
Ensure Success With Updated Verified CISM Exam Dumps [2022]
Exam Materials for You to Prepare & Pass CISM Exam.
NEW QUESTION 224
Which of the following provides the GREATEST assurance that information security is addressed in change management?
- A. Requiring senior management sign-off on change management
- B. Providing security training for change advisory board
- C. Reviewing changes from a security perspective
- D. Performing a security audit on changes
Answer: C
NEW QUESTION 225
In organizations where availability is a primary concern, the MOST critical success factor of the patch management procedure would be the:
- A. automated deployment to all the servers.
- B. technical skills of the team responsible.
- C. certification of validity for deployment.
- D. testing time window prior to deployment.
Answer: D
Explanation:
Explanation
Having the patch tested prior to implementation on critical systems is an absolute prerequisite where availability is a primary concern because deploying patches that could cause a system to fail could be worse than the vulnerability corrected by the patch. It makes no sense to deploy patches on every system. Vulnerable systems should be the only candidate for patching. Patching skills are not required since patches are more often applied via automated tools.
NEW QUESTION 226
Senior management commitment and support for information security can BEST be enhanced through:
- A. periodic review of alignment with business management goals.
- B. a formal security policy sponsored by the chief executive officer (CEO).
- C. senior management signoff on the information security strategy.
- D. regular security awareness training for employees.
Answer: A
Explanation:
Explanation
Ensuring that security activities continue to be aligned and support business goals is critical to obtaining their support. Although having the chief executive officer (CEO) signoff on the security policy and senior management signoff on the security strategy makes for good visibility and demonstrates good tone at the top, it is a one-time discrete event that may be quickly forgotten by senior management. Security awareness training for employees will not have as much effect on senior management commitment.
NEW QUESTION 227
When designing an information security quarterly report to management, the MOST important element to be considered should be the:
- A. baseline against which metrics are evaluated.
- B. information security metrics.
- C. linkage to business area objectives.
- D. knowledge required to analyze each issue.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
The link to business objectives is the most important clement that would be considered by management.
Information security metrics should be put in the context of impact to management objectives. Although important, the security knowledge required would not be the first element to be considered. Baselining against the information security metrics will be considered later in the process.
NEW QUESTION 228
Which of the following should be the PRIMARY consideration when selecting a recovery site?
- A. Geographical location
- B. Recovery point objective
- C. Regulatory requirements
- D. Recovery time objective
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 229
Deciding the level of protection a particular asset should be given is BEST determined by:
- A. a vulnerability assessment
- B. a risk analysis.
- C. a threat assessment.
- D. corporate risk appetite.
Answer: D
NEW QUESTION 230
The BEST way to ensure that security settings on each platform are in compliance with information security policies and procedures is to:
- A. implement vendor default settings.
- B. establish security baselines.
- C. perform penetration testing.
- D. link policies to an independent standard.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Security baselines will provide the best assurance that each platform meets minimum criteria. Penetration testing will not be as effective and can only be performed periodically. Vendor default settings will not necessarily meet the criteria set by the security policies, while linking policies to an independent standard will not provide assurance that the platforms meet these levels of security.
NEW QUESTION 231
An organization is automating data protection by implementing a data loss prevention (DLP) solution. Which of the following should the Information security manager do FIRST?
- A. Define a data classification schema
- B. Perform a cost-benefit analysis.
- C. Evaluate potential DLP solutions.
- D. Define the threshold for reporting data loss
Answer: A
NEW QUESTION 232
Which of the following processes BEST supports the evaluation of incident response effectiveness?
- A. Postincident review
- B. Root cause analysis
- C. Incident logging
- D. Chain of custody
Answer: B
NEW QUESTION 233
Which of the following security activities should be implemented in the change management process to identify key vulnerabilities introduced by changes?
- A. Audit and review
- B. Business impact analysis (BIA)
- C. Penetration testing
- D. Threat analysis
Answer: C
Explanation:
Penetration testing focuses on identifying vulnerabilities. None of the other choices would identify vulnerabilities introduced by changes.
NEW QUESTION 234
Which of the following is the GREATEST benefit of a centralized approach to coordinating information security?
- A. Optimal use of security resources
- B. Integration with business functions
- C. Reduction in the number of policies
- D. Business user buy-in
Answer: A
NEW QUESTION 235
An organization wants to integrate information security into its human resource management processes. Which of the following should be the FIRST step?
- A. Assess the business objectives of the processes
- B. Identify information security risk associated with the processes
- C. Benchmark the processes with best practice to identify gaps
- D. Evaluate the cost of information security integration
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 236
To achieve effective strategic alignment of security initiatives, it is important that:
- A. Inputs be obtained and consensus achieved between the major organizational units.
- B. The business strategy be updated periodically.
- C. Steering committee leadership be selected by rotation.
- D. Procedures and standards be approved by all departmental heads.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
It is important to achieve consensus on risks and controls, and obtain inputs from various organizational entities since security needs to be aligned to the needs of the organization. Rotation of steering committee leadership does not help in achieving strategic alignment. Updating business strategy does not lead to strategic alignment of security initiatives. Procedures and standards need not be approved by all departmental heads
NEW QUESTION 237
An information security manager has identified numerous violations of security policy which prohibits text messaging from personal devices to conduct official business following is the MOST effective way to reduce the number of violations?
- A. Provide awareness training to end users.
- B. Report violations to senior management.
- C. Require management approval for policy exceptions.
- D. Implement a mobile device management (MDM) solution.
Answer: A
NEW QUESTION 238
Without prior approval, a training department enrolled the company in a free cloud-based collaboration site and invited employees to use it. Which of the following is the BEST response of the information security manager?
- A. Update the risk register and review the information security strategy.
- B. Conduct a risk assessment and develop an impact analysis.
- C. Allow temporary use of the site and monitor for data leakage.
- D. Report the activity to senior management.
Answer: A
NEW QUESTION 239
Which of the following stakeholders would provide the BEST guidance in aligning the information security strategy with organizational goals?
- A. information security steering committee
- B. Chief information officer (CIO)
- C. Board of directors
- D. Chief information security officer (CISO)
Answer: A
NEW QUESTION 240
A policy has been established requiting users to install mobile device management (MDM) software on their personal devices Which of the following would BEST mitigate the risk created by noncompliance with this policy?
- A. Disabling remote access from the mobile device
- B. Issuing company-configured mobile devices
- C. Requiring users to sign off on terms and conditions
- D. Issuing warnings and documenting noncompliance
Answer: A
NEW QUESTION 241
An organization's information security processes are currently defined as ad hoc. In seeking to improve their performance level, the next step for the organization should be to:
- A. implement monitoring of key performance indicators for security processes.
- B. ensure that security processes are consistent across the organization.
- C. ensure that security processes are fully documented.
- D. enforce baseline security levels across the organization.
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The organization first needs to move from ad hoc to repeatable processes. The organization then needs to document the processes and implement process monitoring and measurement. Baselining security levels will not necessarily assist in process improvement since baselining focuses primarily on control improvement. The organization needs to standardize processes both before documentation, and before monitoring and measurement.
NEW QUESTION 242
Information security can BEST be enforced by making security:
- A. an integral component of corporate policies.
- B. a flexible system of procedures and guidelines.
- C. a part of each employee's Job objectives.
- D. a business process owner activity.
Answer: C
NEW QUESTION 243
An organization has to comply with recently published industry regulatory requirements-compliance that potentially has high implementation costs. What should the information security manager do FIRST?
- A. Perform a gap analysis.
- B. Implement compensating controls.
- C. Demand immediate compliance.
- D. Implement a security committee.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Since they are regulatory requirements, a gap analysis would be the first step to determine the level of compliance already in place. Implementing a security committee or compensating controls would not be the first step. Demanding immediate compliance would not assess the situation.
NEW QUESTION 244
Which of the following is MOST important for an information security manager to regularly report to senior management?
- A. Audit reports
- B. Threat analysis reports
- C. Results of penetration tests
- D. Impact of unremediated risks
Answer: B
NEW QUESTION 245
Logging is an example of which type of defense against systems compromise?
- A. Containment
- B. Detection
- C. Reaction
- D. Recovery
Answer: B
Explanation:
Detection defenses include logging as well as monitoring, measuring, auditing, detecting viruses and intrusion. Examples of containment defenses are awareness, training and physical security defenses. Examples of reaction defenses are incident response, policy and procedure change, and control enhancement. Examples of recovery defenses are backups and restorations, failover and remote sites, and business continuity plans and disaster recovery plans.
NEW QUESTION 246
Which of the following is the MOST effective way of ensuring that business units comply with an information security governance framework?
- A. Integrating security requirements with processes
- B. Conducting information security awareness training
- C. Performing security assessments and gap analysis
- D. Conducting a business impact analysis (BIA)
Answer: C
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION 247
......
Updated CISM Certification Exam Sample Questions: https://actual4test.exam4labs.com/CISM-practice-torrent.html