CISM Practice Dumps - Verified By TorrentVCE Updated 1340 Questions [Q602-Q624]

Share

CISM Practice Dumps - Verified By TorrentVCE Updated 1340 Questions

Updated CISM  Exam Dumps - PDF Questions and Testing Engine

NEW QUESTION 602
The root cause of a successful cross site request forgery (XSRF) attack against an application is that the vulnerable application:

  • A. is hosted on a server along with other applications.
  • B. uses multiple redirects for completing a data commit transaction.
  • C. has been installed with a non-legitimate license key.
  • D. has implemented cookies as the sole authentication mechanism.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
XSRF exploits inadequate authentication mechanisms in web applications that rely only on elements such as cookies when performing a transaction. XSRF is related to an authentication mechanism, not to redirection.
Option C is related to intellectual property rights, not to XSRF vulnerability. Merely hosting multiple applications on the same server is not the root cause of this vulnerability.

 

NEW QUESTION 603
The organization has decided to outsource the majority of the IT department with a vendor that is hosting servers in a foreign country. Of the following, which is the MOST critical security consideration?

  • A. Laws and regulations of the country of origin may not be enforceable in the foreign country.
  • B. A security breach notification might get delayed due to the time difference.
  • C. The company could lose physical control over the server and be unable to monitor the physical security posture of the servers.
  • D. Additional network intrusion detection sensors should be installed, resulting in an additional cost.

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
A company is held to the local laws and regulations of the country in which the company resides, even if the company decides to place servers with a vendor that hosts the servers in a foreign country. A potential violation of local laws applicable to the company might not be recognized or rectified (i.e., prosecuted) due to the lack of knowledge of the local laws that are applicable and the inability to enforce the laws. Option B is not a problem.
Time difference does not play a role in a 24/7 environment. Pagers, cellular phones, telephones, etc. are usually available to communicate notifications. Option C is a manageable problem that requires additional funding, but can be addressed. Option D is a problem that can be addressed. Most hosting providers have standardized the level of physical security that is in place. Regular physical audits or a SAS 70 report can address such concerns.

 

NEW QUESTION 604
An organization has implemented an enterprise resource planning (ERP) system used by 500 employees from various departments. Which of the following access control approaches is MOST appropriate?

  • A. Rule-based
  • B. Discretionary
  • C. Mandatory
  • D. Role-based

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Role-based access control is effective and efficient in large user communities because it controls system access by the roles defined for groups of users. Users are assigned to the various roles and the system controls the access based on those roles. Rule-based access control needs to define the access rules, which is troublesome and error prone in large organizations. In mandatory access control, the individual's access to information resources needs to be defined, which is troublesome in large organizations. In discretionary access control, users have access to resources based on predefined sets of principles, which is an inherently insecure approach.

 

NEW QUESTION 605
An organization has determined that one of its web servers has been compromised. Which of the following actions should be taken to preserve the evidence of the intrusion for forensic analysis and potential litigation?

  • A. Run analysis tools to detect the source of the intrusion.
  • B. Restrict physical and logical access to the server.
  • C. Reboot the server in a secure area to search for digital evidence.
  • D. Unplug the server from the power.

Answer: B

 

NEW QUESTION 606
Which of the following is the MOST important outcome of a well-implemented awareness program?

  • A. The number of reported security incidents steadily decreases.
  • B. The number of successful social engineering attacks is reduced.
  • C. The board is held accountable for risk management.
  • D. Help desk response time to resolve incidents is improved.

Answer: B

 

NEW QUESTION 607
Which of the following is the MOST important reason for an information security review of contracts? To help ensure that:

  • A. appropriate controls are included.
  • B. the parties to the agreement can perform.
  • C. the right to audit is a requirement.
  • D. confidential data are not included in the agreement.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Agreements with external parties can expose an organization to information security risks that must be assessed and appropriately mitigated. The ability of the parties to perform is normally the responsibility of legal and the business operation involved. Confidential information may be in the agreement by necessity and. while the information security manager can advise and provide approaches to protect the information, the responsibility rests with the business and legal. Audit rights may be one of many possible controls to include in a third-party agreement, but is not necessarily a contract requirement, depending on the nature of the agreement.

 

NEW QUESTION 608
In a well-controlled environment, which of the following activities is MOST likely to lead to the introduction of weaknesses in security software?

  • A. Applying patches
  • B. Backing up files
  • C. Upgrading hardware
  • D. Changing access rules

Answer: D

Explanation:
Security software will generally have a well-controlled process for applying patches, backing up files and upgrading hardware. The greatest risk occurs when access rules are changed since they are susceptible to being opened up too much, which can result in the creation of a security exposure.

 

NEW QUESTION 609
To BEST improve the alignment of the information security objectives in an organization, the chief information security officer (CISO) should:

  • A. conduct regular user awareness sessions.
  • B. perform penetration tests.
  • C. evaluate a balanced business scorecard.
  • D. revise the information security program.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The balanced business scorecard can track the effectiveness of how an organization executes it information security strategy and determine areas of improvement. Revising the information security program may be a solution, but is not the best solution to improve alignment of the information security objectives. User awareness is just one of the areas the organization must track through the balanced business scorecard. Performing penetration tests does not affect alignment with information security objectives.

 

NEW QUESTION 610
Which of the following is the BEST approach for improving information security management processes?

  • A. Survey business units for feedback.
  • B. Define and monitor security metrics.
  • C. Conduct periodic security audits.
  • D. Perform periodic penetration testing.

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Defining and monitoring security metrics is a good approach to analyze the performance of the security management process since it determines the baseline and evaluates the performance against the baseline to identify an opportunity for improvement. This is a systematic and structured approach to process improvement. Audits will identify deficiencies in established controls; however, they are not effective in evaluating the overall performance for improvement. Penetration testing will only uncover technical vulnerabilities, and cannot provide a holistic picture of information security management, feedback is subjective and not necessarily reflective of true performance.

 

NEW QUESTION 611
The main mail server of a financial institution has been compromised at the superuser level; the only way to ensure the system is secure would be to:

  • A. implement multifactor authentication.
  • B. change the root password of the system.
  • C. disconnect the mail server from the network.
  • D. rebuild the system from the original installation medium.

Answer: D

Explanation:
Rebuilding the system from the original installation medium is the only way to ensure all security vulnerabilities and potential stealth malicious programs have been destroyed. Changing the root password of the system does not ensure the integrity of the mail server. Implementing multifactor authentication is an aftermeasure and does not clear existing security threats. Disconnecting the mail server from the network is an initial step, but does not guarantee security.

 

NEW QUESTION 612
During the establishment of a service level agreement (SLA) with a cloud service provider, it is MOST important for the information security manager to:

  • A. ensure security requirements are contractually enforceable.
  • B. understand the cloud storage architecture in use to determine security risk.
  • C. set up proper communication paths with the provider.
  • D. update the security policy to reflect the provider's terms of service.

Answer: A

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 613
Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?

  • A. Identifying critical business processes
  • B. Identifying key business risks
  • C. Identifying risk mitigation options
  • D. Identifying the threat environment

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 614
Which of the following is the MAIN objective of classifying a security incident as soon as it is discovered?

  • A. Engaging appropriate resources
  • B. Preserving relevant evidence
  • C. Enabling appropriate incident investigation
  • D. Downgrading the impact of the incident

Answer: A

 

NEW QUESTION 615
System logs and audit logs for sensitive systems should be stored

  • A. on a shared Internal server
  • B. on a cold site server.
  • C. In an encrypted folder on each server.
  • D. on a dedicated encrypted storage server,

Answer: D

 

NEW QUESTION 616
When establishing the trigger levels for an organization's key risk indicators (KRIs), the thresholds should be based PRIMARILY on the organization's:

  • A. risk appetite.
  • B. risk register.
  • C. current threat level.
  • D. risk response capability.

Answer: A

 

NEW QUESTION 617
A benefit of using a full disclosure (white box) approach as compared to a blind (black box) approach to penetration testing is that:

  • A. it simulates the real-1ife situation of an external security attack.
  • B. less time is spent on reconnaissance and information gathering.
  • C. critical infrastructure information is not revealed to the tester.
  • D. human intervention is not required for this type of test.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Data and information required for penetration are shared with the testers, thus eliminating time that would otherwise have been spent on reconnaissance and gathering of information. Blind (black box) penetration testing is closer to real life than full disclosure (white box) testing. There is no evidence to support that human intervention is not required for this type of test. A full disclosure (white box) methodology requires the knowledge of the subject being tested.

 

NEW QUESTION 618
For workstations used to facilitate a forensic investigation it is MOST important to ensure

  • A. The workstations are backup up and hardened on a regular basis
  • B. a documented chain of custody log is kept for the workstations.
  • C. only forensics-related software is installed on the workstations
  • D. the workstations are only accessed by members of the forensics team

Answer: B

 

NEW QUESTION 619
An information security manager is concerned that executive management does not support information security initiatives. Which of the following is the BEST way to address this situation?

  • A. Report the risk and status of the information security program to the board.
  • B. Escalate noncompliance concerns to the internal audit manager
  • C. Revise the information security strategy to meet executive management's expectations.
  • D. Demonstrate alignment of the information security function with business needs.

Answer: D

 

NEW QUESTION 620
A multinational organization wants to monitor outbound traffic for data leakage from the use of unapproved cloud services. Which of the following should be the information security manager's GREATEST consideration when implementing this control?

  • A. Security of cloud services
  • B. Data privacy regulations
  • C. Resistance from business users
  • D. Allocation of monitoring resources

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 621
An information security manager must understand the relationship between information security and business operations in order to:

  • A. support organizational objectives.
  • B. understand the threats to the business.
  • C. determine likely areas of noncompliance.
  • D. assess the possible impacts of compromise.

Answer: A

Explanation:
Explanation
Security exists to provide a level of predictability for operations, support for the activities of the organization and to ensure preservation of the organization. Business operations must be the driver for security activities in order to set meaningful objectives, determine and manage the risks to those activities, and provide a basis to measure the effectiveness of and provide guidance to the security program. Regulatory compliance may or may not be an organizational requirement. If compliance is a requirement, some level of compliance must be supported but compliance is only one aspect. It is necessary to understand the business goals in order to assess potential impacts and evaluate threats. These are some of the ways in which security supports organizational objectives, but they are not the only ways.

 

NEW QUESTION 622
Which of the following is characteristic of decentralized information security management across a geographically dispersed organization?

  • A. Better adherence to policies
  • B. More savings in total operating costs
  • C. Better alignment to business unit needs
  • D. More uniformity in quality of service

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Decentralization of information security management generally results in better alignment to business unit needs. It is generally more expensive to administer due to the lack of economies of scale. Uniformity in quality of service tends to vary from unit to unit.

 

NEW QUESTION 623
Which of the following practices is BEST to remove system access for contractors and other temporary users when it is no longer required?

  • A. Log all account usage and send it to their manager
  • B. Establish predetermined automatic expiration dates
  • C. Require managers to e-mail security when the user leaves
  • D. Ensure each individual has signed a security acknowledgement

Answer: B

Explanation:
Explanation
Predetermined expiration dates are the most effective means of removing systems access for temporary users.
Reliance on managers to promptly send in termination notices cannot always be counted on, while requiring each individual to sign a security acknowledgement would have little effect in this case.

 

NEW QUESTION 624
......


Who should take the CISM exam

The ISACA Certified Information Security Manager CISM Exam certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled as Certified Information Security Manager. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The ISACA Certified Information Security Manager CISM Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge and skills that are required to pass the ISACA Certified Information Security Manager CISM Exam then he should take this exam.

 

New (2022) ISACA CISM  Exam Dumps: https://www.torrentvce.com/CISM-valid-vce-collection.html

Best Way To Study For ISACA CISM Exam Brilliant CISM Exam Questions PDF: https://drive.google.com/open?id=1Li3KZXySVrOlbiqevv00ZfG55dmbIBjx