[Nov 24, 2021] Get New CISM Practice Test Questions Answers [Q745-Q767]

Share

[Nov 24, 2021] Get New CISM Practice Test Questions Answers 

CISM Dumps and Exam Test Engine


4. Information Security Incident Management – 19%

This is the last subject area you need to successfully master to get the CISM certification. Therefore, you should be ready to demonstrate the following knowledge:

  • To detect and analyze information security events, one should have knowledge of technologies.
  • Knowledge of escalation processes;
  • Knowledge of the relationship of business continuity planning and disaster recovery planning to the incident response plan;
  • Knowledge and ability to effectively equip incident response teams through their training and tools;
  • Knowledge of the main components of an incident response plan and the concepts and practices of its management;

 

NEW QUESTION 745
On which of the following should a firewall be placed?

  • A. Web server
  • B. Intrusion detection system (IDS) server
  • C. Domain boundary
  • D. Screened subnet

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
A firewall should be placed on a (security) domain boundary. Placing it on a web server or screened subnet, which is a demilitarized zone (DMZ), does not provide any protection. Since firewalls should be installed on hardened servers with minimal services enabled, it is inappropriate to have the firewall and the intrusion detection system (IDS) on the same physical device.

 

NEW QUESTION 746
Acceptable risk is achieved when:

  • A. residual risk is minimized.
  • B. control risk is minimized.
  • C. transferred risk is minimized.
  • D. inherent risk is minimized.

Answer: A

Explanation:
Residual risk is the risk that remains after putting into place an effective risk management program; therefore, acceptable risk is achieved when this amount is minimized. Transferred risk is risk that has been assumed by a third party and may not necessarily be equal to the minimal form of residual risk. Control risk is the risk that controls may not prevent/detect an incident with a measure of control effectiveness. Inherent risk cannot be minimized.

 

NEW QUESTION 747
Which of the following disaster recovery testing techniques is the MOST cost-effective way to determine the effectiveness of the plan?

  • A. Full operational tests
  • B. Paper tests
  • C. Preparedness tests
  • D. Actual service disruption

Answer: C

Explanation:
Preparedness tests would involve simulation of the entire test in phases and help the team better understand and prepare for the actual test scenario. Options B, C and D are not cost-effective ways to establish plan effectiveness. Paper tests in a walk-through do not include simulation and so there is less learning and it is difficult to obtain evidence that the team has understood the test plan. Option D is not recommended in most cases. Option C would require an approval from management is not easy or practical to test in most scenarios and may itself trigger a disaster.

 

NEW QUESTION 748
Information security governance is PRIMARILY driven by:

  • A. technology constraints.
  • B. litigation potential.
  • C. business strategy.
  • D. regulatory requirements.

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation/Reference:
Explanation:
Governance is directly tied to the strategy and direction of the business. Technology constraints, regulatory requirements and litigation potential are all important factors, but they are necessarily in line with the business strategy.

 

NEW QUESTION 749
The use of a business case to obtain funding for an information security investment is MOST effective when the business case:

  • A. realigns information security objectives to organizational strategy.
  • B. relates the investment to the organization's strategic plan.
  • C. articulates management's intent and information security directives in clear language.
  • D. relates information security policies and standards into business requirements

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 750
In designing a backup strategy that will be consistent with a disaster recovery strategy, the PRIMARY factor to be taken into account will be the:

  • A. interruption window.
  • B. recovery point objective (RPO).
  • C. volume of sensitive data.
  • D. recovery' time objective (RTO).

Answer: B

Explanation:
Explanation
The recovery point objective (RPO) defines the maximum loss of data (in terms of time) acceptable by the business (i.e., age of data to be restored). It will directly determine the basic elements of the backup strategy frequency of the backups and what kind of backup is the most appropriate (disk-to-disk, on tape, mirroring).
The volume of data will be used to determine the capacity of the backup solution. The recovery time objective (RTO) - the time between disaster and return to normal operation - will not have any impact on the backup strategy. The availability to restore backups in a time frame consistent with the interruption window will have to be checked and will influence the strategy (e.g., full backup vs. incremental), but this will not be the primary factor.

 

NEW QUESTION 751
Which of the following is the BEST resource for evaluating the strengths and weaknesses of an incident response plan5

  • A. Incident response maturity assessment
  • B. Documentation from preparedness tests
  • C. Mission, goals and objectives
  • D. Recovery time objectives (RTOs)

Answer: B

 

NEW QUESTION 752
Which of the following is the MOST important process that an information security manager needs to negotiate with an outsource service provider?

  • A. Encryption between the organization and the provider
  • B. A joint risk assessment of the system
  • C. The right to conduct independent security reviews
  • D. A legally binding data protection agreement

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A key requirement of an outsource contract involving critical business systems is the establishment of the organization's right to conduct independent security reviews of the provider's security controls. A legally binding data protection agreement is also critical, but secondary to choice A, which permits examination of the actual security controls prevailing over the system and. as such, is the more effective risk management tool. Network encryption of the link between the organization and the provider may well be a requirement, but is not as critical since it would also be included in choice A.
A joint risk assessment of the system in conjunction with the outsource provider may be a compromise solution, should the right to conduct independent security reviews of the controls related to the system prove contractually difficult.

 

NEW QUESTION 753
Which of the following should provide the PRIMARY justification to approve the implementation of a disaster recovery (DR) site on the recommendation of an external audit report?

  • A. Cost-benefit analysis
  • B. Security controls at the DR site
  • C. Recovery time objectives (RTOs)
  • D. Regulatory requirements

Answer: D

 

NEW QUESTION 754
Which of the following should be an information security manager s MOST important consideration when conducting a physical security review of a potential outsourced data center?

  • A. Proximity to law enforcement
  • B. Availability of network circuit connections
  • C. Environmental factors of the surrounding location
  • D. Distance of the data center from the corporate office

Answer: D

 

NEW QUESTION 755
Investments in information security technologies should be based on:

  • A. business climate.
  • B. value analysis.
  • C. vulnerability assessments.
  • D. audit recommendations.

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Investments in security technologies should be based on a value analysis and a sound business case.
Demonstrated value takes precedence over the current business climate because it is ever changing. Basing decisions on audit recommendations would be reactive in nature and might not address the key business needs comprehensively. Vulnerability assessments are useful, but they do not determine whether the cost is justified.

 

NEW QUESTION 756
Which of the following should be the PRIMARY consideration for an information security manager when designing security controls for a newly acquired business application?

  • A. Business processes supported by the application
  • B. Cost-benefit analysis of current controls
  • C. The IT security architecture framework
  • D. Known vulnerabilities in the application

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT

 

NEW QUESTION 757
Which of the following would BEST assist an information security manager in measuring the existing level of development of security processes against their desired state?

  • A. Balanced scorecard
  • B. Security audit reports
  • C. Capability maturity model (CMM)
  • D. Systems and business security architecture

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The capability maturity model (CMM) grades each defined area of security processes on a scale of 0 to 5 based on their maturity, and is commonly used by entities to measure their existing state and then determine the desired one. Security audit reports offer a limited view of the current state of security.
Balanced scorecard is a document that enables management to measure the implementation of their strategy and assists in its translation into action. Systems and business security architecture explain the security architecture of an entity in terms of business strategy, objectives, relationships, risks, constraints and enablers, and provides a business-driven and business-focused view of security architecture.

 

NEW QUESTION 758
Which of the following is the BEST strategy to implement an effective operational security posture?

  • A. Vulnerability management
  • B. Defense in depth
  • C. Increased security awareness
  • D. Threat management

Answer: C

 

NEW QUESTION 759
An information security manager has been assigned to implement more restrictive preventive controls. By doing so, the net effect will be to PRIMARILY reduce the:

  • A. vulnerability.
  • B. loss.
  • C. threat.
  • D. probability.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Implementing more restrictive preventive controls mitigates vulnerabilities but not the threats. Losses and probability of occurrence may not be primarily or directly affected.

 

NEW QUESTION 760
When establishing escalation processes for an organization's computer security incident response team, the organization's procedures should:

  • A. require events to be escalated whenever possible to ensure that management is kept informed.
  • B. provide unrestricted communication channels to executive leadership to ensure direct access.
  • C. specify step-by-step escalation paths to ensure an appropriate chain of command.
  • D. recommend the same communication path for events to ensure consistency of

Answer: B

 

NEW QUESTION 761
An organization has a policy in which all criminal activity is prosecuted. What is MOST important for the information security manager to ensure when an employee is suspected of using a company computer to commit fraud?

  • A. Senior management is informed of the situation
  • B. The employee's log files are backed-up
  • C. The forensics process is immediately initiated
  • D. The incident response plan is initiated

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 762
Which of the following is MOST important to the successful promotion of good security management practices?

  • A. Security baselines
  • B. Periodic training
  • C. Management support
  • D. Security metrics

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Without management support, all other efforts will be undermined. Metrics, baselines and training are all important, but they depend on management support for their success.

 

NEW QUESTION 763
Minimum standards for securing the technical infrastructure should be defined in a security:

  • A. model.
  • B. architecture.
  • C. guidelines.
  • D. strategy.

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Minimum standards for securing the technical infrastructure should be defined in a security architecture document. This document defines how components are secured and the security services that should be in place. A strategy is a broad, high-level document. A guideline is advisory in nature, while a security model shows the relationships between components.

 

NEW QUESTION 764
The root cause of a successful cross site request forgery (XSRF) attack against an application is that the vulnerable application:

  • A. is hosted on a server along with other applications.
  • B. uses multiple redirects for completing a data commit transaction.
  • C. has been installed with a non-legitimate license key.
  • D. has implemented cookies as the sole authentication mechanism.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
XSRF exploits inadequate authentication mechanisms in web applications that rely only on elements such as cookies when performing a transaction. XSRF is related to an authentication mechanism, not to redirection.
Option C is related to intellectual property rights, not to XSRF vulnerability. Merely hosting multiple applications on the same server is not the root cause of this vulnerability.

 

NEW QUESTION 765
Which of the following architectures for e-business BEST ensures high availability?

  • A. A single point of entry allowing transactions to be received and processed quickly
  • B. Automatic failover to the web site of another e-business that meets the user's needs
  • C. Intelligent middleware to direct transactions from a downed system to an alternative
  • D. Availability of an adjacent hot site and a standby server with mirrored copies of critical data

Answer: B

 

NEW QUESTION 766
A company is considering a new automated system that requires implementation of wireless devices for data capture. Even though wireless is not an approved technology, senior management has accepted the risk and approved a Proof-of-Concept (POC) to evaluate the technology and proposed solution. Which of the following is the information security manager's BEST course of action?

  • A. Sandbox the proposed solution.
  • B. Provide personnel with wireless security training.
  • C. Implement a wireless intrusion detection system (IDS).
  • D. Develop corporate wireless standards.

Answer: D

 

NEW QUESTION 767
......

2021 New PrepAwayPDF CISM PDF Recently Updated Questions: https://www.prepawaypdf.com/ISACA/CISM-practice-exam-dumps.html

ISACA CISM DUMPS WITH REAL EXAM QUESTIONS: https://drive.google.com/open?id=1S5CVF2yEEdhRWt1U9WHK91EE34GY-r1U