[Q156-Q181] Tested Material Used To CISM Test Engine Exam Questions in here [Nov-2023]

Share

Tested Material Used To CISM Test Engine Exam Questions in here [Nov-2023]

Penetration testers simulate CISM exam PDF

NEW QUESTION # 156
The PRIMARY focus of the change control process is to ensure that changes are:

  • A. documented.
  • B. tested.
  • C. authorized.
  • D. applied.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
All steps in the change control process must be signed off on to ensure proper authorization. It is important that changes are applied, documented and tested; however, they are not the primary focus.


NEW QUESTION # 157
A core business function has created a significant risk. Budget constraints do not allow for effective remediation. Who should be accountable for selecting the appropriate risk treatment?

  • A. Senior management
  • B. Security officer
  • C. Business process owner
  • D. Audit team

Answer: C


NEW QUESTION # 158
When developing an information security program, what is the MOST useful source of information for determining available resources?

  • A. Job descriptions
  • B. Skills inventory
  • C. Proficiency test
  • D. Organization chart

Answer: B

Explanation:
Explanation
A skills inventory would help identify- the available resources, any gaps and the training requirements for developing resources. Proficiency testing is useful but only with regard to specific technical skills. Job descriptions would not be as useful since they may be out of date or not sufficiently detailed. An organization chart would not provide the details necessary to determine the resources required for this activity.


NEW QUESTION # 159
What is the BEST reason to keep information security policies separate from procedures?

  • A. To ensure that individual documents do not contain conflicting information
  • B. To keep policies from having to be changed too frequently
  • C. To ensure policies receive the appropriate approvals
  • D. To keep policy documents from becoming too large

Answer: C


NEW QUESTION # 160
Which of the following situations would MOST inhibit the effective implementation of security governance:

  • A. Conflicting business priorities
  • B. Budgetary constraints
  • C. The complexity of technology
  • D. High-level sponsorship

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The need for senior management involvement and support is a key success factor for the implementation of appropriate security governance. Complexity of technology, budgetary constraints and conflicting business priorities are realities that should be factored into the governance model of the organization, and should not be regarded as inhibitors.


NEW QUESTION # 161
To reduce the possibility of service interruptions, an entity enters into contracts with multiple Internet service providers (ISPs). Which of the following would be the MOST important item to include?

  • A. Service level agreements (SLAs)
  • B. Intrusion detection system (IDS) services
  • C. Right to audit clause
  • D. Spam filtering services

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Service level agreements (SLA) will be most effective in ensuring that Internet service providers (ISPs) comply with expectations for service availability. Intrusion detection system (IDS) and spam filtering services would not mitigate (as directly) the potential for service interruptions. A right-to-audit clause would not be effective in mitigating the likelihood of a service interruption.


NEW QUESTION # 162
Which of the following is MOST important to the successful implementation of an information security program?

  • A. Establishing key performance indicators (KPIs)
  • B. Conducting periodic risk assessments
  • C. Obtaining stakeholder input
  • D. Understanding current and emerging technologies

Answer: C


NEW QUESTION # 163
To gain a clear+ understanding of the impact that a new regulatory requirement will have on an organization s information security controls, an information security manager should FIRST:

  • A. conduct a risk assessment
  • B. perform a gap analysis.
  • C. interview senior management
  • D. conduct a cost-benefit analysis.

Answer: B


NEW QUESTION # 164
An organization is close to going live with the implementation of a cloud-based application. Independent penetration test results have been received that show a high-rated vulnerability. Which of the following would be the BEST way to proceed?

  • A. Assess whether the vulnerability is within the organization's risk tolerance levels.
  • B. Implement the application and request the cloud service provider to fix the vulnerability.
  • C. Commission further penetration tests to validate initial test results,
  • D. Postpone the implementation until the vulnerability has been fixed.

Answer: D


NEW QUESTION # 165
Which of the following is the MOST likely outcome of a well-designed information security awareness course?

  • A. Increase in the number of identified system vulnerabilities
  • B. Increased reporting of security incidents to the incident response function
  • C. Decrease in the number of password resets
  • D. Decreased reporting of security incidents to the incident response function

Answer: B

Explanation:
Explanation/Reference:
Explanation:
A well-organized information security awareness course informs all employees of existing security policies, the importance of following safe practices for data security anil the need to report any possible security incidents to the appropriate individuals in the organization. The other choices would not be the likely outcomes.


NEW QUESTION # 166
What is the MOST appropriate change management procedure for the handling of emergency program changes?

  • A. All changes must follow the same process
  • B. Documentation is completed with approval soon after the change
  • C. Business management approval must be obtained prior to the change
  • D. Formal documentation does not need to be completed before the change

Answer: B

Explanation:
Even in the case of an emergency change, all change management procedure steps should be completed as in the case of normal changes. The difference lies in the timing of certain events. With an emergency change, it is permissible to obtain certain approvals and other documentation on "the morning after" once the emergency has been satisfactorily resolved. Obtaining business approval prior to the change is ideal but not always possible.


NEW QUESTION # 167
Which of the following is the BEST method to defend against social engineering attacks?

  • A. Communicate guidelines to limit information posted to public sites.
  • B. Periodically perform antivirus scans to identify malware.
  • C. Employ the use of a web-content filtering solution.
  • D. Monitor for unauthorized access attempts and failed logins.

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 168
The PRIMARY purpose of using risk analysis within a security program is to:

  • A. justify the security expenditure.
  • B. inform executive management of residual risk value.
  • C. help businesses prioritize the assets to be protected.
  • D. assess exposures and plan remediation.

Answer: D

Explanation:
Risk analysis explores the degree to which an asset needs protecting so this can be managed effectively. Risk analysis indirectly supports the security expenditure, but justifying the security expenditure is not its primary purpose. Helping businesses prioritize the assets to be protected is an indirect benefit of risk analysis, but not its primary purpose. Informing executive management of residual risk value is not directly relevant.


NEW QUESTION # 169
After logging in to a web application, further password credentials are required at various application points.
Which of the following is the PRIMARY reason for such an approach?

  • A. To enforce strong two-factor authentication
  • B. To ensure access is granted to the authorized person
  • C. To ensure session management variables are secure
  • D. To implement single sign-on

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 170
Which of the following areas is MOST susceptible to the introduction of security weaknesses?

  • A. Configuration management
  • B. Database management
  • C. Incident response management
  • D. Tape backup management

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Configuration management provides the greatest likelihood of security weaknesses through misconfiguration and failure to update operating system (OS) code correctly and on a timely basis.


NEW QUESTION # 171
Risk identification, analysis, and mitigation activities can BCST be integrated into business life cycle processes by linking them to:

  • A. configuration management.
  • B. compliance testing
  • C. change management
  • D. continuity planning

Answer: C


NEW QUESTION # 172
When establishing classifications of security incidents for the development of an incident response plan, which of the following provides the MOST valuable input?

  • A. Business impact analysis (BLA) results
  • B. The business continuity plan (BCP)
  • C. Vulnerability assessment results
  • D. Recommendations from senior management

Answer: A


NEW QUESTION # 173
Which of the following would be MOST useful in a report to senior management for evaluating changes in the organization's information security risk position?

  • A. Industry benchmarks
  • B. Risk register
  • C. Management action plan
  • D. Trend analysis

Answer: D


NEW QUESTION # 174
Which of the following analyses will BEST identify the external influences to an organization's information security?

  • A. Vulnerability analysis.
  • B. Threat analysis
  • C. Gap analysis
  • D. Business impact analysis

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 175
Which of the following is MOST critical for an effective information security governance framework?

  • A. Information security policies are reviewed on a regular basis.
  • B. The information security program is continually monitored.
  • C. The CIO is accountable for the information security program.
  • D. Board members are committed to the information security program.

Answer: D

Explanation:
Section: INFORMATION SECURITY GOVERNANCE


NEW QUESTION # 176
After logging in to a web application, further password credentials are required at various application points.
Which of the following is the PRIMARY

  • A. To enforce strong two-factor authentication
  • B. To ensure access is granted to the authorized person
  • C. To ensure session management variables are secure
  • D. To implement single sign-on

Answer: B


NEW QUESTION # 177
A risk was identified during a risk assessment. The business process owner has chosen to accept the risk because the cost of remediation is greater than the projected cost of a worst-case scenario. What should be the information security manager's NEXT course of action?

  • A. Shut down the business application.
  • B. Determine a lower-cost approach to remediation.
  • C. Document and escalate to senior management.
  • D. Document and schedule a date to revisit the issue.

Answer: C


NEW QUESTION # 178
Which of the following metrics BEST measures the effectiveness of an organization's information security program?

  • A. Increase in risk assessments completed
  • B. Return on information security investment
  • C. Reduction in information security incidents
  • D. Number of information security business cases developed

Answer: B


NEW QUESTION # 179
Which of the following BEST measures the effectiveness of an organization's information security strategy?

  • A. Comparison of threats to vulnerabilities
  • B. Comparison of residual risk to risk appetite
  • C. Comparison of mitigated risk to accepted risk
  • D. Comparison of current security budget to previous year's budget

Answer: B


NEW QUESTION # 180
Which of the following methods BEST ensures that a comprehensive approach is used to direct information security activities?

  • A. Promoting security training
  • B. Creating communication channels
  • C. Holding periodic meetings with business owners
  • D. Establishing a steering committee

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 181
......

Authentic Best resources for CISM Online Practice Exam: https://www.dumps4pdf.com/CISM-valid-braindumps.html

Get the superior quality CISM Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=18XGlOEltB5GTJlH_ccYPtWw32zOWABcG