
CISM Exam Dumps Pass with Updated Sep-2024 Tests Dumps
CISM exam questions for practice in 2024 Updated 672 Questions
NEW QUESTION # 306
The MAIN reason for having the Information Security Steering Committee review a new security controls implementation plan is to ensure that:
- A. regulatory oversight requirements are met.
- B. the impact of the plan on the business units is reduced.
- C. departmental budgets are allocated appropriately to pay for the plan.
- D. the plan aligns with the organization's business plan.
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The steering committee controls the execution of the information security strategy according to the needs of the organization and decides on the project prioritization and the execution plan. The steering committee does not allocate department budgets for business units. While ensuring that regulatory oversight requirements are met could be a consideration, it is not the main reason for the review. Reducing the impact on the business units is a secondary concern but not the main reason for the review.
NEW QUESTION # 307
After adopting an information security framework, an information security manager is working with senior management to change the organization-wide perception that information security is solely the responsibility of the information security department. To achieve this objective, what should be the information security manager's FIRST initiative?
- A. Develop an information security awareness campaign with senior management's support.
- B. Develop an operational plan providing best practices for information security projects.
- C. Document and publish the responsibilities of the information security department.
- D. Implement a formal process to conduct periodic compliance reviews.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION # 308
Which of the following should be the PRIMARY objective when establishing a new information security program?
- A. Executing the security strategy
- B. Optimizing resources
- C. Facilitating operational security
- D. Minimizing organizational risk
Answer: A
Explanation:
Explanation
According to the CISM Review Manual, the primary objective when establishing a new information security program is to execute the security strategy that has been defined and approved by the senior management. The security strategy provides the direction, scope, and goals for the information security program, and aligns with the business objectives and requirements. Minimizing organizational risk, optimizing resources, and facilitating operational security are possible outcomes or benefits of the information security program, but they are not the primary objective.
References = CISM Review Manual, 27th Edition, Chapter 3, Section 3.1.1, page 1151.
NEW QUESTION # 309
Which of the following activities performed by a database administrator (DBA) should be performed by a different person?
- A. Deleting database activity logs
- B. Monitoring database usage
- C. Defining backup and recovery procedures
- D. Implementing database optimization tools
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Since database activity logs record activities performed by the database administrator (DBA), deleting them should be performed by an individual other than the DBA. This is a compensating control to aid in ensuring an appropriate segregation of duties and is associated with the DBA's role. A DBA should perform the other activities as part of the normal operations.
NEW QUESTION # 310
Which of the following is the MOST important reason for an organization to develop an information security governance program?
- A. Monitoring of security incidents
- B. Establishment of accountability
- C. Creation of tactical solutions
- D. Compliance with audit requirements
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION # 311
Which of the following poses the GREATEST risk to the operational effectiveness of an incident response team?
- A. The lack of automated communication channels
- B. The lack of forensic investigation skills
- C. The lack of a security information and event management (SIEM) system
- D. The lack of delegated authority
Answer: D
NEW QUESTION # 312
Which of the following is the PRIMARY prerequisite to implementing data classification within an organization?
- A. Defining job roles
- B. Identifying data owners
- C. Establishing data retention policies
- D. Performing a risk assessment
Answer: B
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Identifying the data owners is the first step, and is essential to implementing data classification. Defining job roles is not relevant. Performing a risk assessment is important, but will require the participation of data owners (who must first be identified). Establishing data retention policies may occur after data have been classified.
NEW QUESTION # 313
Which of the following is a PRIMARY function of an incident response team?
- A. To provide a single point of contact for critical incidents
- B. To provide a business impact analysis (BIA)
- C. To provide effective incident mitigation
- D. To provide a risk assessment for zero-day vulnerabilities
Answer: C
NEW QUESTION # 314
The recovery time objective (RTO) is reached at which of the following milestones?
- A. Restoration of the system
- B. Disaster declaration
- C. Recovery of the backups
- D. Return to business as usual processing
Answer: A
Explanation:
Explanation
The recovery time objective (RTO) is based on the amount of time required to restore a system; disaster declaration occurs at the beginning of this period. Recovery of the backups occurs shortly after the beginning of this period. Return to business as usual processing occurs significantly later than the RTO. RTO is an
"objective," and full restoration may or may not coincide with the RTO. RTO can be the minimum acceptable operational level, far short of normal operations.
NEW QUESTION # 315
Which of the following is the PRIMARY advantage of having an established information security governance framework in place when an organization is adopting emerging technologies?
- A. End user acceptance of emerging technologies is established
- B. An effective security risk management process is established
- C. An emerging technologies strategy is in place
- D. A cost-benefit analysis process is easier to perform
Answer: B
NEW QUESTION # 316
Which of the following would be the MOST important goal of an information security governance program?
- A. Review of internal control mechanisms
- B. Total elimination of risk factors
- C. Ensuring trust in data
- D. Effective involvement in business decision making
Answer: C
Explanation:
Explanation/Reference:
Explanation:
The development of trust in the integrity of information among stakeholders should be the primary goal of information security governance. Review of internal control mechanisms relates more to auditing, while the total elimination of risk factors is not practical or possible. Proactive involvement in business decision making implies that security needs dictate business needs when, in fact, just the opposite is true.
Involvement in decision making is important only to ensure business data integrity so that data can be trusted.
NEW QUESTION # 317
Which of the following is the MOST likely to change an organization's culture to one that is more security conscious?
- A. Adequate security policies and procedures
- B. Periodic compliance reviews
- C. Security steering committees
- D. Security awareness campaigns
Answer: D
Explanation:
Explanation
Security awareness campaigns will be more effective at changing an organizational culture than the creation of steering committees and security policies and procedures. Compliance reviews are helpful; however, awareness by all staff is more effective because compliance reviews are focused on certain areas groups and do not necessarily educate.
NEW QUESTION # 318
Which of the following is the PRIMARY objective of a business impact analysis (BIA):
- A. Define the recovery point objective (RPO).
- B. Determine recovery priorities.
- C. Confirm control effectiveness.
- D. Analyze vulnerabilities
Answer: A
NEW QUESTION # 319
Which of the following is MOST important to the successful implementation of an information security governance framework across the organization?
- A. The existing organizational security culture
- B. Security management processes aligned with security objectives
- C. Security policies that adhere to industry best practices
- D. Organizational security controls deployed in line with regulations
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION # 320
In addition to executive sponsorship and business alignment, which of the following is MOST critical for information security governance?
- A. Compliance with policies
- B. Allocation of training resources
- C. Auditability of systems
- D. Ownership of security
Answer: D
NEW QUESTION # 321
Organization A offers e-commerce services and uses secure transport protacal to protect Internet communication. To confirm communication with Organization A, which of the following would be the BEST for a client to verify?
- A. The browser's indication of SSL use
- B. The URL of the 6-commerce server
- C. The certificate of the e-commerce server
- D. The IP address of the e-commerce server
Answer: C
NEW QUESTION # 322
Which of the following would be MOST effective in gaining senior management approval of security investments in network infrastructure?
- A. Demonstrating that targeted security controls tie to business objectives
- B. Presenting comparable security implementation estimates from several vendors
- C. Highlighting competitor performance regarding network best security practices
- D. Performing penetration tests against the network to demonstrate business vulnerability
Answer: A
Explanation:
Explanation
The most effective way to gain senior management approval of security investments in network infrastructure is by demonstrating that targeted security controls tie to business objectives.
Security investments should be tied to business objectives and should support the overall goals of the organization. By demonstrating that the security controls will directly support the organization's business objectives, senior management will be more likely to approve the investment.
According to the Certified Information Security Manager (CISM) Study Manual, "To gain senior management's approval for investments in security, it is essential to show how the security controls tie to business objectives and are in support of the overall goals of the organization." While performing penetration tests against the network, highlighting competitor performance, and presenting comparable security implementation estimates from vendors are all useful in presenting the value of security investments, they are not as effective as demonstrating how the security controls will support the organization's business objectives.
NEW QUESTION # 323
To ensure that payroll systems continue on in an event of a hurricane hitting a data center, what would be the FIRS T crucial step an information security manager would take in ensuring business continuity planning?
- A. Assigning value to the assets.
- B. Conducting a qualitative and quantitative risk analysis.
- C. Conducting a business impact analysis (BIA).
- D. Weighing the cost of implementing the plan vs. financial loss.
Answer: C
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
BIA is an essential component of an organization's business continuity plan; it includes an exploratory component to reveal any vulnerabilities and a planning component to develop strategies for minimizing risk.
It is the first crucial step in business continuity planning. Qualitative and quantitative risk analysis will have been completed to define the dangers to individuals, businesses and government agencies posed by potential natural and human-caused adverse events. Assigning value to assets is part of the BIA process.
Weighing the cost of implementing the plan vs. financial loss is another part of the BIA.
NEW QUESTION # 324
In designing a backup strategy that will be consistent with a disaster recovery strategy, the PRIMARY factor to be taken into account will be the:
- A. recovery point objective (RPO).
- B. volume of sensitive data.
- C. recovery' time objective (RTO).
- D. interruption window.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The recovery point objective (RPO) defines the maximum loss of data (in terms of time) acceptable by the business (i.e., age of data to be restored). It will directly determine the basic elements of the backup strategy frequency of the backups and what kind of backup is the most appropriate (disk-to-disk, on tape, mirroring). The volume of data will be used to determine the capacity of the backup solution. The recovery time objective (RTO) - the time between disaster and return to normal operation - will not have any impact on the backup strategy. The availability to restore backups in a time frame consistent with the interruption window will have to be checked and will influence the strategy (e.g., full backup vs.
incremental), but this will not be the primary factor.
NEW QUESTION # 325
Reevaluation of risk is MOST critical when there is:
- A. a change in the threat landscape.
- B. a management request for updated security reports.
- C. resistance to the implementation of mitigating controls.
- D. a change in security policy.
Answer: A
Explanation:
Section: INFORMATION RISK MANAGEMENT
NEW QUESTION # 326
The PRIMARY benefit of introducing a single point of administration in network monitoring is that it:
- A. promotes efficiency in control of the environment.
- B. reduces unauthorized access to systems.
- C. allows administrative staff to make management decisions.
- D. prevents inconsistencies in information in the distributed environment.
Answer: C
NEW QUESTION # 327
An organization is planning to open a new office in another country. Sensitive data will be routinely sent between the two offices. What should be the information security manager s FIRST course of action?
- A. Update privacy policies to include the other country's laws and regulations.
- B. Apply the current corporate security policies to the new office.
- C. Identify applicable regulatory requirements to establish security policies
- D. Encrypt the data for transfer to the head office based on security manager approval
Answer: B
NEW QUESTION # 328
......
Authentic CISM Dumps With 100% Passing Rate Practice Tests Dumps: https://www.getvalidtest.com/CISM-exam.html
Updated Premium CISM Exam Engine pdf: https://drive.google.com/open?id=1SkwQV6A3KoE_Hr-2_qa-MkOLobJTH8eA