Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 5 out of 18 pages
Viewing questions 81-100 out of questions
Questions # 81:

Which of the following BEST indicates ongoing senior management commitment to the organization’s information security strategy?

Options:

A.

Established key performance indicators


B.

A comprehensive security awareness training program


C.

An efficient incident response program


D.

Adequate funding for the information security program


Expert Solution
Questions # 82:

Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?

Options:

A.

Evaluate the results of business continuity testing.


B.

Review key performance indicators (KPIs).


C.

Evaluate the business impact of incidents.


D.

Engage business process owners.


Expert Solution
Questions # 83:

Which of the following components of an information security risk assessment is MOST valuable to senior management?

Options:

A.

Threat profile


B.

Residual risk


C.

Return on investment (ROI)


D.

Mitigation actions


Expert Solution
Questions # 84:

An information security manager has been tasked with developing materials to update the board, regulatory agencies, and the media about a security incident. Which of the following should the information security manager do FIRST?

Options:

A.

Set up communication channels for the target audience.


B.

Determine the needs and requirements of each audience.


C.

Create a comprehensive singular communication


D.

Invoke the organization ' s incident response plan.


Expert Solution
Questions # 85:

Which of the following is the PRIMARY benefit of training service desk staff to recognize incidents?

Options:

A.

Incident response plan can be activated in a timely manner.


B.

Incident metrics can be communicated.


C.

Risk response options can be identified quickly.


D.

Incident classification times can be improved.


Expert Solution
Questions # 86:

The MOST appropriate time to conduct a disaster recovery test would be after:

Options:

A.

major business processes have been redesigned.


B.

the business continuity plan (BCP) has been updated.


C.

the security risk profile has been reviewed


D.

noncompliance incidents have been filed.


Expert Solution
Questions # 87:

Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?

Options:

A.

Verify that information security requirements are included in the contract.


B.

Request customer references from the vendor.


C.

Require vendors to complete information security questionnaires.


D.

Review the results of the vendor ' s independent control reports.


Expert Solution
Questions # 88:

Which of the following is MOST important to have in place to help ensure an organization ' s cybersecurity program meets the needs of the business?

Options:

A.

Risk assessment program


B.

Information security awareness training


C.

Information security governance


D.

Information security metrics


Expert Solution
Questions # 89:

Which of the following is MOST important when conducting a forensic investigation?

Options:

A.

Analyzing system memory


B.

Documenting analysis steps


C.

Capturing full system images


D.

Maintaining a chain of custody


Expert Solution
Questions # 90:

A department has reported that a security control is no longer effective. Which of the following is the information security manager ' s BEST course of action?

Options:

A.

Replace the control


B.

Check for defense in depth


C.

Assess the control state


D.

Report the failure to management


Expert Solution
Questions # 91:

Which of the following is MOST important for the information security manager to include when presenting changes in the security risk profile to senior management?

Options:

A.

Industry benchmarks


B.

Security training test results


C.

Performance measures for existing controls


D.

Number of false positives


Expert Solution
Questions # 92:

Of the following, who is BEST suited to own the risk discovered in an application?

Options:

A.

Information security manager


B.

Senior management


C.

System owner


D.

Control owner


Expert Solution
Questions # 93:

Which of the following activities is MOST appropriate to conduct during the eradication phase of a cyber incident response?

Options:

A.

Restore affected systems for normal operations.


B.

Mitigate exploited vulnerabilities to stop future incidents.


C.

Estimate the amount of damage caused by the incident.


D.

Isolate affected systems to prevent further damage


Expert Solution
Questions # 94:

Which of the following BEST supports investments in an information security program?

Options:

A.

Business cases


B.

Business impact analysis (BIA)


C.

Gap analysis results


D.

Risk assessment results


Expert Solution
Questions # 95:

During which of the following phases should an incident response team document actions required to remove the threat that caused the incident?

Options:

A.

Post-incident review


B.

Eradication


C.

Containment


D.

Identification


Expert Solution
Questions # 96:

Which of the following service offerings in a typical Infrastructure as a Service (laaS) model will BEST enable a cloud service provider to assist customers when recovering from a security incident?

Options:

A.

Availability of web application firewall logs.


B.

Capability of online virtual machine analysis


C.

Availability of current infrastructure documentation


D.

Capability to take a snapshot of virtual machines


Expert Solution
Questions # 97:

The PRIMARY advantage of single sign-on (SSO) is that it will:

Options:

A.

increase efficiency of access management


B.

increase the security of related applications.


C.

strengthen user passwords.


D.

support multiple authentication mechanisms.


Expert Solution
Questions # 98:

In order to understand an organization ' s security posture, it is MOST important for an organization ' s senior leadership to:

Options:

A.

evaluate results of the most recent incident response test.


B.

review the number of reported security incidents.


C.

ensure established security metrics are reported.


D.

assess progress of risk mitigation efforts.


Expert Solution
Questions # 99:

Which of the following should an information security manager do FIRST upon confirming a privileged user ' s unauthorized modifications to a security application?

Options:

A.

Report the risk associated with the policy breach.


B.

Enforce the security configuration and require the change to be reverted.


C.

Implement compensating controls to address the risk.


D.

Implement a privileged access management system.


Expert Solution
Questions # 100:

The PRIMARY advantage of performing black-box control tests as opposed to white-box control tests is that they:

Options:

A.

cause fewer potential production issues.


B.

require less IT staff preparation.


C.

simulate real-world attacks.


D.

identify more threats.


Expert Solution
Viewing page 5 out of 18 pages
Viewing questions 81-100 out of questions