
Updated Aug-2024 100% Cover Real CISM Exam Questions - 100% Pass Guarantee
Use Real ISACA Dumps - 100% Free CISM Exam Dumps
NEW QUESTION # 325
When application-level security controlled by business process owners is found to be poorly managed, which of the following could BEST improve current practices?
- A. Periodic compliance reviews
- B. Policy enforcement by IT management
- C. Centralizing security management
- D. Implementing sanctions for noncompliance
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
By centralizing security management, the organization can ensure that security standards are applied to all systems equally and in line with established policy. Sanctions for noncompliance would not be the best way to correct poor management practices caused by work overloads or insufficient knowledge of security practices. Enforcement of policies is not solely the responsibility of IT management. Periodic compliance reviews would not correct the problems, by themselves, although reports to management would trigger corrective action such as centralizing security management.
NEW QUESTION # 326
Which of the following is a PRIMARY security responsibility of an information owner?
- A. Determining the controls associated with information classification
- B. Maintaining the integrity of data in the information system
- C. Testing information classification controls
- D. Deciding what level of classification the information requires
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation/Reference:
NEW QUESTION # 327
The MAIN reason for having senior management review and approve an information security strategic plan is to ensure:
- A. the organization has the required funds to implement the plan.
- B. the plan aligns with corporate governance.
- C. compliance with legal and regulatory requirements.
- D. staff participation in information security efforts.
Answer: B
Explanation:
Explanation
Senior management review and approval of an information security strategic plan is important to ensure that the plan is aligned with the organization's overall corporate governance objectives. It is also important to ensure that the plan takes into account any legal and regulatory requirements, as well as the resources and staff needed to properly implement the plan.
NEW QUESTION # 328
During a post-incident review, the sequence and correlation of actions must be analyzed PRIMARILY based on:
- A. interviews with personnel.
- B. documents created during the incident.
- C. a consolidated event timeline
- D. logs from systems involved.
Answer: D
NEW QUESTION # 329
Which of the following should an information security manager do FIRST when creating an organization's disaster recovery plan (DRP)?
- A. Develop response and recovery strategies.
- B. Review the communications plan.
- C. Identify the response and recovery learns.
- D. Conduct a business impact analysis (BIA)
Answer: D
Explanation:
Explanation
Conducting a business impact analysis (BIA) is the first step when creating an organization's disaster recovery plan (DRP) because it helps to identify and prioritize the critical business functions or processes that need to be restored after a disruption, and determine their recovery time objectives (RTOs) and recovery point objectives (RPOs)2. Identifying the response and recovery teams is not the first step, but rather a subsequent step that involves assigning roles and responsibilities for executing the DRP. Reviewing the communications plan is not the first step, but rather a subsequent step that involves defining the communication channels and protocols for notifying and updating the stakeholders during and after a disruption. Developing response and recovery strategies is not the first step, but rather a subsequent step that involves selecting and implementing the appropriate solutions and procedures for restoring the critical business functions or processes. References:
2
https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/business-impact-analysis-bia-and-disaster-r
NEW QUESTION # 330
Which of the following is MOST important when defining how an information security budget should be allocated?
- A. Information security policy
- B. Regulatory compliance standards
- C. Business impact assessment
- D. Information security strategy
Answer: D
Explanation:
Explanation
Information security strategy is the most important factor when defining how an information security budget should be allocated because it helps to align the security objectives and initiatives with the business goals and priorities. An information security strategy is a high-level plan that defines the vision, mission, scope, and direction of the security program, as well as the roles and responsibilities, governance structures, policies and standards, risk management approaches, and performance measurement methods. An information security strategy helps to identify and prioritize the security needs and requirements of the organization, as well as to allocate the resources and funding accordingly. An information security strategy also helps to communicate the value and benefits of security to the stakeholders and justify the security investments. Therefore, information security strategy is the correct answer.
References:
* https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-breakdown-and-best-practices
* https://www.csoonline.com/article/3671108/how-2023-cybersecurity-budget-allocations-are-shaping-up.ht
* https://www.statista.com/statistics/1319677/companies-it-budget-allocated-to-security-worldwide/
NEW QUESTION # 331
The MOST important factor in planning for the long-term retention of electronically stored business records is to take into account potential changes in:
- A. business strategy and direction.
- B. application systems and media.
- C. regulatory and legal requirements.
- D. storage capacity and shelf life.
Answer: B
Explanation:
Long-term retention of business records may be severely impacted by changes in application systems and media. For example, data stored in nonstandard formats that can only be read and interpreted by previously decommissioned applications may be difficult, if not impossible, to recover. Business strategy and direction do not generally apply, nor do legal and regulatory requirements. Storage capacity and shelf life are important but secondary issues.
NEW QUESTION # 332
Which of the following would raise security awareness among an organization's employees?
- A. Distributing industry statistics about security incidents
- B. Encouraging employees to behave in a more conscious manner
- C. Monitoring the magnitude of incidents
- D. Continually reinforcing the security policy
Answer: D
Explanation:
Employees must be continually made aware of the policy and expectations of their behavior. Choice A would have little relevant bearing on the employee's behavior. Choice B does not involve the employees. Choice C could be an aspect of continual reinforcement of the security policy.
NEW QUESTION # 333
An organization faces severe fines and penalties if not in compliance with local regulatory requirements by an established deadline. Senior management has asked the information security manager to prepare an action plan to achieve compliance.
Which of the following would provide the MOST useful information for planning purposes?
- A. An inventory of security controls currently in place
- B. Results from a business impact analysis (BIA)
- C. Results from a gap analysis
- D. Deadlines and penalties for noncompliance
Answer: C
Explanation:
Results from a gap analysis would provide the most useful information for planning purposes when preparing an action plan to achieve compliance with local regulatory requirements by an established deadline. A gap analysis is an assessment of the difference between an organization's current state of compliance and its desired level or standard. It is a process used to identify potential areas for improvement by comparing actual performance with expected performance. A gap analysis can help to prioritize the actions needed to close the gaps and comply with the regulatory requirements, as well as to estimate the resources and time required for each action1. The other options are not as useful as results from a gap analysis for planning purposes when preparing an action plan to achieve compliance with local regulatory requirements by an established deadline. Deadlines and penalties for noncompliance are important factors to consider, but they do not provide information on how to achieve compliance or what actions are needed2. Results from a business impact analysis (BIA) are useful for identifying the critical processes and assets that need to be protected, but they do not provide information on how to comply with the regulatory requirements or what actions are needed3. An inventory of security controls currently in place is useful for assessing the current state of compliance, but it does not provide information on how to comply with the regulatory requirements or what actions are needed4. Reference: 3: Business impact analysis (BIA) - Wikipedia 2: Compliance Gap Analysis & Effectiveness Evaluation | SMS 1: What is Gap Analysis in Compliance | Scytale 4: Gap Analysis & Risk Assessment - Riddle Compliance
NEW QUESTION # 334
Which of the following is the FIRST phase in which security should be addressed in the development cycle of a project?
- A. Feasibility
- B. Implementation
- C. Design
- D. Application security testing
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Information security should be considered at the earliest possible stage. Security requirements must be defined before you enter into design specification, although changes in design may alter these requirements later on. Security requirements defined during system implementation are typically costly add-ons that are frequently ineffective. Application security testing occurs after security has been implemented.
NEW QUESTION # 335
Rn information security team is investigating an alleged breach of an organization's network. Which of the following would be the BEST single source of evidence to review?
- A. Security information and event management (SIEM) tool
- B. File integrity monitoring (FIM) software
- C. Intrusion detection system (IDS)
- D. Antivirus software
Answer: A
NEW QUESTION # 336
Which of the following is MOST closely associated with a business continuity program?
- A. Updating the hot site equipment configuration every quarter
- B. Developing recovery time objectives (RTOs) for critical functions
- C. Periodically testing network redundancy
- D. Confirming that detailed technical recovery plans exist
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Technical recovery plans, network redundancy and equipment needs are all associated with infrastructure disaster recovery. Only recovery time objectives (RTOs) directly relate to business continuity.
NEW QUESTION # 337
Which of the following is MOST helpful for protecting an enterprise from advanced persistent threats (APTs)?
- A. Regular antivirus updates
- B. Defined security standards
- C. Threat intelligence
- D. Updated security policies
Answer: C
Explanation:
Explanation
Threat intelligence is the most helpful method for protecting an enterprise from advanced persistent threats (APTs), as it provides relevant and actionable information about the sources, methods, and intentions of the adversaries who conduct APTs. Threat intelligence can help to identify and anticipate the APTs that target the enterprise, as well as to enhance the detection, prevention, and response capabilities of the information security program. Threat intelligence can also help to reduce the impact and duration of the APTs, as well as to improve the resilience and recovery of the enterprise. Threat intelligence can be obtained from various sources, such as internal data, external feeds, industry peers, government agencies, or security vendors.
The other options are not as helpful as threat intelligence, as they do not provide a specific and timely way to protect the enterprise from APTs. Updated security policies are important to establish the rules, roles, and responsibilities for information security within the enterprise, as well as to align the information security program with the business objectives, standards, and regulations. However, updated security policies alone are not enough to protect the enterprise from APTs, as they do not address the dynamic and sophisticated nature of the APTs, nor do they provide the technical or operational measures to counter the APTs. Defined security standards are important to specify the minimum requirements and best practices for information security within the enterprise, as well as to ensure the consistency, quality, and compliance of the information security program. However, defined security standards alone are not enough to protect the enterprise from APTs, as they do not account for the customized and targeted nature of the APTs, nor do they provide the situational or contextual awareness to deal with the APTs. Regular antivirus updates are important to keep the antivirus software up to date with the latest signatures and definitions of the known malware, viruses, and other malicious code. However, regular antivirus updates alone are not enough to protect the enterprise from APTs, as they do not detect or prevent the unknown or zero-day malware, viruses, or other malicious code that are often used by the APTs, nor do they provide the behavioral or heuristic analysis to identify the APTs. References = CISM Review Manual, 16th Edition, ISACA, 2022, pp. 211-212, 215-216, 233-234, 237-238.
CISM Questions, Answers & Explanations Database, ISACA, 2022, QID 1021.
Advanced Persistent Threats and Nation-State Actors 1
Book Review: Advanced Persistent Threats 2
Advanced Persistent Threat (APT) Protection 3
Establishing Advanced Persistent Security to Combat Long-Term Threats 4 What is the difference between Anti - APT (Advanced Persistent Threat) and ATP (Advanced Threat Protection)5
NEW QUESTION # 338
Priority should be given to which of the following to ensure effective implementation of information security governance?
- A. Planning
- B. Negotiation
- C. Facilitation
- D. Consultation
Answer: A
Explanation:
Planning is the key to effective implementation of information security governance. Consultation, negotiation and facilitation come after planning.
NEW QUESTION # 339
Which of the following is the MOST important consideration for an organization interacting with the media during a disaster?
- A. Referring the media to the authorities
- B. Refusing to comment until recovery
- C. Communicating specially drafted messages by an authorized person
- D. Reporting the losses and recovery strategy to the media
Answer: C
Explanation:
Proper messages need to be sent quickly through a specific identified person so that there are no rumors or statements made that may damage reputation. Choices B, C and D are not recommended until the message to be communicated is made clear and the spokesperson has already spoken to the media.
NEW QUESTION # 340
What would a security manager PRIMARILY utilize when proposing the implementation of a security solution?
- A. Risk assessment report
- B. Budgetary requirements
- C. Technical evaluation report
- D. Business case
Answer: D
Explanation:
Explanation
The information security manager needs to prioritize the controls based on risk management and the requirements of the organization. The information security manager must look at the costs of the various controls and compare them against the benefit the organization will receive from the security solution. The information security manager needs to have knowledge of the development of business cases to illustrate the costs and benefits of the various controls. All other choices are supplemental.
NEW QUESTION # 341
A small organization has a contract with a multinational cloud computing vendor. Which of the following would present the GREATEST concern to an information security manager if omitted from the contract?
- A. Authority of the subscriber to approve access to its data
- B. Commingling of subscribers' data on the same physical server
- C. Right of the subscriber to conduct onsite audits of the vendor
- D. Escrow of software code with conditions for code release
Answer: A
Explanation:
Explanation
Authority of the subscriber to approve access to its data is the greatest concern for an information security manager if omitted from the contract, as it may expose the subscriber's data to unauthorized or inappropriate access by the vendor or third parties. The subscriber should have the right to control who can access its data, for what purposes, and under what conditions. The contract should also specify the vendor's obligations to protect the confidentiality, integrity, and availability of the subscriber's data, and to notify the subscriber of any breaches or incidents.
References = CISM Review Manual, 27th Edition, Chapter 4, Section 4.2.1, page 2201; Drafting and Negotiating Effective Cloud Computing Agreements2; CISM Online Review Course, Module 4, Lesson 2,
NEW QUESTION # 342
Which of the following would generally have the GREATEST negative impact on an organization?
- A. Internal fraud resulting in monetary loss
- B. Loss of customer confidence
- C. Interruption of utility services
- D. Theft of computer software
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Although the theft of software, interruption of utility services and internal frauds are all significant, the loss of customer confidence is the most damaging and could cause the business to fail.
NEW QUESTION # 343
The PRIMARY goal of a corporate risk management program is to ensure that an organization's:
- A. IT assets in key business functions are protected.
- B. business risks are addressed by preventive controls.
- C. IT facilities and systems are always available.
- D. stated objectives are achievable.
Answer: D
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Risk management's primary goal is to ensure an organization maintains the ability to achieve its objectives.
Protecting IT assets is one possible goal as well as ensuring infrastructure and systems availability.
However, these should be put in the perspective of achieving an organization's objectives. Preventive controls are not always possible or necessary; risk management will address issues with an appropriate mix of preventive and corrective controls.
NEW QUESTION # 344
During which stage of the software development life cycle (SDLC) should application security controls FIRST be addressed?
- A. Software code development
- B. Configuration management
- C. Requirements gathering
- D. Application system design
Answer: D
Explanation:
Based on this classification, security controls are integrated during the application design process. It is important to understand application priorities in terms of uptimes and security. For example, we were developing a financially sensitive application for a telecom company.
NEW QUESTION # 345
Which of the following is the MOST effective way to identify changes in an information security environment?
- A. Business impact analysis (BIA)
- B. Regular penetration testing
- C. Annual risk assessments
- D. Continuous monitoring
Answer: D
Explanation:
Explanation
Continuous monitoring is the most effective way to identify changes in an information security environment, as it provides ongoing awareness of the security status, vulnerabilities, and threats that may affect the organization's information assets and risk posture. Continuous monitoring also helps to evaluate the performance and effectiveness of the security controls and processes, and to detect and respond to any deviations or incidents in a timely manner. (From CISM Review Manual 15th Edition and NIST Special Publication 800-1371) References: CISM Review Manual 15th Edition, page 181, section 4.3.2.4; NIST Special Publication
800-1371, page 1, section 1.1.
NEW QUESTION # 346
......
CISM Dumps PDF - CISM Real Exam Questions Answers: https://www.practicedump.com/CISM_actualtests.html
Realistic CISM Dumps Latest Practice Tests Dumps: https://drive.google.com/open?id=14IpgnUeSyXmeXji4pUH8Ga6YDM4o6PqG