
Isaca Certification CISM Real Exam Questions and Answers FREE Updated on Oct 09, 2021
CISM Ultimate Study Guide - PracticeDump
NEW QUESTION 353
In a social engineering scenario, which of the following will MOST likely reduce the likelihood of an unauthorized individual gaining access to computing resources?
- A. Implementing on-screen masking of passwords
- B. Increasing the frequency of password changes
- C. Conducting periodic security awareness programs
- D. Requiring that passwords be kept strictly confidential
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Social engineering can best be mitigated through periodic security awareness training for users who may be the target of such an attempt. Implementing on-screen masking of passwords and increasing the frequency of password changes are desirable, but these will not be effective in reducing the likelihood of a successful social engineering attack. Requiring that passwords be kept secret in security policies is a good control but is not as effective as periodic security awareness programs that will alert users of the dangers posed by social engineering.
NEW QUESTION 354
An investigation of a recent security incident determined that the root cause was negligent handling of incident alerts by system administrators. What is the BEST way for the information security manager to address this issue?
- A. Conduct a risk assessment and share the results with senior management.
- B. Provide incident response training to data owners.
- C. Provide incident response training to data custodians.
- D. Revise the incident response plan to align with business processes.
Answer: A
NEW QUESTION 355
The recovery point objective (RPO) is required in which of the following?
- A. Disaster recovery plan
- B. Business continuity plan
- C. Incident response plan
- D. Information security plan
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 356
During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way to prevent future occurrences?
- A. Providing annual information security awareness training
- B. Implementing a strict change control process
- C. Updating configuration baselines to allow exceptions
- D. Conducting periodic vulnerability scanning
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation
NEW QUESTION 357
Which of the following is MOST appropriate for inclusion in an information security strategy?
- A. Firewall rule sets, network defaults and intrusion detection system (IDS) settings
- B. Business controls designated as key controls
- C. Security processes, methods, tools and techniques
- D. Budget estimates to acquire specific security tools
Answer: C
Explanation:
A set of security objectives, processes, methods, tools and techniques together constitute a security strategy. Although IT and business governance are intertwined, business controls may not be included in a security strategy. Budgets will generally not be included in an information security strategy. Additionally, until information security strategy is formulated and implemented, specific tools will not be identified and specific cost estimates will not be available. Firewall rule sets, network defaults and intrusion detection system (IDS) settings are technical details subject to periodic change, and are not appropriate content for a strategy document.
NEW QUESTION 358
A benefit of using a full disclosure (white box) approach as compared to a blind (black box) approach to penetration testing is that:
- A. human intervention is not required for this type of test.
- B. it simulates the real-1ife situation of an external security attack.
- C. less time is spent on reconnaissance and information gathering.
- D. critical infrastructure information is not revealed to the tester.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Data and information required for penetration are shared with the testers, thus eliminating time that would otherwise have been spent on reconnaissance and gathering of information. Blind (black box) penetration testing is closer to real life than full disclosure (white box) testing. There is no evidence to support that human intervention is not required for this type of test. A full disclosure (white box) methodology requires the knowledge of the subject being tested.
NEW QUESTION 359
What should an information security team do FIRST when notified by the help desk that an employee's computer has been infected with malware?
- A. Isolate the computer from the network.
- B. Take a forensic copy of the hard drive.
- C. Restore the files from a secure backup.
- D. Use anti-malware software to clean the infected computer.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 360
What will have the HIGHEST impact on standard information security governance models?
- A. Number of employees
- B. Distance between physical locations
- C. Complexity of organizational structure
- D. Organizational budget
Answer: C
Explanation:
Information security governance models are highly dependent on the overall organizational structure. Some of the elements that impact organizational structure are multiple missions and functions across the organization, leadership and lines of communication. Number of employees and distance between physical locations have less impact on information security governance models since well-defined process, technology and people components intermingle to provide the proper governance. Organizational budget is not a major impact once good governance models are in place, hence governance will help in effective management of the organization's budget.
NEW QUESTION 361
What should be information security manager's FIRST course of action when it is discovered a staff member has been posting corporate information on social media sites?
- A. Refer the staff member to the information security policy
- B. Asses the classification of the data posted.
- C. Notify senior management
- D. Implement controls to block the social media sites.
Answer: B
NEW QUESTION 362
Which of the following would be the MOST effective countermeasure against malicious programming that rounds down transaction amounts and transfers them to the perpetrator's account?
- A. Implement controls for continuous monitoring of middleware transactions
- B. Apply the latest patch programs to the production operating systems
- C. Ensure that proper controls exist for code review and release management
- D. Set up an agent to run a virus-scanning program across platforms
Answer: A
NEW QUESTION 363
Which of the following is the GREATEST
- A. One administrator maintains the single sign-on solutions without segregation of duty.
- B. Integration of single sign-on with the rest of the infrastructure is complicated.
- C. Password carelessness by one user may render the entire infrastructure vulnerable.
- D. It is a single point of failure for an enterprise access control process.
Answer: D
NEW QUESTION 364
In an organization that has undergone an expansion through an acquisition which of the following would BEST secure the enterprise network?
- A. Log analysis od system access
- B. Using security groups
- C. Business or role-based segmentation
- D. Encryption of data traversing networks
Answer: B
NEW QUESTION 365
The valuation of IT assets should be performed by:
- A. an independent security consultant.
- B. an IT security manager.
- C. the chief financial officer (CFO).
- D. the information owner.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Information asset owners are in the best position to evaluate the value added by the IT asset under review within a business process, thanks to their deep knowledge of the business processes and of the functional IT requirements. An IT security manager is an expert of the IT risk assessment methodology and IT asset valuation mechanisms. However, the manager could not have a deep understanding of all the business processes of the firm. An IT security subject matter expert will take part of the process to identify threats and vulnerabilities and will collaborate with the business information asset owner to define the risk profile of the asset. A chief financial officer (CFO) will have an overall costs picture but not detailed enough to evaluate the value of each IT asset.
NEW QUESTION 366
The MOST important objective of a post incident review is to:
- A. develop a business case for the security program budget.
- B. develop a process for continuous improvement.
- C. capture lessons learned to improve the process.
- D. identify new incident management tools.
Answer: C
Explanation:
The main purpose of a post incident review is to identify areas of improvement in the process. Developing a process for continuous improvement is not true in every case. Developing a business case for the security program budget and identifying new incident management tools may come from the analysis of the incident, but are not the key objectives.
NEW QUESTION 367
Which of the following is the PRIMARY benefit to an organization using an automated event monitoring solution?
- A. Improved network protection
- B. Reduced need for manual analysis
- C. Improved response time to incidents
- D. Enhanced forensic analysis
Answer: C
NEW QUESTION 368
Which of the following is MOST likely to be discretionary?
- A. Procedures
- B. Standards
- C. Guidelines
- D. Policies
Answer: C
Explanation:
Explanation
Policies define security goals and expectations for an organization. These are defined in more specific terms within standards and procedures. Standards establish what is to be done while procedures describe how it is to be done. Guidelines provide recommendations that business management must consider in developing practices within their areas of control; as such, they are discretionary.
NEW QUESTION 369
Which of the following is the BEST method to determine whether an information security program meets an organization's business objectives?
- A. Perform a business impact analysis (BIA).
- B. Review against international security standards.
- C. Implement performance measures.
- D. Conduct an annual enterprise-wide security evaluation.
Answer: C
NEW QUESTION 370
A root kit was used to capture detailed accounts receivable information. To ensure admissibility of evidence from a legal standpoint, once the incident was identified and the server isolated, the next step should be to:
- A. notify law enforcement.
- B. document how the attack occurred.
- C. take an image copy of the media.
- D. close the accounts receivable system.
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Taking an image copy of the media is a recommended practice to ensure legal admissibility. All of the other choices are subsequent and may be supplementary.
NEW QUESTION 371
To determine how a security breach occurred on the corporate network, a security manager looks at the logs of various devices. Which of the following BEST facilitates the correlation and review of these logs?
- A. Database server
- B. Proxy server
- C. Domain name server (DNS)
- D. Time server
Answer: D
Explanation:
To accurately reconstruct the course of events, a time reference is needed and that is provided by the time server. The other choices would not assist in the correlation and review1 of these logs.
NEW QUESTION 372
The PRIMARY benefit of integrating information security risk into enterprise risk management is to:
- A. obtain senior management's commitment.
- B. provide a holistic view of risk.
- C. justify the information security budget.
- D. ensure timely risk mitigation.
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 373
......
Ultimate Guide to Prepare CISM Certification Exam for Isaca Certification: https://www.practicedump.com/CISM_actualtests.html
Use Real CISM Dumps - ISACA Correct Answers: https://drive.google.com/open?id=14IpgnUeSyXmeXji4pUH8Ga6YDM4o6PqG