
[Nov 10, 2023] CISM Sample with Accurate & Updated Questions
CISM Exam Info and Free Practice Test | PassSureExam
The benefits of earning a CISM certification are numerous. It demonstrates a candidate's commitment to and knowledge of information security management, which can lead to increased job opportunities and higher salaries. It also provides a competitive advantage over other professionals in the field, as well as a sense of personal and professional achievement. Furthermore, CISM certification holders are required to maintain their certification through continuing education, ensuring they stay up-to-date with the latest developments and trends in information security management.
ISACA CISM (Certified Information Security Manager) Certification Exam is one of the most prestigious and globally recognized certifications in the field of information security management. It is designed for professionals who are responsible for managing, designing, and overseeing information security systems in organizations. The CISM certification is a demonstration of a candidate's knowledge and expertise in information security management and is highly valued by employers worldwide.
NEW QUESTION # 112
The PRIMARY purpose of performing an internal attack and penetration test as part of an incident response program is to identify:
- A. the optimum response to internal hacker attacks.
- B. ways to improve the incident response process.
- C. weaknesses in network and server security.
- D. potential attack vectors on the network perimeter.
Answer: C
Explanation:
An internal attack and penetration test are designed to identify weaknesses in network and server security. They do not focus as much on incident response or the network perimeter.
NEW QUESTION # 113
Which of the following reduces the potential impact of social engineering attacks?
- A. Security awareness programs
- B. Compliance with regulatory requirements
- C. Effective performance incentives
- D. Promoting ethical understanding
Answer: A
Explanation:
Explanation
Because social engineering is based on deception of the user, the best countermeasure or defense is a security awareness program. The other choices are not user-focused.
NEW QUESTION # 114
Which of the following would BEST help an information security manager prioritize remediation activities to meet regulatory requirements?
- A. Cost of associated controls
- B. Alignment with the IT strategy
- C. A capability maturity model matrix
- D. Annual toss expectancy (ALE) of noncompliance
Answer: D
NEW QUESTION # 115
Which of the following actions should be taken when an online trading company discovers a network attack in progress?
- A. Enable trace logging on all event
- B. Dump all event logs to removable media
- C. Isolate the affected network segment
- D. Shut off all network access points
Answer: C
Explanation:
Explanation
Isolating the affected network segment will mitigate the immediate threat while allowing unaffected portions of the business to continue processing. Shutting off all network access points would create a denial of service that could result in loss of revenue. Dumping event logs and enabling trace logging, while perhaps useful, would not mitigate the immediate threat posed by the network attack.
NEW QUESTION # 116
A core business unit relies on an effective legacy system that does not meet the current security standards and threatens that enterprise network. Which of the following is the BEST course of action to address the situation?
- A. Disconnect the legacy system from the rest of the network.
- B. Require that new systems that can meet the standards be implemented.
- C. Document the deficiencies in the risk register.
- D. Develop processes to compensate for the deficiencies.
Answer: D
NEW QUESTION # 117
Which of the following risks would BEST be assessed using quantitative risk assessment techniques?
- A. An electrical power outage
- B. Customer data stolen
- C. A web site defaced by hackers
- D. Loss of the software development team
Answer: A
Explanation:
The effect of the theft of customer data or web site defacement by hackers could lead to a permanent decline in customer confidence, which does not lend itself to measurement by quantitative techniques. Loss of a majority of the software development team could have similar unpredictable repercussions. However, the loss of electrical power for a short duration is more easily measurable and can be quantified into monetary amounts that can be assessed with quantitative techniques.
NEW QUESTION # 118
To address the issue that performance pressures on IT may conflict with information security controls, it is MOST important that:
- A. the security policy is changed to accommodate IT performance pressure
- B. senior management provides guidance and dispute resolution
- C. information security management understands business performance issues
- D. noncompliance issues are reported to senior management
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 119
During the establishment of a service level agreement (SLA) with a cloud service provider, it is MOST important for the information security manager to:
- A. set up proper communication paths with the provider.
- B. understand the cloud storage architecture in use to determine security risk.
- C. ensure security requirements are contractually enforceable.
- D. update the security policy to reflect the provider's terms of service.
Answer: C
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION # 120
To justify the need to invest in a forensic analysis tool, an information security manager should FIRST:
- A. provide examples of situations where such a tool would be useful.
- B. review comparison reports of tool implementation in peer companies.
- C. review the functionalities and implementation requirements of the solution.
- D. substantiate the investment in meeting organizational needs.
Answer: D
Explanation:
Any investment must be reviewed to determine whether it is cost effective and supports the organizational strategy. It is important to review the features and functionalities provided by such a tool, and to provide examples of situations where the tool would be useful, but that comes after substantiating the investment and return on investment to the organization.
NEW QUESTION # 121
The PRIMARY goal in developing an information security strategy is to:
- A. support the business objectives of the organization.
- B. establish security metrics and performance monitoring.
- C. educate business process owners regarding their duties.
- D. ensure that legal and regulatory requirements are met
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The business objectives of the organization supersede all other factors. Establishing metrics and measuring performance, meeting legal and regulatory requirements, and educating business process owners are all subordinate to this overall goal.
NEW QUESTION # 122
Which is the BEST way to measure and prioritize aggregate risk deriving from a chain of linked system vulnerabilities?
- A. Penetration tests
- B. Code reviews
- C. Vulnerability scans
- D. Security audits
Answer: A
Explanation:
Explanation
A penetration test is normally the only security assessment that can link vulnerabilities together by exploiting them sequentially. This gives a good measurement and prioritization of risks. Other security assessments such as vulnerability scans, code reviews and security audits can help give an extensive and thorough risk and vulnerability overview', but will not be able to test or demonstrate the final consequence of having several vulnerabilities linked together. Penetration testing can give risk a new perspective and prioritize based on the end result of a sequence of security problems.
NEW QUESTION # 123
An organization's information security manager is performing a post-incident review of a security incident in which the following events occurred:
* A bad actor broke into a business-critical FTP server by brute forcing an administrative password
* The third-party service provider hosting the server sent an automated alert message to the help desk, but was ignored
* The bad actor could not access the administrator console, but was exposed to encrypted data transferred to the server
* After three (3) hours, the bad actor deleted the FTP directory causing incoming FTP attempts by legitimate customers to fail Which of the following poses the GREATEST risk to the organization related to This event?
- A. Downtime of the service
- B. Removal of data
- C. Disclosure of stolen data
- D. Potential access to the administrator console
Answer: A
NEW QUESTION # 124
Following a risk assessment, new countermeasures have been approved by management. Which of the following should be performed NEXT
- A. Calculate the residual risk for each countermeasure.
- B. Schedule the target end date for implementation activities.
- C. Budget the total cost of implementation activities.
- D. Develop an implementation strategy.
Answer: D
NEW QUESTION # 125
The MOST important reason to use a centralized mechanism to identify information security incidents is to:
- A. comply with corporate policies
- B. detect threats across environments
- C. prevent unauthorized changes to networks
- D. detect potential fraud
Answer: B
NEW QUESTION # 126
Which of the following presents the MOST significant challenge when classifying IT assets?
- A. Vulnerabilities in information assets
- B. Disagreement between asset owners and custodians
- C. Complex asset classification scheme
- D. Information assets without owners
Answer: D
NEW QUESTION # 127
Which of the following actions should lake place immediately after a security breach is reported to an information security manager?
- A. Notify affected stakeholders
- B. Isolate the incident
- C. Confirm the incident
- D. Determine impact
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Before performing analysis of impact, resolution, notification or isolation of an incident, it must be validated as a real security incident.
NEW QUESTION # 128
Which of the following is the BEST way for an information security
manager to justify ongoing annual maintenance fees associated with an
intrusion prevention system (IPS)?
- A. Perform industry research annually and document the overall ranking of the IPS.
- B. Provide yearly competitive pricing to illustrate the value of the IPS.
- C. Perform a penetration test to demonstrate the ability to protect
- D. Establish and present appropriate metrics that track performance.
Answer: D
NEW QUESTION # 129
Which of the following should be the PRIMARY consideration when developing an incident response plan?
- A. Previously reported incidents
- B. Management support
- C. Compliance with regulations
- D. The definition of an incident
Answer: C
NEW QUESTION # 130
Which of the following is MOST important for measuring the effectiveness of a security awareness program?
- A. Reduced number of security violation reports
- B. Increased number of security violation reports
- C. Increased interest in focus groups on security issues
- D. A quantitative evaluation to ensure user comprehension
Answer: D
Explanation:
Explanation
To truly judge the effectiveness of security awareness training, some means of measurable testing is necessary to confirm user comprehension. Focus groups may or may not provide meaningful feedback but, in and of themselves, do not provide metrics. An increase or reduction in the number of violation reports may not be indicative of a high level of security awareness.
NEW QUESTION # 131
Which of the following is the MOST effective way to demonstrate alignment of information security strategy with business objectives?
- A. Benchmarking
- B. Heat map
- C. Risk matrix
- D. Balanced scorecard
Answer: D
Explanation:
Explanation
The balanced scorecard is a management tool that can be used to demonstrate the alignment of information security strategy with business objectives. The balanced scorecard provides a comprehensive view of an organization's performance by considering multiple dimensions, including financial performance, customer satisfaction, internal processes, and learning and growth.
By integrating information security objectives and metrics into the balanced scorecard, organizations can demonstrate how their information security investments support and align with their overall business objectives. This can help to gain the support and commitment of senior management and other stakeholders, as well as ensure that information security investments are effectively managed and optimized to deliver maximum value to the organization.
While other tools, such as risk matrices, benchmarking, and heat maps, can also provide valuable information, the balanced scorecard provides a more holistic and integrated view of organizational performance and the alignment of information security with business objectives.
NEW QUESTION # 132
An information security manager learns that the root password of an external FTP server may be subject to brute force attacks. Which of the following would be the MOST appropriate way to reduce the likelihood of a successful attack?
- A. Install an intrusion detection system (IDS).
- B. Block the source IP address of the attacker.
- C. Disable access to the externally facing server.
- D. Lock remote logon after multiple failed attempts.
Answer: D
NEW QUESTION # 133
From an information security manager perspective, what is the immediate benefit of clearly-defined roles and responsibilities?
- A. Better accountability
- B. Segregation of duties
- C. Enhanced policy compliance
- D. Improved procedure flows
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Without well-defined roles and responsibilities, there cannot be accountability. Choice A is incorrect because policy compliance requires adequately defined accountability first and therefore is a byproduct. Choice B is incorrect because people can be assigned to execute procedures that are not well designed. Choice C is incorrect because segregation of duties is not automatic, and roles may still include conflicting duties.
NEW QUESTION # 134
Which of the following is BEST determined by using technical metrics?
- A. How well security risk is being managed
- B. How well the security strategy is aligned with organizational objectives
- C. Whether security resources are adequately allocated
- D. Whether controls are operating effectively.
Answer: B
NEW QUESTION # 135
Which would be one of the BEST metrics an information security manager can employ to effectively evaluate the results of a security program?
- A. Percent of control objectives accomplished
- B. Percent of compliance with the security policy
- C. Reduction in the number of reported security incidents
- D. Number of controls implemented
Answer: A
Explanation:
Control objectives are directly related to business objectives; therefore, they would be the best metrics. Number of controls implemented does not have a direct relationship with the results of a security program. Percentage of compliance with the security policy and reduction in the number of security incidents are not as broad as choice B.
NEW QUESTION # 136
An organization with multiple data centers has designated one of its own facilities as the recovery site. The MOST important concern is the:
- A. communication line capacity between data centers.
- B. differences in logical security at each center.
- C. synchronization of system software release versions.
- D. current processing capacity loads at data centers.
Answer: D
Explanation:
Explanation
If data centers are operating at or near capacity, it may prove difficult to recover critical operations at an alternate data center. Although line capacity is important from a mirroring perspective, this is secondary to having the necessary capacity to restore critical systems. By comparison, differences in logical and physical security and synchronization of system software releases are much easier issues to overcome and are, therefore, of less concern.
NEW QUESTION # 137
......
Pass ISACA CISM Premium Files Test Engine pdf - Free Dumps Collection: https://www.passsureexam.com/CISM-pass4sure-exam-dumps.html
New 2023 Realistic CISM Dumps Test Engine Exam Questions in here: https://drive.google.com/open?id=1pR1hvtecLXuklZEKq4LLsnf8_hRjpQBU