Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 7 out of 18 pages
Viewing questions 121-140 out of questions
Questions # 121:

Prior to implementing a bring your own device (BYOD) program, it is MOST important to:

Options:

A.

select mobile device management (MDM) software.


B.

survey employees for requested applications.


C.

develop an acceptable use policy.


D.

review currently utilized applications.


Expert Solution
Questions # 122:

To inform a risk treatment decision, which of the following should the information security manager compare with the organization ' s risk appetite?

Options:

A.

Gap analysis results


B.

Level of residual risk


C.

Level of risk treatment


D.

Configuration parameters


Expert Solution
Questions # 123:

Which of the following is the BEST approach for data owners to use when defining access privileges for users?

Define access privileges based on user roles.

Adopt user account settings recommended by the vendor.

Perform a risk assessment of the users ' access privileges.

Options:

A.

Implement an identity and access management (IDM) tool.


Expert Solution
Questions # 124:

Which of the following BEST enables the design of an effective incident escalation process?

Options:

A.

Enforceable control baselines


B.

Controls designed for defense in depth


C.

A well-defined organizational hierarchy


D.

A comprehensive risk register


Expert Solution
Questions # 125:

An organization has recently purchased cybersecurity insurance after the board voiced concern about the potential for a security breach. With this response to the perceived risk, the organization:

Options:

A.

Has avoided the risk associated with a security breach


B.

Can safely reduce its internal security expenditure


C.

Remains ultimately accountable for the impact of a breach


D.

Has implemented redundant controls against a breach


Expert Solution
Questions # 126:

A security review identifies that confidential information on the file server has been accessed by unauthorized users in the organization. Which of the following should the information security manager do FIRST?

Options:

A.

Invoke the incident response plan


B.

Implement role-based access control (RBAC)


C.

Remove access to the information


D.

Delete the information from the file server


Expert Solution
Questions # 127:

Which of the following roles is BEST able to influence the security culture within an organization?

Options:

A.

Chief information security officer (CISO)


B.

Chief information officer (CIO)


C.

Chief executive officer (CEO)


D.

Chief operating officer (COO)


Expert Solution
Questions # 128:

Which of the following is the MOST important consideration when attempting to create a security-focused culture?

Options:

A.

Current security strategy benchmarks against peer organizations


B.

The regional rules and legislation regarding information security


C.

The current security awareness level of the employees


D.

The organization’s existing security policies, procedures, and frameworks


Expert Solution
Questions # 129:

Which of the following is the BEST strategy when determining an organization’s approach to risk treatment?

Options:

A.

Advancing the maturity of existing controls based on risk tolerance


B.

Prioritizing controls that directly mitigate the organization ' s most critical risks


C.

Implementing risk mitigation controls that are considered quick wins


D.

Implementing a one-size-fits-all set of controls across all organizational units


Expert Solution
Questions # 130:

Which of the following is the BEST way to monitor the effectiveness of security controls?

Options:

A.

Benchmark security controls against similar organizations


B.

Review application and system audit logs


C.

Establish and report security metrics


D.

Conduct regular threat assessments


Expert Solution
Questions # 131:

Once a suite of security controls has been successfully implemented for an organization ' s business units, it is MOST important for the information security manager to:

Options:

A.

hand over the controls to the relevant business owners.


B.

ensure the controls are regularly tested for ongoing effectiveness.


C.

perform testing to compare control performance against industry levels.


D.

prepare to adapt the controls for future system upgrades.


Expert Solution
Questions # 132:

Which of the following would provide the MOST value to senior management when presenting the results of a risk assessment?

Options:

A.

Mapping the risks to the security classification scheme


B.

Illustrating risk on a heat map


C.

Mapping the risks to existing controls


D.

Providing a technical risk assessment report


Expert Solution
Questions # 133:

Which of the following is the BEST approach for addressing noncompliance with security standards?

Options:

A.

Develop new security standards.


B.

Maintain a security exceptions process.


C.

Discontinue affected activities until security requirements can be met.


D.

Apply additional logging and monitoring to affected assets.


Expert Solution
Questions # 134:

Which of the following BEST helps to ensure a risk response plan will be developed and executed in a timely manner?

Options:

A.

Establishing risk metrics


B.

Training on risk management procedures


C.

Reporting on documented deficiencies


D.

Assigning a risk owner


Expert Solution
Questions # 135:

An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?

Options:

A.

Benchmark the processes with best practice to identify gaps.


B.

Calculate the return on investment (ROI).


C.

Provide security awareness training to HR.


D.

Assess the business objectives of the processes.


Expert Solution
Questions # 136:

Which of the following is the responsibility of a risk owner?

Options:

A.

Implementing risk treatment plan activities with control owners


B.

Evaluating control effectiveness


C.

Approving risk treatment plans


D.

Approving the selection of risk mitigation measures


Expert Solution
Questions # 137:

Which of the following is the MOST important consideration when planning to implement artificial intelligence to enhance an organization’s vulnerability and control deficiency analysis capabilities?

Options:

A.

The alignment of artificial intelligence tools with the organization’s existing security policies


B.

The adaptability and scalability of artificial intelligence tools


C.

The interoperability of artificial intelligence tools with the existing security infrastructure and technologies


D.

The artificial intelligence-related training requirements for existing security staff


Expert Solution
Questions # 138:

Which of the following is the PRIMARY objective of the incident management recovery phase?

Options:

A.

To recover business operation support


B.

To perform a lessons-learned review


C.

To document actions taken to restore IT systems


D.

To bring IT services back online


Expert Solution
Questions # 139:

Which of the following will BEST facilitate the integration of information security governance into enterprise governance?

Options:

A.

Developing an information security policy based on risk assessments


B.

Establishing an information security steering committee


C.

Documenting the information security governance framework


D.

Implementing an information security awareness program


Expert Solution
Questions # 140:

Which of the following has the GREATEST impact on the ability to successfully execute a disaster recovery plan (DRP)?

Options:

A.

Conducting tabletop exercises of the plan


B.

Updating the plan periodically


C.

Communicating the plan to all stakeholders


D.

Reviewing escalation procedures


Expert Solution
Viewing page 7 out of 18 pages
Viewing questions 121-140 out of questions