[Aug 28, 2021] Step by Step Guide to Prepare for CISM Exam BrainDumps [Q659-Q679]

Share

Aug 28, 2021 Step by Step Guide to Prepare for CISM Exam BrainDumps

Isaca Certification CISM Real Exam Questions and Answers FREE Updated on 2021

NEW QUESTION 659
Which of the following is the NEXT course of action for an incident response team if an Incident cannot be investigated in the allocated time?

  • A. Escalate to senior management for resolution.
  • B. Discontinue the investigation.
  • C. Request an exception to the service level agreement (SLA).
  • D. Activate the business continuity plan (BCP).

Answer: A

 

NEW QUESTION 660
The MOST effective way to ensure that outsourced service providers comply with the organization's information security policy would be:

  • A. periodically auditing.
  • B. security awareness training.
  • C. service level monitoring.
  • D. penetration testing.

Answer: A

Explanation:
Regular audit exercise can spot any gap in the information security compliance. Service level monitoring can only pinpoint operational issues in the organization's operational environment.
Penetration testing can identify security vulnerability but cannot ensure information compliance Training can increase users' awareness on the information security policy, but is not more effective than auditing.

 

NEW QUESTION 661
Which of the following is the MOST essential task for a chief information security officer (CISO) to perform?

  • A. Develop an information security strategy paper
  • B. Update platform-level security settings
  • C. Approve access to critical financial systems
  • D. Conduct disaster recovery test exercises

Answer: A

Explanation:
Developing a strategy paper on information security would be the most appropriate. Approving access would be the job of the data owner. Updating platform-level security and conducting recovery test exercises would be less essential since these are administrative tasks.

 

NEW QUESTION 662
Which of the following would be MOST appropriate for collecting and preserving evidence?

  • A. Generic audit software
  • B. Log correlation software
  • C. Encrypted hard drives
  • D. Proven forensic processes

Answer: D

Explanation:
When collecting evidence about a security incident, it is very important to follow appropriate forensic procedures to handle electronic evidence by a method approved by local jurisdictions. All other options will help when collecting or preserving data about the incident; however these data might not be accepted as evidence in a court of law if they are not collected by a method approved by local jurisdictions.

 

NEW QUESTION 663
The MAIN reason why asset classification is important to a successful information security program is because classification determines:

  • A. the priority and extent of risk mitigation efforts.
  • B. the appropriate level of protection to the asset.
  • C. the amount of insurance needed in case of loss.
  • D. how protection levels compare to peer organizations.

Answer: B

Explanation:
Protection should be proportional to the value of the asset. Classification is based upon the value of the asset to the organization. The amount of insurance needed in case of loss may not be applicable in each case. Peer organizations may have different classification schemes for their assets.

 

NEW QUESTION 664
What should an information security team do FIRST when notified by the help desk that an employee's computer has been infected with ma I ware?

  • A. Isolate the computer from the network.
  • B. Take a forensic copy of the hard drive.
  • C. Restore the files from a secure backup.
  • D. Use anti-malware software to clean the infected computer.

Answer: A

 

NEW QUESTION 665
Which of the following techniques is MOST useful when an incident response team needs to respond to external attacks on multiple corporate network devices?

  • A. Endpoint baseline configuration analysis
  • B. Vulnerability assessment of network devices
  • C. Penetration testing of network devices
  • D. Security event correlation analysis

Answer: D

 

NEW QUESTION 666
Which of the following would be the MOST important factor to be considered in the loss of mobile equipment with unencrypted data?

  • A. Replacement cost of the equipment
  • B. Sufficient coverage of the insurance policy for accidental losses
  • C. Disclosure of personal information
  • D. Intrinsic value of the data stored on the equipment

Answer: D

Explanation:
When mobile equipment is lost or stolen, the information contained on the equipment matters most in determining the impact of the loss. The more sensitive the information, the greater the liability. If staff carries mobile equipment for business purposes, an organization must develop a clear policy as to what information should be kept on the equipment and for what purpose. Personal information is not defined in the question as the data that were lost. Insurance may be a relatively smaller issue as compared with information theft or opportunity loss, although insurance is also an important factor for a successful business. Cost of equipment would be a less important issue as compared with other choices.

 

NEW QUESTION 667
When evaluating cloud storage solutions the FIRST consideration should be:

  • A. how the organization's sensitive data will be transferred
  • B. who controls the encryption keys
  • C. the level of protection of data stored in the cloud.
  • D. alignment with the organization's data classification policy

Answer: C

 

NEW QUESTION 668
Documented standards/procedures for the use of cryptography across the enterprise should PRIMARILY:

  • A. define cryptographic algorithms and key lengths.
  • B. establish the use of cryptographic solutions.
  • C. describe handling procedures of cryptographic keys.
  • D. define the circumstances where cryptography should be used.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
There should be documented standards-procedures for the use of cryptography across the enterprise; they should define the circumstances where cryptography should be used. They should cover the selection of cryptographic algorithms and key lengths, but not define them precisely, and they should address the handling of cryptographic keys. However, this is secondary to how and when cryptography should be used.
The use of cryptographic solutions should be addressed but, again, this is a secondary consideration.

 

NEW QUESTION 669
Utilizing external resources for highly technical information security tasks allows an information security manager to:

  • A. leverage limited resources,
  • B. transfer business risk,
  • C. distribute technology risk
  • D. outsource responsibility,

Answer: C

 

NEW QUESTION 670
Which of the following is the BEST resource for evaluating the strengths and weaknesses of an incident response plan5

  • A. Mission, goals and objectives
  • B. Documentation from preparedness tests
  • C. Incident response maturity assessment
  • D. Recovery time objectives (RTOs)

Answer: B

 

NEW QUESTION 671
Which of the following tools is MOST appropriate for determining how long a security project will take to implement?

  • A. Waterfall chart
  • B. Critical path
  • C. Gantt chart
  • D. Rapid Application Development (RAD)

Answer: B

Explanation:
The critical path method is most effective for determining how long a project will take. A waterfall chart is used to understand the flow of one process into another. A Gantt chart facilitates the proper estimation and allocation of resources. The Rapid Application Development (RAD) method is used as an aid to facilitate and expedite systems development.

 

NEW QUESTION 672
In an organization, information systems security is the responsibility of:

  • A. all personnel.
  • B. functional personnel.
  • C. information systems security personnel.
  • D. information systems personnel.

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
All personnel of the organization have the responsibility of ensuring information systems security-this can include indirect personnel such as physical security personnel. Information systems security cannot be the responsibility of information systems personnel alone since they cannot ensure security. Information systems security cannot be the responsibility of information systems security personnel alone since they cannot ensure security. Information systems security cannot be the responsibility of functional personnel alone since they cannot ensure security.

 

NEW QUESTION 673
Which of the following situations must be corrected FIRST to ensure successful information security governance within an organization?

  • A. The information security oversight committee only meets quarterly.
  • B. The information security department has difficulty filling vacancies.
  • C. The data center manager has final signoff on all security projects.
  • D. The chief information officer (CIO) approves security policy changes.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A steering committee should be in place to approve all security projects. The fact that the data center manager has final signoff for all security projects indicates that a steering committee is not being used and that information security is relegated to a subordinate place in the organization. This would indicate a failure of information security governance. It is not inappropriate for an oversight or steering committee to meet quarterly. Similarly, it may be desirable to have the chief information officer (CIO) approve the security policy due to the size of the organization and frequency of updates. Difficulty in filling vacancies is not uncommon due to the shortage of good, qualified information security professionals.

 

NEW QUESTION 674
Which of the following would be the BEST metric for the IT risk management process?

  • A. Percentage of unresolved risk exposures
  • B. Percentage of critical assets with budgeted remedial
  • C. Number of security incidents identified
  • D. Number of risk management action plans

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Percentage of unresolved risk exposures and the number of security incidents identified contribute to the IT risk management process, but the percentage of critical assets with budgeted remedial is the most indicative metric. Number of risk management action plans is not useful for assessing the quality of the process.

 

NEW QUESTION 675
Which of the following is the BEST method to ensure that data owners take responsibility for implementing information security processes'

  • A. Include security tasks into employee job descriptions
  • B. Increase security awareness training
  • C. Include membership on project teams
  • D. Provide job rotation into the security organization.

Answer: C

 

NEW QUESTION 676
A company's mail server allows anonymous file transfer protocol (FTP) access which could be exploited.
What process should the information security manager deploy to determine the necessity for remedial action?

  • A. A risk assessment
  • B. A business impact analysis (BIA)
  • C. A security baseline review
  • D. A penetration test

Answer: A

Explanation:
Explanation
A risk assessment will identify- the business impact of such vulnerability being exploited and is, thus, the correct process. A penetration test or a security baseline review may identify the vulnerability but not the remedy. A business impact analysis (BIA) will more likely identify the impact of the loss of the mail server.

 

NEW QUESTION 677
Which of the following would represent a violation of the chain of custody when a backup tape has been identified as evidence in a fraud investigation? The tape was:

  • A. sealed in a signed envelope and locked in a safe under dual control.
  • B. removed into the custody of law enforcement investigators.
  • C. kept in the tape library' pending further analysis.
  • D. handed over to authorized independent investigators.

Answer: C

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Since a number of individuals would have access to the tape library, and could have accessed and tampered with the tape, the chain of custody could not be verified. All other choices provide clear indication of who was in custody of the tape at all times.

 

NEW QUESTION 678
When creating an incident response plan, the PRIMARY benefit of establishing a clear definition of a security incident is that it helps to:

  • A. adequately staff and train incident response teams.
  • B. communicate the incident response process to stakeholders
  • C. develop effective escalation and response procedures.
  • D. make tabletop testing more effective.

Answer: C

 

NEW QUESTION 679
......

Ultimate Guide to Prepare CISM Certification Exam for Isaca Certification: https://www.prepawaypdf.com/ISACA/CISM-practice-exam-dumps.html

CISM Ultimate Study Guide: https://drive.google.com/open?id=1tDYNvNUTiWF33Zaegtc-vQQZnTE76VA3