Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 4 out of 18 pages
Viewing questions 61-80 out of questions
Questions # 61:

Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?

Options:

A.

Benchmarking against industry peers


B.

Adoption of an industry recognized framework


C.

Approval from senior management


D.

Identification of business-specific risk factors


Expert Solution
Questions # 62:

Which of the following is the MOST important consideration when evaluating the performance of existing security controls?

Options:

A.

Obtaining senior management support to facilitate testing


B.

Interviewing control owners to accurately collect metrics data


C.

Selecting testing methods that match the purpose of the testing


D.

Establishing testing scenarios based on international standards


Expert Solution
Questions # 63:

Penetration testing is MOST appropriate when a:

Options:

A.

new system is about to go live.


B.

new system is being designed.


C.

security policy is being developed.


D.

security incident has occurred,


Expert Solution
Questions # 64:

An organization needs to comply with new security incident response requirements. Which of the following should the information security manager do FIRST?

Options:

A.

Create a business case for a new incident response plan.


B.

Revise the existing incident response plan.


C.

Conduct a gap analysis.


D.

Assess the impact to the budget,


Expert Solution
Questions # 65:

Which of the following should be done FIRST when establishing a new data protection program that must comply with applicable data privacy regulations?

Options:

A.

Evaluate privacy technologies required for data protection.


B.

Encrypt all personal data stored on systems and networks.


C.

Update disciplinary processes to address privacy violations.


D.

Create an inventory of systems where personal data is stored.


Expert Solution
Questions # 66:

Measuring which of the following is the MOST accurate way to determine the alignment of an information security strategy with organizational goals?

Options:

A.

Number of blocked intrusion attempts


B.

Number of business cases reviewed by senior management


C.

Trends in the number of identified threats to the business


D.

Percentage of controls integrated into business processes


Expert Solution
Questions # 67:

The PRIMARY purpose for deploying information security metrics is to:

Options:

A.

compare program effectiveness to benchmarks.


B.

support ongoing security budget requirements.


C.

ensure that technical operations meet specifications.


D.

provide information needed to make decisions.


Expert Solution
Questions # 68:

Which of the following should an information security manager do FIRST when creating an organization ' s disaster recovery plan (DRP)?

Options:

A.

Conduct a business impact analysis (BIA)


B.

Identify the response and recovery learns.


C.

Review the communications plan.


D.

Develop response and recovery strategies.


Expert Solution
Questions # 69:

When an organization experiences a disruptive event, the business continuity plan (BCP) should be triggered PRIMARILY based on:

Options:

A.

expected duration of outage.


B.

management direction.


C.

type of security incident.


D.

the root cause of the event.


Expert Solution
Questions # 70:

Which of the following is MOST important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals?

Options:

A.

Skills required for the incident response team


B.

A list of external resources to assist with incidents


C.

Service level agreements (SLAs)


D.

A detailed incident notification process


Expert Solution
Questions # 71:

Which of the following BEST determines the allocation of resources during a security incident response?

Options:

A.

Senior management commitment


B.

A business continuity plan (BCP)


C.

An established escalation process


D.

Defined levels of severity


Expert Solution
Questions # 72:

A business unit recently integrated the organization ' s new strong password policy into its business application which requires users to reset passwords every 30 days. The help desk is now flooded with password reset requests. Which of the following is the information security manager ' s BEST course of action to address this situation?

Options:

A.

Provide end-user training.


B.

Escalate to senior management.


C.

Continue to enforce the policy.


D.

Conduct a business impact analysis (BIA).


Expert Solution
Questions # 73:

Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?

Options:

A.

Projected Increase in maturity level


B.

Estimated reduction in risk


C.

Projected costs over time


D.

Estimated increase in efficiency


Expert Solution
Questions # 74:

Which of the following MOST directly influences the efficiency of incident response immediately after an incident has been detected?

Options:

A.

Incident containment and mitigation


B.

Root cause analysis


C.

Incident categorization


D.

Lessons learned


Expert Solution
Questions # 75:

Which of the following is the GREATEST benefit of including incident classification criteria within an incident response plan?

Options:

A.

Ability to monitor and control incident management costs


B.

More visibility to the impact of disruptions


C.

Effective protection of information assets


D.

Optimized allocation of recovery resources


Expert Solution
Questions # 76:

Which of the following should be the NEXT step after a security incident has been reported?

Options:

A.

Recovery


B.

Investigation


C.

Escalation


D.

Containment


Expert Solution
Questions # 77:

For the information security manager, integrating the various assurance functions of an organization is important PRIMARILY to enable:

Options:

A.

consistent security.


B.

comprehensive audits


C.

a security-aware culture


D.

compliance with policy


Expert Solution
Questions # 78:

When evaluating cloud storage solutions, the FIRST consideration should be:

Options:

A.

The service level agreement (SLA) for encryption keys


B.

Alignment with the organization’s data classification policy


C.

How the organization’s sensitive data will be transferred


D.

The volume of data to be stored in the cloud


Expert Solution
Questions # 79:

A healthcare company is working with a virtual reality (VR) vendor to provide a training solution for customers of the organization’s products. Which of the following is MOST important to include in the contract?

Options:

A.

A requirement to encrypt the organization’s data


B.

A clause prohibiting reuse of the organization’s data


C.

A clause establishing the right to audit the vendor


D.

A service level agreement (SLA) for uptime


Expert Solution
Questions # 80:

Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?

Options:

A.

Identifying potential risks posed by devices on the network


B.

Identifying vulnerabilities within organizational processes


C.

Ensuring complex vulnerabilities are not missed


D.

Automating the information security risk analysis program


Expert Solution
Viewing page 4 out of 18 pages
Viewing questions 61-80 out of questions