[Sep-2022] Feel ISACA CISM Dumps PDF Will likely be The best Option [Q235-Q254]

Share

[Sep-2022] Feel ISACA CISM Dumps PDF Will likely be The best Option

CISM exam torrent ISACA study guide

NEW QUESTION 235
Which of the following is the BEST indicator that an organization is appropriately managing risk?

  • A. The number of events reported from the intrusion detection system (IDS) has declined.
  • B. Risk assessment results are within tolerance
  • C. A penetration test does not identify any high-risk system vulnerabilities
  • D. The number of security incident events reported by staff has increased

Answer: B

 

NEW QUESTION 236
Which of the following is the BEST indicator of a successful external intrusion into computer systems?

  • A. Decrease in the number of login failures.
  • B. Unexpected increase of malformed URLs.
  • C. Spikes in the number of login failures.
  • D. Unexpected use of protocols within the DMZ.

Answer: D

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 237
When developing a tabletop test plan for incident response testing, the PRIMARY purpose of the scenario should be to:

  • A. challenge the incident response team to solve the problem under pressure
  • B. give the business a measure of the organization's overall readiness
  • C. measure management engagement as part of an incident response team
  • D. provide participants with situations to ensure understanding of their roles

Answer: C

Explanation:
Explanation
Explanations
Tabletop scenarios that need to be completed with one hour per scenario using full escalation as per decision trees to accurately simulate and evaluate responses of each team member and the processes within the playbooks.

 

NEW QUESTION 238
Data owners are normally responsible for which of the following?

  • A. Administering security over database records
  • B. Determining the level of application security required
  • C. Migrating application code changes to production
  • D. Applying emergency changes to application data

Answer: B

Explanation:
Data owners approve access to data and determine the degree of protection that should be applied (data classification). Administering database security, making emergency changes to data and migrating code to production are infrastructure tasks performed by custodians of the data.

 

NEW QUESTION 239
Which of the following should be the PRIMARY consideration when developing a security governance framework for an enterprise?

  • A. Benchmarking against industry best practice
  • B. Assessment of the current security architecture
  • C. Understanding of the current business strategy
  • D. Results of a business impact analysis (BIA)

Answer: C

 

NEW QUESTION 240
Which of the following security activities should be implemented in the change management process to identify key vulnerabilities introduced by changes?

  • A. Audit and review
  • B. Business impact analysis (BIA)
  • C. Penetration testing
  • D. Threat analysis

Answer: C

Explanation:
Penetration testing focuses on identifying vulnerabilities. None of the other choices would identify vulnerabilities introduced by changes.

 

NEW QUESTION 241
Which of the following metrics is the BEST indicator of an abuse of the change management process that could compromise information security?

  • A. Small number of change request
  • B. High ratio of lines of code changed to total lines of code
  • C. Large percentage decrease in monthly change requests
  • D. Percentage of changes that include post-approval supplemental add-ons

Answer: C

 

NEW QUESTION 242
When performing a quantitative risk analysis, which of the following is MOST important to estimate the potential loss?

  • A. Evaluate productivity losses
  • B. Assess the impact of confidential data disclosure
  • C. Measure the probability of occurrence of each threat
  • D. Calculate the value of the information or asset

Answer: D

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Calculating the value of the information or asset is the first step in a risk analysis process to determine the impact to the organization, which is the ultimate goal. Determining how much productivity could be lost and how much it would cost is a step in the estimation of potential risk process. Knowing the impact if confidential information is disclosed is also a step in the estimation of potential risk. Measuring the probability of occurrence for each threat identified is a step in performing a threat analysis and therefore a partial answer.

 

NEW QUESTION 243
An email digital signature will:

  • A. automatically correct unauthorized modification of an email message.
  • B. protect the confidentiality of an email message.
  • C. verify to recipients the integrity of an email message.
  • D. prevent unauthorized modification of an email message.

Answer: D

 

NEW QUESTION 244
Business units within an organization are resistant to proposed changes to the information security program. Which of the following is the BEST way to address this issue?

  • A. Communicating critical risk assessment results to business unit managers
  • B. Including business unit representation on the security steering committee
  • C. Implementing additional security awareness training
  • D. Publishing updated information security policies

Answer: A

 

NEW QUESTION 245
What should be the PRIMARY basis for establishing a recovery time objective (RTO) for a critical business application?

  • A. Business impact analysis (BIA) results
  • B. Legal and regulatory requirements
  • C. Risk assessment results
  • D. Related business benchmarks

Answer: C

 

NEW QUESTION 246
A border router should be placed on which of the following?

  • A. Domain boundary
  • B. IDS server
  • C. Web server
  • D. Screened subnet

Answer: A

Explanation:
Explanation
A border router should be placed on a (security) domain boundary. Placing it on a web server or screened subnet, which is a demilitarized zone (DMZ) would not provide any protection. Border routers are positioned on the boundary of the network, but do not reside on a server.

 

NEW QUESTION 247
Shortly after installation, an intrusion detection system (IDS) reports a violation. Which of the following is the MOST likely explanation?

  • A. A routine IDS log file upload has occurred,
  • B. The violation is a false positive.
  • C. A routine IDS signature file download has occurred.
  • D. An intrusion has occurred-

Answer: D

 

NEW QUESTION 248
Which of the following is the BEST approach for an information security manager to effectively manage third-party risk?

  • A. Ensure risk management efforts are commensurate with risk exposure.
  • B. Ensure vendor governance controls are in place.
  • C. Ensure senior management has approved the vendor relationship.
  • D. Ensure controls are implemented to address changes in risk.

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 249
A risk profile supports effective security decisions PRIMARILY because it:

  • A. describes security threats.
  • B. identifies priorities for risk reduction.
  • C. defines how to best mitigate future risks.
  • D. enables comparison with industry best practices.

Answer: B

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 250
Which of the following should be the PRIMARY goal of an information security manager when designing information security policies?

  • A. Improving the protection of information
  • B. Achieving organizational objectives
  • C. Reducing organizational security risk
  • D. Minimizing the cost of security controls

Answer: B

 

NEW QUESTION 251
Which of the following environments represents the GREATEST risk to organizational security?

  • A. Centrally managed data switch
  • B. Locally managed file server
  • C. Load-balanced, web server cluster
  • D. Enterprise data warehouse

Answer: B

Explanation:
A locally managed file server will be the least likely to conform to organizational security policies because it is generally subject to less oversight and monitoring. Centrally managed data switches, web server clusters and data warehouses are subject to close scrutiny, good change control practices and monitoring.

 

NEW QUESTION 252
The PRIORITY action to be taken when a server is infected with a virus is to:

  • A. isolate the infected server(s) from the network.
  • B. ensure that the virus database files are current.
  • C. identify all potential damage caused by the infection.
  • D. establish security weaknesses in the firewall.

Answer: A

Explanation:
The priority in this event is to minimize the effect of the virus infection and to prevent it from spreading by removing the infected server(s) from the network. After the network is secured from further infection, the damage assessment can be performed, the virus database updated and any weaknesses sought.

 

NEW QUESTION 253
Which of the following is MOST critical for the successful implementation and maintenance of a security policy?

  • A. Enforcement of security rules by providing punitive actions for any violation of security rules
  • B. Stringent implementation, monitoring and enforcing of rules by the security officer through access control software
  • C. Assimilation of the framework and intent of a written security policy by all appropriate parties
  • D. Management support and approval for the implementation and maintenance of a security policy

Answer: C

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation
Explanation:
Assimilation of the framework and intent of a written security policy by the users of the system is critical to the successful implementation and maintenance of the security policy. A good password system may exist, but if the users of the system keep passwords written on their desk, the password is of little value. Management support and commitment is no doubt important, but for successful implementation and maintenance of security policy, educating the users on the importance of security is paramount. The stringent implementation, monitoring and enforcing of rules by the security officer through access control software, and provision for punitive actions for violation of security rules, is also required, along with the user's education on the importance of security.

 

NEW QUESTION 254
......

Use Valid New CISM Test Notes & CISM Valid Exam Guide: https://www.dumpsactual.com/CISM-actualtests-dumps.html

CISM Actual Questions Answers PDF 100% Cover Real Exam Questions: https://drive.google.com/open?id=1G2oOjMEiws4vxeQBzmCtSeIVGCTUPFfy