
Released ISACA CISM Updated Questions PDF
CISM Dumps and Practice Test (417 Exam Questions)
NEW QUESTION # 132
The PRIMARY objective of a security steering group is to:
- A. implement all decisions on security management across the organization.
- B. ensure information security aligns with business goals.
- C. raise information security awareness across the organization.
- D. ensure information security covers all business functions.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The security steering group comprises senior management of key business functions and has the primary objective to align the security strategy with the business direction. Option A is incorrect because all business areas may not be required to be covered by information security; but, if they do, the main purpose of the steering committee would be alignment more so than coverage. While raising awareness is important, this goal would not be carried out by the committee itself. The steering committee may delegate part of the decision making to the information security manager; however, if it retains this authority, it is not the primary' goal.
NEW QUESTION # 133
Which of the following is MOST important to the successful development of an information security strategy?
- A. A well-implemented governance framework
- B. An implemented development lite cyck process
- C. Current state and desired objectives
- D. Approved policies and standards
Answer: C
NEW QUESTION # 134
Which of the following BEST enables an information security manager to communicate the capability of security program functions?
- A. Security architecture diagrams
- B. Vulnerability scan results
- C. Security maturity assessments
- D. Key risk indicators (KRls)
Answer: C
NEW QUESTION # 135
An attacker was able to gain access to an organization's perimeter firewall and made changes to allow wider external access and to steal data. Which of the following would have provided timely identification of this incident?
- A. Deploying a security information and event management system (SIEM)
- B. Deploying an intrusion prevention system (IPS)
- C. Conducting regular system administrator awareness training
- D. Implementing a data loss prevention (DLP) suite
Answer: A
NEW QUESTION # 136
Which of the following could be detected by a network intrusion detection system (IDS)?
- A. Internally generated attacks
- B. Unauthorized file change
- C. Undocumented open ports
- D. Emailed virus attachments
Answer: C
NEW QUESTION # 137
An information security program should be established PRIMARILY on the basis of:
- A. senior management input
- B. the approved information security strategy.
- C. the approved risk management approach.
- D. data security regulatory requirements.
Answer: B
NEW QUESTION # 138
Which of the following presents the GREATEST threat to the security of an enterprise resource planning (ERP) system?
- A. User ad hoc reporting is not logged
- B. Database security defaults to ERP settings
- C. Network traffic is through a single switch
- D. Operating system (OS) security patches have not been applied
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The fact that operating system (OS) security patches have not been applied is a serious weakness. Routing network traffic through a single switch is not unusual. Although the lack of logging for user ad hoc reporting is not necessarily good, it does not represent as serious a security-weakness as the failure to install security patches. Database security defaulting to the ERP system's settings is not as significant.
NEW QUESTION # 139
Which of the following is an important criterion for developing effective key risk indicators (KRIs) to monitor information security risk?
- A. The indicator should provide a retrospective view of risk impacts and be measured annually.
- B. The indicator should possess a high correlation with a specific risk and be measured on a regular basis.
- C. The indicator should align with key performance indicators and measure root causes of process performance issues.
- D. The indicator should focus on IT and accurately represent risk variances.
Answer: B
NEW QUESTION # 140
Which of the following is the BEST course of action for the information security manager when residual risk is above the acceptable level of risk?
- A. Defer to business management
- B. Carry out risk assessment
- C. Recommend additional controls
- D. Perform cost-benefit analysis
Answer: C
NEW QUESTION # 141
Which of the following is the MAIN objective in contracting with an external company to perform penetration testing?
- A. To identify a complete list of vulnerabilities
- B. To have an independent certification of network security
- C. To receive an independent view of security exposures
- D. To mitigate technical risks
Answer: C
Explanation:
Explanation
Even though the organization may have the capability to perform penetration testing with internal resources, third-party penetration testing should be performed to gain an independent view of the security exposure.
Mitigating technical risks is not a direct result of a penetration test. A penetration test would not provide certification of network security nor provide a complete list of vulnerabilities.
NEW QUESTION # 142
Which of the following would BEST enable an organization to effectively monitor the implementation of standardized configurations?
- A. Perform periodic audits to detect non-com pliant configurations.
- B. Develop policies requiring use of the established benchmarks.
- C. Implement automated scanning against the established benchmarks.
- D. Implement a separate change tracking system to record changes to configurations.
Answer: C
NEW QUESTION # 143
Which of the following is the MOST important step when establishing guidelines for the use of social networking sites in an organization?
- A. Define acceptable information for posting
- B. Perform a vulnerability assessment.
- C. Establish disciplinary actions for noncompliance.
- D. Identify secure social networking sites.
Answer: A
NEW QUESTION # 144
Which of the following should an information security manager perform FIRST when an organization's residual risk has increased?
- A. Transfer the risk to third parties.
- B. Implement security measures to reduce the risk.
- C. Communicate the information to senior management.
- D. Assess the business impact.
Answer: D
NEW QUESTION # 145
Which of the following BEST describes an information security manager's role in a multidisciplinary team that will address a new regulatory requirement regarding operational risk?
- A. Evaluate the impact of information security risks
- B. Ensure that all IT risks are identified
- C. Suggest new IT controls to mitigate operational risk
- D. Demonstrate that IT mitigating controls are in place
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The job of the information security officer on such a team is to assess the risks to the business operation.
Choice A is incorrect because information security is not limited to IT issues. Choice C is incorrect because at the time a team is formed to assess risk, it is premature to assume that any demonstration of IT controls will mitigate business operations risk. Choice D is incorrect because it is premature at the time of the formation of the team to assume that any suggestion of new IT controls will mitigate business operational risk.
NEW QUESTION # 146
Before engaging outsourced providers, an information security manager should ensure that the organization's data classification requirements:
- A. exceed those of the outsourcer.
- B. are stated in the contract.
- C. are compatible with the provider's own classification.
- D. are communicated to the provider.
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The most effective mechanism to ensure that the organization's security standards are met by a third party, would be a legal agreement. Choices A. B and C are acceptable options, but not as comprehensive or as binding as a legal contract.
NEW QUESTION # 147
Which of the following BEST demonstrates that the objectives of an information security governance framework are being met?
- A. Risk dashboard
- B. Balanced scorecard
- C. Key performance indicators (KPIs)
- D. Penetration test results
Answer: C
NEW QUESTION # 148
Which of the following would be of GREATEST importance to the security manager in determining whether to accept residual risk?
- A. Acceptable level of potential business impacts
- B. Cost versus benefit of additional mitigating controls
- C. Annualized loss expectancy (ALE)
- D. Historical cost of the asset
Answer: B
Explanation:
The security manager would be most concerned with whether residual risk would be reduced by a greater amount than the cost of adding additional controls. The other choices, although relevant, would not be as important.
NEW QUESTION # 149
Which of the following devices could potentially stop a Structured Query Language (SQL) injection attack?
- A. An intrusion prevention system (IPS)
- B. A host-based firewall
- C. An intrusion detection system (IDS)
- D. A host-based intrusion detection system (HIDS)
Answer: A
Explanation:
Explanation/Reference:
Explanation:
SQL injection attacks occur at the application layer. Most IPS vendors will detect at least basic sets of SQL injection and will be able to stop them. IDS will detect, but not prevent I IIDS will be unaware of SQL injection problems. A host-based firewall, be it on the web server or the database server, will allow the connection because firewalls do not check packets at an application layer.
NEW QUESTION # 150
To determine how a security breach occurred on the corporate network, a security manager looks at the logs of various devices. Which of the following BEST facilitates the correlation and review of these logs?
- A. Database server
- B. Time server
- C. Domain name server (DNS)
- D. Proxy server
Answer: B
Explanation:
Explanation
To accurately reconstruct the course of events, a time reference is needed and that is provided by the time server. The other choices would not assist in the correlation and review of these logs.
NEW QUESTION # 151
Which of the following is the PRIMARY goal of business continuity management?
- A. Implement controls to prevent disaster.
- B. Assess the impact to business processes.
- C. Establish incident response procedures.
- D. Increase survivability of the organization.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION # 152
Which of the following tools BEST demonstrates the effectiveness of the information security program?
- A. Risk heat map
- B. A security balanced scorecard
- C. Management satisfaction surveys
- D. Key risk indicators (KRls)
Answer: D
NEW QUESTION # 153
......
The CISM exam is designed for professionals who have experience in information security management and are looking to advance their careers in this field. CISM exam covers four domains: Information Security Governance, Risk Management, Information Security Program Development and Management, and Information Security Incident Management. Each domain focuses on a particular aspect of information security management, and the exam requires candidates to demonstrate their knowledge and understanding of each domain.
CISM Exam Dumps Pass with Updated 2023 Certified Exam Questions: https://www.practicedump.com/CISM_actualtests.html
Guide (New 2023) Actual ISACA CISM Exam Questions: https://drive.google.com/open?id=1rNg6YnD8PAw_xi2upBfXdb7NEgTXty_x