Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 3 out of 18 pages
Viewing questions 41-60 out of questions
Questions # 41:

Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?

Options:

A.

An industry peer experienced a recent breach with a similar application.


B.

The system can be replicated for additional use cases.


C.

The cost of implementing the system is less than the impact of downtime.


D.

The solution is within the organization ' s risk tolerance.


Expert Solution
Questions # 42:

Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?

Options:

A.

Maturity of incident response activities


B.

Threat environment


C.

Quantity of impacted assets


D.

Incident impact


Expert Solution
Questions # 43:

Which of the following is the MOST important objective of post-incident review activities?

Options:

A.

Evidence collection


B.

Continuous improvement


C.

Incident triage


D.

Incident documentation


Expert Solution
Questions # 44:

Which of the following would be the GREATEST threat posed by a distributed denial of service (DDoS) attack on a public-facing web server?

Options:

A.

Execution of unauthorized commands


B.

Prevention of authorized access


C.

Defacement of website content


D.

Unauthorized access to resources


Expert Solution
Questions # 45:

Which of the following should be done NEXT following senior management ' s decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?

Options:

A.

Encrypt data in transit and at rest.


B.

Complete a return on investment (ROI) analysis.


C.

Create and implement a data minimization plan.


D.

Conduct a gap analysis.


Expert Solution
Questions # 46:

An information security manager learns that an existing supplier plans to begin using its recently developed generative AI technology for the same scope of service. A risk assessment was performed on the supplier three months ago with no outstanding findings. Which of the following is the BEST course of action to address the associated risk?

Options:

A.

Suspend the use of the supplier until a risk assessment of the AI technology has been performed


B.

Report the change in risk to senior management


C.

Review the results of the previous risk assessment


D.

Add an indemnity clause in the contractual agreement at the renewal stage


Expert Solution
Questions # 47:

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager ' s MOST important course of action?

Options:

A.

Engage an independent audit of the third party ' s external provider.


B.

Recommend canceling the contract with the third party.


C.

Evaluate the third party ' s agreements with its external provider.


D.

Conduct an external audit of the contracted third party.


Expert Solution
Questions # 48:

Which of the following is the PRIMARY role of an information security manager in a software development project?

Options:

A.

To enhance awareness for secure software design


B.

To assess and approve the security application architecture


C.

To identify noncompliance in the early design stage


D.

To identify software security weaknesses


Expert Solution
Questions # 49:

The use of a business case to obtain funding for an information security investment is MOST effective when the business case:

Options:

A.

relates the investment to the organization ' s strategic plan.


B.

translates information security policies and standards into business requirements.


C.

articulates management ' s intent and information security directives in clear language.


D.

realigns information security objectives to organizational strategy.


Expert Solution
Questions # 50:

Which of the following is the GREATEST privacy concern when personal data is collected and processed?

Options:

A.

More storage required to store collected data


B.

Increased time and resources needed


C.

Data collected without consent


D.

Outdated privacy policy


Expert Solution
Questions # 51:

Which of the following BEST enables staff acceptance of information security policies?

Options:

A.

Strong senior management support


B.

Gomputer-based training


C.

Arobust incident response program


D.

Adequate security funding


Expert Solution
Questions # 52:

In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?

Options:

A.

Maturity of the security policy


B.

Clarity of security roles and responsibilities


C.

Corporate culture


D.

Corporate risk framework


Expert Solution
Questions # 53:

Which of the following is MOST important to the effectiveness of an information security steering committee?

Options:

A.

The committee has strong regulatory knowledge.


B.

The committee is comprised of representatives from senior management.


C.

The committee has cross-organizational representation.


D.

The committee uses a risk management framework.


Expert Solution
Questions # 54:

Which of the following should be the PRIMARY focus of a lessons learned exercise following a successful response to a cybersecurity incident?

Options:

A.

Establishing the root cause of the incident


B.

Identifying attack vectors utilized in the incident


C.

When business operations were restored after the incident


D.

How incident management processes were executed


Expert Solution
Questions # 55:

An organization is planning to outsource network management to a service provider. Including which of the following in the contract would be the MOST effective way to mitigate information security risk?

Options:

A.

Requirement for regular information security awareness


B.

Right-to-audit clause


C.

Service level agreement (SLA)


D.

Requirement to comply with corporate security policy


Expert Solution
Questions # 56:

The MAIN reason for having senior management review and approve an information security strategic plan is to ensure:

Options:

A.

the organization has the required funds to implement the plan.


B.

compliance with legal and regulatory requirements.


C.

staff participation in information security efforts.


D.

the plan aligns with corporate governance.


Expert Solution
Questions # 57:

A technical vulnerability assessment on a personnel information management server should be performed when:

Options:

A.

the data owner leaves the organization unexpectedly.


B.

changes are made to the system configuration.


C.

the number of unauthorized access attempts increases.


D.

an unexpected server outage has occurred.


Expert Solution
Questions # 58:

Which of the following is the MOST important detail to capture in an organization ' s risk register?

Options:

A.

Risk appetite


B.

Risk severity level


C.

Risk acceptance criteria


D.

Risk ownership


Expert Solution
Questions # 59:

An organization is implementing an information security governance framework. To communicate the program ' s effectiveness to stakeholders, it is MOST important to establish:

Options:

A.

a control self-assessment (CSA) process.


B.

automated reporting to stakeholders.


C.

a monitoring process for the security policy.


D.

metrics for each milestone.


Expert Solution
Questions # 60:

Which of the following is MOST important to emphasize when presenting information to gain senior management support for control enhancements?

Options:

A.

Residual risk exposure


B.

Threats against internal systems


C.

Control gaps within defense-in-depth architecture


D.

Recent data breaches in the same industry sector


Expert Solution
Viewing page 3 out of 18 pages
Viewing questions 41-60 out of questions