Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 2 out of 18 pages
Viewing questions 21-40 out of questions
Questions # 21:

Which of the following is the MOST important consideration when establishing an organization ' s information security governance committee?

Options:

A.

Members have knowledge of information security controls.


B.

Members are business risk owners.


C.

Members are rotated periodically.


D.

Members represent functions across the organization.


Expert Solution
Questions # 22:

An information security manager has become aware that a third-party provider is not in compliance with the statement of work (SOW). Which of the following is the BEST course of action?

Options:

A.

Notify senior management of the issue.


B.

Report the issue to legal personnel.


C.

Initiate contract renegotiation.


D.

Assess the extent of the issue.


Expert Solution
Questions # 23:

Which of the following would be the GREATEST obstacle to implementing incident notification and escalation processes in an organization with high turnover?

Options:

A.

Lack of knowledgeable personnel


B.

Lack of communication processes


C.

Lack of process documentation


D.

Lack of alignment with organizational goals


Expert Solution
Questions # 24:

Which of the following should be the PRIMARY objective of the information security incident response process?

Options:

A.

Conducting incident triage


B.

Communicating with internal and external parties


C.

Minimizing negative impact to critical operations


D.

Classifying incidents


Expert Solution
Questions # 25:

Meeting which of the following security objectives BEST ensures that information is protected against unauthorized disclosure?

Options:

A.

Integrity


B.

Authenticity


C.

Confidentiality


D.

Nonrepudiation


Expert Solution
Questions # 26:

The MOST important reason for having an information security manager serve on the change management committee is to:

Options:

A.

identify changes to the information security policy.


B.

ensure that changes are tested.


C.

ensure changes are properly documented.


D.

advise on change-related risk.


Expert Solution
Questions # 27:

Which of the following is the BEST method to protect against emerging advanced persistent threat (APT) actors?

Options:

A.

Providing ongoing training to the incident response team


B.

Implementing proactive systems monitoring


C.

Implementing a honeypot environment


D.

Updating information security awareness materials


Expert Solution
Questions # 28:

An organization has updated its business goals in the middle of the fiscal year to respond to changes in market conditions. Which of the following is MOST important for the information security manager to update in support of the new goals?

Options:

A.

Information security threat profile


B.

Information security policy


C.

Information security objectives


D.

Information security strategy


Expert Solution
Questions # 29:

Which of the following is MOST important in order to obtain senior leadership support when presenting an information security strategy?

Options:

A.

The strategy aligns with management’s acceptable level of risk.


B.

The strategy addresses ineffective information security controls.


C.

The strategy aligns with industry benchmarks and standards.


D.

The strategy addresses organizational maturity and the threat environment.


Expert Solution
Questions # 30:

Which of the following Is MOST useful to an information security manager when conducting a post-incident review of an attack?

Options:

A.

Cost of the attack to the organization


B.

Location of the attacker


C.

Method of operation used by the attacker


D.

Details from intrusion detection system (IDS) logs


Expert Solution
Questions # 31:

Which of the following is the BEST reason to implement an information security architecture?

Options:

A.

Assess the cost-effectiveness of the integration.


B.

Fast-track the deployment of information security components.


C.

Serve as a post-deployment information security road map.


D.

Facilitate consistent implementation of security requirements.


Expert Solution
Questions # 32:

Which of the following is the BEST way to obtain organization-wide support for an information security program?

Options:

A.

Mandate regular security awareness training.


B.

Develop security performance metrics.


C.

Position security as a business enabler.


D.

Prioritize security initiatives based on IT strategy.


Expert Solution
Questions # 33:

When developing a business case to justify an information security investment, which of the following would BEST enable an informed decision by senior management?

Options:

A.

The information security strategy


B.

Losses due to security incidents


C.

The results of a risk assessment


D.

Security investment trends in the industry


Expert Solution
Questions # 34:

Which of the following is the MOST important reason for obtaining input from risk owners when implementing controls?

Options:

A.

To reduce risk mitigation costs


B.

To resolve vulnerabilities in enterprise architecture (EA)


C.

To manage the risk to an acceptable level


D.

To eliminate threats impacting the business


Expert Solution
Questions # 35:

Which of the following BEST encourages staff to report issues related to information security?

Options:

A.

Tabletop exercises are performed on a regular basis


B.

Incentives are offered for security skills training


C.

The leaders set a positive security culture


D.

Formal incident response processes are in place


Expert Solution
Questions # 36:

Which of the following will BEST facilitate timely and effective incident response?

Options:

A.

Including penetration test results in incident response planning


B.

Assessing the risk of compromised assets


C.

Classifying the severity of an incident


D.

Notifying stakeholders when invoking the incident response plan


Expert Solution
Questions # 37:

Which of the following is the BEST way to improve an organization’s ability to detect and respond to incidents?

Options:

A.

Perform a security gap analysis.


B.

Conduct a business impact analysis (BIA).


C.

Conduct periodic awareness training.


D.

Perform network penetration testing.


Expert Solution
Questions # 38:

Which of the following teams is BEST suited to prepare a disaster recovery plan?

Options:

A.

Incident response


B.

Information technology


C.

Senior management


D.

Information security


Expert Solution
Questions # 39:

Which of the following should be the PRIMARY focus of a status report on the information security program to senior management?

Options:

A.

Providing evidence that resources are performing as expected


B.

Verifying security costs do not exceed the budget


C.

Demonstrating risk is managed at the desired level


D.

Confirming the organization complies with security policies


Expert Solution
Questions # 40:

Which of the following is MOST important to enable effective recovery from security incidents?

Options:

A.

Response team cross-training


B.

Network architecture reviews


C.

Penetration testing


D.

Offsite data backups


Expert Solution
Viewing page 2 out of 18 pages
Viewing questions 21-40 out of questions