills in integrating IS governance into corporate governance to ensure that all the organizational objectives and goals are supported by the IS program. The potential candidates need to be ready to define and communicate IS responsibilities throughout the organization as well.
- Information Security Program Development & Management (27%)
Here, you need to know the methods to align the IS program requirements with those of other business functions, establish effective IS awareness and training programs, as well as design and implement operational IS metrics. As for your practical skills, it is required to know how to establish and maintain the IS program in the alignment with the IS strategy, integrate the IS requirements into the organizational processes, and compile your reports to the key stakeholders.
- Information Security Incident Management (19%)
In this last topic, it is important to have the relevant knowledge of the external and internal incident reporting procedures and requirements, components of an incident response plan, as well as notification and escalation processes. While answering the questions from this domain, you will be tested on whether you are able to establish integration among an incident response plan, disaster recovery plan, and business continuity plan or not. Additionally, you need to have the skills in organizing, training, and equipping the incident response teams to respond to IS incidents in an effective and timely manner.
- Information Risk Management (30%)
This section will evaluate your knowledge of gap analysis techniques related to IS, risk reporting requirements, and information asset valuation methodologies. You should also know about the methods that can be used to monitor internal and external risk factors. Your skills in identifying regulatory, organizational, legal, and other applicable requirements to manage the risk of noncompliance to acceptable levels as well as monitoring for external and internal factors will be measured.
NEW QUESTION 123
An organization's senior management is encouraging employees to use social media for promotional purposes.
Which of the following should be the information security manager's FIRST step to support this strategy?
- A. Develop a business case for a data loss prevention solution.
- B. Develop a guideline on the acceptable use of social media.
- C. Employ the use of a web content filtering solution.
- D. Incorporate social media into the security awareness program.
Answer: B
NEW QUESTION 124
Which of the following is the MOST appropriate individual to implement and maintain the level of information security needed for a specific business application?
- A. Quality control manager
- B. Information security manager
- C. System analyst
- D. Process owner
Answer: D
Explanation:
Explanation
Process owners implement information protection controls as determined by the business' needs. Process owners have the most knowledge about security requirements for the business application for which they are responsible. The system analyst, quality control manager, and information security manager do not possess the necessary knowledge or authority to implement and maintain the appropriate level of business security.
NEW QUESTION 125
When implementing effective security governance within the requirements of the company's security strategy, which of the following is the MOST important factor to consider?
- A. Establishing international security standards for data sharing
- B. Preserving the confidentiality of sensitive data
- C. Establishing system manager responsibility for information security
- D. Adhering to corporate privacy standards
Answer: B
Explanation:
Explanation
The goal of information security is to protect the organization's information assets. International security standards are situational, depending upon the company and its business. Adhering to corporate privacy standards is important, but those standards must be appropriate and adequate and are not the most important factor to consider. All employees are responsible for information security, but it is not the most important factor to consider.
NEW QUESTION 126
In addition to backup data, which of the following is the MOST important to store offsite in the event of a disaster?
- A. Copies of the business continuity plan
- B. List of emergency numbers of service providers
- C. Copies of critical contracts and service level agreements (SLAs)
- D. Key software escrow agreements for the purchased systems
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Without a copy of the business continuity plan, recovery efforts would be severely hampered or may not be effective. All other choices would not be as immediately critical as the business continuity plan itself. The business continuity plan would contain a list of the emergency numbers of service providers.
NEW QUESTION 127
Which of the following should be an information security manager's PRIMARY consideration when developing an incident response plan?
- A. The organization's external communications plan
- B. The organization's risk tolerance and appetite
- C. Skills and competencies of the help desk
- D. Incident response plan testing methods and frequency
Answer: D
NEW QUESTION 128
Who can BEST approve plans to implement an information security governance framework?
- A. Information security management
- B. Internal auditor
- C. Infrastructure management
- D. Steering committee
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Senior management that is part of the security steering committee is in the best position to approve plans to implement an information security governance framework. An internal auditor is secondary' to the authority and influence of senior management. Information security management should not have the authority to approve the security governance framework. Infrastructure management will not be in the best position since it focuses more on the technologies than on the business.
NEW QUESTION 129
An organization has a policy in which all criminal activity is prosecuted. What is MOST important for the information security manager to ensure when an employee is suspected of using a company computer to commit fraud?
- A. Senior management is informed of the situation.
- B. The forensics process is immediately initiated.
- C. The employee's log files are backed-up.
- D. The incident response plan is initiated.
Answer: C
NEW QUESTION 130
On a company's e-commerce web site, a good legal statement regarding data privacy should include:
- A. a statement regarding where the information is being hosted.
- B. a statement regarding what the company will do with the information it collects.
- C. a disclaimer regarding the accuracy of information on its web site.
- D. technical information regarding how information is protected.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Most privacy laws and regulations require disclosure on how information will be used. A disclaimer is not necessary since it does not refer to data privacy. Technical details regarding how information is protected are not mandatory to publish on the web site and in fact would not be desirable. It is not mandatory to say where information is being hosted.
NEW QUESTION 131
Which of the following is the MOST appropriate method of ensuring password strength in a large organization?
- A. Install code to capture passwords for periodic audit
- B. Attempt to reset several passwords to weaker values
- C. Review general security settings on each platform
- D. Sample a subset of users and request their passwords for review
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Reviewing general security settings on each platform will be the most efficient method for determining password strength while not compromising the integrity of the passwords. Attempting to reset several passwords to weaker values may not highlight certain weaknesses. Installing code to capture passwords for periodic audit, and sampling a subset of users and requesting their passwords for review, would compromise the integrity of the passwords.
NEW QUESTION 132
Detailed business continuity plans should be based PRIMARILY on:
- A. strategies that cover all applications.
- B. consideration of different alternatives.
- C. the solution that is least expensive.
- D. strategies validated by senior management.
Answer: D
Explanation:
Explanation
A recovery strategy identifies the best way to recover a system in ease of disaster and provides guidance based on detailed recovery procedures that can be developed. Different strategies should be developed and all alternatives presented to senior management. Senior management should select the most appropriate strategy from the alternatives provided. The selected strategy should be used for further development of the detailed business continuity plan. The selection of strategy depends on criticality of the business process and applications supporting the processes. It need not necessarily cover all applications. All recovery strategies have associated costs, which include costs of preparing for disruptions and putting them to use in the event of a disruption. The latter can be insured against, but not the former. The best recovery option need not be the least expensive.
NEW QUESTION 133
In implementing information security governance, the information security manager is PRIMARILY responsible for:
- A. developing the security strategy.
- B. reviewing the security strategy.
- C. communicating the security strategy.
- D. approving the security strategy
Answer: A
Explanation:
The information security manager is responsible for developing a security strategy based on business objectives with the help of business process owners. Reviewing the security strategy is the responsibility of a steering committee. The information security manager is not necessarily responsible for communicating or approving the security strategy.
NEW QUESTION 134
Which of the following is the PRIMARY reason to conduct periodic business impact assessments?
- A. Meet the needs of the business continuity policy
- B. Update recovery objectives based on new risks
- C. Decrease the recovery times
- D. Improve the results of last business impact assessment
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 135
Which of the following is the BEST method to provide a new user with their initial password for e-mail system access?
- A. Require no password but force the user to set their own in 10 days
- B. Set initial password equal to the user ID with expiration in 30 days
- C. Give a dummy password over the telephone set for immediate expiration
- D. Interoffice a system-generated complex password with 30 days expiration
Answer: C
Explanation:
Documenting the password on paper is not the best method even if sent through interoffice mail if the password is complex and difficult to memorize, the user will likely keep the printed password and this creates a security concern. A dummy (temporary) password that will need to be changed upon first logon is the best method because it is reset immediately and replaced with the user's choice of password, which will make it easier for the user to remember. If it is given to the wrong person, the legitimate user will likely notify security if still unable to access the system, so the security risk is low. Setting an account with no initial password is a security concern even if it is just for a few days. Choice D provides the greatest security threat because user IDs are typically known by both users and security staff, thus compromising access for up to 30 days.
NEW QUESTION 136
Which of the following is the MOST appropriate course of action when the risk occurrence rate is low but the impact is high?
- A. Risk transfer
- B. Risk acceptance
- C. Risk avoidance
- D. Risk mitigation
Answer: C
NEW QUESTION 137
To BEST improve the alignment of the information security objectives in an organization, the chief information security officer (CISO) should:
- A. conduct regular user awareness sessions.
- B. perform penetration tests.
- C. evaluate a balanced business scorecard.
- D. revise the information security program.
Answer: C
Explanation:
The balanced business scorecard can track the effectiveness of how an organization executes it information security strategy and determine areas of improvement. Revising the information security program may be a solution, but is not the best solution to improve alignment of the information security objectives. User awareness is just one of the areas the organization must track through the balanced business scorecard. Performing penetration tests does not affect alignment with information security objectives.
NEW QUESTION 138
Data owners are PRIMARILY responsible for establishing risk mitigation methods to address which of the following areas?
- A. Entitlement changes
- B. Intrusion detection
- C. Antivirus controls
- D. Platform security
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Data owners are responsible for assigning user entitlements and approving access to the systems for which they are responsible. Platform security, intrusion detection and antivirus controls are all within the responsibility of the information security manager.
NEW QUESTION 139
After assessing and mitigating the risks of a web application, who should decide on the acceptance of residual application risks?
- A. Chief information officer (CIO)
- B. Information security officer
- C. Business owner
- D. Chief executive officer (CFO)
Answer: C
Explanation:
Explanation
The business owner of the application needs to understand and accept the residual application risks.
NEW QUESTION 140
An information security manager is reviewing a contract with a third-party service provider. Which of the following issues should be of MOST concern?
- A. Penalties for breach of contract are not defined.
- B. There is no provision for a right to audit.
- C. The provider states the client is responsible for data classification.
- D. The provider lacks compliance certification.
Answer: A
NEW QUESTION 141
An inexperienced information security manager is relying on its internal audit department to design and implement key security controls. Which of the following is the GREATEST risk?
- A. Inadequate audit skills
- B. Conflict of interest
- C. Violation of the audit charter
- D. Inadequate implementation of controls
Answer: B
NEW QUESTION 142
A message* that has been encrypted by the sender's private key and again by the receiver's public key achieves:
- A. authentication and nonrepudiation.
- B. authentication and authorization.
- C. confidentiality and nonrepudiation.
- D. confidentiality and integrity.
Answer: C
Explanation:
Encryption by the private key of the sender will guarantee authentication and nonrepudiation. Encryption by the public key of the receiver will guarantee confidentiality.
NEW QUESTION 143
......
What is the duration of the CISM Exam
- Number of Questions: 200
- Length of Examination: 4 hours
- Format: Multiple choices, multiple answers
Powerful CISM PDF Dumps for CISM Questions: https://www.pass4surequiz.com/CISM-exam-quiz.html
Authentic CISM Dumps - Free PDF Questions to Pass: https://drive.google.com/open?id=1CGgWfhSUPIXGOXS4GcrXUelhJQirAx8H