
CISM exam questions for practice in 2022 Updated 395 Questions
Updated Nov-2022 Premium CISM Exam Engine pdf - Download Free Updated 395 Questions
Career Growth
After getting the CISM certificate, one can become an Information System Security Officer, an Information Risk Consultant, or an Information Security Manager. Furthermore, there are different levels starting from the Entry one, which involves a System Analyst, Security Auditor Trainee, etc. Besides that, you can become a Technical Specialist, a Technical Manager, or go for the expert-level positions, which include a Senior IT Systems Professional, a Senior IT Architect, a Development Engineer, etc. Obtaining this ISACA certification can also cause a huge salary bump of around $128,000 per year, but your salary may vary according to the job title you choose.
NEW QUESTION 83
Which of the following is MOST helpful in securing funding for a commercial vulnerability assessment tool?
- A. Explaining the business value of vulnerability remediation
- B. Developing security metrics linked to business objectives
- C. Presenting a vulnerability scan report for current business systems
- D. Identifying applicable legal and regulatory requirements
Answer: A
NEW QUESTION 84
Which of the following should be an information security manager's PRIMARY consideration when developing an incident response plan?
- A. Skills and competencies of the help desk
- B. The organization's external communications plan
- C. The organization's risk tolerance and appetite
- D. Incident response plan testing methods and frequency
Answer: D
NEW QUESTION 85
Documented standards/procedures for the use of cryptography across the enterprise should PRIMARILY:
- A. describe handling procedures of cryptographic keys.
- B. establish the use of cryptographic solutions.
- C. define cryp, Graphic algorithms and key lengths.
- D. define the circumstances where cryptography should be used.
Answer: D
Explanation:
There should be documented standards- procedures for the use of cryptography across the enterprise; they should define the circumstances where cryptography should be used. They should cover the selection of cryptographic algorithms and key lengths, but not define them precisely, and they should address the handling of cryptographic keys. However, this is secondary to how and when cryptography should be used. The use of cryptographic solutions should be addressed but, again, this is a secondary consideration.
NEW QUESTION 86
Which of the following is the MOST important reason why information security objectives should be defined?
- A. General understanding of goals
- B. Tool for measuring effectiveness
- C. Consistency with applicable standards
- D. Management sign-off and support initiatives
Answer: B
Explanation:
Explanation
The creation of objectives can be used in part as a source of measurement of the effectiveness of information security management, which feeds into the overall governance. General understanding of goals and consistency with applicable standards are useful, but are not the primary reasons for having clearly defined objectives. Gaining management understanding is important, but by itself will not provide the structure for governance.
NEW QUESTION 87
Which of the following stakeholders would provide the BEST guidance in aligning the information security strategy with organizational goals?
- A. information security steering committee
- B. Board of directors
- C. Chief information security officer (CISO)
- D. Chief information officer (CIO)
Answer: D
NEW QUESTION 88
Which of the following is an indicator of improvement in the ability to identify security risks?
- A. Decreased number of information security risk assessments
- B. Increased number of reported security incidents
- C. Decreased number of staff requiring information security training
- D. Increased number of security audit issues resolved
Answer: B
NEW QUESTION 89
Which of the following controls would BEST prevent accidental system shutdown from the console or operations area?
- A. Redundant power supplies
- B. Biometric readers
- C. Protective switch covers
- D. Shutdown alarms
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Protective switch covers would reduce the possibility of an individual accidentally pressing the power button on a device, thereby turning off the device. Redundant power supplies would not prevent an individual from powering down a device. Shutdown alarms would be after the fact. Biometric readers would be used to control access to the systems.
NEW QUESTION 90
Evidence from a compromised server has to be acquired for a forensic investigation. What would be the BEST source?
- A. Backup servers
- B. The last verified backup stored offsite
- C. Data from volatile memory
- D. A bit-level copy of all hard drive data
Answer: D
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
The bit-level copy image file ensures forensic quality evidence that is admissible in a court of law. Choices B and D may not provide forensic quality data for investigative work, while choice C alone may not provide enough evidence.
NEW QUESTION 91
Which of the following would be a MAJOR consideration for an organization defining its business continuity plan (BCP) or disaster recovery program (DRP)?
- A. Data backup frequency
- B. Aligning with recovery time objectives (RTOs)
- C. Maintaining redundant systems
- D. Setting up a backup site
Answer: B
Explanation:
BCP.'DRP should align with business RTOs. The RTO represents the amount of time allowed for the recovery of a business function or resource after a disaster occurs. The RTO must be taken into consideration when prioritizing systems for recovery efforts to ensure that those systems that the business requires first are the ones that are recovered first.
NEW QUESTION 92
An information security program should be sponsored by:
- A. the corporate audit department.
- B. key business process owners.
- C. information security management.
- D. infrastructure management.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The information security program should ideally be sponsored by business managers, as represented by key business process owners. Infrastructure management is not sufficiently independent and lacks the necessary knowledge regarding specific business requirements. A corporate audit department is not in as good a position to fully understand how an information security program needs to meet the needs of the business. Audit independence and objectivity will be lost, impeding traditional audit functions. Information security implements and executes the program. Although it should promote it at all levels, it cannot sponsor the effort due to insufficient operational knowledge and lack of proper authority.
NEW QUESTION 93
A new version of an information security regulation is published that requires an organization's compliance.
The information security manager should FIRST:
- A. perform a gap analysis against the new regulation.
- B. conduct a risk assessment to determine the risk of noncompliance.
- C. perform an audit based on the new version of the regulation.
- D. conduct benchmarking against similar organizations.
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION 94
Which of the following MOST commonly falls within the scope of an information security governance steering committee?
- A. Developing content for security awareness programs
- B. Interviewing candidates for information security specialist positions
- C. Approving access to critical financial systems
- D. Prioritizing information security initiatives
Answer: D
Explanation:
Explanation
Prioritizing information security initiatives is the only appropriate item. The interviewing of specialists should be performed by the information security manager, while the developing of program content should be performed by the information security staff. Approving access to critical financial systems is the responsibility of individual system data owners.
NEW QUESTION 95
The MOST important characteristic of good security policies is that they:
- A. are aligned with organizational goals.
- B. state expectations of IT management.
- C. state only one general security mandate.
- D. govern the creation of procedures and guidelines.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The most important characteristic of good security policies is that they be aligned with organizational goals.
Failure to align policies and goals significantly reduces the value provided by the policies. Stating expectations of IT management omits addressing overall organizational goals and objectives. Stating only one general security mandate is the next best option since policies should be clear; otherwise, policies may be confusing and difficult to understand. Governing the creation of procedures and guidelines is most relevant to information security standards.
NEW QUESTION 96
Which of the following would BEST enable effective decision-making?
- A. Formalized acceptance of risk analysis by business management
- B. A universally applied list of generic threats, impacts, and vulnerabilities
- C. A consistent process to analyze new and historical information risk
- D. Annualized loss estimates determined from past security events
Answer: C
NEW QUESTION 97
Which of the following would be of GREATEST importance to the security manager in determining whether to accept residual risk?
- A. Historical cost of the asset
- B. Annualized loss expectancy (ALE)
- C. Acceptable level of potential business impacts
- D. Cost versus benefit of additional mitigating controls
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The security manager would be most concerned with whether residual risk would be reduced by a greater amount than the cost of adding additional controls. The other choices, although relevant, would not be as important.
NEW QUESTION 98
Which of the following is MOST critical for an effective information security governance framework?
- A. The CIO is accountable for the information security program.
- B. Information security policies are reviewed on a regular basis.
- C. The information security program is continually monitored.
- D. Board members are committed to the information security program.
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION 99
In performing a risk assessment on the impact of losing a server, the value of the server should be calculated using the:
- A. original cost to acquire.
- B. cost of the software stored.
- C. annualized loss expectancy (ALE).
- D. cost to obtain a replacement.
Answer: D
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
The value of the server should be based on its cost of replacement. The original cost may be significantly different from the current cost and, therefore, not as relevant. The value of the software is not at issue because it can be restored from backup media. The ALE for all risks related to the server does not represent the server's value.
NEW QUESTION 100
Which of the following is the MOST important reason for logging firewall activity?
- A. Auditing purposes
- B. Intrusion detection
- C. Incident investigation
- D. Firewall tuning
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION 101
What is the PRIMARY objective of performing a vulnerability assessment following a business system update?
- A. Review the effectiveness of controls
- B. Improve the change control process
- C. Determine operational losses
- D. Update the threat landscape
Answer: A
NEW QUESTION 102
Which of the following is the BEST mechanism to prevent data loss in the event personal computing equipment is stolen or lost?
- A. Personal firewall
- B. Remote access to device
- C. Data encryption
- D. Data leakage prevention (DLP)
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 103
In the course of responding 10 an information security incident, the BEST way to treat evidence for possible legal action is defined by:
- A. generally accepted best practices.
- B. local regulations.
- C. organizational security policies.
- D. international standards.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Legal follow-up will most likely be performed locally where the incident took place; therefore, it is critical that the procedure of treating evidence is in compliance with local regulations. In certain countries, there are strict regulations on what information can be collected. When evidence collected is not in compliance with local regulations, it may not be admissible in court. There are no common regulations to treat computer evidence that are accepted internationally. Generally accepted best practices such as a common chain-of-custody concept may have different implementation in different countries, and thus may not be a good assurance that evidence will be admissible. Local regulations always take precedence over organizational security policies.
NEW QUESTION 104
Which of the following is the MOST appropriate method for deploying operating system (OS) patches to production application servers?
- A. Initially load the patches on a test machine
- B. Batch patches into frequent server updates
- C. Set up servers to automatically download patches
- D. Automatically push all patches to the servers
Answer: A
Explanation:
Explanation
Some patches can conflict with application code. For this reason, it is very important to first test all patches in a test environment to ensure that there are no conflicts with existing application systems. For this reason, choices C and D are incorrect as they advocate automatic updating. As for frequent server updates, this is an incomplete (vague) answer from the choices given.
NEW QUESTION 105
The MOST useful way to describe the objectives in the information security strategy is through:
- A. attributes and characteristics of the 'desired state."
- B. mapping the IT systems to key business processes.
- C. calculation of annual loss expectations.
- D. overall control objectives of the security program.
Answer: A
Explanation:
Explanation
Security strategy will typically cover a wide variety of issues, processes, technologies and outcomes that can best be described by a set of characteristics and attributes that are desired. Control objectives are developed after strategy and policy development. Mapping IT systems to key business processes does not address strategy issues. Calculation of annual loss expectations would not describe the objectives in the information security strategy.
NEW QUESTION 106
Which of the following presents the GREATEST threat to the security of an enterprise resource planning (ERP) system?
- A. User ad hoc reporting is not logged
- B. Network traffic is through a single switch
- C. Operating system (OS) security patches have not been applied
- D. Database security defaults to ERP settings
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The fact that operating system (OS) security patches have not been applied is a serious weakness. Routing network traffic through a single switch is not unusual. Although the lack of logging for user ad hoc reporting is not necessarily good, it does not represent as serious a security-weakness as the failure to install security patches. Database security defaulting to the ERP system's settings is not as significant.
NEW QUESTION 107
......
What Is CISM Certification All About?
Earning CISM, or Certified Information Security Manager, is a credible way to prove your capacity to handle various security programs. Through your expertise, this helps in building a strategic team that complies with the standards set by the company. And as a result of your management, this boosts business productivity for better outcomes and product retention. Furthermore, the certification allows you to transition into a coveted individual in the enterprise leadership scope.
Authentic CISM Dumps With 100% Passing Rate Practice Tests Dumps: https://torrentpdf.vceengine.com/CISM-vce-test-engine.html
