
ISACA CISM Exam Dumps - PDF Questions and Testing Engine
Latest CISM Exam Dumps for Pass Guaranteed
ISACA CISM: What resources should you use to prepare for the certification exam?
The CISM certification exam is not quite easy. You will have to make an effort in order to pass it. Even if you have significant competence in the industry, you must take the appropriate training. Thus, those professionals who have about 3-5 years of experience in the IS industry say that they needed two months of 3-4 hours a day learning and practicing in order to pass the test.
NEW QUESTION # 74
At the conclusion of a disaster recovery test, which of the following should ALWAYS be performed prior to leaving the vendor's hot site facility?
- A. Conduct a meeting to evaluate the test
- B. Complete an assessment of the hot site provider
- C. Evaluate the results from all test scripts
- D. Erase data and software from devices
Answer: D
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
For security and privacy reasons, all organizational data and software should be erased prior to departure.
Evaluations can occur back at the office after everyone is rested, and the overall results can be discussed and compared objectively.
NEW QUESTION # 75
Nonrepudiation can BEST be ensured by using:
- A. a digital hash.
- B. symmetric encryption.
- C. digital signatures.
- D. strong passwords.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Digital signatures use a private and public key pair, authenticating both parties. The integrity of the contents exchanged is controlled through the hashing mechanism that is signed by the private key of the exchanging party. A digital hash in itself helps in ensuring integrity of the contents, but not nonrepudiation.
Symmetric encryption wouldn't help in nonrepudiation since the keys are always shared between parties.
Strong passwords only ensure authentication to the system and cannot be used for nonrepudiation involving two or more parties.
NEW QUESTION # 76
Which of the following would represent a violation of the chain of custody when a backup tape has been identified as evidence in a fraud investigation? The tape was:
- A. kept in the tape library' pending further analysis.
- B. sealed in a signed envelope and locked in a safe under dual control.
- C. removed into the custody of law enforcement investigators.
- D. handed over to authorized independent investigators.
Answer: A
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Since a number of individuals would have access to the tape library, and could have accessed and tampered with the tape, the chain of custody could not be verified. All other choices provide clear indication of who was in custody of the tape at all times.
NEW QUESTION # 77
Which of the following is the BEST method for determining whether a firewall has been configured to provide a comprehensive perimeter defense9
- A. A simulated denial of service (DoS) attack against the firewall
- B. A ping test from an external source
- C. A port scan of the firewall from an internal source
- D. A validation of the current firewall rule set
Answer: D
Explanation:
Explanation
A validation of the current firewall rule set is the best method for determining whether a firewall has been configured to provide a comprehensive perimeter defense because it verifies that the firewall rules are consistent, accurate, and effective in allowing or blocking traffic according to the security policies and standards of the organization. A port scan of the firewall from an internal source is not a good method because it does not test the firewall's behavior from an external perspective, which is more relevant for perimeter defense. A ping test from an external source is not a good method because it only tests the firewall's availability and responsiveness, not its security or functionality. A simulated denial of service (DoS) attack against the firewall is not a good method because it only tests the firewall's resilience and performance under high traffic load, not its security or functionality. References:
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 78
Which of the following is MOST helpful when justifying the funding required for a compensating control?
- A. Threat assessment
- B. Business case
- C. Business impact analysis (B1A)
- D. Risk analysis
Answer: B
NEW QUESTION # 79
Which of the following features is normally missing when using Secure Sockets Layer (SSL) in a web browser?
- A. Multiple encryption algorithms
- B. Certificate-based authentication of web client
- C. Certificate-based authentication of web server
- D. Data confidentiality between client and web server
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Web browsers have the capability of authenticating through client-based certificates; nevertheless, it is not commonly used. When using https, servers always authenticate with a certificate and, once the connection is established, confidentiality will be maintained between client and server. By default, web browsers and servers support multiple encryption algorithms and negotiate the best option upon connection.
NEW QUESTION # 80
Of the following, who should have PRIMARY responsibility for assessing the security risk associated with an outsourced cloud provider contract?
- A. Service delivery manager
- B. Information security manager
- C. Chief information officer
- D. Compliance manager
Answer: B
NEW QUESTION # 81
There is reason to believe that a recently modified web application has allowed unauthorized access. Which is the BEST way to identify an application backdoor?
- A. Security audit
- B. Black box pen test
- C. Vulnerability scan
- D. Source code review
Answer: D
Explanation:
Explanation
Source code review is the best way to find and remove an application backdoor. Application backdoors can be almost impossible to identify' using a black box pen test or a security audit. A vulnerability scan will only find
"known" vulnerability patterns and will therefore not find a programmer's application backdoor.
NEW QUESTION # 82
Information security should be:
- A. driven by regulatory requirements.
- B. a balance between technical and business requirements.
- C. focused on eliminating all risks.
- D. defined by the board of directors.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Information security should ensure that business objectives are met given available technical capabilities, resource constraints and compliance requirements. It is not practical or feasible to eliminate all risks.
Regulatory requirements must be considered, but are inputs to the business considerations. The board of directors does not define information security, but provides direction in support of the business goals and objectives.
NEW QUESTION # 83
When developing an information security strategy for an organization, which of the following is MOST helpful for understanding where to focus efforts?
- A. Business impact analysis (BIA)
- B. Vulnerability assessment
- C. Gap analysis
- D. Project plans
Answer: C
Explanation:
Explanation
Gap analysis is the MOST helpful tool for understanding where to focus efforts when developing an information security strategy for an organization, because it helps to identify the current state and the desired state of the information security governance, and the gaps between them. Gap analysis also helps to prioritize the actions and resources needed to close the gaps and achieve the information security objectives.
References =
CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: "Gap analysis is the process of comparing the current state and the desired state of information security governance and identifying the gaps that need to be addressed." CISM Review Manual, 16th Edition, ISACA, 2020, p. 37: "Gap analysis should be performed periodically to assess the effectiveness and efficiency of the information security strategy and program and to identify the areas for improvement." CISM domain 1: Information security governance [Updated 2022] - Infosec Resources: "Gap analysis: This is a comparison of the current state of security with the desired state. It helps to identify the gaps in security and prioritize the actions required to close them."
NEW QUESTION # 84
The PRIMARY objective of performing a post-incident review is to:
- A. re-evaluate the impact of incidents.
- B. identify the root cause.
- C. identify vulnerabilities.
- D. identify control improvements.
Answer: B
Explanation:
The primary objective of performing a post-incident review is to identify the root cause of the incident. This information is used to develop and implement corrective actions to prevent similar incidents from occurring in the future. The post-incident review process may also include a re-evaluation of the impact of the incidents, the identification of vulnerabilities, and the identification of control improvements, but the primary objective is to determine the root cause of the incident. By understanding the root cause, the organization can take proactive steps to prevent similar incidents from occurring in the future and improve the overall security posture of the organization.
NEW QUESTION # 85
Which of the following is the MOST significant contributor to the effectiveness of an incident response plan?
- A. Sufficient financial resources
- B. Incident response team experience
- C. Regular tabletop exercises
- D. Defined key performance indicators (KPIs)
Answer: C
NEW QUESTION # 86
An organization's information security strategy should be based on:
- A. avoiding occurrence of risks so that insurance is not required.
- B. managing risk to a zero level and minimizing insurance premiums.
- C. managing risk relative to business objectives.
- D. transferring most risks to insurers and saving on control costs.
Answer: C
Explanation:
Organizations must manage risks to a level that is acceptable for their business model, goals and objectives. A zero-level approach may be costly and not provide the effective benefit of additional revenue to the organization. Long-term maintenance of this approach may not be cost effective. Risks vary as business models, geography, and regulatory- and operational processes change. Insurance covers only a small portion of risks and requires that the organization have certain operational controls in place.
NEW QUESTION # 87
Which of the following is the MOST important reason for an information security review of contracts? To help ensure that:
- A. the parties to the agreement can perform.
- B. appropriate controls are included.
- C. confidential data are not included in the agreement.
- D. the right to audit is a requirement.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Agreements with external parties can expose an organization to information security risks that must be assessed and appropriately mitigated. The ability of the parties to perform is normally the responsibility of legal and the business operation involved. Confidential information may be in the agreement by necessity and. while the information security manager can advise and provide approaches to protect the information, the responsibility rests with the business and legal. Audit rights may be one of many possible controls to include in a third-party agreement, but is not necessarily a contract requirement, depending on the nature of the agreement.
NEW QUESTION # 88
Which of the following tools is MOST appropriate to assess whether information security governance objectives are being met?
- A. SWOT analysis
- B. Balanced scorecard
- C. Waterfall chart
- D. Gap analysis
Answer: B
Explanation:
The balanced scorecard is most effective for evaluating the degree to which information security objectives are being met. A SWOT analysis addresses strengths, weaknesses, opportunities and threats. Although useful, a SWOT analysis is not as effective a tool. Similarly, a gap analysis, while useful for identifying the difference between the current state and the desired future state, is not the most appropriate tool. A waterfall chart is used to understand the flow of one process into another.
NEW QUESTION # 89
The BEST way to ensure that an external service provider complies with organizational security policies is to:
- A. Receive acknowledgment in writing stating the provider has read all policies.
- B. Cross-reference to policies in the service level agreement
- C. Explicitly include the service provider in the security policies.
- D. Perform periodic reviews of the service provider.
Answer: D
Explanation:
Explanation
Periodic reviews will be the most effective way of obtaining compliance from the external service provider.
References in policies and service level agreements and requesting written acknowledgement will not be as effective since they will not trigger the detection of noncompliance.
NEW QUESTION # 90
To determine how a security breach occurred on the corporate network, a security manager looks at the logs of various devices. Which of the following BEST facilitates the correlation and review of these logs?
- A. Time server
- B. Proxy server
- C. Database server
- D. Domain name server (DNS)
Answer: A
Explanation:
To accurately reconstruct the course of events, a time reference is needed and that is provided by the time server. The other choices would not assist in the correlation and review1 of these logs.
NEW QUESTION # 91
The PRIMARY benefit of integrating information security activities into change management processes is to:
- A. protect the business from collusion and compliance threats.
- B. provide greater accountability for security-related changes In the business
- C. protect the organization from unauthorized changes.
- D. ensure required controls are Included in changes.
Answer: C
NEW QUESTION # 92
What is the PRIMARY goal of an incident management program?
- A. Identify root cause.
- B. Communicate to external entities.
- C. Minimize impact to the organization.
- D. Contain the incident.
Answer: C
NEW QUESTION # 93
When developing an escalation process for an incident response plan, the information security manager should PRIMARILY consider the:
- A. availability of technical resources.
- B. media coverage.
- C. incident response team.
- D. affected stakeholders.
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION # 94
Which of the following will result in the MOST accurate controls assessment?
- A. Unannounced testing
- B. Well-defined security policies
- C. Mature change management processes
- D. Senior management support
Answer: D
NEW QUESTION # 95
Which of the following should be of GREATEST concern to a newly hired information security manager regarding security compliance?
- A. Lack of standard operating procedures
- B. Lack of risk assessments
- C. Lack of security audits
- D. Lack of executive support
Answer: D
Explanation:
Section: MIXED QUESTIONS
NEW QUESTION # 96
......
Difficulty in writing CISM Exam
ISACA CISM exam help Candidates in developing their professionals and academic career and It is a very tough task to pass ISACA CISM exam for those Candidates who have not done hard work and get some relevant ISACA CISM exam preparation material. There are many peoples have passed ISACA CISM exam by following these three things such as look for the latest ISACA CISM exam dumps, get relevant ISACA CISM exam dumps and develop their knowledge about ISACA CISM exam new questions. At the same time, it can also stress out some people as they found passing ISACA CISM exam a tough task. It is just a wrong assumption as many of the peoples have passed ISACA CISM exam questions. All you have to do is to work hard, get some relevant ISACA CISM exam preparation material and go thoroughly from them. Prep4away is here to help you with this problem. We have the relevant ISACA CISM exam preparation material which are providing the latest ISACA CISM exam questions with the detailed view of every ISACA CISM exam topic. Prep4away offered an ISACA CISM exam dumps which are more than enough to pass the ISACA CISM exam questions. We are providing all thing such as ISACA CISM exam dumps, ISACA CISM practice test, and ISACA CISM pdf exam dumps that will help the candidate to pass the exam with good grades.
Reliable Isaca Certification CISM Dumps PDF Aug 08, 2024 Recently Updated Questions: https://passguide.testkingpass.com/CISM-testking-dumps.html