Prepare for the Actual Isaca Certification CISM Exam Practice Materials Collection [Q217-Q240]

Share

Prepare for the Actual Isaca Certification CISM Exam Practice Materials Collection

Isaca Certification Certified Official Practice Test CISM - Aug-2023


How to study the CISM Exam

Prep4away expert team recommends you to prepare some notes on these topics along with it don't forget to practice ISACA CISM Exam exam dumps which been written by our expert team, Both these will help you a lot to clear this exam with good marks.

 

NEW QUESTION # 217
Which of the following BEST supports effective information security governance"*

  • A. A baseline risk assessment is performed.
  • B. Compliance with regulations is demonstrated.
  • C. The information security manager develops the strategy
  • D. A steering committee is established

Answer: D


NEW QUESTION # 218
The BEST way to report to the board on the effectiveness of the Information security program is to present:

  • A. a dashboard illustrating key performance metrics.
  • B. a report of cost savings from process improvements
  • C. a summary of the most recent audit findings.
  • D. poor-group Industry benchmark.

Answer: B


NEW QUESTION # 219
To justify its ongoing security budget, which of the following would be of MOST use to the information security' department?

  • A. Cost-benefit analysis
  • B. Security breach frequency
  • C. Annualized loss expectancy (ALE)
  • D. Peer group comparison

Answer: A

Explanation:
Cost-benefit analysis is the legitimate way to justify budget. The frequency of security breaches may assist the argument for budget but is not the key tool; it does not address the impact. Annualized loss expectancy (ALE) does not address the potential benefit of security investment. Peer group comparison would provide a good estimate for the necessary security budget but it would not take into account the specific needs of the organization.


NEW QUESTION # 220
Which of the following would be the MOST effective countermeasure against malicious programming that rounds down transaction amounts and transfers them to the perpetrator's account?

  • A. Apply the latest patch programs to the production operating systems
  • B. Set up an agent to run a virus-scanning program across platforms
  • C. Ensure that proper controls exist for code review and release management
  • D. Implement controls for continuous monitoring of middleware transactions

Answer: C


NEW QUESTION # 221
Temporarily deactivating some monitoring processes, even if supported by an acceptance of operational risk, may not be acceptable to the information security manager if:

  • A. it implies compliance risks.
  • B. changes in the roles matrix cannot be detected.
  • C. it violates industry security practices.
  • D. short-term impact cannot be determined.

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Monitoring processes are also required to guarantee fulfillment of laws and regulations of the organization and, therefore, the information security manager will be obligated to comply with the law. Choices B and C are evaluated as part of the operational risk. Choice D is unlikely to be as critical a breach of regulatory legislation. The acceptance of operational risks overrides choices B, C and D.


NEW QUESTION # 222
Which of the following is an information security manager's MOST important consideration during the investigative process of analyzing the hard drive of 3 compromises..

  • A. Determining the classification of stored data
  • B. Identifying the relevant strain of malware
  • C. Maintaining chain of custody
  • D. Notifying the relevant stakeholders

Answer: A


NEW QUESTION # 223
Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:

  • A. hand over the controls to the relevant business owners.
  • B. ensure the controls are regularly tested for ongoing effectiveness.
  • C. prepare to adapt the controls for future system upgrades.
  • D. perform testing to compare control performance against industry levels.

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 224
The MOST important reason to use a centralized mechanism to identify information security incidents is to:

  • A. threats across environments.
  • B. detect potential fraud.
  • C. prevent unauthorized changes to networks.
  • D. comply with corporate policies.

Answer: D


NEW QUESTION # 225
An information security manager is developing a business case for an investment in an information security control. The FIRST step should be to:

  • A. assess potential impact to the organization
  • B. gain audit buy-in for the security control
  • C. demonstrate increased productivity of security staff
  • D. research vendor pricing to show cost efficiency

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 226
An organization has contracted with an outsourcing company to address a security gap. Which of the following is the BEST way to determine if the security gap has been addressed?

  • A. Security audit
  • B. Service level agreement (SLA)
  • C. Vulnerability scan
  • D. Security risk assessment

Answer: A


NEW QUESTION # 227
When speaking to an organization's human resources department about information security, an information security manager should focus on the need for:

  • A. periodic risk assessments.
  • B. recruitment of technical IT employees.
  • C. security awareness training for employees.
  • D. an adequate budget for the security program.

Answer: C

Explanation:
An information security manager has to impress upon the human resources department the need for security awareness training for all employees. Budget considerations are more of an accounting function. The human resources department would become involved once they are convinced for the need of security awareness training. Recruiting lT-savvy staff may bring in new employees with better awareness of information security, but that is not a replacement for the training requirements of the other employees. Periodic risk assessments may or may not involve the human resources department function.


NEW QUESTION # 228
Which of the following is the PRIMARY responsibility of the information security steering committee?

  • A. Developing security polices aligned with the corporate and IT strategies
  • B. Identifying risks associated with new security initiatives
  • C. Reviewing business cases where benefits have not been realized
  • D. Developing and presenting business cases for security initiatives

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 229
Which of the following is MOST important to understand when developing a meaningful information security strategy?

  • A. International security standards
  • B. Organizational goals
  • C. Regulatory environment
  • D. Organizational risks

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Alignment of security with business objectives requires an understanding of what an organization is trying to accomplish. The other choices are all elements that must be considered, but their importance is secondary and will vary depending on organizational goals.


NEW QUESTION # 230
To help ensure that an information security training program is MOST effective, its contents should be:

  • A. aligned to business processes.
  • B. based on employees' roles.
  • C. based on recent incidents.
  • D. focused on information security policy.

Answer: B

Explanation:
To help ensure that an information security training program is MOST effective, its contents should be based on employees' roles. This is because different roles have different responsibilities and access levels to information and systems, and therefore face different types of threats and risks. By tailoring the training content to the specific needs and expectations of each role, the training program can increase the relevance and retention of the information security knowledge and skills for the employees. Role-based training can also help employees understand their accountability and obligations for protecting information assets in their daily tasks


NEW QUESTION # 231
Which of the following is the MOST effective, positive method to promote security awareness?

  • A. Competitions and rewards for compliance
  • B. Disciplinary action for noncompliance
  • C. Lock-out after three incorrect password attempts
  • D. Strict enforcement of password formats

Answer: A

Explanation:
Explanation
Competitions and rewards are a positive encouragement to user participation in the security program. Merely locking users out for forgetting their passwords does not enhance user awareness. Enforcement of password formats and disciplinary actions do not positively promote awareness.


NEW QUESTION # 232
Which of the following is the MOST important consideration when developing an incident management program?

  • A. Risk assessment
  • B. IT architecture
  • C. Escalation procedures
  • D. Impact assessment

Answer: C


NEW QUESTION # 233
Which of the following is the BEST way to determine if an organization's current risk is within the risk appetite?

  • A. Implementing key risk indicators (KRIs)
  • B. Conducting a business impact analysis (BIA)
  • C. Developing additional mitigating controls
  • D. Implementing key performance indicators (KPIs)

Answer: A


NEW QUESTION # 234
The MOST appropriate owner of customer data stored in a central database, used only by an organization's sales department, would be the:

  • A. sales department.
  • B. head of the sales department.
  • C. database administrator.
  • D. chief information officer (CIO).

Answer: B

Explanation:
The owner of the information asset should be the person with the decision-making power in the department deriving the most benefit from the asset. In this case, it would be the head of the sales department. The organizational unit cannot be the owner of the asset because that removes personal responsibility. The database administrator is a custodian. The chief information officer (CIO) would not be an owner of this database because the CTO is less likely to be knowledgeable about the specific needs of sales operations and security concerns.


NEW QUESTION # 235
Application data integrity risk is MOST directly addressed by a design that includes:

  • A. reconciliation routines such as checksums, hash totals, and record counts.
  • B. strict application of an authorized data dictionary.
  • C. application log requirements such as field-level audit trails and user activity logs.
  • D. access control technologies such as role-based entitlements.

Answer: D


NEW QUESTION # 236
Which of the following is the MOST important reason why information security objectives should be defined?

  • A. Management sign-off and support initiatives
  • B. Tool for measuring effectiveness
  • C. Consistency with applicable standards
  • D. General understanding of goals

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The creation of objectives can be used in part as a source of measurement of the effectiveness of information security management, which feeds into the overall governance. General understanding of goals and consistency with applicable standards are useful, but are not the primary reasons for having clearly defined objectives. Gaining management understanding is important, but by itself will not provide the structure for governance.


NEW QUESTION # 237
When developing security standards, which of the following would be MOST appropriate to include?

  • A. Inventory management
  • B. Accountability for licenses
  • C. Acceptable use of IT assets
  • D. operating system requirements

Answer: C


NEW QUESTION # 238
Which of the following is the MOST important requirement for the successful implementation of security governance?

  • A. Implementing a security balanced scorecard
  • B. Mapping to organizational
  • C. Performance an enterprise-wide risk assessment
  • D. Aligning to an international security framework

Answer: B


NEW QUESTION # 239
In an organization with a rapidly changing environment, business management has accepted an information security risk. It is MOS important for the information security manager to ensure:

  • A. compliance with the risk acceptance framework
  • B. change activities are documented
  • C. the rationale for acceptance is periodically reviewed
  • D. the acceptance is aligned with business strategy.

Answer: D


NEW QUESTION # 240
......

Ace ISACA CISM Certification with Actual Questions Aug 04, 2023 Updated: https://passguide.testkingpass.com/CISM-testking-dumps.html