Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 8 out of 18 pages
Viewing questions 141-160 out of questions
Questions # 141:

Which of the following is MOST important for an information security manager to verify before conducting full-functional continuity testing?

Options:

A.

Risk acceptance by the business has been documented


B.

Teams and individuals responsible for recovery have been identified


C.

Copies of recovery and incident response plans are kept offsite


D.

Incident response and recovery plans are documented in simple language


Expert Solution
Questions # 142:

To overcome the perception that security is a hindrance to business activities, it is important for an information security manager to:

Options:

A.

rely on senior management to enforce security.


B.

promote the relevance and contribution of security.


C.

focus on compliance.


D.

reiterate the necessity of security.


Expert Solution
Questions # 143:

Which of the following is the FIRST step in developing a business continuity plan (BCP)?

Options:

A.

Determine the business recovery strategy


B.

Determine available resources.


C.

Identify the applications with the shortest recovery time objectives (RTOs).


D.

Identify critical business processes.


Expert Solution
Questions # 144:

Communicating which of the following would be MOST helpful to gain senior management support for risk treatment options?

Options:

A.

Quantitative loss


B.

Industry benchmarks


C.

Threat analysis


D.

Root cause analysis


Expert Solution
Questions # 145:

Which of the following is established during the preparation phase of an incident response plan?

Options:

A.

Recovery time objectives (RTOs)


B.

Chain of custody procedures


C.

Stakeholder communication plan


D.

Mean time to respond (MTTR)


Expert Solution
Questions # 146:

An organization faces severe fines and penalties if not in compliance with local regulatory requirements by an established deadline. Senior management has asked the information security manager to prepare an action plan to achieve compliance.

Which of the following would provide the MOST useful information for planning purposes? »

Options:

A.

Results from a business impact analysis (BIA)


B.

Deadlines and penalties for noncompliance


C.

Results from a gap analysis


D.

An inventory of security controls currently in place


Expert Solution
Questions # 147:

An organization has identified a weakness in the ability of its employees to identify and report cybersecurity incidents. Although training materials have been provided, employees show a lack of interest. Which of the following is the information security manager’s BEST course of action?

Options:

A.

Block network access until security awareness training is complete.


B.

Conduct an enterprise cybersecurity risk assessment.


C.

Obtain key stakeholder and leadership support.


D.

Send an email mandating training for the employees.


Expert Solution
Questions # 148:

Which is MOST important to identify when developing an effective information security strategy?

Options:

A.

Security awareness training needs


B.

Potential savings resulting from security governance


C.

Business assets to be secured


D.

Residual risk levels


Expert Solution
Questions # 149:

An organization is planning to open a new office in another country. Sensitive data will be routinely sent between the two offices. What should be the information security manager’s FIRST course of action?

Options:

A.

Develop customized security training for employees at the new office


B.

Encrypt the data for transfer to the head office based on security manager approval


C.

Update privacy policies to include the other country’s laws and regulations


D.

Identify applicable regulatory requirements to establish security policies


Expert Solution
Questions # 150:

Which of the following is the MOST important reason to involve external forensics experts in evidence collection when responding to a major security breach?

Options:

A.

To ensure evidence is handled by qualified resources


B.

To validate the incident response process


C.

To provide the response team with expert training on evidence handling


D.

To prevent evidence from being disclosed to any internal staff members


Expert Solution
Questions # 151:

Which of the following should be the FIRST consideration when developing a strategy for protecting an organization ' s data?

Options:

A.

Classification


B.

Encryption


C.

Access monitoring


D.

Access rights


Expert Solution
Questions # 152:

An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?

Options:

A.

Data masking


B.

Data retention strategy


C.

Data encryption standards


D.

Data loss prevention (DLP)


Expert Solution
Questions # 153:

An organization is going through a digital transformation process, which places the IT organization in an unfamiliar risk landscape. The information security manager has been tasked with leading the IT risk management process. Which of the following should be given the HIGHEST priority?

Options:

A.

Identification of risk


B.

Analysis of control gaps


C.

Design of key risk indicators (KRIs)


D.

Selection of risk treatment options


Expert Solution
Questions # 154:

Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?

Options:

A.

Enterprise risk committee


B.

Information security steering committee


C.

Data privacy officer (DPO)


D.

Chief information security officer (CISO)


Expert Solution
Questions # 155:

Which of the following would BEST help to ensure compliance with an organization ' s information security requirements by an IT service provider?

Options:

A.

Requiring an external security audit of the IT service provider


B.

Requiring regular reporting from the IT service provider


C.

Defining information security requirements with internal IT


D.

Defining the business recovery plan with the IT service provider


Expert Solution
Questions # 156:

Senior management has expressed concern that the organization ' s intrusion prevention system (IPS) may repeatedly disrupt business operations Which of the following BEST indicates that the information security manager has tuned the system to address this concern?

Options:

A.

Increasing false negatives


B.

Decreasing false negatives


C.

Decreasing false positives


D.

Increasing false positives


Expert Solution
Questions # 157:

Which of the following is the BEST tool to monitor the effectiveness of information security governance?

Options:

A.

Key performance indicators (KPIs)


B.

Balanced scorecard


C.

Business impact analysis (BIA)


D.

Risk profile


Expert Solution
Questions # 158:

Which of the following is the MOST effective way to help ensure web developers understand the growing severity of web application security risks?

Options:

A.

Incorporate security requirements into job descriptions


B.

Integrate security into the early phases of the development life cycle


C.

Implement a tailored security awareness training program


D.

Standardize secure web development practices


Expert Solution
Questions # 159:

Which of the following has the GREATEST impact on efforts to improve an organization ' s security posture?

Options:

A.

Regular reporting to senior management


B.

Supportive tone at the top regarding security


C.

Automation of security controls


D.

Well-documented security policies and procedures


Expert Solution
Questions # 160:

From an information security perspective, legal issues associated with a transborder flow of technology-related items are MOST often

Options:

A.

website transactions and taxation.


B.

software patches and corporate date.


C.

encryption tools and personal data.


D.

lack of competition and free trade.


Expert Solution
Viewing page 8 out of 18 pages
Viewing questions 141-160 out of questions