[Mar 09, 2025] New CISM Exam Dumps with High Passing Rate [Q245-Q270]

Share

[Mar 09, 2025] New CISM Exam Dumps with High Passing Rate

Get CISM Braindumps & CISM Real Exam Questions


The CISM certification exam is ideal for IT professionals who are responsible for managing, designing, and assessing information security programs. CISM exam covers four key domains: Information Security Governance, Risk Management, Information Security Program Development and Management, and Information Security Incident Management. Candidates must have a minimum of five years of experience in information security, with at least three years in a management role, to be eligible for the certification.


To be eligible for the CISM certification, candidates must have at least five years of experience in information security, with at least three years of experience in information security management. Candidates must also adhere to the ISACA Code of Professional Ethics and complete the CISM exam within five years of passing their application.

 

NEW QUESTION # 245
The most important information for influencing management's support of inrormaao security control performance has improved?

  • A. an identification of the overall threat landscape
  • B. an identification of organizational risk.
  • C. a demonstration of alignment with the business strategy
  • D. a report of a successful attack on a competitor.

Answer: C


NEW QUESTION # 246
Which of the following is the MOST important criterion when deciding whether to accept residual risk?

  • A. Cost of additional mitigation
  • B. Annual rate of occurrence
  • C. Cost of replacing the asset
  • D. Annual loss expectancy (ALE)

Answer: A


NEW QUESTION # 247
Which of the following provides the BEST evidence that a newly implemented security awareness program has been effective?

  • A. There have been no reported successful phishing attempts since the training started.
  • B. Senior management supports funding for ongoing awareness training.
  • C. There has been an increase in the number of phishing attempts reported.
  • D. Employees from each department have completed the required training.

Answer: C


NEW QUESTION # 248
Which of the following features is normally missing when using Secure Sockets Layer (SSL) in a web browser?

  • A. Certificate-based authentication of web client
  • B. Data confidentiality between client and web server
  • C. Multiple encryption algorithms
  • D. Certificate-based authentication of web server

Answer: A

Explanation:
Explanation
Web browsers have the capability of authenticating through client-based certificates; nevertheless, it is not commonly used. When using https, servers always authenticate with a certificate and, once the connection is established, confidentiality will be maintained between client and server. By default, web browsers and servers support multiple encryption algorithms and negotiate the best option upon connection.


NEW QUESTION # 249
When investigating an information security incident, details of the incident should be shared:

  • A. only with internal audit.
  • B. widely to demonstrate positive intent.
  • C. only with management.
  • D. only as needed,

Answer: D

Explanation:
When investigating an information security incident, details of the incident should be shared only as needed, according to the principle of least privilege and the need-to-know basis. This means that only the authorized and relevant parties who have a legitimate purpose and role in the incident response process should have access to the incident information, and only to the extent that is necessary for them to perform their duties. Sharing incident details only as needed helps to protect the confidentiality, integrity, and availability of the incident information, as well as the privacy and reputation of the affected individuals and the organization. Sharing incident details only as needed also helps to prevent unauthorized disclosure, modification, deletion, or misuse of the incident information, which could compromise the investigation, evidence, remediation, or legal actions.
Reference = CISM Review Manual, 16th Edition, Chapter 4: Information Security Incident Management, Section: Incident Response Process, page 2311; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 49, page 462.


NEW QUESTION # 250
Which of the following is the MOST important requirement for the successful implementation of security governance?

  • A. Performance an enterprise-wide risk assessment
  • B. Implementing a security balanced scorecard
  • C. Aligning to an international security framework
  • D. Mapping to organizational

Answer: D


NEW QUESTION # 251
An organization has received complaints from users that some of their files have been encrypted.
These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?

  • A. Rebuild the affected systems.
  • B. Isolate the affected systems.
  • C. Conduct an impact assessment.
  • D. Initiate incident response.

Answer: D


NEW QUESTION # 252
To achieve effective strategic alignment of security initiatives, it is important that:

  • A. Inputs be obtained and consensus achieved between the major organizational units.
  • B. The business strategy be updated periodically.
  • C. Steering committee leadership be selected by rotation.
  • D. Procedures and standards be approved by all departmental heads.

Answer: A

Explanation:
Explanation
It is important to achieve consensus on risks and controls, and obtain inputs from various organizational entities since security needs to be aligned to the needs of the organization. Rotation of steering committee leadership does not help in achieving strategic alignment. Updating business strategy does not lead to strategic alignment of security initiatives. Procedures and standards need not be approved by all departmental heads


NEW QUESTION # 253
Who should have PRIMARY responsibility for authorizing access to data residing in an enterprise resource application?

  • A. Data custodian
  • B. Process owner
  • C. Identity and access management team
  • D. Application administrator

Answer: B


NEW QUESTION # 254
Which of the following BEST enables the assignment of risk and control ownership?

  • A. Adopting a risk management framework
  • B. Obtaining senior management buy-in
  • C. Developing an information security strategy
  • D. Aligning to an industry-recognized control framework

Answer: B

Explanation:
Obtaining senior management buy-in is the best way to enable the assignment of risk and control ownership because it helps to establish the authority and accountability of the risk and control owners, as well as to provide them with the necessary resources and support to perform their roles. Risk and control ownership refers to the assignment of specific responsibilities and accountabilities for managing risks and controls to individuals or groups within the organization. Obtaining senior management buy-in helps to ensure that risk and control ownership is aligned with the organizational objectives, structure, and culture, as well as to communicate the expectations and benefits of risk and control ownership to all stakeholders. Therefore, obtaining senior management buy-in is the correct answer.
References:
* https://www.protechtgroup.com/en-au/blog/risk-control-management
* https://www.mckinsey.com/~/media/mckinsey/dotcom/client_service/risk/working%20papers
/23_getting_risk_ownership_right.ashx
* https://www.linkedin.com/pulse/risk-controls-who-owns-them-david-tattam


NEW QUESTION # 255
Which of the following is the MOST important reason for an organization to communicate to affected parties that a security incident has occurred?

  • A. To comply with regulations regarding notification
  • B. To improve awareness of information security
  • C. To disclose the root cause of the incident
  • D. To increase goodwill toward the organization

Answer: A

Explanation:
Explanation
Complying with regulations regarding notification is the most important reason for an organization to communicate to affected parties that a security incident has occurred, as it helps to avoid legal penalties, fines, or sanctions that may result from failing to notify the relevant authorities, customers, or other stakeholders in a timely and appropriate manner. Additionally, complying with regulations regarding notification may also help to preserve the trust and reputation of the organization, as well as to facilitate the investigation and resolution of the incident.
References = CISM Review Manual 2022, page 3151; CISM Exam Content Outline, Domain 4, Task 4.5


NEW QUESTION # 256
Capacity planning would prevent:

  • A. application failures arising from insufficient hardware resources.
  • B. software failures arising from exploitation of buffer capacity vulnerabilities.
  • C. system downtime for scheduled security maintenance.
  • D. file system overload arising from distributed denial of service (DDoS) attacks.

Answer: A

Explanation:
Capacity planning is the process of estimating and allocating the required resources (such as CPU, memory, disk space, bandwidth, etc.) to meet the current and future demands of the information systems and applications. Capacity planning would prevent application failures arising from insufficient hardware resources, as it would ensure that the applications have enough resources to function properly and efficiently, and avoid performance degradation, errors, or crashes.
Reference = CISM Review Manual 2022, page 3081; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.92; What is Capacity Planning? Definition and Examples


NEW QUESTION # 257
Which of the following is the BEST way to achieve compliance with new global regulations related to the protection of personal information?

  • A. Execute a risk treatment plan.
  • B. Review contracts and statements of work (SOWs) with vendors.
  • C. Implement data regionalization controls.
  • D. Determine current and desired state of controls.

Answer: D

Explanation:
The best way to achieve compliance with new global regulations related to the protection of personal information is to determine the current and desired state of controls, as this helps the information security manager to identify the gaps and requirements for compliance, and to prioritize and implement the necessary actions and measures to meet the regulatory standards. The current state of controls refers to the existing level of protection and compliance of the personal information, while the desired state of controls refers to the target level of protection and compliance that is required by the new regulations. By comparing the current and desired state of controls, the information security manager can assess the maturity and effectiveness of the information security program, and plan and execute a risk treatment plan to address the risks and issues related to the protection of personal information. Executing a risk treatment plan, reviewing contracts and statements of work (SOWs) with vendors, and implementing data regionalization controls are also important, but not as important as determining the current and desired state of controls, as they are dependent on the outcome of the gap analysis and the risk assessment, and may not be sufficient or appropriate to achieve compliance with the new regulations. Reference = CISM Review Manual 2023, page 491; CISM Review Questions, Answers & Explanations Manual 2023, page 352; ISACA CISM - iSecPrep, page 203


NEW QUESTION # 258
Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?

  • A. Increased influence of security management
  • B. Improved accountability to shareholders
  • C. Optimized information security resources
  • D. Consistent execution of information security strategy

Answer: B


NEW QUESTION # 259
Communicating which of the following would be MOST helpful to gain senior management support for risk treatment options?

  • A. Industry benchmarks
  • B. Root cause analysis
  • C. Threat analysis
  • D. Quantitative loss

Answer: D

Explanation:
Explanation
communicating the quantitative loss associated with the risk scenarios and the risk treatment options would be the most helpful to gain senior management support, as it helps to demonstrate the value and effectiveness of the risk treatment options in terms of reducing the likelihood and impact of the risk. Quantitative loss also helps to compare the cost and benefit of the risk treatment options and to prioritize the most critical risks.
Industry benchmarks, threat analysis, and root cause analysis may be useful for understanding and assessing the risk, but they do not directly measure the performance of the risk treatment options.
References = Five Key Considerations When Developing Information Security Risk Treatment Plans, CISM Domain 2: Information Risk Management (IRM) [2022 update]


NEW QUESTION # 260
Which of the following is MOST important to consider when handling digital evidence during the forensics investigation of a cybercrime?

  • A. Business strategies
  • B. Local regulations
  • C. Industry best practices
  • D. Global standards

Answer: B


NEW QUESTION # 261
Which of the following should an organization do FIRST when confronted with the transfer of personal data across borders?

  • A. Research cyber insurance policies
  • B. Define policies and standards for data processing.
  • C. Implement applicable privacy principles
  • D. Assess local or regional regulations

Answer: D

Explanation:
Before transferring personal data across borders, an organization should first assess the local or regional regulations that apply to the data protection and privacy of the data subjects. This will help the organization to identify the legal requirements and risks involved in the data transfer, and to choose the appropriate tools and safeguards to ensure compliance and protection. For example, the organization may need to obtain consent from the data subjects, use adequacy decisions, standard contractual clauses, or other mechanisms to ensure an adequate level of protection in the third country, or rely on specific derogations for certain situations. The other options are not the first steps to take, although they may be relevant at later stages of the data transfer process. References =
* Guide to the cross-border transfer of personal data in the GDPR
* New guidance issued by the EDPB on international transfers of personal data
* Requirements for transferring personal information across borders


NEW QUESTION # 262
Which of the following actions should be taken when an information security manager discovers that a hacker is foot printing the network perimeter?

  • A. Check IDS logs and monitor for any active attacks
  • B. Enable server trace logging on the DMZ segment
  • C. Reboot the border router connected to the firewall
  • D. Update IDS software to the latest available version

Answer: A

Explanation:
Information security should check the intrusion detection system (IDS) logs and continue to monitor the situation. It would be inappropriate to take any action beyond that. In fact, updating the IDS could create a temporary exposure until the new version can be properly tuned. Rebooting the router and enabling server trace routing would not be warranted.


NEW QUESTION # 263
When developing an escalation process for an incident response plan, the information security manager should PRIMARILY consider the:

  • A. affected stakeholders.
  • B. media coverage.
  • C. availability of technical resources.
  • D. incident response team.

Answer: D

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation/Reference:


NEW QUESTION # 264
An information security manager has observed multiple exceptions for a number of different security controls. Which of the following should be the information security manager's FIRST course of action?

  • A. Design mitigating controls tor the exceptions
  • B. Inform respective risk owners of the impact of exceptions
  • C. Report the noncompliance to the board of directors
  • D. Prioritize the risk and implement treatment options

Answer: B


NEW QUESTION # 265
Which of the following is MOST effective in preventing the introduction of vulnerabilities that may disrupt the availability of a critical business application?

  • A. A patch management process
  • B. Change management controls
  • C. Version control
  • D. Logical access controls

Answer: A


NEW QUESTION # 266
The BEST time to ensure that a corporation acquires secure software products when outsourcing software development is during:

  • A. contract negotiation.
  • B. corporate security reviews.
  • C. security policy development.
  • D. contract performance audits.

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:


NEW QUESTION # 267
Which of the following is the GREATEST benefit of an information security architecture?

  • A. Alignment with industry best practices
  • B. Ease of integration between different security components
  • C. Closer integration with the incident response team function
  • D. Fewer false positives in the security incident and event management (SIEM)

Answer: B


NEW QUESTION # 268
Which of the following tasks should be performed once a disaster recovery plan (DRP) has been developed?

  • A. Identify recovery time objectives (RTOs).
  • B. Develop the test plan.
  • C. Define response team roles.
  • D. Analyze the business impact.

Answer: B

Explanation:
= Developing the test plan is the task that should be performed once a disaster recovery plan (DRP) has been developed. The test plan is a document that describes the objectives, scope, methods, and procedures for testing the DRP. The test plan should also define the roles and responsibilities of the test team, the test scenarios and criteria, the test schedule and resources, and the test reporting and evaluation. The purpose of testing the DRP is to verify its effectiveness, identify any gaps or weaknesses, and improve its reliability and usability. Testing the DRP also helps to increase the awareness and readiness of the staff and stakeholders involved in the disaster recovery process. Analyzing the business impact, defining response team roles, and identifying recovery time objectives (RTOs) are all tasks that should be performed before developing the DRP, not after. These tasks are part of the business continuity planning (BCP) process, which aims to identify the critical business functions and assets, assess the potential threats and impacts, and determine the recovery strategies and requirements. The DRP is a subset of the BCP that focuses on restoring the IT systems and services after a disaster. Therefore, the DRP should be based on the results of the BCP process, and tested after it has been developed. Reference = CISM Review Manual 2023, page 218 1; CISM Practice Quiz 2


NEW QUESTION # 269
Which of the following is MOST helpful to maintain cohesiveness within an organization's information security resource?

  • A. Business impact analysis
  • B. Information security steering committee
  • C. Security gap analysis
  • D. Information security architecture

Answer: D


NEW QUESTION # 270
......

CISM Dumps To Pass ISACA Exam in 24 Hours - Exam4Labs: https://www.exam4labs.com/CISM-practice-torrent.html

ISACA CISM Actual Questions and Braindumps: https://drive.google.com/open?id=1JRqHd_xwaLNk-_CvKt6qwGBaoof_T9BN