[2022] Pass CISM Exam - Real Questions & Answers [Q117-Q137]

Share

[2022] Pass CISM Exam - Real Questions and Answers

CISM Exam Questions Get Updated [2022] with Correct Answers


As for the tasks that you should be able to perform, they include the following:

  • Effectively manage risks and determine whether information security controls are appropriate or not;
  • Determine the risk factors to ensure proper management;
  • To enable a consistent and precise information risk management program, it should be integrated into the business and IT processes.

What Is CISM Certification All About?

Earning CISM, or Certified Information Security Manager, is a credible way to prove your capacity to handle various security programs. Through your expertise, this helps in building a strategic team that complies with the standards set by the company. And as a result of your management, this boosts business productivity for better outcomes and product retention. Furthermore, the certification allows you to transition into a coveted individual in the enterprise leadership scope.


The benefit in Obtaining the CISM Exam Certification

  • CISM can likewise offer a profession jump as an advancement by separating candidates from different people who are not CISM confirmed
  • Allows candidate capability in IS audit, control and security profession.
  • Candidates with this certification for the best part they earn 47.54% higher pay.
  • CISM supports candidate knowledge and experience in the assigned region and shows their capacity for responding to any challenge.
  • A internationally accepted as the characteristic of excellence for the IS audit professional.

 

NEW QUESTION 117
When security policies are strictly enforced, the initial impact is that:

  • A. they may have to be modified more frequently.
  • B. the total cost of security is increased.
  • C. they will be less subject to challenge.
  • D. the need for compliance reviews is decreased.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
When security policies are strictly enforced, more resources are initially required, thereby increasing, the total cost of security. There would be less need for frequent modification. Challenges would be rare and the need for compliance reviews would not necessarily be less.

 

NEW QUESTION 118
Which of the following ensures that newly identified security weaknesses in an operating system are mitigated in a timely fashion?

  • A. Patch management
  • B. Acquisition management
  • C. Change management
  • D. Security baselines

Answer: A

Explanation:
Patch management involves the correction of software weaknesses and helps ensure that newly identified exploits are mitigated in a timely fashion. Change management controls the process of introducing changes to systems. Security baselines provide minimum recommended settings. Acquisition management controls the purchasing process.

 

NEW QUESTION 119
Which of the following is the MOST important consideration when implementing an intrusion detection system (IDS)?

  • A. Encryption
  • B. Packet filtering
  • C. Patching
  • D. Tuning

Answer: D

Explanation:
If an intrusion detection system (IDS) is not properly tuned it will generate an unacceptable number of false positives and/or fail to sound an alarm when an actual attack is underway. Patching is more related to operating system hardening, while encryption and packet filtering would not be as relevant.

 

NEW QUESTION 120
Which of the following individuals would be in the BEST position to sponsor the creation of an information security steering group?

  • A. Legal counsel
  • B. Information security manager
  • C. Internal auditor
  • D. Chief operating officer (COO)

Answer: D

Explanation:
Explanation
The chief operating officer (COO) is highly-placed within an organization and has the most knowledge of business operations and objectives. The chief internal auditor and chief legal counsel are appropriate members of such a steering group. However, sponsoring the creation of the steering committee should be initiated by someone versed in the strategy and direction of the business. Since a security manager is looking to this group for direction, they are not in the best position to oversee formation of this group.

 

NEW QUESTION 121
Which of the following is the MOST important outcome of senior management's analysis of information security metrics?

  • A. The alignment of the information security budget to corporate funding
  • B. The alignment of security and IT objectives
  • C. The establishment of a risk acceptance process
  • D. The integration of information security with corporate governance

Answer: B

 

NEW QUESTION 122
The BEST strategy for risk management is to:

  • A. reduce risk to an acceptable level.
  • B. ensure that all unmitigated risks are accepted by management.
  • C. achieve a balance between risk and organizational goals.
  • D. ensure that policy development properly considers organizational risks.

Answer: A

Explanation:
The best strategy for risk management is to reduce risk to an acceptable level, as this will take into account the organization's appetite for risk and the fact that it would not be practical to eliminate all risk. Achieving balance between risk and organizational goals is not always practical. Policy development must consider organizational risks as well as business objectives. It may be prudent to ensure that management understands and accepts risks that it is not willing to mitigate, but that is a practice and is not sufficient to l>e considered a strategy.

 

NEW QUESTION 123
Good information security standards should:

  • A. address high-level objectives of the organization.
  • B. be updated frequently as new software is released.
  • C. define precise and unambiguous allowable limits.
  • D. describe the process for communicating violations.

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation
Explanation:
A security standard should clearly state what is allowable; it should not change frequently. The process for communicating violations would be addressed by a security procedure, not a standard. High-level objectives of an organization would normally be addressed in a security policy.

 

NEW QUESTION 124
Which of the following will BEST prevent external security attacks?

  • A. Static IP addressing
  • B. Securing and analyzing system access logs
  • C. Network address translation
  • D. Background checks for temporary employees

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Network address translation is helpful by having internal addresses that are nonroutable. Background checks of temporary employees are more likely to prevent an attack launched from within the enterprise.
Static IP addressing does little to prevent an attack. Writing all computer logs to removable media does not help in preventing an attack.

 

NEW QUESTION 125
Over the last year, an information security manager has performed risk assessments on multiple third-party vendors. Which of the following criteria would be MOST helpful in determining the associated level of risk applied to each vendor?

  • A. Corresponding breaches associated with each vendor
  • B. Compensating controls in place to protect information security
  • C. Criticality of the service to the organization
  • D. Compliance requirements associated with the regulation

Answer: B

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 126
The BEST reason for an organization to have two discrete firewalls connected directly to the Internet and to the same DMZ would be to:

  • A. provide in-depth defense.
  • B. prevent a denial-of-service attack.
  • C. separate test and production.
  • D. permit traffic load balancing.

Answer: D

Explanation:
Explanation
Having two entry points, each guarded by a separate firewall, is desirable to permit traffic load balancing. As they both connect to the Internet and to the same demilitarized zone (DMZ), such an arrangement is not practical for separating test from production or preventing a denial-of-service attack.

 

NEW QUESTION 127
Based on the information provided, which of the following situations presents the GREATEST information security risk for an organization with multiple, but small, domestic processing locations?

  • A. Systems development is outsourced
  • B. Systems operation procedures are not enforced
  • C. Systems capacity management is not performed
  • D. Change management procedures are poor

Answer: D

Explanation:
The lack of change management is a severe omission and will greatly increase information security risk. Since procedures are generally nonauthoritative, their lack of enforcement is not a primary concern. Systems that are developed by third-party vendors are becoming commonplace and do not represent an increase in security risk as much as poor change management. Poor capacity management may not necessarily represent a security risk.

 

NEW QUESTION 128
Which of the following actions should be taken when an information security manager discovers that a hacker is foot printing the network perimeter?

  • A. Update IDS software to the latest available version
  • B. Enable server trace logging on the DMZ segment
  • C. Reboot the border router connected to the firewall
  • D. Check IDS logs and monitor for any active attacks

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Information security should check the intrusion detection system (IDS) logs and continue to monitor the situation. It would be inappropriate to take any action beyond that. In fact, updating the IDS could create a temporary exposure until the new version can be properly tuned. Rebooting the router and enabling server trace routing would not be warranted.

 

NEW QUESTION 129
In the course of responding 10 an information security incident, the BEST way to treat evidence for possible legal action is defined by:

  • A. local regulations.
  • B. international standards.
  • C. generally accepted best practices.
  • D. organizational security policies.

Answer: A

Explanation:
Explanation
Legal follow-up will most likely be performed locally where the incident took place; therefore, it is critical that the procedure of treating evidence is in compliance with local regulations. In certain countries, there are strict regulations on what information can be collected. When evidence collected is not in compliance with local regulations, it may not be admissible in court. There are no common regulations to treat computer evidence that are accepted internationally. Generally accepted best practices such as a common chain-of-custody concept may have different implementation in different countries, and thus may not be a good assurance that evidence will be admissible. Local regulations always take precedence over organizational security policies.

 

NEW QUESTION 130
An information security program should be established PRIMARILY on the basis of:

  • A. senior management input
  • B. the approved information security strategy.
  • C. data security regulatory requirements.
  • D. the approved risk management approach.

Answer: B

 

NEW QUESTION 131
Which of the following is MOST important to the successful development of an information security strategy?

  • A. Current state and desired objectives
  • B. A well-implemented governance framework
  • C. An implemented development life cycle process
  • D. Approved policies and standards

Answer: B

 

NEW QUESTION 132
The MOST important reason to use a centralized mechanism to identify information security incidents is to:

  • A. detect threats across environments
  • B. detect potential fraud.
  • C. prevent unauthorized changes to networks
  • D. comply with corporate policies

Answer: B

 

NEW QUESTION 133
When developing incident response procedures involving servers hosting critical applications, which of the following should be the FIRST to be notified?

  • A. Business management
  • B. Information security manager
  • C. System users
  • D. Operations manager

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The escalation process in critical situations should involve the information security manager as the first contact so that appropriate escalation steps are invoked as necessary. Choices A, B and D would be notified accordingly.

 

NEW QUESTION 134
Which item would be the BEST to include in the information security awareness training program for new general staff employees?

  • A. Review of roles that have privileged access
  • B. Discussion of how to construct strong passwords
  • C. Discussion of vulnerability assessment results
  • D. Review of various security models

Answer: D

Explanation:
All new employees will need to understand techniques for the construction of strong passwords. The other choices would not be applicable to general staff employees.

 

NEW QUESTION 135
Which of the following situations must be corrected FIRST to ensure successful information security governance within an organization?

  • A. The information security oversight committee only meets quarterly.
  • B. The chief information officer (CIO) approves security policy changes.
  • C. The data center manager has final signoff on all security projects.
  • D. The information security department has difficulty filling vacancies.

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
A steering committee should be in place to approve all security projects. The fact that the data center manager has final signoff for all security projects indicates that a steering committee is not being used and that information security is relegated to a subordinate place in the organization. This would indicate a failure of information security governance. It is not inappropriate for an oversight or steering committee to meet quarterly. Similarly, it may be desirable to have the chief information officer (CIO) approve the security policy due to the size of the organization and frequency of updates. Difficulty in filling vacancies is not uncommon due to the shortage of good, qualified information security professionals.

 

NEW QUESTION 136
Which of the following is the BEST approach to identify noncompliance issues with legal, regulatory, and contractual requirements?

  • A. Gap analysis
  • B. Business impact analysis (BIA)
  • C. Risk assessment
  • D. Vulnerability assessment

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 137
......

Practice CISM Questions With Certification guide Q&A from Training Expert Actual4Exams: https://braindumps.actual4exams.com/CISM-real-braindumps.html