
New 2022 Realistic CISM Dumps Test Engine Exam Questions in here
Updated Official licence for CISM Certified by CISM Dumps PDF
ISACA Certified Information Security Manager CISM Exam
ISACA Certified Information Security Manager CISM Exam is related to Certified Information Security Manager CISM certification. This CISM Exam validates the ability to maintain and establish an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives. Candidate must have the ability to manage information risk appropriately and program resources are managed responsibly. It also deals with the ability to ensure that organizational goals and objectives are supported by the information security program communicate managements directives and guide the development of standards, procedures, and guidelines and develop business cases to support investments in information security. Security Managers Industry Leaders and Industry Practitioners usually hold or pursue this certification and you can expect the same job roles after completion of this certification.
NEW QUESTION 551
Which of the following activities would BEST incorporate security into the software development life cycle
{SOLO7
- A. Scan operating systems for vulnerabilities
- B. Minimize the use of open source software
- C. Include security training for the development team
- D. Test applications before go-live
Answer: C
NEW QUESTION 552
Prior to having a third party perform an attack and penetration test against an organization, the MOST important action is to ensure that:
- A. goals and objectives are clearly defined.
- B. special backups of production servers are taken.
- C. the technical staff has been briefed on what to expect.
- D. the third party provides a demonstration on a test system.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The most important action is to clearly define the goals and objectives of the test. Assuming that adequate backup procedures are in place, special backups should not be necessary. Technical staff should not be briefed nor should there be a demo as this will reduce the spontaneity of the test.
NEW QUESTION 553
Good information security procedures should:
- A. define the allowable limits of behavior.
- B. describe security baselines for each platform.
- C. underline the importance of security governance.
- D. be updated frequently as new software is released.
Answer: D
Explanation:
Explanation
Security procedures often have to change frequently to keep up with changes in software. Since a procedure is a how-to document, it must be kept up-to-date with frequent changes in software. A security standard such as platform baselines - defines behavioral limits, not the how-to process; it should not change frequently.
High-level objectives of an organization, such as security governance, would normally be addressed in a security policy.
NEW QUESTION 554
Documented standards/procedures for the use of cryptography across the enterprise should PRIMARILY:
- A. describe handling procedures of cryptographic keys.
- B. establish the use of cryptographic solutions.
- C. define cryp,0 raphic algorithms and key lengths.
- D. define the circumstances where cryptography should be used.
Answer: D
Explanation:
There should be documented standards- procedures for the use of cryptography across the enterprise; they should define the circumstances where cryptography should be used. They should cover the selection of cryptographic algorithms and key lengths, but not define them precisely, and they should address the handling of cryptographic keys. However, this is secondary to how and when cryptography should be used. The use of cryptographic solutions should be addressed but, again, this is a secondary consideration.
NEW QUESTION 555
An organization is entering into an agreement with a new business partner to conduct customer mailings.
What is the MOST important action that the information security manager needs to perform?
- A. A due diligence security review of the business partner's security controls
- B. Ensuring that the business partner has an effective business continuity program
- C. Talking to other clients of the business partner to check references for performance
- D. Ensuring that the third party is contractually obligated to all relevant security requirements
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The key requirement is that the information security manager ensures that the third party is contractually bound to follow the appropriate security requirements for the process being outsourced. This protects both organizations. All other steps are contributory to the contractual agreement, but are not key.
NEW QUESTION 556
The FIRST step in an incident response plan is to:
- A. develop response strategies for systematic attacks.
- B. contain the effects of the incident to limit damage.
- C. validate the incident.
- D. notify- the appropriate individuals.
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Appropriate people need to be notified; however, one must first validate the incident. Containing the effects of the incident would be completed after validating the incident. Developing response strategies for systematic attacks should have already been developed prior to the occurrence of an incident.
NEW QUESTION 557
In business critical applications, where shared access to elevated privileges by a small group is necessary, the BEST approach to implement adequate segregation of duties is to:
- A. implement role-based access control in the application.
- B. enforce manual procedures ensuring separation of conflicting duties.
- C. create service accounts that can only be used by authorized team members.
- D. ensure access to individual functions can be granted to individual users only.
Answer: A
Explanation:
Explanation
Role-based access control is the best way to implement appropriate segregation of duties. Roles will have to be defined once and then the user could be changed from one role to another without redefining the content of the role each time. Access to individual functions will not ensure appropriate segregation of duties. Giving a user access to all functions and implementing, in parallel, a manual procedure ensuring segregation of duties is not an effective method, and would be difficult to enforce and monitor. Creating service accounts that can be used by authorized team members would not provide any help unless their roles are properly segregated.
NEW QUESTION 558
A recent comprehensive vulnerability assessment identified emerging threats to the continuity of critical business services. What should be the information security manager s FIRST course of action?
- A. Perform a patch update.
- B. Perform a penetration test.
- C. Conduct a gap analysis.
- D. Conduct a risk assessment.
Answer: D
NEW QUESTION 559
Which of the following will BEST protect confidential data when connecting large wireless networks to an existing wired-network infrastructure?
- A. Mandatory access control (MAC) address filtering
- B. Firewall
- C. Strong passwords
- D. Virtual private network (VPN)
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 560
Which of the following disaster recovery testing techniques is the MOST cost-effective way to determine the effectiveness of the plan?
- A. Full operational tests
- B. Paper tests
- C. Preparedness tests
- D. Actual service disruption
Answer: C
Explanation:
Explanation
Preparedness tests would involve simulation of the entire test in phases and help the team better understand and prepare for the actual test scenario. Options B, C and D are not cost-effective ways to establish plan effectiveness. Paper tests in a walk-through do not include simulation and so there is less learning and it is difficult to obtain evidence that the team has understood the test plan. Option D is not recommended in most cases. Option C would require an approval from management is not easy or practical to test in most scenarios and may itself trigger a disaster.
NEW QUESTION 561
An organization to integrate information security into its human resource management processes. Which of the following should be the FIRST step?
- A. Benchmark the processes with best practice to identify gaps
- B. Identify information security risk associated with the processes
- C. Assess the business objectives of the processes
- D. Evaluate the cost of information security integration
Answer: C
NEW QUESTION 562
An IT department has given a vendor remote access to the internal network for troubleshooting network performance problems. After discovering the remote activity during a firewall log review, which of the following is the FIRST course of action for an information security manager?
- A. Declare a security incident.
- B. Determine the level of access granted
- C. Revoke the access.
- D. Review the related service level agreement (SLA).
Answer: B
NEW QUESTION 563
Which of the following, using public key cryptography, ensures authentication, confidentiality and nonrepudiation of a message?
- A. Encrypting first by receiver's private key and second by sender's public key
- B. Encrypting first by sender's private key and second decrypting by sender's public key
- C. Encrypting first by sender's public key and second by receiver's private key
- D. Encrypting first by sender's private key and second by receiver's public key
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Encrypting by the sender's private key ensures authentication. By being able to decrypt with the sender's public key, the receiver would know that the message is sent by the sender only and the sender cannot deny/ repudiate the message. By encrypting with the sender's public key secondly, only the sender will be able to decrypt the message and confidentiality is assured. The receiver's private key is private to the receiver and the sender cannot have it for encryption. Similarly, the receiver will not have the private key of the sender to decrypt the second-level encryption. In the case of encrypting first by the sender's private key and. second, decrypting by the sender's public key, confidentiality is not ensured since the message can be decrypted by anyone using the sender's public key. The receiver's private key would not be available to the sender for second-level encryption. Similarly, the sender's private key would not be available to the receiver for decrypting the message.
NEW QUESTION 564
A computer incident response team (CIRT) manual should PRIMARILY contain which of the following documents?
- A. Table of critical backup files
- B. Risk assessment results
- C. Emergency call tree directory
- D. Severity criteria
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Quickly ranking the severity criteria of an incident is a key element of incident response. The other choices refer to documents that would not likely be included in a computer incident response team (CIRT) manual.
NEW QUESTION 565
Which of the following metrics would provide management with the useful information about the progress of a security awareness program?
- A. Increased number of downloads of the organization's security policy
- B. Completion rate of user awareness training within each business unit
- C. Decreased number of security incidents
- D. Increased reported of security incidents
Answer: C
NEW QUESTION 566
Which of the following would be MOST helpful in gaining support for a business case for an information security initiative?
- A. Demonstrating organizational alignment
- B. Referencing control deficiencies
- C. Presenting a solution comparison matrix
- D. Emphasizing threats to the organization
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 567
What is the BEST way to ensure data protection upon termination of employment?
- A. Retrieve identification badge and card keys
- B. Retrieve all personal computer equipment
- C. Erase all of the employee's folders
- D. Ensure all logical access is removed
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Ensuring all logical access is removed will guarantee that the former employee will not be able to access company data and that the employee's credentials will not be misused. Retrieving identification badge and card keys would only reduce the capability to enter the building. Retrieving the personal computer equipment and the employee's folders are necessary tasks, but that should be done as a second step.
NEW QUESTION 568
An organization faces severe fines and penalties if not in compliance with local regulatory requirements by an established deadline. Senior management has asked the information security manager to prepare an action plan to achieve compliance. Which of the following would provide the MOST useful information for planning purposes?
- A. Results from a business impact analysis
- B. Results from a gap analysis
- C. Deadlines and penalties for noncompliance
- D. An inventory of security controls currently in place
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 569
Which of the following BEST reflects the maturity of an information security program?
- A. The number of policies traceable to usable metrics
- B. The number of security incidents detected
- C. The number of findings corrected annually
- D. The number of security issues reported
Answer: A
NEW QUESTION 570
An organization was forced to pay a ransom to regain access to a critical database that had been encrypted in a ransomware attack. What would have BEST prevented The need to make this ransom payment?
- A. Ensuring all changes are approved
- B. Storing backups on a segregated network.
- C. Training employees on ransomware
- D. Verifying the firewall is configured properly
Answer: B
NEW QUESTION 571
Which of the following is MOST important to consider when determining asset valuation?
- A. Potential business loss
- B. Cost of insurance premiums
- C. Asset classification level
- D. Asset recovery cost
Answer: A
NEW QUESTION 572
When developing an information security governance framework, which of the following should be the FIRST activity?
- A. Develop response measures to detect and ensure the closure of security breaches.
- B. Integrate security within the system's devetoojtam life cycle process.
- C. Develop policies and procedures to support the framework.
- D. Align the information security program with the organization's other risk and control activities.
Answer: D
NEW QUESTION 573
......
How much CISM Exam Cost
- The early Registration fee for the CISA exam is $415 for Members and $545 for Non-Members.
- The final Registration fee for the CISA is $465 USD for members and $595 for Non-Members.
Grab latest ISACA CISM Dumps as PDF Updated: https://www.prep4sureguide.com/CISM-prep4sure-exam-guide.html
Newly Released CISM Dumps for Isaca Certification Certified: https://drive.google.com/open?id=1_2pPtoCVQjUYCGAoe81eFwC9rVRVmuGF