Exam Questions and Answers for CISM Study Guide Questions and Answers! [Q225-Q247]

Share

Exam Questions and Answers for  CISM Study Guide Questions and Answers!

Certified Information Security Manager Certification Sample Questions and Practice Exam

NEW QUESTION 225
Risk management programs are designed to reduce risk to:

  • A. a level that the organization is willing to accept.
  • B. the point at which the benefit exceeds the expense.
  • C. a rate of return that equals the current cost of capital.
  • D. a level that is too small to be measurable.

Answer: A

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Risk should be reduced to a level that an organization is willing to accept. Reducing risk to a level too small to measure is impractical and is often cost-prohibitive. To tie risk to a specific rate of return ignores the qualitative aspects of risk that must also be considered. Depending on the risk preference of an organization, it may or may not choose to pursue risk mitigation to the point at which the benefit equals or exceeds the expense. Therefore, choice C is a more precise answer.

 

NEW QUESTION 226
Because of its importance to the business, an organization wants to quickly implement a technical solution which deviates from the company's policies. An information security manager should:

  • A. recommend a risk assessment and implementation only if the residual risks are accepted.
  • B. conduct a risk assessment and allow or disallow based on the outcome.
  • C. recommend revision of current policy.
  • D. recommend against implementation because it violates the company's policies.

Answer: A

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Whenever the company's policies cannot be followed, a risk assessment should be conducted to clarify the risks. It is then up to management to accept the risks or to mitigate them. Management determines the level of risk they are willing to take. Recommending revision of current policy should not be triggered by a single request.

 

NEW QUESTION 227
Which of the following is the MOST relevant metric to include in an information security quarterly report to the executive committee?

  • A. Number of security patches applied
  • B. Security patches applied trend report
  • C. Percentage of security compliant servers
  • D. Security compliant servers trend report

Answer: D

Explanation:
Explanation
The percentage of compliant servers will be a relevant indicator of the risk exposure of the infrastructure.
However, the percentage is less relevant than the overall trend, which would provide a measurement of the efficiency of the IT security program. The number of patches applied would be less relevant, as this would depend on the number of vulnerabilities identified and patches provided by vendors.

 

NEW QUESTION 228
When considering the value of assets, which of the following would give the information security manager the MOST objective basis for measurement of value delivery in information security governance?

  • A. Cost of achieving control objectives
  • B. Number of controls
  • C. Effectiveness of controls
  • D. Test results of controls

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Comparison of cost of achievement of control objectives and corresponding value of assets sought to be protected would provide a sound basis for the information security manager to measure value delivery. Number of controls has no correlation with the value of assets unless the effectiveness of the controls and their cost are also evaluated. Effectiveness of controls has no correlation with the value of assets unless their costs are also evaluated. Test results of controls have no correlation with the value of assets unless the effectiveness of the controls and their cost are also evaluated.

 

NEW QUESTION 229
To justify its ongoing security budget, which of the following would be of MOST use to the information security' department?

  • A. Peer group comparison
  • B. Security breach frequency
  • C. Cost-benefit analysis
  • D. Annualized loss expectancy (ALE)

Answer: C

Explanation:
Cost-benefit analysis is the legitimate way to justify budget. The frequency of security breaches may assist the argument for budget but is not the key tool; it does not address the impact. Annualized loss expectancy (ALE) does not address the potential benefit of security investment.
Peer group comparison would provide a good estimate for the necessary security budget but it would not take into account the specific needs of the organization.

 

NEW QUESTION 230
A successful information security management program should use which of the following to determine the amount of resources devoted to mitigating exposures?

  • A. Penetration test results
  • B. Audit report findings
  • C. Amount of IT budget available
  • D. Risk analysis results

Answer: D

Explanation:
Risk analysis results are the most useful and complete source of information for determining the amount of resources to devote to mitigating exposures. Audit report findings may not address all risks and do not address annual loss frequency. Penetration test results provide only a limited view of exposures, while the IT budget is not tied to the exposures faced by the organization.

 

NEW QUESTION 231
A global organization has developed a strategy to share a customer information database between offices in two countries. In this situation, it is MOST important to ensure:

  • A. a nondisclosure agreement is signed.
  • B. risk coverage is split between the two locations sharing data.
  • C. data is encrypted in tram* and at rest
  • D. data sharing complies with local laws and regulations at both locations.

Answer: D

 

NEW QUESTION 232
Implementing a strong password policy is part of an organization s information security strategy for the year. A business unit believes the strategy may adversely affect a client's adoption of a recently developed mobile application and has decided not to implement the policy. Which of the following is the information security manager s BEST course of action?

  • A. Benchmark with similar mobile applications to identify gaps
  • B. Escalate non-implementation of the policy to senior management
  • C. Develop and implement a password policy for d mobile application
  • D. Analyze the risk and impact of not implementing the policy.

Answer: D

 

NEW QUESTION 233
Which of the following individuals would be in the BEST position to sponsor the creation of an information security steering group?

  • A. Internal auditor
  • B. Chief operating officer (COO)
  • C. Information security manager
  • D. Legal counsel

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The chief operating officer (COO) is highly-placed within an organization and has the most knowledge of business operations and objectives. The chief internal auditor and chief legal counsel are appropriate members of such a steering group. However, sponsoring the creation of the steering committee should be initiated by someone versed in the strategy and direction of the business. Since a security manager is looking to this group for direction, they are not in the best position to oversee formation of this group.

 

NEW QUESTION 234
Which of the following is the MOST effective way to ensure the information security risk associated with third-party services is addressed?

  • A. Provide security awareness training to third-party employees.
  • B. Include appropriate security requirements in the contract.
  • C. Conduct a security test of the services prior to implementation.
  • D. Perform a risk assessment on the services.

Answer: D

 

NEW QUESTION 235
An organization's operations staff places payment files in a shared network folder and then the disbursement staff picks up the files for payment processing. This manual intervention will be automated some months later, thus cost-efficient controls are sought to protect against file alterations. Which of the following would be the BEST solution?

  • A. Set role-based access permissions on the shared folder
  • B. Design a training program for the staff involved to heighten information security awareness
  • C. Shared folder operators sign an agreement to pledge not to commit fraudulent activities
  • D. The end user develops a PC macro program to compare sender and recipient file contents

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Ideally, requesting that the IT department develop an automated integrity check would be desirable, but given the temporary nature of the problem, the risk can be mitigated by setting stringent access permissions on the shared folder. Operations staff should only have write access and disbursement staff should only have read access, and everyone else, including the administrator, should be disallowed. An information security awareness program and/or signing an agreement to not engage in fraudulent activities may help deter attempts made by employees: however, as long as employees see a chance of personal gain when internal control is loose, they may embark on unlawful activities such as alteration of payment files. A PC macro would be an inexpensive automated solution to develop with control reports. However, sound independence or segregation of duties cannot be expected in the reconciliation process since it is run by an end-user group. Therefore, this option may not provide sufficient proof.

 

NEW QUESTION 236
A multinational organization's information security manager has been advised that the city in which a contracted regional data center is located is experiencing civil unrest. The information security manager should FIRST:

  • A. engage another service provider at a safer location
  • B. delete the organization's sensitive data at the provider's location
  • C. evaluate options to recover if the data center becomes unreachable
  • D. verify the provider's ability to protect the organization's data

Answer: D

 

NEW QUESTION 237
During which phase of an incident response process should corrective actions to the response procedure be considered and implemented?

  • A. Eradication
  • B. Containment
  • C. Review
  • D. Identification

Answer: A

 

NEW QUESTION 238
Data owners must provide a safe and secure environment to ensure confidentiality, integrity and availability of the transaction. This is an example of an information security:

  • A. baseline.
  • B. policy.
  • C. procedure.
  • D. strategy.

Answer: B

Explanation:
Explanation
A policy is a high-level statement of an organization's beliefs, goals, roles and objectives. Baselines assume a minimum security level throughout an organization. The information security strategy aligns the information security program with business objectives rather than making control statements. A procedure is a step-by-step process of how policy and standards will be implemented.

 

NEW QUESTION 239
Which of the following tools is MOST appropriate to assess whether information security governance objectives are being met?

  • A. Balanced scorecard
  • B. Waterfall chart
  • C. Gap analysis
  • D. SWOT analysis

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
The balanced scorecard is most effective for evaluating the degree to which information security objectives are being met. A SWOT analysis addresses strengths, weaknesses, opportunities and threats. Although useful, a SWOT analysis is not as effective a tool. Similarly, a gap analysis, while useful for identifying the difference between the current state and the desired future state, is not the most appropriate tool. A waterfall chart is used to understand the flow of one process into another.

 

NEW QUESTION 240
An information security manager is advised by contacts in law enforcement that there is evidence that his/ her company is being targeted by a skilled gang of hackers known to use a variety of techniques, including social engineering and network penetration. The FIRST step that the security manager should take is to:

  • A. increase monitoring activities to provide early detection of intrusion.
  • B. immediately advise senior management of the elevated risk.
  • C. initiate awareness training to counter social engineering.
  • D. perform a comprehensive assessment of the organization's exposure to the hacker's techniques.

Answer: B

Explanation:
Information about possible significant new risks from credible sources should be provided to management along with advice on steps that need to be taken to counter the threat. The security manager should assess the risk, but senior management should be immediately advised. It may be prudent to initiate an awareness campaign subsequent to sounding the alarm if awareness training is not current. Monitoring activities should also be increased.

 

NEW QUESTION 241
Risk reporting requirements should be PRIMARILY based on:

  • A. policies approved by information security.
  • B. events defined by information security.
  • C. criteria approved by management,
  • D. the criticality of assets.

Answer: C

 

NEW QUESTION 242
Utilizing external resources for highly technical information security tasks allows an information security manager to:

  • A. distribute technology risk.
  • B. outsource responsibility.
  • C. transfer business risk.
  • D. leverage limited resources.

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 243
For an organization with operations in different parts of the world, the BEST approach for ensuring that security policies do not conflict with local laws and regulations is to:

  • A. adopt uniform policies
  • B. establish a hierarchy of global and local policies
  • C. refer to an external global standard to avoid any regional conflict
  • D. make policies at a sufficiently high level, so they are globally applicable

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:

 

NEW QUESTION 244
Which of the following environments represents the GREATEST risk to organizational security?

  • A. Enterprise data warehouse
  • B. Locally managed file server
  • C. Centrally managed data switch
  • D. Load-balanced, web server cluster

Answer: B

Explanation:
Explanation/Reference:
Explanation:
A locally managed file server will be the least likely to conform to organizational security policies because it is generally subject to less oversight and monitoring. Centrally managed data switches, web server clusters and data warehouses are subject to close scrutiny, good change control practices and monitoring.

 

NEW QUESTION 245
Which of the following is an example of a change to the external threat landscape?

  • A. Organizational security standards have been modified.
  • B. New legislation has been enacted in a region where the organization does business.
  • C. Infrastructure changes to the organization have been implemented.
  • D. A commonly used encryption algorithm has been compromised.

Answer: B

 

NEW QUESTION 246
Which of the following is the PRIMARY responsibility of an information security manager in an organization that is implementing the use of company-owned mobile devices in its operations?

  • A. Enforce passwords and data encryption on the devices.
  • B. Require remote wipe capabilities for devices.
  • C. Review and update existing security policies.
  • D. Conduct security awareness training.

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT

 

NEW QUESTION 247
......

CISM certification dumps - Isaca Certification CISM guides - 100% valid: https://www.prep4sureguide.com/CISM-prep4sure-exam-guide.html

100% Pass Your CISM at First Attempt with Prep4sureGuide: https://drive.google.com/open?id=1iQ2cP-s2f0r0D2eF_3L0ekAvAOn2s57x