Pass CISM Exam with Updated CISM Exam Dumps PDF 2024 [Q55-Q78]

Share

Pass CISM Exam with Updated CISM Exam Dumps PDF 2024

CISM Exam Dumps - Free Demo & 365 Day Updates

NEW QUESTION # 55
The BEST protocol to ensure confidentiality of transmissions in a business-to-customer (B2C) financial web application is:

  • A. Secure Shell (SSH).
  • B. Secure Sockets Layer (SSL).
  • C. Secure/Multipurpose Internet Mail Extensions (S/MIME ).
  • D. IP Security (IPSec).

Answer: B

Explanation:
Secure Sockets Layer (SSL) is a cryptographic protocol that provides secure communications providing end point authentication and communications privacy over the Internet. In typical use, all data transmitted between the customer and the business are, therefore, encrypted by the business's web server and remain confidential. SSH File Transfer Protocol (SFTP) is a network protocol that provides file transfer and manipulation functionality over any reliable data stream. It is typically used with the SSH-2 protocol to provide secure file transfer. IP Security (IPSec) is a standardized framework for securing Internet Protocol (IP) communications by encrypting and/or authenticating each IP packet in a data stream. There are two modes of IPSec operation: transport mode and tunnel mode. Secure/Multipurpose Internet Mail Extensions (S/MIME) is a standard for public key encryption and signing of e-mail encapsulated in MIME; it is not a web transaction protocol.


NEW QUESTION # 56
The "separation of duties" principle is violated if which of the following individuals has update rights to the database access control list (ACL)?

  • A. Data owner
  • B. Systems programmer
  • C. Security administrator
  • D. Data custodian

Answer: B

Explanation:
Explanation
A systems programmer should not have privileges to modify the access control list (ACL) because this would give the programmer unlimited control over the system. The data owner would request and approve updates to the ACL, but it is not a violation of the separation of duties principle if the data owner has update rights to the ACL. The data custodian and the security administrator could carry out the updates on the ACL since it is part of their duties as delegated to them by the data owner.


NEW QUESTION # 57
Which of the following is the MOST important reason why information security objectives should be defined?

  • A. Management sign-off and support initiatives
  • B. General understanding of goals
  • C. Tool for measuring effectiveness
  • D. Consistency with applicable standards

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The creation of objectives can be used in part as a source of measurement of the effectiveness of information security management, which feeds into the overall governance. General understanding of goals and consistency with applicable standards are useful, but are not the primary reasons for having clearly defined objectives. Gaining management understanding is important, but by itself will not provide the structure for governance.


NEW QUESTION # 58
Which of the following provides an information security manager with the MOST accurate indication of the organization's ability to respond to a cyber attack?

  • A. Red team exercise
  • B. Simulated phishing exercise
  • C. Walk-through of the incident response plan
  • D. Black box penetration test

Answer: A


NEW QUESTION # 59
Security technologies should be selected PRIMARILY on the basis of their:

  • A. use of new and emerging technologies.
  • B. ability to mitigate business risks.
  • C. benefits in comparison to their costs.
  • D. evaluations in trade publications.

Answer: B

Explanation:
Explanation
The most fundamental evaluation criterion for the appropriate selection of any security technology is its ability to reduce or eliminate business risks. Investments in security technologies should be based on their overall value in relation to their cost; the value can be demonstrated in terms of risk mitigation. This should take precedence over whether they use new or exotic technologies or how they are evaluated in trade publications.


NEW QUESTION # 60
An information security manager mapping a job description to types of data access is MOST likely to adhere to which of the following information security principles?

  • A. Accountability
  • B. Proportionality
  • C. Ethics
  • D. Integration

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Information security controls should be proportionate to the risks of modification, denial of use or disclosure of the information. It is advisable to learn if the job description is apportioning more data than are necessary for that position to execute the business rules (types of data access). Principles of ethics and integration have the least to do with mapping job description to types of data access. The principle of accountability would be the second most adhered to principle since people with access to data may not always be accountable but may be required to perform an operation.


NEW QUESTION # 61
Which of the following is the BEST evidence of the maturity of an organization's information security program?

  • A. The number of reported incidents has decreased
  • B. IT security staff implements strict technical security controls.
  • C. Management has approved the information security policy.
  • D. The number of reported incidents has increased

Answer: C


NEW QUESTION # 62
An intranet server should generally be placed on the:

  • A. firewall server.
  • B. primary domain controller.
  • C. internal network.
  • D. external router.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
An intranet server should be placed on the internal network. Placing it on an external router leaves it defenseless. Since firewalls should be installed on hardened servers with minimal services enabled, it is inappropriate to store the intranet server on the same physical device as the firewall. Similarly, primary- domain controllers do not normally share the physical device as the intranet server.


NEW QUESTION # 63
To justify its ongoing security budget, which of the following would be of MOST use to the information security' department?

  • A. Annualized loss expectancy (ALE)
  • B. Cost-benefit analysis
  • C. Security breach frequency
  • D. Peer group comparison

Answer: B

Explanation:
Cost-benefit analysis is the legitimate way to justify budget. The frequency of security breaches may assist the argument for budget but is not the key tool; it does not address the impact. Annualized loss expectancy (ALE) does not address the potential benefit of security investment. Peer group comparison would provide a good estimate for the necessary security budget but it would not take into account the specific needs of the organization.


NEW QUESTION # 64
Risk acceptance is a component of which of the following?

  • A. Assessment
  • B. Monitoring
  • C. Evaluation
  • D. Mitigation

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Risk acceptance is one of the alternatives to be considered in the risk mitigation process. Assessment and evaluation are components of the risk analysis process. Risk acceptance is not a component of monitoring.


NEW QUESTION # 65
Which is the BEST method to evaluate the effectiveness of an alternate processing site when continuous uptime is required?

  • A. Simulation test
  • B. Full interruption test
  • C. Parallel test
  • D. Tabletop test

Answer: C

Explanation:
Explanation
A parallel test is the best method to evaluate the effectiveness of an alternate processing site when continuous uptime is required. A parallel test involves processing the same transactions or data at both the primary and the alternate site simultaneously, and comparing the results for accuracy and consistency. A parallel test can validate the functionality, performance, and reliability of the alternate site without disrupting the normal operations at the primary site. A parallel test can also identify and resolve any issues or discrepancies between the two sites before a real disaster occurs. A parallel test can provide a high level of assurance and confidence that the alternate site can support the organization's continuity requirements.
References = CISM Review Manual, 16th Edition, Chapter 3: Information Security Program Development and Management, Section: Business Continuity Plan (BCP) Testing, page 1861; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 56, page 522.
A parallel test is the best method to evaluate the effectiveness of an alternate processing site when continuous uptime is required because it involves processing data at both the primary and alternate sites simultaneously without disrupting the normal operations1. A full interruption test would cause downtime and potential loss of data or revenue2. A simulation test would not provide a realistic assessment of the alternate site's capabilities3. A tabletop test would only involve a discussion of the procedures and scenarios without actually testing the site4.
1: CISM Exam Content Outline | CISM Certification | ISACA 2: CISM - ISACA Certified Information Security Manager Exam Prep - NICCS 3: Prepare for the ISACA Certified Information Security Manager Exam: CISM ... 4: CISM: Certified Information Systems Manager | Official ISACA ... - NICCS


NEW QUESTION # 66
When performing a business impact analysis (BIA), which of the following should calculate the recovery time and cost estimates?

  • A. Business continuity coordinator
  • B. Business process owners
  • C. Industry averages benchmarks
  • D. Information security manager

Answer: B

Explanation:
Business process owners are in the best position to understand the true impact on the business that a system outage would create. The business continuity coordinator, industry averages and even information security will not be able to provide that level of detailed knowledge.


NEW QUESTION # 67
Which of the following BEST supports effective communication during information security incidents7

  • A. Frequent incident response training sessions
  • B. Predetermined service level agreements (SLAs)
  • C. Responsibilities defined within role descriptions
  • D. Centralized control monitoring capabilities

Answer: B

Explanation:
The best way to support effective communication during information security incidents is to have predetermined service level agreements (SLAs) because they define the expectations and responsibilities of the parties involved in the incident response process, and specify the communication channels, methods, and frequency for reporting and updating on the incident status and resolution. Frequent incident response training sessions are not very effective because they do not address the communication needs or challenges during an actual incident. Centralized control monitoring capabilities are not very effective because they do not address the communication needs or challenges during an actual incident. Responsibilities defined within role descriptions are not very effective because they do not address the communication needs or challenges during an actual incident. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned


NEW QUESTION # 68
Which of the following is MOST important to consider when developing a business case to support the investment In an information security program?

  • A. Results of a risk assessment
  • B. Results of a cost-benefit analysis
  • C. Impact on the risk profile
  • D. Senior management support

Answer: D


NEW QUESTION # 69
Which of the following is the MAIN benefit of performing an assessment of existing incident response processes?

  • A. Benchmarking against industry peers
  • B. Prioritization of action plans
  • C. Identification of threats and vulnerabilities
  • D. Validation of current capabilities

Answer: D


NEW QUESTION # 70
Which of the following, using public key cryptography, ensures authentication, confidentiality and nonrepudiation of a message?

  • A. Encrypting first by sender's public key and second by receiver's private key
  • B. Encrypting first by sender's private key and second by receiver's public key
  • C. Encrypting first by receiver's private key and second by sender's public key
  • D. Encrypting first by sender's private key and second decrypting by sender's public key

Answer: B

Explanation:
Explanation
Encrypting by the sender's private key ensures authentication. By being able to decrypt with the sender's public key, the receiver would know that the message is sent by the sender only and the sender cannot deny/repudiate the message. By encrypting with the sender's public key secondly, only the sender will be able to decrypt the message and confidentiality is assured. The receiver's private key is private to the receiver and the sender cannot have it for encryption. Similarly, the receiver will not have the private key of the sender to decrypt the second-level encryption. In the case of encrypting first by the sender's private key and. second, decrypting by the sender's public key, confidentiality is not ensured since the message can be decrypted by anyone using the sender's public key. The receiver's private key would not be available to the sender for second-level encryption. Similarly, the sender's private key would not be available to the receiver for decrypting the message.


NEW QUESTION # 71
Which of the following is responsible for legal and regulatory liability?

  • A. Board and senior management
  • B. Information security steering group
  • C. Chief legal counsel (CLC)
  • D. Chief security officer (CSO)

Answer: A

Explanation:
The board of directors and senior management are ultimately responsible for all that happens in the organization. The others are not individually liable for failures of security in the organization.


NEW QUESTION # 72
A n employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?

  • A. Initiate incident response.
  • B. Initiate a device reset.
  • C. Disable remote access.
  • D. Conduct a risk assessment.

Answer: C


NEW QUESTION # 73
What is the MOST important factor in the successful implementation of an enterprise wide information security program?

  • A. Support of senior management
  • B. Security awareness
  • C. Recalculation of the work factor
  • D. Realistic budget estimates

Answer: A

Explanation:
Explanation
Without the support of senior management, an information security program has little chance of survival. A company's leadership group, more than any other group, will more successfully drive the program. Their authoritative position in the company is a key factor. Budget approval, resource commitments, and companywide participation also require the buy-in from senior management. Senior management is responsible for providing an adequate budget and the necessary resources. Security awareness is important, but not the most important factor. Recalculation of the work factor is a part of risk management.


NEW QUESTION # 74
The MOST effective way to ensure that outsourced service providers comply with the organization's information security policy would be:

  • A. security awareness training.
  • B. periodically auditing.
  • C. penetration testing.
  • D. service level monitoring.

Answer: B

Explanation:
Regular audit exercise can spot any gap in the information security compliance. Service level monitoring can only pinpoint operational issues in the organization's operational environment. Penetration testing can identify security vulnerability but cannot ensure information compliance Training can increase users' awareness on the information security policy, but is not more effective than auditing.


NEW QUESTION # 75
Management would like to understand the risk associated with engaging an Infrastructure-as-a-Service (laaS) provider compared to hosting internally. Which of the following would provide the BEST method of comparing risk scenarios?

  • A. Performing a risk assessment on the laaS provider
  • B. Reviewing mitigating and compensating controls for each risk scenario
  • C. Mapping risk scenarios according to sensitivity of data
  • D. Mapping the risk scenarios by likelihood and impact on a chart

Answer: D

Explanation:
Explanation
Mapping the risk scenarios by likelihood and impact on a chart is the best method of comparing risk scenarios, as it helps to visualize and prioritize the different types and levels of risks associated with each option. A chart can also facilitate the communication and decision-making process by showing the trade-offs and benefits of each option. A chart can be based on qualitative or quantitative data, depending on the availability and accuracy of the information.
References = CISM Review Manual 2022, page 371; CISM Exam Content Outline, Domain 1, Task 1.32; A risk assessment model for selecting cloud service providers; Security best practices for IaaS workloads in Azure


NEW QUESTION # 76
Which of the following eradication methods is MOST appropriate when responding to an incident resulting in malware on an application server?

  • A. Change passwords on the compromised system.
  • B. Restore the system from a known good backup.
  • C. Perform operation system hardening.
  • D. Disconnect the system from the network.

Answer: B

Explanation:
Explanation
Restoring the system from a known good backup is the most appropriate eradication method when responding to an incident resulting in malware on an application server, as it ensures that the system is free of any malicious code and that the data and applications are consistent with the expected state. Disconnecting the system from the network may prevent further spread of the malware, but it does not eradicate it from the system. Changing passwords on the compromised system may reduce the risk of unauthorized access, but it does not remove the malware from the system. Performing operation system hardening may improve the security configuration of the system, but it does not guarantee that the malware is eliminated from the system.
References = CISM Review Manual 2022, page 3131; CISM Exam Content Outline, Domain 4, Task 4.4


NEW QUESTION # 77
What is the GREATEST advantage of documented guidelines and operating procedures from a security perspective?

  • A. Ensure compliance to security standards and regulatory requirements
  • B. Provide detailed instructions on how to carry out different types of tasks
  • C. Ensure consistency of activities to provide a more stable environment
  • D. Ensure reusability to meet compliance to quality requirements

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Developing procedures and guidelines to ensure that business processes address information security risk is critical to the management of an information security program. Developing procedures and guidelines establishes a baseline for security program performance and consistency of security activities.


NEW QUESTION # 78
......

CISM Dumps - Pass Your Certification Exam: https://actual4test.exam4labs.com/CISM-practice-torrent.html