
VALID CISM Exam Dumps For Certification Exam Preparation
CISM Dumps PDF 2025 Strategy Your Preparation Efficiently
NEW QUESTION # 125
Which of the following should an information security manager do FIRST after discovering that a business unit has implemented a newly purchased application and bypassed the change management process?
- A. Remove the application from production.
- B. Discuss the issue with senior leadership.
- C. Update the change management process.
- D. Revise the procurement process.
Answer: B
Explanation:
An information security manager should first discuss the issue with senior leadership to escalate the problem and seek their support and guidance. Bypassing the change management process can introduce significant risks to the organization, such as unauthorized access, data loss, system instability, or compliance violations.
The information security manager should explain the potential impact and consequences of the incident, and recommend corrective actions to remediate the situation. The information security manager should also review the root cause of the incident and identify any gaps or weaknesses in the existing policies, procedures, or controls that allowed the business unit to implement the new application without proper authorization, testing, or documentation. The information security manager should then revise the procurement process, update the change management process, or implement other measures to prevent similar incidents from occurring in the future. Removing the application from production may not be feasible or desirable, depending on the business needs and the severity of the risks involved. References = CISM Review Manual,
16th Edition, pages 100-1011; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page
2692
Learn more:
1. isaca.org2. amazon.com3. gov.uk
NEW QUESTION # 126
Which of the following BEST enables an organization to transform its culture to support information security?
- A. Incentives for security incident reporting
- B. Periodic compliance audits
- C. Strong management support
- D. Robust technical security controls
Answer: C
Explanation:
Explanation
According to the CISM Review Manual (Digital Version), page 5, information security culture is the set of values, attitudes, and behaviors that shape how an organization and its employees view and practice information security. Transforming the information security culture requires a change management process that involves the following steps: creating a sense of urgency, forming a powerful coalition, developing a vision and strategy, communicating the vision, empowering broad-based action, generating short-term wins, consolidating gains and producing more change, and anchoring new approaches in the culture1. Among the four options, strong management support is the best enabler for transforming the information security culture, as it can provide the necessary leadership, resources, sponsorship, and alignment for the change management process. Periodic compliance audits, robust technical security controls, and incentives for security incident reporting are important elements of information security, but they are not sufficient to change the culture without strong management support. References = 1: CISM Review Manual (Digital Version), page 5
NEW QUESTION # 127
Which of the following practices is MOST effective for determining the adequacy of incident management operations?
- A. Assessing incident response team members' incident response skills
- B. Testing current incident response plans with relevant stakeholders
- C. Reviewing incident response procedures against best practices
- D. Conducting unannounced external vulnerability testing
Answer: B
NEW QUESTION # 128
Which of the following analyses will BEST identify the external influences to an organization's information security?
- A. Threat analysis
- B. Gap analysis
- C. Business impact analysis
- D. Vulnerability analysis.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 129
Which of the following is a MAIN security challenge when conducting a post-incident review related to bring your own device (BYOD) in a mature, diverse organization?
- A. Ability to access device remotely
- B. Ability to obtain possession of device
- C. Diversity of operating systems
- D. Lack of mobile forensics expertise
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION # 130
Which of the following is PRIMARILY determined by asset classification?
- A. Replacement cost of assets
- B. Level of protection required for assets
- C. Insurance coverage required for assets
- D. Priority for asset replacement
Answer: B
Explanation:
Explanation
Asset classification is the process of assigning a value to information assets based on their importance to the organization and the potential impact of their compromise, loss or damage1. Asset classification helps to determine the level of protection required for assets, which is proportional to their value and sensitivity2. Asset classification also facilitates risk assessment and management, as well as compliance with legal, regulatory and contractual requirements3. Asset classification does not primarily determine the insurance coverage, priority for replacement, or replacement cost of assets, as these factors depend on other criteria such as risk appetite, business impact, availability and market value4. References = 1: CISM - Information Asset Classification Flashcards | Quizlet 2: CISM Exam Content Outline | CISM Certification | ISACA 3: CIS Control 1: Inventory and Control of Enterprise Assets 4: CISSP versus the CISM Certification | ISC2
NEW QUESTION # 131
Which of the following is the BEST way to prevent employees from making unauthorized comments to the media about security incidents in progress?
- A. Communicate potential disciplinary actions for noncompliance.
- B. Include communication policies In regular information security training
- C. Establish standard media responses for employees to control the message
- D. training Implement controls to prevent discussion with media during an Incident.
Answer: B
NEW QUESTION # 132
In an organization implementing a data classification program, ultimate responsibility for the data on the database server lies with the:
- A. information technology manager
- B. information security manager
- C. database administrator (DBA).
- D. business unit manager.
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION # 133
Which of the following will identify a deviation in the information security management process from generally accepted standards of good practices?
- A. Gap analysis
- B. Risk assessment
- C. Penetration testing
- D. Business impact analysis (BIA)
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 134
Which of the following presents the GREATEST concern to the information security manager when using account locking features on an online application? It can increase vulnerability to.
- A. social engineering.
- B. denial of service.
- C. brute force attacks.
- D. phishing.
Answer: B
NEW QUESTION # 135
A software vendor has announced a zero-day vulnerability that exposes an organization's critical business systems, following should be the information security manager's PRIMARY concern?
- A. Ability to test patches prior to deployment
- B. Adequacy of the incident response plan
- C. Availability of resources to implement controls
- D. Business tolerance of downtime
Answer: C
Explanation:
Section: INFORMATION RISK MANAGEMENT
NEW QUESTION # 136
An organization's board of directors has learned of recent legislation requiring organizations within the industry to enact specific safeguards to protect confidential customer information. What actions should the board take next?
- A. Nothing; information security does not report to the board
- B. Direct information security on what they need to do
- C. Research solutions to determine the proper solutions
- D. Require management to report on compliance
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Information security governance is the responsibility of the board of directors and executive management.
In this instance, the appropriate action is to ensure that a plan is in place for implementation of needed safeguards and to require updates on that implementation.
NEW QUESTION # 137
To determine the selection of controls required to meet business objectives, an information security manager should:
- A. restrict controls to only critical applications.
- B. focus on key controls.
- C. prioritize the use of role-based access controls.
- D. focus on automated controls.
Answer: B
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Key controls primarily reduce risk and are most effective for the protection of information assets. The other choices could be examples of possible key controls.
NEW QUESTION # 138
Which of the following outsourced services has the GREATEST need for security monitoring?
- A. Virtual private network (VPN) services
- B. Application development
- C. Enterprise infrastructure
- D. Web site hosting
Answer: C
NEW QUESTION # 139
To achieve effective strategic alignment of security initiatives, it is important that:
- A. Inputs be obtained and consensus achieved between the major organizational units.
- B. The business strategy be updated periodically.
- C. Steering committee leadership be selected by rotation.
- D. Procedures and standards be approved by all departmental heads.
Answer: A
Explanation:
It is important to achieve consensus on risks and controls, and obtain inputs from various organizational entities since security needs to be aligned to the needs of the organization. Rotation of steering committee leadership does not help in achieving strategic alignment. Updating business strategy does not lead to strategic alignment of security initiatives. Procedures and standards need not be approved by all departmental heads
NEW QUESTION # 140
Which of the following is the MOST important information to include in an information security standard?
- A. Last review date
- B. Initial draft approval date
- C. Author name
- D. Creation date
Answer: A
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The last review date confirms the currency of the standard, affirming that management has reviewed the standard to assure that nothing in the environment has changed that would necessitate an update to the standard. The name of the author as well as the creation and draft dates are not that important.
NEW QUESTION # 141
Which of the following is MOST likely to increase end user security awareness in an organization?
- A. A dedicated channel for reporting suspicious emails
- B. Red team penetration testing
- C. Simulated phishing attacks
- D. Security objectives included in job descriptions
Answer: D
NEW QUESTION # 142
An information security manager has been notified about a compromised endpoint device Which of the following is the BEST course of action to prevent further damage?
- A. Wipe and reset the endpoint device.
- B. Run a virus scan on the endpoint device.
- C. Isolate the endpoint device.
- D. Power off the endpoint device.
Answer: C
Explanation:
Explanation
The best course of action to prevent further damage is to isolate the endpoint device. Isolating the endpoint device will prevent the compromised system from connecting to other systems on the network and spreading the infection. Other possible courses of action include wiping and resetting the endpoint device, running a virus scan, and powering off the endpoint device. However, these actions will not prevent the compromised system from continuing to spread the infection.
NEW QUESTION # 143
Security technologies should be selected PRIMARILY on the basis of their:
- A. use of new and emerging technologies.
- B. ability to mitigate business risks.
- C. evaluations in trade publications.
- D. benefits in comparison to their costs.
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The most fundamental evaluation criterion for the appropriate selection of any security technology is its ability to reduce or eliminate business risks. Investments in security technologies should be based on their overall value in relation to their cost; the value can be demonstrated in terms of risk mitigation. This should take precedence over whether they use new or exotic technologies or how they are evaluated in trade publications.
NEW QUESTION # 144
Which of the following would be of GREATEST assistance in determining whether to accept residual risk of a critical security system?
- A. Cost-benefit analysis of mitigating controls
- B. Recovery time objective (RTO)
- C. Available annual budget
- D. Maximum tolerable outage (MTO)
Answer: A
NEW QUESTION # 145
A digital signature using a public key infrastructure (PKI) will:
- A. require two parties to the message exchange.
- B. rely on the extent to which the certificate authority (CA) is trusted.
- C. provide a high level of confidentiality.
- D. not ensure the integrity of a message.
Answer: B
Explanation:
The certificate authority (CA) is a trusted third party that attests to the identity of the signatory, and reliance will be a function of the level of trust afforded the CA. A digital signature would provide a level of assurance of message integrity, but it is a three-party exchange, including the CA. Digital signatures do not require encryption of the message in order to preserve confidentiality.
NEW QUESTION # 146
Which of the following devices should be placed within a DMZ?
- A. Firewall
- B. Authentication server
- C. Mail relay
- D. Router
Answer: C
Explanation:
Explanation/Reference:
Explanation:
A mail relay should normally be placed within a demilitarized zone (DMZ) to shield the internal network. An authentication server, due to its sensitivity, should always be placed on the internal network, never on a DMZ that is subject to compromise. Both routers and firewalls may bridge a DMZ to another network, but do not technically reside within the DMZ, network segment.
NEW QUESTION # 147
An organization's IT department needs to implement security patches. Recent reports indicate these patches could result in stability issues. Which of the following is the information security manager's BEST recommendation?
- A. Research compensating security controls.
- B. Evaluate the patches in a test environment.
- C. Increase monitoring after patch implementation.
- D. Research alternative software solutions,
Answer: B
NEW QUESTION # 148
After a ransomware incident an organization's systems were restored. Which of the following should be of MOST concern to the information security manager?
- A. Notification to stakeholders was delayed.
- B. The root cause was not identified.
- C. The recovery time objective (RTO) was not met.
- D. The service level agreement (SLA) was not met.
Answer: B
NEW QUESTION # 149
......
Difficulty in writing CISM Exam
ISACA CISM exam help Candidates in developing their professionals and academic career and It is a very tough task to pass ISACA CISM exam for those Candidates who have not done hard work and get some relevant ISACA CISM exam preparation material. There are many peoples have passed ISACA CISM exam by following these three things such as look for the latest ISACA CISM exam dumps, get relevant ISACA CISM exam dumps and develop their knowledge about ISACA CISM exam new questions. At the same time, it can also stress out some people as they found passing ISACA CISM exam a tough task. It is just a wrong assumption as many of the peoples have passed ISACA CISM exam questions. All you have to do is to work hard, get some relevant ISACA CISM exam preparation material and go thoroughly from them. TorrentVCE is here to help you with this problem. We have the relevant ISACA CISM exam preparation material which are providing the latest ISACA CISM exam questions with the detailed view of every ISACA CISM exam topic. TorrentVCE offered an ISACA CISM exam dumps which are more than enough to pass the ISACA CISM exam questions. We are providing all thing such as ISACA CISM exam dumps, ISACA CISM practice test, and ISACA CISM pdf exam dumps that will help the candidate to pass the exam with good grades.
Latest Verified & Correct CISM Questions: https://www.torrentvce.com/CISM-valid-vce-collection.html
100% Pass Guaranteed Download Isaca Certification Exam PDF Q&A: https://drive.google.com/open?id=1iBuelmaV7xtKJVvBkI7IbZj-UVaVMYGL