Most UptoDate ISACA CISM Exam Dumps PDF 2023 [Q132-Q152]

Share

Most UptoDate ISACA CISM Exam Dumps PDF 2023

100% Free Isaca Certification CISM Dumps PDF Demo Cert Guide Cover

NEW QUESTION # 132
In organizations where availability is a primary concern, the MOST critical success factor of the patch management procedure would be the:

  • A. automated deployment to all the servers.
  • B. certification of validity for deployment.
  • C. testing time window prior to deployment.
  • D. technical skills of the team responsible.

Answer: C

Explanation:
Having the patch tested prior to implementation on critical systems is an absolute prerequisite where availability is a primary concern because deploying patches that could cause a system to fail could be worse than the vulnerability corrected by the patch. It makes no sense to deploy patches on every system. Vulnerable systems should be the only candidate for patching. Patching skills are not required since patches are more often applied via automated tools.


NEW QUESTION # 133
The PRIMARY purpose of a security information and event management (SIEM) system is to:

  • A. resolve incidents
  • B. provide status of incidents
  • C. track ongoing incidents
  • D. identify potential incidents.

Answer: D


NEW QUESTION # 134
A risk has been formally accepted and documented. Which of the following is the MOST important action for an information security manager?

  • A. Re-evaluate the organization's risk appetite
  • B. Notify senior management and the board.
  • C. Update risk tolerance levels.
  • D. Monitor the environment for changes

Answer: D


NEW QUESTION # 135
When properly tested, which of the following would MOST effectively support an information security manager in handling a security breach?

  • A. Disaster recovery plan
  • B. Incident response plan
  • C. Vulnerability management plan
  • D. Business continuity plan

Answer: B

Explanation:
Explanation/Reference:
Explanation:
An incident response plan documents the step-by-step process to follow, as well as the related roles and responsibilities pertaining to all parties involved in responding to an information security breach. A business continuity plan or disaster recovery plan would be triggered during the execution of the incident response plan in the case of a breach impacting the business continuity. A vulnerability management plan is a procedure to address technical vulnerabilities and mitigate the risk through configuration changes (patch management).


NEW QUESTION # 136
Which of the following is MOST important for an information security manager to regularly report to senior management?

  • A. Impact of unremediated risks
  • B. Results of penetration tests
  • C. Threat analysis reports
  • D. Audit reports

Answer: C


NEW QUESTION # 137
An online bank identifies a successful network attack in progress. The bank should FIRST:

  • A. assess whether personally identifiable information (Pll) is compromised.
  • B. shut down the entire network.
  • C. report the root cause to the board of directors.
  • D. isolate the affected network segment.

Answer: D


NEW QUESTION # 138
The PRIMARY reason for involving information security at each stage in the systems development life cycle (SDLC) is to identify the security implications and potential solutions required for:

  • A. the existing systems that will be affected.
  • B. complying with segregation of duties.
  • C. sustaining the organization's security posture.
  • D. identifying vulnerabilities in the system.

Answer: C

Explanation:
Explanation
It is important to maintain the organization's security posture at all times. The focus should not be confined to the new system being developed or acquired, or to the existing systems in use. Segregation of duties is only part of a solution to improving the security of the systems, not the primary reason to involve security in the systems development life cycle (SDLC).


NEW QUESTION # 139
Which of the following BEST ensures that security risks will be reevaluated when modifications in application developments are made?

  • A. A problem management process
  • B. Business impact analysis (BIA)
  • C. Background screening
  • D. A change control process

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
A change control process is the methodology that ensures that anything that could be impacted by a development change will be reevaluated. Problem management is the general process intended to manage all problems, not those specifically related to security. Background screening is the process to evaluate employee references when they are hired. BIA is the methodology used to evaluate risks in the business continuity process.


NEW QUESTION # 140
Which of the following would BEST prepare an information security manager for regulatory reviews?

  • A. Ensure all regulatory inquiries are sanctioned by the legal department
  • B. Perform self-assessments using regulatory guidelines and reports
  • C. Assess previous regulatory reports with process owners input
  • D. Assign an information security administrator as regulatory liaison

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Self-assessments provide the best feedback on readiness and permit identification of items requiring remediation. Directing regulators to a specific person or department, or assessing previous reports, is not as effective. The legal department should review all formal inquiries but this does not help prepare for a regulatory review.


NEW QUESTION # 141
Which of the following is the BEST approach to identify noncompliance issues with legal, regulatory, and contractual requirements?

  • A. Business impact analysis (BIA)
  • B. Risk assessment
  • C. Vulnerability assessment
  • D. Gap analysis

Answer: D

Explanation:
Section: INFORMATION SECURITY GOVERNANCE


NEW QUESTION # 142
What is the MOST important element to include when developing user security awareness material?

  • A. Senior management endorsement
  • B. Detailed security policies
  • C. Information regarding social engineering
  • D. Easy-to-read and compelling information

Answer: D

Explanation:
Explanation
Making security awareness material easy and compelling to read is the most important success factor. Users must be able to understand, in easy terms, complex security concepts in a way that makes compliance more accessible. Choice A would also be important but it needs to be presented in an adequate format. Detailed security policies might not necessarily be included in the training materials. Senior management endorsement is important for the security program as a whole and not necessarily for the awareness training material.


NEW QUESTION # 143
Which of the following activities BEST enables executive management to ensure value delivery within an information security program?

  • A. Assigning an information security manager to a senior management position
  • B. Approving an industry-recognized information security framework
  • C. Requiring employees to undergo information security awareness training
  • D. Reviewing business cases for information security initiatives

Answer: D


NEW QUESTION # 144
A CEO requests access to corporate documents from a mobile device that does not comply with organizational policy. The information security manager should FIRST:

  • A. evaluate the business risk.
  • B. evaluate a third-party solution.
  • C. deploy additional security controls.
  • D. initiate an exception approval process.

Answer: A


NEW QUESTION # 145
Senior management has launched an enterprise-wide initiative to streaming internal processes to reduce costs, including security processes. What should the information security manager rely on MOST to allocate resources efficiently?

  • A. Return on investment (ROI)
  • B. Internal audit reports
  • C. Risk classification
  • D. Capability maturity assessment

Answer: C


NEW QUESTION # 146
Which of the following should be the FIRST step in developing an information security plan?

  • A. Perform a business impact analysis
  • B. Assess the current levels of security awareness
  • C. Perform a technical vulnerabilities assessment
  • D. Analyze the current business strategy

Answer: D


NEW QUESTION # 147
Employees in a large multinational organization frequently travel among various geographic locations. Which type of authorization policy BEST addresses this practice?

  • A. Discretionary
  • B. Multilevel
  • C. Identity
  • D. Role-based

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference:


NEW QUESTION # 148
Which of the following attacks is BEST mitigated by utilizing strong passwords?

  • A. Man-in-the-middle attack
  • B. Root kit
  • C. Brute force attack
  • D. Remote buffer overflow

Answer: C

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
A brute force attack is normally successful against weak passwords, whereas strong passwords would not prevent any of the other attacks. Man-in-the-middle attacks intercept network traffic, which could contain passwords, but is not naturally password-protected. Remote buffer overflows rarely require a password to exploit a remote host. Root kits hook into the operating system's kernel and, therefore, operate underneath any authentication mechanism.


NEW QUESTION # 149
What should be an information security manager's FIRST step when developing a business case for a new intrusion detection system (IDS) solution?

  • A. Perform a cost-benefit analysis.
  • B. Conduct a feasibility study.
  • C. Define the issues to be addressed.
  • D. Calculate the total cost of ownership (TCO).

Answer: C

Explanation:
The first step when developing a business case for a new intrusion detection system (IDS) solution is to define the issues to be addressed. A business case is a document that provides the rationale and justification for initiating a project or investment. It typically includes information such as the problem statement, the objectives, the alternatives, the costs and benefits, the risks and assumptions, and the expected outcomes. The first step in developing a business case is to define the issues to be addressed, which means identifying and describing the current situation, the problems or challenges faced by the organization, and the needs or opportunities for improvement. By defining the issues to be addressed, the information security manager can establish the scope and purpose of the business case, and provide a clear and compelling problem statement that explains why a new IDS solution is needed. The other options are not the first step when developing a business case for a new IDS solution, although they may be part of the subsequent steps. Performing a cost-benefit analysis is a step that involves comparing the costs and benefits of different alternatives, including the new IDS solution and the status quo. A cost-benefit analysis can help evaluate and justify the feasibility and desirability of each alternative, and support the decision-making process. Calculating the total cost of ownership (TCO) is a step that involves estimating the direct and indirect costs associated with acquiring, operating, maintaining, and disposing of an asset or a system over its entire life cycle. A TCO calculation can help determine the long-term financial implications of investing in a new IDS solution, and compare it with other alternatives. Conducting a feasibility study is a step that involves assessing the technical, operational, legal, and economic aspects of implementing a project or an investment. A feasibility study can help identify and mitigate any potential issues or risks that may affect the success of the project or investment, and provide recommendations for improvement


NEW QUESTION # 150
The MAIN benefit of implementing a data loss prevention (DLP) solution is to:

  • A. complement the organization's detective controls.
  • B. eliminate the risk of data loss.
  • C. enhance the organization's antivirus controls.
  • D. reduce the need for a security awareness program.

Answer: B


NEW QUESTION # 151
Which of the following should be an information security manager's PRIMARY consideration when developing an incident response plan?

  • A. The organization's risk tolerance and appetite
  • B. The organization's external communications plan
  • C. Skills and competencies of the help desk
  • D. Incident response plan testing methods and frequency

Answer: D


NEW QUESTION # 152
......

Updated ISACA CISM Dumps – PDF & Online Engine: https://www.pass4surequiz.com/CISM-exam-quiz.html

PDF Exam Material 2023 Realistic CISM Dumps Questions: https://drive.google.com/open?id=189o3dKQXfgEkuQlpgtCJNXaLz-u0D9VN