[Dec-2021] CISM Dumps Full Questions - Isaca Certification Exam Study Guide [Q744-Q769]

Share

[Dec-2021] CISM Dumps Full Questions - Isaca Certification Exam Study Guide

Exam Questions and Answers for  CISM Study Guide


ISACA CISM: What career benefits can you get?

Holding the CISM certification will support your career growth. If you are an IT Security Architect, an Information Security Analyst, or a Chief Information Security Officer, this certificate will help you significantly get a promotion or find a new job. It demonstrates your knowledge in the information security sphere and makes finding a new job easier.

In addition, you will surely earn more. The average salary for those professionals who have the CISM certification ranges from $52,400 to $243,600 per year. Therefore, if you want to get a pay raise, this certificate is the right choice for you.

 

NEW QUESTION 744
Following a successful and well-publicized hacking incident, an organization has plans to improve application security.
Which of the following is a security project risk?

  • A. A trapdoor may have been installed in the application.
  • B. The reputation of the organization may be damaged.
  • C. Critical evidence may be lost.
  • D. Resources may not be available to support the implementation.

Answer: D

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 745
Which of the following is the BEST way to ensure that Incidents are Identified and reported?

  • A. Publish a punitive action policy for failure to report Incidents.
  • B. Implement an automated monitoring program to detect incidents.
  • C. Implement an ongoing incident response training program for employees.
  • D. Develop and communicate a comprehensive incident response plan.

Answer: C

 

NEW QUESTION 746
The objective of risk management is to reduce risk to the minimum level that is:

  • A. compliant with security policies
  • B. acceptable given the preference of the organization.
  • C. achievable from technical and financial perspectives.
  • D. practical given industry and regulatory environments.

Answer: A

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 747
Which of the following is BEST determined by using technical metrics?

  • A. Whether controls are operating effectively.
  • B. Whether security resources are adequately allocated
  • C. How well the security strategy is aligned with organizational objectives
  • D. How well security risk is being managed

Answer: A

 

NEW QUESTION 748
To determine the selection of controls required to meet business objectives, an information security manager should:

  • A. restrict controls to only critical applications.
  • B. prioritize the use of role-based access controls.
  • C. focus on key controls.
  • D. focus on automated controls.

Answer: C

Explanation:
Explanation
Key controls primarily reduce risk and are most effective for the protection of information assets. The other choices could be examples of possible key controls.

 

NEW QUESTION 749
Nonrepudiation can BEST be ensured by using:

  • A. strong passwords.
  • B. digital signatures.
  • C. a digital hash.
  • D. symmetric encryption.

Answer: B

Explanation:
Digital signatures use a private and public key pair, authenticating both parties. The integrity of the contents exchanged is controlled through the hashing mechanism that is signed by the private key of the exchanging party. A digital hash in itself helps in ensuring integrity of the contents, but not nonrepudiation. Symmetric encryption wouldn't help in nonrepudiation since the keys are always shared between parties. Strong passwords only ensure authentication to the system and cannot be used for nonrepudiation involving two or more parties.

 

NEW QUESTION 750
Logging is an example of which type of defense against systems compromise?

  • A. Reaction
  • B. Detection
  • C. Containment
  • D. Recovery

Answer: B

Explanation:
Detection defenses include logging as well as monitoring, measuring, auditing, detecting viruses and intrusion. Examples of containment defenses are awareness, training and physical security defenses. Examples of reaction defenses are incident response, policy and procedure change, and control enhancement. Examples of recovery defenses are backups and restorations, failover and remote sites, and business continuity plans and disaster recovery plans.

 

NEW QUESTION 751
Which of the following will BEST enable an effective information asset classification process?

  • A. Assigning ownership
  • B. Reviewing the recovery time objective (RTO) requirements of the asset
  • C. Analyzing audit findings
  • D. Including security requirements in the classification process

Answer: A

 

NEW QUESTION 752
An information security manager is recommending an investment in a new security initiative to address recently published threats. Which of the following would be important to include in the business case?

  • A. Alignment of the new initiative with the approved business strategy
  • B. Business impact if threats materialize
  • C. Threat information from reputable sources
  • D. Availability of unused funds in the security budget

Answer: B

 

NEW QUESTION 753
The effectiveness of security awareness programs in fostering positive security cultures is MOST dependent upon employee:

  • A. ability to carry out security-related procedures.
  • B. awareness of regulatory requirements.
  • C. understanding of the penalties for noncompliance.
  • D. ownership of security responsibilities.

Answer: D

 

NEW QUESTION 754
Which of the following is the MOST important consideration when securing customer credit card data acquired by a point-of-sale (POS) cash register?

  • A. Nonrepudiation
  • B. Authentication
  • C. Encryption
  • D. Hardening

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Cardholder data should be encrypted using strong encryption techniques. Hardening would be secondary in importance, while nonrepudiation would not be as relevant. Authentication of the point-of-sale (POS) terminal is a previous step to acquiring the card information.

 

NEW QUESTION 755
Risk management programs are designed to reduce risk to:

  • A. a rate of return that equals the current cost of capital.
  • B. a level that the organization is willing to accept.
  • C. a level that is too small to be measurable.
  • D. the point at which the benefit exceeds the expense.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Risk should be reduced to a level that an organization is willing to accept. Reducing risk to a level too small to measure is impractical and is often cost-prohibitive. To tie risk to a specific rate of return ignores the qualitative aspects of risk that must also be considered. Depending on the risk preference of an organization, it may or may not choose to pursue risk mitigation to the point at which the benefit equals or exceeds the expense. Therefore, choice C is a more precise answer.

 

NEW QUESTION 756
Which of the following is the MOST important guideline when using software to scan for security exposures within a corporate network?

  • A. Follow a linear process for attacks
  • B. Never use open source tools
  • C. Focus only on production servers
  • D. Do not interrupt production processes

Answer: D

Explanation:
Explanation
The first rule of scanning for security exposures is to not break anything. This includes the interruption of any running processes. Open source tools are an excellent resource for performing scans. Scans should focus on both the test and production environments since, if compromised, the test environment could be used as a platform from which to attack production servers. Finally, the process of scanning for exposures is more of a spiral process than a linear process.

 

NEW QUESTION 757
Which of the following is the MOST effective approach to ensure IT processes are performed in compliance with the information security policies?

  • A. Providing information security policy training to the process owners
  • B. Allocating sufficient resources
  • C. Identifying risks in the processes and managing those risks
  • D. Ensuring that key controls are embedded in the processes

Answer: C

 

NEW QUESTION 758
Which of the following is the BEST way for senior leadership to demonstrate commitment for an effective information security strategy?

  • A. Allocating adequate resources for information security
  • B. Communicating organizational risk appetite and tolerance
  • C. Appointing the top information security role to report to the CEO
  • D. Approving a comprehensive risk management program

Answer: A

 

NEW QUESTION 759
Which of the following is the MOST effective data loss control when connecting a personally owned mobile device to the corporate email system?

  • A. Users must agree to allow the mobile device to be wiped if it is lost.
  • B. A senior manager must approve each connection.
  • C. Email must be stored in an encrypted format on the mobile device.
  • D. Email synchronization must be prevented when connected to a public Wi-Fi hotspot.

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 760
A message* that has been encrypted by the sender's private key and again by the receiver's public key achieves:

  • A. confidentiality and nonrepudiation.
  • B. authentication and authorization.
  • C. confidentiality and integrity.
  • D. authentication and nonrepudiation.

Answer: A

Explanation:
Encryption by the private key of the sender will guarantee authentication and nonrepudiation. Encryption by the public key of the receiver will guarantee confidentiality.

 

NEW QUESTION 761
Which of the following would be the FIRST step in establishing an information security program?

  • A. Develop the security policy.
  • B. Conduct a security controls study.
  • C. Develop the security plan.
  • D. Develop security operating procedures.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A security plan must be developed to implement the security strategy. All of the other choices should follow the development of the security plan.

 

NEW QUESTION 762
Which of the following is the BEST metric for evaluating the effectiveness of an intrusion detection mechanism?

  • A. Number of successful attacks
  • B. Ratio of false positives to false negatives
  • C. Ratio of successful to unsuccessful attacks
  • D. Number of attacks detected

Answer: B

Explanation:
Explanation
The ratio of false positives to false negatives will indicate whether an intrusion detection system (IDS) is properly tuned to minimize the number of false alarms while, at the same time, minimizing the number of omissions. The number of attacks detected, successful attacks or the ratio of successful to unsuccessful attacks would not indicate whether the IDS is properly configured.

 

NEW QUESTION 763
A validated patch to address a new vulnerability that may affect a mission-critical server has been released. What should be done immediately?

  • A. Conduct an impact analysis.
  • B. Check the server s security and install the patch.
  • C. Take the server off-line and install the patch.
  • D. Add mitigating controls.

Answer: A

 

NEW QUESTION 764
Which of the following would BEST enable effective decision-making?

  • A. Annualized loss estimates determined from past security events
  • B. A consistent process to analyze new and historical information risk
  • C. Formalized acceptance of risk analysis by business management
  • D. A universally applied list of generic threats, impacts, and vulnerabilities

Answer: B

 

NEW QUESTION 765
Who is ultimately responsible for ensuring that information is categorized and that protective measures are taken?

  • A. Information security officer
  • B. Data owner
  • C. Data custodian
  • D. Security steering committee

Answer: D

Explanation:
Routine administration of all aspects of security is delegated, but senior management must retain overall responsibility. The information security officer supports and implements information security for senior management. The data owner is responsible for categorizing data security requirements. The data custodian supports and implements information security as directed.

 

NEW QUESTION 766
An organization is considering a self-service solution for the deployment of virtualized development servers.

  • A. Ability to maintain server security baseline
  • B. Ability to remain current with patches
  • C. Segregation of servers from the production environment
  • D. Generation of excessive security event logs

Answer: C

 

NEW QUESTION 767
How would an information security manager balance the potentially conflicting requirements of an international organization's security standards and local regulation?

  • A. Give organization standards preference over local regulations
  • B. Negotiate a local version of the organization standards
  • C. Follow local regulations only
  • D. Make the organization aware of those standards where local regulations causes conflicts

Answer: B

Explanation:
Explanation
Adherence to local regulations must always be the priority. Not following local regulations can prove detrimental to the group organization. Following local regulations only is incorrect since there needs to be some recognition of organization requirements. Making an organization aware of standards is a sensible step, but is not a total solution. Negotiating a local version of the organization standards is the most effective compromise in this situation.

 

NEW QUESTION 768
When developing security processes for handling credit card data on the business unit's information system, the information security manager should

  • A. review corporate policies regarding credit card information.
  • B. implement the credit card companies' security requirements.
  • C. review industry's best practices for handling secure payments.
  • D. ensure that systems handle credit card data are segmented.

Answer: A

 

NEW QUESTION 769
......

Certified Information Security Manager Free Update With 100% Exam Passing Guarantee: https://www.prepawayexam.com/ISACA/braindumps.CISM.ete.file.html

Real Exam Questions & Answers - ISACA CISM Dump is Ready: https://drive.google.com/open?id=1EoyFq3wRAO9nvGI0MBe0BOoYr9nlVxB1