Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Updated Jan-2022 100% Cover Real CISM Exam Questions - 100% Pass Guarantee [Q153-Q169]

Share

Updated Jan-2022 100% Cover Real CISM Exam Questions - 100% Pass Guarantee

Use Real ISACA Dumps - 100% Free CISM Exam Dumps

NEW QUESTION 153
An organization has a process in place that involves the use of a vendor. A risk assessment was completed during the development of the process. A year after the implementation a monetary decision has been made to use a different vendor. What, if anything, should occur?

  • A. Nothing, since a risk assessment was completed during development.
  • B. A vulnerability assessment should be conducted.
  • C. The new vendor's SAS 70 type II report should be reviewed.
  • D. A new risk assessment should be performed.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The risk assessment process is continual and any changes to an established process should include a new- risk assessment. While a review of the SAS 70 report and a vulnerability assessment may be components of a risk assessment, neither would constitute sufficient due diligence on its own.

 

NEW QUESTION 154
Which of the following metrics would BEST monitor how well information security requirements are incorporated into the change management process?

  • A. Information security incidents caused due to unauthorized changes
  • B. Information security related changes
  • C. Denied changes due to insufficient security details
  • D. Unauthorized changes in the environment

Answer: A

 

NEW QUESTION 155
When the inherent risk of a business activity is lower than the acceptable risk level, the BEST course of action would be to:

  • A. monitor for business changes
  • B. report compliance to management
  • C. review the residual risk level
  • D. implement controls to mitigate the risk

Answer: C

 

NEW QUESTION 156
When properly tested, which of the following would MOST effectively support an information security manager in handling a security breach?

  • A. Vulnerability management plan
  • B. Incident response plan
  • C. Business continuity plan
  • D. Disaster recovery plan

Answer: B

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation
Explanation:
An incident response plan documents the step-by-step process to follow, as well as the related roles and responsibilities pertaining to all parties involved in responding to an information security breach. A business continuity plan or disaster recovery plan would be triggered during the execution of the incident response plan in the case of a breach impacting the business continuity. A vulnerability management plan is a procedure to address technical vulnerabilities and mitigate the risk through configuration changes (patch management).

 

NEW QUESTION 157
Which of the following is the BEST method to protect consumer private information for an online public website?

  • A. Encrypt consumer's data in transit and at rest.
  • B. Use secure encrypted transport layer.
  • C. Apply a masking policy to the consumer data.
  • D. Apply strong authentication to online accounts.

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 158
Which of the following is necessary to determine what would constitute a disaster for an organization?

  • A. Risk analysis
  • B. Threat probability analysis
  • C. Recovery strategy analysis
  • D. Backup strategy analysis

Answer: A

 

NEW QUESTION 159
Recovery point objectives (RPOs) can be used to determine which of the following?

  • A. Baseline for operational resiliency
  • B. Time to restore backups
  • C. Maximum tolerable period of data loss
  • D. Maximum tolerable downtime

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The RPO is determined based on the acceptable data loss in the case of disruption of operations. It indicates the farthest point in time prior to the incident to which it is acceptable to recover the data. RPO effectively quantifies the permissible amount of data loss in the case of interruption. It also dictates the frequency of backups required for a given data set since the smaller the allowable gap in data, the more frequent that backups must occur.

 

NEW QUESTION 160
Ongoing tracking of remediation efforts to mitigate identified risks can BEST be accomplished through the use of which of the following?

  • A. Bar charts
  • B. Heat charts
  • C. Tree diagrams
  • D. Venn diagrams

Answer: B

Explanation:
Meat charts, sometimes referred to as stoplight charts, quickly and clearly show the current status of remediation efforts. Venn diagrams show the connection between sets; tree diagrams are useful for decision analysis; and bar charts show relative size.

 

NEW QUESTION 161
Which of the following is the BEST indicator that security awareness training has been effective?

  • A. Employees sign to acknowledge the security policy
  • B. More incidents are being reported
  • C. A majority of employees have completed training
  • D. No incidents have been reported in three months

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
More incidents being reported could be an indicator that the staff is paying more attention to security.
Employee signatures and training completion may or may not have anything to do with awareness levels.
The number of individuals trained may not indicate they are more aware. No recent security incidents do not reflect awareness levels, but may prompt further research to confirm.

 

NEW QUESTION 162
What would be an information security manager's BEST course of action when notified that the implementation of some security controls is being delayed due to budget constraints?

  • A. Suggest less expensive alternative security controls.
  • B. Request a budget exception for the security controls
  • C. Prioritize security controls based on risk.
  • D. Begin the risk acceptance process

Answer: C

 

NEW QUESTION 163
An information security manager has been asked to develop a change control process. What is the FIRST thing the information security manager should do?

  • A. Establish change control procedures
  • B. Research best practices
  • C. Identify critical systems
  • D. Meet with stakeholders

Answer: D

Explanation:
Explanation/Reference:
Explanation:
No new process will be successful unless it is adhered to by all stakeholders; to the extent stakeholders have input, they can be expected to follow the process. Without consensus agreement from the stakeholders, the scope of the research is too wide; input on the current environment is necessary to focus research effectively. It is premature to implement procedures without stakeholder consensus and research.
Without knowing what the process will be the parameters to baseline are unknown as well.

 

NEW QUESTION 164
What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?

  • A. Create an addendum to the existing contract.
  • B. Transfer the risk to the provider.
  • C. Initiate an external audit of the provider's data center.
  • D. Cancel the outsourcing contract.

Answer: A

 

NEW QUESTION 165
What should an information security manager do FIRST when a service provider that stores the organization's confidential customer data experiences a breach in its data center?

  • A. Apply remediation actions to counteract the breach.
  • B. Determine the impact of the breach.
  • C. Recommend canceling the outsourcing contract.
  • D. Engage an audit of the provider's data center.

Answer: B

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 166
What is the BEST method to verify that all security patches applied to servers were properly documented?

  • A. Trace OS patch logs to change control requests
  • B. Trace OS patch logs to OS vendor's update documentation
  • C. Review change control documentation for key servers
  • D. Trace change control requests to operating system (OS) patch logs

Answer: A

Explanation:
Explanation
To ensure that all patches applied went through the change control process, it is necessary to use the operating system (OS) patch logs as a starting point and then check to see if change control documents are on file for each of these changes. Tracing from the documentation to the patch log will not indicate if some patches were applied without being documented. Similarly, reviewing change control documents for key servers or comparing patches applied to those recommended by the OS vendor's web site does not confirm that these security patches were properly approved and documented.

 

NEW QUESTION 167
Which of the following should occur FIRST in the process of managing security risk associated with the transfer of data from unsupported legacy systems to supported systems?

  • A. Assign owners to be responsible for the transfer of each asset.
  • B. Make backups of the affected systems prior to transfer.
  • C. Increase cyber insurance coverage.
  • D. Identify all information assets in the legacy environment.

Answer: D

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 168
An e-commerce order fulfillment web server should generally be placed on which of the following?

  • A. Domain controller
  • B. Demilitarized zone (DMZ)
  • C. Database server
  • D. Internal network

Answer: B

Explanation:
Explanation/Reference:
Explanation:
An e-commerce order fulfillment web server should be placed within a DMZ to protect it and the internal network from external attack. Placing it on the internal network would expose the internal network to potential attack from the Internet. Since a database server should reside on the internal network, the same exposure would exist. Domain controllers would not normally share the same physical device as a web server.

 

NEW QUESTION 169
......

CISM Dumps PDF - CISM Real Exam Questions Answers: https://www.examstorrent.com/CISM-exam-dumps-torrent.html

Realistic CISM Dumps Latest Practice Tests Dumps: https://drive.google.com/open?id=1Yjf8qiP_1876NmqUlWyqKEqZjTXHYvad