[Q174-Q198] Latest ISACA CISM First Attempt, Exam real Dumps Updated [Sep-2021]

Share

Latest ISACA CISM First Attempt, Exam real Dumps Updated [Sep-2021]

Get the superior quality CISM Dumps Questions from Exam4Labs. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!

NEW QUESTION 174
Which of the following is the MOST appropriate method for deploying operating system (OS) patches to production application servers?

  • A. Initially load the patches on a test machine
  • B. Set up servers to automatically download patches
  • C. Batch patches into frequent server updates
  • D. Automatically push all patches to the servers

Answer: A

Explanation:
Explanation
Some patches can conflict with application code. For this reason, it is very important to first test all patches in a test environment to ensure that there are no conflicts with existing application systems. For this reason, choices C and D are incorrect as they advocate automatic updating. As for frequent server updates, this is an incomplete (vague) answer from the choices given.

 

NEW QUESTION 175
Of the following, whose input is of GREATEST importance in the development of an information security strategy?

  • A. End users
  • B. Process owners
  • C. Security architects
  • D. Corporate auditors

Answer: C

 

NEW QUESTION 176
What should be an information security manager's FIRST course of action when an organization is subject to a new regulatory requirement?

  • A. Submit a business case to support compliance.
  • B. Update the risk register.
  • C. Complete a control assessment.
  • D. Perform a gap analysis,

Answer: D

 

NEW QUESTION 177
When creating security baselines, it is MOST important to:

  • A. identify critical systems storing sensitive data
  • B. establish consistent enterprise-wide controls
  • C. establish maximum security requirements.
  • D. demonstrate adherence to compliance criteria

Answer: D

 

NEW QUESTION 178
Which of the following is the BEST way to provide management with meaningful information regarding the performance of the information security program against strategic objectives?

  • A. Develop an information security heat map.
  • B. Publish the information security strategy across the organization.
  • C. Establish a balanced scorecard dashboard.
  • D. Issue periodic reports to demonstrate compliance with security standards.

Answer: C

 

NEW QUESTION 179
Which of the following is MOST helpful to an information security manager when determining service level requirements for an outsourced application?

  • A. Application capabilities
  • B. Business functionality
  • C. Data classification
  • D. Information security policy

Answer: B

 

NEW QUESTION 180
For a business operating in a competitive and evolving online market, it is MOST important for a security policy to focus on:

  • A. requiring accreditation for new technologies.
  • B. enabling adoption of new technologies.
  • C. defining policies for new technologies.
  • D. managing risks of new technologies.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT

 

NEW QUESTION 181
When developing security standards, which of the following would be MOST appropriate to include?

  • A. Acceptable use of IT assets
  • B. Operating system requirements
  • C. Inventory management
  • D. Accountability for licenses

Answer: B

 

NEW QUESTION 182
The MOST effective way to communicate the level of impact of information security risks on organizational objectives is to present:

  • A. detailed threat analysis results.
  • B. business impact analysis (BIA) results.
  • C. a risk heat map.
  • D. risk treatment options.

Answer: C

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 183
Which of the following is the MOST important reason to identify and classify the sensitivity of assets?

  • A. To allocate the information security program budget
  • B. To assign appropriate controls
  • C. To determine the scope of the information security program
  • D. To reduce the cost of protective controls

Answer: B

 

NEW QUESTION 184
Nonrepudiation can BEST be ensured by using:

  • A. symmetric encryption.
  • B. strong passwords.
  • C. a digital hash.
  • D. digital signatures.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Digital signatures use a private and public key pair, authenticating both parties. The integrity of the contents exchanged is controlled through the hashing mechanism that is signed by the private key of the exchanging party. A digital hash in itself helps in ensuring integrity of the contents, but not nonrepudiation. Symmetric encryption wouldn't help in nonrepudiation since the keys are always shared between parties. Strong passwords only ensure authentication to the system and cannot be used for nonrepudiation involving two or more parties.

 

NEW QUESTION 185
In designing a backup strategy that will be consistent with a disaster recovery strategy, the PRIMARY factor to be taken into account will be the:

  • A. interruption window.
  • B. recovery' time objective (RTO).
  • C. recovery point objective (RPO).
  • D. volume of sensitive data.

Answer: C

Explanation:
The recovery point objective (RPO) defines the maximum loss of data (in terms of time) acceptable by the business (i.e., age of data to be restored). It will directly determine the basic elements of the backup strategy frequency of the backups and what kind of backup is the most appropriate (disk-to-disk, on tape, mirroring). The volume of data will be used to determine the capacity of the backup solution. The recovery time objective (RTO)-the time between disaster and return to normal operation-will not have any impact on the backup strategy. The availability to restore backups in a time frame consistent with the interruption window will have to be checked and will influence the strategy (e.g., full backup vs. incremental), but this will not be the primary factor.

 

NEW QUESTION 186
Which of the following would be MOST useful to help senior management understand the status of information security compliance?

  • A. Key performance indicators (KPIs)
  • B. Business impact analysis (BIA) results
  • C. Risk assessment results
  • D. Industry benchmarks

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 187
Which of the following are likely to be updated MOST frequently?

  • A. Procedures for hardening database servers
  • B. Standards for document retention and destruction
  • C. Policies addressing information security governance
  • D. Standards for password length and complexity

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Policies and standards should generally be more static and less subject to frequent change. Procedures on the other hand, especially with regard to the hardening of operating systems, will be subject to constant change; as operating systems change and evolve, the procedures for hardening will have to keep pace.

 

NEW QUESTION 188
When developing security standards, which of the following would be MOST appropriate to include?

  • A. Acceptable use of IT assets
  • B. Inventory management
  • C. Accountability for licenses
  • D. operating system requirements

Answer: A

 

NEW QUESTION 189
An organization has acquired a company that manufactures Internet of Things (loT) devices What should the information security manager do NEXT?

  • A. Update the information security strategy
  • B. Review the acquired company's audit reports
  • C. Conduct a vulnerability assessment
  • D. Review the acquired company's data sharing agreements

Answer: D

 

NEW QUESTION 190
Which of the following is the MOST effective at preventing an unauthorized individual from following an authorized person through a secured entrance (tailgating or piggybacking)?

  • A. Biometric scanners
  • B. Photo identification
  • C. Awareness training
  • D. Card-key door locks

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Awareness training would most likely result in any attempted tailgating being challenged by the authorized employee. The other choices are physical controls which by themselves would not be effective against tailgating.

 

NEW QUESTION 191
An organization is concerned with the risk of information leakage caused by incorrect use of personally owned smart devices by employees. What is the BEST way for the information security manager to mitigate the associated risk?

  • A. implement a multi-factor authentication solution.
  • B. Implement a mobile device management solution.
  • C. Document a bong-your-own-device (BYODJ policy.
  • D. Require employees to sign a nondisclosure agreement

Answer: B

 

NEW QUESTION 192
Which of the following is the BEST method for determining whether new risks exist in legacy systems?

  • A. Regularly scheduled security audits
  • B. Automated vulnerability scans
  • C. Frequent updates to the risk register
  • D. Regularly scheduled risk assessments

Answer: B

 

NEW QUESTION 193
Which of the following is necessary to determine what would constitute a disaster for an organization?

  • A. Recovery strategy analysis
  • B. Threat probability analysis
  • C. Risk analysis
  • D. Backup strategy analysis

Answer: C

 

NEW QUESTION 194
Which of the following should be determined FIRST when establishing a business continuity program?

  • A. Incremental daily cost of the unavailability of systems
  • B. Location and cost of offsite recovery facilities
  • C. Composition and mission of individual recovery teams
  • D. Cost to rebuild information processing facilities

Answer: A

Explanation:
Explanation
Prior to creating a detailed business continuity plan, it is important to determine the incremental daily cost of losing different systems. This will allow recovery time objectives to be determined which, in turn, affects the location and cost of offsite recovery facilities, and the composition and mission of individual recovery teams.
Determining the cost to rebuild information processing facilities would not be the first thing to determine.

 

NEW QUESTION 195
A CEO requests access to corporate documents from a mobile device that does not comply with organizational policy. The information security manager should FIRST:

  • A. evaluate the business risk.
  • B. initiate an exception approval process.
  • C. deploy additional security controls.
  • D. evaluate a third-party solution.

Answer: A

Explanation:
Section: MIXED QUESTIONS

 

NEW QUESTION 196
What should an information security manager do NEXT when management does not accept control recommendations resulting from a risk assessment?

  • A. Implement the recommendations.
  • B. Perform a reassessment.
  • C. Document the decision.
  • D. Remove the recommendations.

Answer: C

 

NEW QUESTION 197
Which of the following is the MOST appropriate individual to ensure that new exposures have not been introduced into an existing application during the change management process?

  • A. System user
  • B. System analyst
  • C. Data security officer
  • D. Operations manager

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
System users, specifically the user acceptance testers, would be in the best position to note whether new exposures are introduced during the change management process. The system designer or system analyst, data security officer and operations manager would not be as closely involved in testing code changes.

 

NEW QUESTION 198
......

ISACA Practice Test Engine with CISM Questions: https://drive.google.com/open?id=1JRqHd_xwaLNk-_CvKt6qwGBaoof_T9BN

Guaranteed Success with Valid ISACA CISM Dumps: https://www.exam4labs.com/CISM-practice-torrent.html