
[Oct 09, 2021] CISM Dumps Full Questions - Exam Study Guide
Isaca Certification Free Certification Exam Material from PrepAwayPDF with 1340 Questions
NEW QUESTION 592
When developing a security architecture, which of the following steps should be executed FIRST?
- A. Defining roles and responsibilities
- B. Specifying an access control methodology
- C. Developing security procedures
- D. Defining a security policy
Answer: D
Explanation:
Explanation
Defining a security policy for information and related technology is the first step toward building a security architecture. A security policy communicates a coherent security standard to users, management and technical staff. Security policies will often set the stage in terms of what tools and procedures are needed for an organization. The other choices should be executed only after defining a security policy.
NEW QUESTION 593
A business impact analysis should be periodically executed
- A. analyze the importance of assets.
- B. validate vulnerabilities on environmental changes.
- C. check compliance with regulations.
- D. verify the effectiveness of controls.
Answer: B
NEW QUESTION 594
When preparing a strategy for protection from SQL injection attacks, it is MOST important for the information security manager to involve:
- A. business owners.
- B. the security operations center.
- C. senior management
- D. application developers.
Answer: C
Explanation:
Section: MIXED QUESTIONS
NEW QUESTION 595
When a user employs a client-side digital certificate to authenticate to a web server through Secure Socket Layer (SSI.), confidentiality is MOST vulnerable to which of the following?
- A. Trojan
- B. Repudiation
- C. IP spoofing
- D. Man-in-the-middle attack
Answer: A
Explanation:
A Trojan is a program that gives the attacker full control over the infected computer, thus allowing the attacker to hijack, copy or alter information after authentication by the user. IP spoofing will not work because IP is not used as an authentication mechanism. Man-in-the-middle attacks are not possible if using SSL with client-side certificates. Repudiation is unlikely because client-side certificates authenticate the user.
NEW QUESTION 596
Which of the following methods is the BEST way to demonstrate that an information security program provides appropriate coverage?
- A. Gap assessment
- B. Maturity assessment
- C. Security risk analysis
- D. Vulnerability scan report
Answer: A
NEW QUESTION 597
When developing a new system, detailed information security functionality should FIRST be addressed:
- A. during the system design phase.
- B. as part of application development.
- C. as part of prototyping.
- D. when system requirements are defined.
Answer: A
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION 598
Which of the following is the BEST way to determine if an information security program aligns with corporate governance?
- A. Review information security policies
- B. Review the balanced scorecard
- C. Survey end users about corporate governance
- D. Evaluate funding for security initiatives
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation
One of the most important aspects of the action plan to execute the strategy is to create or modify, as needed, policies and standards. Policies are one of the primary elements of governance and each policy should state only one general security mandate. The road map should show the steps and the sequence, dependencies, and milestones.
NEW QUESTION 599
When outsourcing data to a cloud service provider, which of the following should be the information security manager's MOST important consideration?
- A. Cloud servers are located in the same country as the organization.
- B. Data stored at the cloud service provider is not co-mingled.
- C. Access authorization includes biometric security verification.
- D. Roles and responsibilities have been defined for the subscriber organization.
Answer: B
NEW QUESTION 600
The MOST important reason for formally documenting security procedures is to ensure:
- A. objective criteria for the application of metrics.
- B. alignment with business objectives.
- C. auditability by regulatory agencies.
- D. processes are repeatable and sustainable.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Without formal documentation, it would be difficult to ensure that security processes are performed in the proper manner every time that they are performed. Alignment with business objectives is not a function of formally documenting security procedures. Processes should not be formally documented merely to satisfy an audit requirement. Although potentially useful in the development of metrics, creating formal documentation to assist in the creation of metrics is a secondary objective.
NEW QUESTION 601
A risk analysis for a new system is being performed. For which of the following is business knowledge MORE important than IT knowledge?
- A. Balanced scorecard
- B. Vulnerability analysis
- C. Cost-benefit analysis
- D. Impact analysis
Answer: D
NEW QUESTION 602
When a user employs a client-side digital certificate to authenticate to a web server through Secure Socket Layer (SSL), confidentiality is MOST vulnerable to which of the following?
- A. Trojan
- B. Repudiation
- C. IP spoofing
- D. Man-in-the-middle attack
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:
Explanation:
A Trojan is a program that gives the attacker full control over the infected computer, thus allowing the attacker to hijack, copy or alter information after authentication by the user. IP spoofing will not work because IP is not used as an authentication mechanism. Man-in-the-middle attacks are not possible if using SSL with client-side certificates. Repudiation is unlikely because client-side certificates authenticate the user.
NEW QUESTION 603
Which of the following is the MOST important consideration when updating procedures for managing security devices?
- A. Notification to management of the procedural changes
- B. Updates based on the organization's security framework
- C. Updates based on changes in risk, technology, and process
- D. Review and approval of procedures by management
Answer: B
NEW QUESTION 604
An organization utilizes a third party to classify its customers' personally identifiable information (PII). What is the BEST way to hold the third party accountable for data leaks?
- A. Submit a formal request for proposal (RFP) containing detailed documentation of requirements.
- B. Include detailed documentation requirements within the formal statement of work.
- C. Ensure a nondisclosure agreement is signed by both parties' senior management.
- D. Require the service provider to sign off on the organization's acceptable use policy.
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION 605
Which of the following should be the FIRST course of action when it becomes apparent that the recovery time objective (RTO) will not be met during incident response
- A. Escalate the emergency status rating.
- B. Request additional financial recovery resources.
- C. Notify the risk management team.
Answer: C
Explanation:
D Modify the RTO as needed
NEW QUESTION 606
An organization implemented a mandatory information security awareness training program a year ago. What is the BEST way to determine its effectiveness?
- A. Analyze results of a social engineering test
- B. Analyze findings from previous audit reports
- C. Analyze responses from an employee survey of training satisfaction
- D. Analyze results from training completion reports
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference:
NEW QUESTION 607
In addition to backup data, which of the following is the MOST important to store offsite in the event of a disaster?
- A. List of emergency numbers of service providers
- B. Copies of the business continuity plan
- C. Key software escrow agreements for the purchased systems
- D. Copies of critical contracts and service level agreements (SLAs)
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Without a copy of the business continuity plan, recovery efforts would be severely hampered or may not be effective. All other choices would not be as immediately critical as the business continuity plan itself. The business continuity plan would contain a list of the emergency numbers of service providers.
NEW QUESTION 608
......
Dumps Brief Outline Of The CISM Exam: https://www.prepawaypdf.com/ISACA/CISM-practice-exam-dumps.html
Use Real CISM - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1oqN6Sv5hIRBtlkGrnop4A94wzA63jdvy