Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 1 out of 18 pages
Viewing questions 1-20 out of questions
Questions # 1:

Predetermined containment methods to be used in a cybersecurity incident response should be based PRIMARILY on the:

Options:

A.

number of impacted users.


B.

capability of incident handlers.


C.

type of confirmed incident.


D.

predicted incident duration.


Expert Solution
Questions # 2:

Which of the following functions is MOST critical when initiating the removal of system access for terminated employees?

Options:

A.

Legal


B.

Information security


C.

Help desk


D.

Human resources (HR)


Expert Solution
Questions # 3:

An organization that conducts business globally is planning to utilize a third-party service provider to process payroll information. Which of the following issues poses the GREATEST risk to the organization?

Options:

A.

The third party does not have an independent assessment of controls available for review.


B.

The third party has not provided evidence of compliance with local regulations where data is generated.


C.

The third-party contract does not include an indemnity clause for compensation in the event of a breach.


D.

The third party ' s service level agreement (SLA) does not include guarantees of uptime.


Expert Solution
Questions # 4:

A common drawback of email software packages that provide native encryption of messages is that the encryption:

Options:

A.

cannot encrypt attachments


B.

cannot interoperate across product domains.


C.

has an insufficient key length.


D.

has no key-recovery mechanism.


Expert Solution
Questions # 5:

After a server has been attacked, which of the following is the BEST course of action?

Options:

A.

Initiate incident response.


B.

Review vulnerability assessment.


C.

Conduct a security audit.


D.

Isolate the system.


Expert Solution
Questions # 6:

An organization plans to implement a new e-commerce operation in a highly regulated market. Which of the following is MOST important to consider when updating the risk management strategy?

Options:

A.

Strategy of industry peers


B.

Outsourcing needs


C.

Business culture


D.

Compliance requirements


Expert Solution
Questions # 7:

Which of the following is the PRIMARY reason for an information security manager to periodically review existing controls?

Options:

A.

To prioritize security initiatives


B.

To avoid redundant controls


C.

To align with emerging risk


D.

To address end-user control complaints


Expert Solution
Questions # 8:

Which type of test is MOST effective in communicating the roles of end users to support timely identification and response to information security incidents?

Options:

A.

Parallel


B.

Complete failover


C.

Checklist


D.

Walkthrough


Expert Solution
Questions # 9:

Which of the following is the MOST effective defense against malicious insiders compromising confidential information?

Options:

A.

Regular audits of access controls


B.

Strong background checks when hiring staff


C.

Prompt termination procedures


D.

Role-based access control (RBAC)


Expert Solution
Questions # 10:

Within the confidentiality, integrity, and availability (CIA) triad, which of the following activities BEST supports the concept of

confidentiality?

Options:

A.

Ensuring hashing of administrator credentials


B.

Enforcing service level agreements (SLAs)


C.

Ensuring encryption for data in transit


D.

Utilizing a formal change management process


Expert Solution
Questions # 11:

Which of the following is the PRIMARY objective of incident triage?

Options:

A.

Coordination of communications


B.

Mitigation of vulnerabilities


C.

Categorization of events


D.

Containment of threats


Expert Solution
Questions # 12:

Which of the following is the BEST reason to implement a comprehensive information security management system?

To ensure continuous alignment with the organizational strategy

To gain senior management support for the information security program

To support identification of key risk indicators (KRIs)

Options:

A.

To facilitate compliance with external regulatory requirements


Expert Solution
Questions # 13:

Which of the following is the MOST effective way to address an organizations security concerns during contract negotiations with a third party?

Options:

A.

Ensure security is involved in the procurement process.


B.

Review the third-party contract with the organization ' s legal department.


C.

Conduct an information security audit on the third-party vendor.


D.

Communicate security policy with the third-party vendor.


Expert Solution
Questions # 14:

Which of the following is MOST likely to be the cause of systems and applications missing critical patches?

Options:

A.

Insufficient management oversight


B.

Inadequate reporting on damaged hardware


C.

Lack of a release and deployment policy


D.

Outdated configuration management database (CMDB)


Expert Solution
Questions # 15:

Which of the following BEST facilitates effective strategic alignment of security initiatives?

Options:

A.

The business strategy is periodically updated


B.

Procedures and standards are approved by department heads.


C.

Periodic security audits are conducted by a third-party.


D.

Organizational units contribute to and agree on priorities


Expert Solution
Questions # 16:

A business impact analysis (BIA) BEST enables an organization to establish:

Options:

A.

annualized loss expectancy (ALE).


B.

recovery methods.


C.

total cost of ownership (TCO).


D.

restoration priorities.


Expert Solution
Questions # 17:

An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?

Options:

A.

Initiate incident response.


B.

Disable remote


C.

Initiate a device reset.


D.

Conduct a risk assessment.


Expert Solution
Questions # 18:

The PRIMARY benefit of integrating information security activities into change management processes is to:

Options:

A.

protect the organization from unauthorized changes.


B.

ensure required controls are included in changes.


C.

provide greater accountability for security-related changes in the business.


D.

protect the business from collusion and compliance threats.


Expert Solution
Questions # 19:

As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?

Options:

A.

The risk owner is able to reassess the risk following remediation.


B.

The risk owner has the authority to take action on the risk.


C.

The risk owner is able to make timely updates to the risk register.


D.

The risk owner also owns the associated control that failed.


Expert Solution
Questions # 20:

What is the BEST way to reduce the impact of a successful ransomware attack?

Options:

A.

Perform frequent backups and store them offline.


B.

Purchase or renew cyber insurance policies.


C.

Include provisions to pay ransoms ih the information security budget.


D.

Monitor the network and provide alerts on intrusions.


Expert Solution
Viewing page 1 out of 18 pages
Viewing questions 1-20 out of questions