
2024 Free ISACA CISM Exam Files Downloaded Instantly
Pass ISACA CISM exam Dumps 100 Pass Guarantee With Latest Demo
NEW QUESTION # 40
Information security managers should use risk assessment techniques to:
- A. maximize the return on investment (ROD.
- B. quantify risks that would otherwise be subjective.
- C. justify selection of risk mitigation strategies.
- D. provide documentation for auditors and regulators.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Information security managers should use risk assessment techniques to justify and implement a risk mitigation strategy as efficiently as possible. None of the other choices accomplishes that task, although they are important components.
NEW QUESTION # 41
Without prior approval, a training department enrolled the company in a free cloud-based collaboration site and invited employees to use it. Which of the following is the BEST response of the information security manager?
- A. Report the activity to senior management.
- B. Update the risk register and review the information security strategy.
- C. Allow temporary use of the site and monitor for data leakage.
- D. Conduct a risk assessment and develop an impact analysis.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 42
Access control to a sensitive intranet application by mobile users can BEST be implemented through:
- A. two-factor authentication.
- B. digital signatures.
- C. data encryption.
- D. strong passwords.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:
Explanation:
Two-factor authentication through the use of strong passwords combined with security tokens provides the highest level of security. Data encryption, digital signatures and strong passwords do not provide the same level of protection.
NEW QUESTION # 43
What would a security manager PRIMARILY utilize when proposing the implementation of a security solution?
- A. Technical evaluation report
- B. Risk assessment report
- C. Business case
- D. Budgetary requirements
Answer: C
Explanation:
Explanation
The information security manager needs to prioritize the controls based on risk management and the requirements of the organization. The information security manager must look at the costs of the various controls and compare them against the benefit the organization will receive from the security solution. The information security manager needs to have knowledge of the development of business cases to illustrate the costs and benefits of the various controls. All other choices are supplemental.
NEW QUESTION # 44
An organization with a large number of users finds it necessary to improve access control applications.
Which of the following would BEST help to prevent unauthorized user access to networks and applications?
- A. Single sign-on
- B. Complex user passwords
- C. Access control lists
- D. Biometric systems
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 45
Which of the following would MOST effectively ensure that information security is implemented in a new system?
- A. Secure code reviews
- B. Penetration testing
- C. Security baselines
- D. Security scanning
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION # 46
A risk assessment and business impact analysis (BIA) have been completed for a major proposed purchase and new process for an organization. There is disagreement between the information security manager and the business department manager who will own the process regarding the results and the assigned risk. Which of the following would be the BES T approach of the information security manager?
- A. Acceptance of the business manager's decision on the risk to the corporation
- B. Review of the assessment with executive management for final input
- C. Acceptance of the information security manager's decision on the risk to the corporation
- D. A new risk assessment and BIA are needed to resolve the disagreement
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Executive management must be supportive of the process and fully understand and agree with the results since risk management decisions can often have a large financial impact and require major changes. Risk management means different things to different people, depending upon their role in the organization, so the input of executive management is important to the process.
NEW QUESTION # 47
An information security manager is preparing an incident response plan. Which of the following is the MOST important consideration when responding to an incident involving sensitive customer data?
- A. Following defined post-incident review procedures
- B. The assignment of a forensics team
- C. The ability to recover from the incident in a timely manner
- D. The ability to obtain incident information in a timely manner
Answer: B
NEW QUESTION # 48
Which of the following mechanisms is the MOST secure way to implement a secure wireless network?
- A. Use a Wired Equivalent Privacy (WEP) key
- B. Use a Wi-Fi Protected Access (WPA2) protocol
- C. Filter media access control (MAC) addresses
- D. Web-based authentication
Answer: B
Explanation:
Explanation
WPA2 is currently one of the most secure authentication and encryption protocols for mainstream wireless products. MAC address filtering by itself is not a good security mechanism since allowed MAC addresses can be easily sniffed and then spoofed to get into the network. WEP is no longer a secure encryption mechanism for wireless communications. The WEP key can be easily broken within minutes using widely available software. And once the WEP key is obtained, all communications of every other wireless client are exposed.
Finally, a web-based authentication mechanism can be used to prevent unauthorized user access to a network, but it will not solve the wireless network's main security issues, such as preventing network sniffing.
NEW QUESTION # 49
Which of the following BEST enables an organization to provide ongoing assurance that legal and regulatory compliance requirements can be met?
- A. Engaging external experts to provide guidance on changes in compliance requirements
- B. Assigning the operations manager accountability for meeting compliance requirements
- C. Embedding compliance requirements within operational processes
- D. Performing periodic audits for compliance with legal and regulatory requirements
Answer: C
Explanation:
Embedding compliance requirements within operational processes ensures that they are consistently followed and monitored as part of normal business activities. This provides ongoing assurance that legal and regulatory compliance requirements can be met. The other choices are not as effective as embedding compliance requirements within operational processes.
Regulatory compliance involves following external legal mandates set forth by state, federal, or international government2. Compliance requirements may vary depending on the industry, location, and nature of the organization2. Compliance helps organizations avoid legal penalties, protect their reputation, and ensure ethical conduct2.
NEW QUESTION # 50
Which of the following would be the MOST important factor to be considered in the loss of mobile equipment with unencrypted data?
- A. Replacement cost of the equipment
- B. Disclosure of personal information
- C. Sufficient coverage of the insurance policy for accidental losses
- D. Intrinsic value of the data stored on the equipment
Answer: D
Explanation:
Explanation/Reference:
Explanation:
When mobile equipment is lost or stolen, the information contained on the equipment matters most in determining the impact of the loss. The more sensitive the information, the greater the liability. If staff carries mobile equipment for business purposes, an organization must develop a clear policy as to what information should be kept on the equipment and for what purpose. Personal information is not defined in the question as the data that were lost. Insurance may be a relatively smaller issue as compared with information theft or opportunity loss, although insurance is also an important factor for a successful business. Cost of equipment would be a less important issue as compared with other choices.
NEW QUESTION # 51
Which of the following tools is MOST appropriate for determining how long a security project will take to implement?
- A. Waterfall chart
- B. Rapid Application Development (RAD)
- C. Gantt chart
- D. Critical path
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The critical path method is most effective for determining how long a project will take. A waterfall chart is used to understand the flow of one process into another. A Gantt chart facilitates the proper estimation and allocation of resources. The Rapid Application Development (RAD) method is used as an aid to facilitate and expedite systems development.
NEW QUESTION # 52
The BEST way to isolate corporate data stored on employee-owned mobile devices would be to implement:
- A. two-factor authentication.
- B. a strong password policy.
- C. device encryption.
- D. a sandbox environment.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 53
An organization is MOST at risk from a new worm being introduced through the intranet when:
- A. hosts have static IP addresses.
- B. system software does not undergo integrity checks.
- C. executable code is run from inside the firewall.
- D. desktop virus definition files are not up to date.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 54
Which of the following is the MOST important reason for an information security review of contracts? To help ensure that:
- A. confidential data are not included in the agreement.
- B. the right to audit is a requirement.
- C. the parties to the agreement can perform.
- D. appropriate controls are included.
Answer: D
Explanation:
Explanation
Agreements with external parties can expose an organization to information security risks that must be assessed and appropriately mitigated. The ability of the parties to perform is normally the responsibility of legal and the business operation involved. Confidential information may be in the agreement by necessity and.
while the information security manager can advise and provide approaches to protect the information, the responsibility rests with the business and legal. Audit rights may be one of many possible controls to include in a third-party agreement, but is not necessarily a contract requirement, depending on the nature of the agreement.
NEW QUESTION # 55
Which of the following actions should be taken when an information security manager discovers that a hacker is foot printing the network perimeter?
- A. Update IDS software to the latest available version
- B. Enable server trace logging on the DMZ segment
- C. Reboot the border router connected to the firewall
- D. Check IDS logs and monitor for any active attacks
Answer: D
Explanation:
Explanation
Information security should check the intrusion detection system (IDS) logs and continue to monitor the situation. It would be inappropriate to take any action beyond that. In fact, updating the IDS could create a temporary exposure until the new version can be properly tuned. Rebooting the router and enabling server trace routing would not be warranted.
NEW QUESTION # 56
What is the MOST important role of an organization's data custodian in support of the information security function?
- A. Evaluating data security technology vendors
- B. Approving access rights to departmental data
- C. Assessing data security risks to the organization
- D. Applying approved security policies
Answer: D
NEW QUESTION # 57
Which of the following is the BEST reason for delaying the application of a critical security patch?
- A. Lack of vulnerability management
- B. Conflicts with software development lifecycle
- C. Resource limitations
- D. Technology interdependencies
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference:
NEW QUESTION # 58
......
Read Online CISM Test Practice Test Questions Exam Dumps: https://www.actual4dump.com/ISACA/CISM-actualtests-dumps.html
The CISM PDF Dumps Greatest for the ISACA Exam Study Guide!: https://drive.google.com/open?id=1DI9f3TNXQCufLTyXi0-Zykxw0lSMh0bY