Get 100% Authentic ISACA CISM Dumps with Correct Answers [Q165-Q186]

Share

Get 100% Authentic ISACA CISM Dumps with Correct Answers

New Training Course CISM Tutorial Preparation Guide

NEW QUESTION # 165
A corporate web site has become compromised as a result of a malicious attack. Which of the following should the information security manager do FIRST?

  • A. Escalate the incident to senior management.
  • B. Contain the incident.
  • C. Perform a root cause analysis.
  • D. Restore the system from backup.

Answer: C


NEW QUESTION # 166
An organization provides information to its supply chain partners and customers through an extranet infrastructure. Which of the following should be the GREATEST concern to an IS auditor reviewing the firewall security architecture?

  • A. Firewall policies are updated on the basis of changing requirements.
  • B. A Secure Sockets Layer (SSL) has been implemented for user authentication and remote administration of the firewall.
  • C. inbound traffic is blocked unless the traffic type and connections have been specifically permitted.
  • D. The firewall is placed on top of the commercial operating system with all installation options.

Answer: D

Explanation:
Explanation
The greatest concern when implementing firewalls on top of commercial operating systems is the potential presence of vulnerabilities that could undermine the security posture of the firewall platform itself. In most circumstances, when commercial firewalls are breached that breach is facilitated by vulnerabilities in the underlying operating system. Keeping all installation options available on the system further increases the risks of vulnerabilities and exploits. Using SSL for firewall administration (choice A) is important, because changes in user and supply chain partners' roles and profiles will be dynamic. Therefore, it is appropriate to maintain the firewall policies daily (choice B), and prudent to block all inbound traffic unless permitted (choice C).


NEW QUESTION # 167
Which of the following should be included in an annual information security budget that is submitted for management approval?

  • A. Total cost of ownership (TC'O)
  • B. A cost-benefit analysis of budgeted resources
  • C. Baseline comparisons
  • D. All of the resources that are recommended by the business

Answer: B

Explanation:
A brief explanation of the benefit of expenditures in the budget helps to convey the context of how the purchases that are being requested meet goals and objectives, which in turn helps build credibility for the information security function or program. Explanations of benefits also help engage senior management in the support of the information security program. While the budget should consider all inputs and recommendations that are received from the business, the budget that is ultimately submitted to management for approval should include only those elements that are intended for purchase. TC'O may be requested by management and may be provided in an addendum to a given purchase request, but is not usually included in an annual budget. Baseline comparisons (cost comparisons with other companies or industries) may be useful in developing a budget or providing justification in an internal review for an individual purchase, but would not be included with a request for budget approval.


NEW QUESTION # 168
Which of the following is the MOST important to keep in mind when assessing the value of information?

  • A. The cost of recreating the information
  • B. The potential financial loss
  • C. The cost of insurance coverage
  • D. Regulatory requirement

Answer: B

Explanation:
Explanation
The potential for financial loss is always a key factor when assessing the value of information. Choices B, C and D may be contributors, but not the key factor.


NEW QUESTION # 169
Which of the following is the MOST effective solution for preventing internal users from modifying sensitive and classified information?

  • A. Baseline security standards
  • B. System access violation logs
  • C. Exit routines
  • D. Role-based access controls

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Role-based access controls help ensure that users only have access to files and systems appropriate for their job role. Violation logs are detective and do not prevent unauthorized access. Baseline security standards do not prevent unauthorized access. Exit routines are dependent upon appropriate role-based access.


NEW QUESTION # 170
To reduce the possibility of service interruptions, an entity enters into contracts with multiple Internet service providers (ISPs). Which of the following would be the MOS T important item to include?

  • A. Intrusion detection system (IDS) services
  • B. Service level agreements (SLAs)
  • C. Spam filtering services
  • D. Right to audit clause

Answer: B

Explanation:
Service level agreements (SLAs) will be most effective in ensuring that Internet service providers (ISPs) comply with expectations for service availability. Intrusion detection system (IDS) and spam filtering services would not mitigate (as directly) the potential for service interruptions. A right-to-audit clause would not be effective in mitigating the likelihood of a service interruption.


NEW QUESTION # 171
Which of the following is the GREATEST concern resulting from the lack of severity criteria in incident classification?

  • A. Timely detection of attacks will be impossible.
  • B. Escalation procedures will be ineffective.
  • C. The service desk will be staffed incorrectly.
  • D. Statistical reports will be incorrect.

Answer: B

Explanation:
The greatest concern resulting from the lack of severity criteria in incident classification is that escalation procedures will be ineffective because they rely on severity criteria to determine when and how to escalate an incident to higher levels of authority or responsibility, and what actions or resources are required for resolving an incident. Statistical reports will be incorrect is not a great concern because they do not affect the incident response process directly, but rather provide information or analysis for improvement or evaluation purposes. The service desk will be staffed incorrectly is not a great concern because it does not affect the incident response process directly, but rather affects the availability or efficiency of one of its components. Timely detection of attacks will be impossible is not a great concern because it does not depend on severity criteria, but rather on monitoring and alerting mechanisms. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned


NEW QUESTION # 172
To reduce the possibility of service interruptions, an entity enters into contracts with multiple Internet service providers (ISPs). Which of the following would be the MOS T important item to include?

  • A. Intrusion detection system (IDS) services
  • B. Service level agreements (SLAs)
  • C. Spam filtering services
  • D. Right to audit clause

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Service level agreements (QAs) will be most effective in ensuring that Internet service providers (ISPs) comply with expectations for service availability. Intrusion detection system (IDS) and spam filtering services would not mitigate (as directly) the potential for service interruptions. A right-to-audit clause would not be effective in mitigating the likelihood of a service interruption.


NEW QUESTION # 173
The PRIMARY reason to create and externally store the disk hash value when performing forensic data acquisition from a hard disk is to:

  • A. provide backup in case of media failure.
  • B. validate the confidentiality during analysis.
  • C. validate the integrity during analysis.
  • D. reinstate original data when accidental changes occur.

Answer: C

Explanation:
Explanation
The main purpose of creating and storing an external disk hash value when performing forensic data acquisition from a hard disk is to validate the integrity of the data during the analysis. This is done by comparing the original hash value of the disk to the hash value created during the acquisition process, which can be used to ensure that the data has not been tampered with or corrupted in any way. Additionally, by creating a hash value of the disk, it can be used to quickly verify the integrity of any data that is accessed from the disk in the future.


NEW QUESTION # 174
In business critical applications, where shared access to elevated privileges by a small group is necessary, the BEST approach to implement adequate segregation of duties is to:

  • A. enforce manual procedures ensuring separation of conflicting duties.
  • B. create service accounts that can only be used by authorized team members.
  • C. ensure access to individual functions can be granted to individual users only.
  • D. implement role-based access control in the application.

Answer: D

Explanation:
Role-based access control is the best way to implement appropriate segregation of duties. Roles will have to be defined once and then the user could be changed from one role to another without redefining the content of the role each time. Access to individual functions will not ensure appropriate segregation of duties. Giving a user access to all functions and implementing, in parallel, a manual procedure ensuring segregation of duties is not an effective method, and would be difficult to enforce and monitor. Creating service accounts that can be used by authorized team members would not provide any help unless their roles are properly segregated.


NEW QUESTION # 175
Which is the BEST way to measure and prioritize aggregate risk deriving from a chain of linked system vulnerabilities?

  • A. Penetration tests
  • B. Code reviews
  • C. Vulnerability scans
  • D. Security audits

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
A penetration test is normally the only security assessment that can link vulnerabilities together by exploiting them sequentially. This gives a good measurement and prioritization of risks. Other security assessments such as vulnerability scans, code reviews and security audits can help give an extensive and thorough risk and vulnerability overview', but will not be able to test or demonstrate the final consequence of having several vulnerabilities linked together. Penetration testing can give risk a new perspective and prioritize based on the end result of a sequence of security problems.


NEW QUESTION # 176
Which of the following should be done when establishing security measures for personal data stored and processed on a human resources management system?

  • A. Conduct a vulnerability assessment.
  • B. Move the system into a separate network.
  • C. Conduct a privacy impact assessment.
  • D. Evaluate data encryption technologies.

Answer: C


NEW QUESTION # 177
Which of the following is the BEST reason to perform a business impact analysis (BIA)?

  • A. To help determine the current state of risk
  • B. To budget appropriately for needed controls
  • C. To analyze the effect on the business
  • D. To satisfy regulatory requirements

Answer: A

Explanation:
Explanation
The BIA is included as part of the process to determine the current state of risk and helps determine the acceptable levels of response from impacts and the current level of response, leading to a gap analysis.
Budgeting appropriately may come as a result, but is not the reason to perform the analysis. Performing an analysis may satisfy regulatory requirements, bill is not the reason to perform one. Analyzing the effect on the business is part of the process, but one must also determine the needs or acceptable effect or response.


NEW QUESTION # 178
A multinational organization operating in fifteen countries is considering implementing an information security program. Which factor will MOST influence the design of the Information security program?

  • A. Composition of the board
  • B. Representation by regional business leaders
  • C. Cultures of the different countries
  • D. IT security skills

Answer: C

Explanation:
Explanation
Culture has a significant impact on how information security will be implemented. Representation by regional business leaders may not have a major influence unless it concerns cultural issues. Composition of the board may not have a significant impact compared to cultural issues. IT security skills are not as key or high impact in designing a multinational information security program as would be cultural issues.


NEW QUESTION # 179
Which of the following is MOST important to present to stakeholders to help obtain support for implementing a new information

  • A. An overview of competitors' information security strategies
  • B. An assessment of current technological exposures
  • C. A statement of generally accepted good practices
  • D. The potential impact of current threats

Answer: D


NEW QUESTION # 180
An information security manager terms that the root password of an external FTP server may be subject to brute force attacks. Which of the following would be the MOST appropriate way to reduce the likelihood of a successful attack?.

  • A. Block the source IP address of the attacker.
  • B. Lock remote logon after multiple failed attempts.
  • C. Disable access to the externally facing server.
  • D. Install an intrusion detection system (IDS).

Answer: B


NEW QUESTION # 181
What is the MOST important factor in the successful implementation of an enterprise wide information security program?

  • A. Recalculation of the work factor
  • B. Support of senior management
  • C. Security awareness
  • D. Realistic budget estimates

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Without the support of senior management, an information security program has little chance of survival. A company's leadership group, more than any other group, will more successfully drive the program. Their authoritative position in the company is a key factor. Budget approval, resource commitments, and companywide participation also require the buy-in from senior management. Senior management is responsible for providing an adequate budget and the necessary resources. Security awareness is important, but not the most important factor. Recalculation of the work factor is a part of risk management.


NEW QUESTION # 182
For computer forensics evidence to be admissible in a court of law, the evidence MUST:

  • A. be stored in the original media.
  • B. meet standards of relevance
  • C. be identifiable and reproducible
  • D. have integrity and accountability

Answer: D


NEW QUESTION # 183
Which of the following defines the triggers within a business continuity plan (BCP)?

  • A. Gap analysis
  • B. Disaster recovery plan
  • C. Needs of the organization
  • D. Information security policy

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 184
Which of the following would provide the HIGHEST level of confidence in the integrity of data when sent from one party to another?

  • A. Enforce multi-factor authentication (MFA) on both ends of the communication.
  • B. Require data to be transmitted over a secure connection.
  • C. Require files to be digitally signed before they are transmitted.
  • D. Harden the communication infrastructure.

Answer: C


NEW QUESTION # 185
Which of the following is the MOST important element to ensure the successful recovery of a business during a disaster?

  • A. Appropriate declaration criteria have been established
  • B. Detailed technical recovery plans are maintained offsite
  • C. Network redundancy is maintained through separate providers
  • D. Hot site equipment needs are recertified on a regular basis

Answer: B

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
In a major disaster, staff can be injured or can be prevented from traveling to the hot site, so technical skills and business knowledge can be lost. It is therefore critical to maintain an updated copy of the detailed recovery plan at an offsite location. Continuity of the business requires adequate network redundancy, hot site infrastructure that is certified as compatible and clear criteria for declaring a disaster. Ideally, the business continuity program addresses all of these satisfactorily. However, in a disaster situation, where all these elements are present, but without the detailed technical plan, business recovery will be seriously impaired.


NEW QUESTION # 186
......

Dumps of CISM Cover all the requirements of the Real Exam: https://www.actual4dump.com/ISACA/CISM-actualtests-dumps.html

Correct Practice Tests of CISM Dumps with Practice Exam: https://drive.google.com/open?id=1Eeuis0DDjwYNa6MCBiTzOzFWdSZqc9rb