Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISM Questions and answers with CertsForce

Viewing page 9 out of 18 pages
Viewing questions 161-180 out of questions
Questions # 161:

Which of the following should be the MOST important consideration of business continuity management?

Options:

A.

Ensuring human safety


B.

Identifying critical business processes


C.

Ensuring the reliability of backup data


D.

Securing critical information assets


Expert Solution
Questions # 162:

Which of the following is the MOST useful input for an information security manager when updating the organization’s security policy?

Options:

A.

Security team capabilities


B.

Industry benchmarks


C.

Risk appetite


D.

Vulnerability scan results


Expert Solution
Questions # 163:

Which of the following should be given the HIGHEST priority during an information security post-incident review?

Options:

A.

Documenting actions taken in sufficient detail


B.

Updating key risk indicators (KRIs)


C.

Evaluating the performance of incident response team members


D.

Evaluating incident response effectiveness


Expert Solution
Questions # 164:

Which of the following incident response phases involves actions to help safeguard critical systems while maintaining business operations?

Options:

A.

Recovery


B.

Identification


C.

Containment


D.

Preparation


Expert Solution
Questions # 165:

An organization has acquired a company in a foreign country to gain an advantage in a new market. Which of the following is the FIRST step the information security manager should take?

Options:

A.

Determine which country ' s information security regulations will be used.


B.

Merge the two existing information security programs.


C.

Apply the existing information security program to the acquired company.


D.

Evaluate the information security laws that apply to the acquired company.


Expert Solution
Questions # 166:

Security administration efforts will be greatly reduced following the deployment of which of the following techniques?

Options:

A.

Discretionary access control


B.

Role-based access control


C.

Access control lists


D.

Distributed access control


Expert Solution
Questions # 167:

Which of the following BEST indicates senior management support for an information security program?

Options:

A.

Top-down communication


B.

Regular security awareness training


C.

Steering committee involvement


D.

Participation in a certification program


Expert Solution
Questions # 168:

Which of the following metrics would provide an accurate measure of an information security program ' s performance?

Options:

A.

A collection of qualitative indicators that accurately measure security exceptions


B.

A combination of qualitative and quantitative trends that enable decision making


C.

A collection of quantitative indicators that are compared against industry benchmarks


D.

A single numeric score derived from various measures assigned to the security program


Expert Solution
Questions # 169:

Which of the following would BEST guide the development and maintenance of an information security program?

Options:

A.

A business impact assessment


B.

A comprehensive risk register


C.

An established risk assessment process


D.

The organization ' s risk appetite


Expert Solution
Questions # 170:

When performing a business impact analysis (BIA), who should be responsible for determining the initial recovery time objective (RTO)?

Options:

A.

External consultant


B.

Information owners


C.

Information security manager


D.

Business continuity coordinator


Expert Solution
Questions # 171:

Which of the following is the BEST way to ensure the organization ' s security objectives are embedded in business operations?

Options:

A.

Publish adopted information security standards.


B.

Perform annual information security compliance reviews.


C.

Implement an information security governance framework.


D.

Define penalties for information security noncompliance.


Expert Solution
Questions # 172:

An incident response team has established that an application has been breached. Which of the following should be done NEXT?

Options:

A.

Maintain the affected systems in a forensically acceptable state


B.

Conduct a risk assessment on the affected application


C.

Inform senior management of the breach.


D.

Isolate the impacted systems from the rest of the network


Expert Solution
Questions # 173:

Which of the following is MOST important for an information security manager to consider when determining whether data should be stored?

Options:

A.

Data protection regulations


B.

Data storage limitations


C.

Business requirements


D.

Type and nature of data


Expert Solution
Questions # 174:

Which of the following is the MOST important consideration when briefing executives about the current state of the information security program?

Options:

A.

Including a situational forecast


B.

Using appropriate language for the target audience


C.

Including trend charts for metrics


D.

Using a rating system to demonstrate program effectiveness


Expert Solution
Questions # 175:

When management changes the enterprise business strategy which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?

Options:

A.

Configuration management


B.

Risk management


C.

Access control management


D.

Change management


Expert Solution
Questions # 176:

Which of the following BEST facilitates effective incident response testing?

Options:

A.

Including all business units in testing


B.

Simulating realistic test scenarios


C.

Reviewing test results quarterly


D.

Testing after major business changes


Expert Solution
Questions # 177:

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Options:

A.

To define security roles and responsibilities


B.

To determine return on investment (ROI)


C.

To establish incident severity levels


D.

To determine the criticality of information assets


Expert Solution
Questions # 178:

An incident response team has been assembled from a group of experienced individuals, Which type of exercise would be MOST beneficial for the team at the first drill?

Options:

A.

Red team exercise


B.

Black box penetration test


C.

Disaster recovery exercise


D.

Tabletop exercise


Expert Solution
Questions # 179:

An organization requires that business-critical applications be recovered within 30 minutes in the event of a disaster. Which of the following metrics should be in the business continuity plan (BCP) to manage this requirement?

Options:

A.

Maximum tolerable downtime (MTD)


B.

Service level agreement (SLA)


C.

Recovery point objective (RPO)


D.

Recovery time objective (RTO)


Expert Solution
Questions # 180:

Which of the following is the MOST important issue in a penetration test?

Options:

A.

Having an independent group perform the test


B.

Obtaining permission from audit


C.

Performing the test without the benefit of any insider knowledge


D.

Having a defined goal as well as success and failure criteria


Expert Solution
Viewing page 9 out of 18 pages
Viewing questions 161-180 out of questions