
Latest CISM Study Guides 2023 - With Test Engine PDF
Get New CISM Practice Test Questions Answers
NEW QUESTION 53
Which of the following would be MOST helpful when justifying the funding required for a compensating control?
- A. Threat assessment
- B. Business impact analysis
- C. Business case
- D. Risk analysis
Answer: C
NEW QUESTION 54
A good privacy statement should include:
- A. a description of the information classification process.
- B. what the company will do with information it collects.
- C. notification of liability on accuracy of information.
- D. notification that information will be encrypted.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Most privacy laws and regulations require disclosure on how information will be used. Choice A is incorrect because that information should be located in the web site's disclaimer. Choice B is incorrect because, although encryption may be applied, this is not generally disclosed. Choice D is incorrect because information classification would be contained in a separate policy.
NEW QUESTION 55
Which of the following would BEST help to ensure an organization's security program is aligned with business objectives?
- A. Security policies are reviewed and approved by the chief information officer.
- B. The organization's board of directors includes a dedicated information security specialist.
- C. The security strategy is reviewed and approved by the organization's executive committee.
- D. Project managers receive annual information security awareness training.
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 56
In a cloud technology environment, which of the following would pose the GREATEST challenge to the investigation of security incidents?
- A. Non-standard event logs
- B. Data encryption
- C. Compressed customer data
- D. Access to the hardware
Answer: D
NEW QUESTION 57
What should the information security manager do FIRST when end users express that new security controls are too restrictive?
- A. Perform a cost-benefit analysis on modifying the control environment
- B. Conduct a business impact analysis (BIA)
- C. Obtain process owner buy-in to remove the controls
- D. Perform a risk assessment on modifying the control environment
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference:
NEW QUESTION 58
Which of the following would be the MOST significant security risk in a pharmaceutical institution?
- A. Compromised customer information
- B. Theft of a Research and Development laptop
- C. Unavailability of online transactions
- D. Theft of security tokens
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The research and development department is usually the most sensitive area of the pharmaceutical organization, Theft of a laptop from this area could result in the disclosure of sensitive formulas and other intellectual property which could represent the greatest security breach. A pharmaceutical organization does not normally have direct contact with end customers and their transactions are not time critical:
therefore, compromised customer information and unavailability of online transactions are not the most significant security risks. Theft of security tokens would not be as significant since a pin would still be required for their use.
NEW QUESTION 59
A global organization has developed a strategy to share a customer information database between offices in two countries. In this situation, it is MOST important to ensure:
- A. data sharing complies with local laws and regulations at both locations.
- B. a nondisclosure agreement is signed.
- C. data is encrypted in transit and at rest
- D. risk coverage is split between the two locations sharing data.
Answer: A
NEW QUESTION 60
Which of the following would be the MOST important goal of an information security governance program?
- A. Review of internal control mechanisms
- B. Effective involvement in business decision making
- C. Total elimination of risk factors
- D. Ensuring trust in data
Answer: D
Explanation:
The development of trust in the integrity of information among stakeholders should be the primary goal of information security governance. Review of internal control mechanisms relates more to auditing, while the total elimination of risk factors is not practical or possible. Proactive involvement in business decision making implies that security needs dictate business needs when, in fact, just the opposite is true. Involvement in decision making is important only to ensure business data integrity so that data can be trusted.
NEW QUESTION 61
An internal review of a web-based application system finds the ability to gain access to all employees' accounts by changing the employee's ID on the URL used for accessing the account. The vulnerability identified is:
- A. cross-site scripting.
- B. broken authentication.
- C. structured query language (SQL) injection.
- D. unvalidated input.
Answer: B
Explanation:
The authentication process is broken because, although the session is valid, the application should reauthenticate when the input parameters are changed. The review provided valid employee IDs, and valid input was processed. The problem here is the lack of reauthentication when the input parameters are changed. Cross-site scripting is not the problem in this case since the attack is not transferred to any other user's browser to obtain the output. Structured query language (SQL) injection is not a problem since input is provided as a valid employee ID and no SQL queries are injected to provide the output.
NEW QUESTION 62
To effectively manage an organization's information security risk, it is MOST important to:
- A. establish and communicate risk tolerance
- B. assign risk management responsibility to end users
- C. benchmark risk scenarios against peer organizations
- D. periodically identify and correct new systems vulnerabilities
Answer: D
Explanation:
Section: INFORMATION RISK MANAGEMENT
NEW QUESTION 63
Which of the following BEST indicates an effective vulnerability management program?
- A. Vulnerabilities are managed proactively.
- B. Risks are managed within acceptable limits.
- C. Vulnerabilities are reported in a timely manner.
- D. Threats are identified accurately.
Answer: A
NEW QUESTION 64
The FIRST step in developing an information security management program is to:
- A. identify business risks that affect the organization.
- B. clarify organizational purpose for creating the program.
- C. assign responsibility for the program.
- D. assess adequacy of controls to mitigate business risks.
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
In developing an information security management program, the first step is to clarify the organization's purpose for creating the program. This is a business decision based more on judgment than on any specific quantitative measures. After clarifying the purpose, the other choices are assigned and acted upon.
NEW QUESTION 65
An unauthorized user gained access to a merchant's database server and customer credit card information. Which of the following would be the FIRST step to preserve and protect unauthorized intrusion activities?
- A. Duplicate the hard disk of the server immediately.
- B. Copy the database log file to a protected server.
- C. Shut down and power off the server.
- D. Isolate the server from the network.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Isolating the server will prevent further intrusions and protect evidence of intrusion activities left in memory and on the hard drive. Some intrusion activities left in virtual memory may be lost if the system is shut down. Duplicating the hard disk will only preserve the evidence on the hard disk, not the evidence in virtual memory, and will not prevent further unauthorized access attempts. Copying the database log file to a protected server will not provide sufficient evidence should the organization choose to pursue legal recourse.
NEW QUESTION 66
What is the FIRST action an information security manager should take when a company laptop is reported stolen?
- A. Update the corporate laptop inventory
- B. Evaluate the impact of the information loss
- C. Disable the user account immediately
- D. Ensure compliance with reporting procedures
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The key step in such an incident is to report it to mitigate any loss. After this, the other actions should follow.
NEW QUESTION 67
Which of the following is the MOST important criterion when deciding whether to accept residual risk?
- A. Cost of additional mitigation
- B. Annual loss expectancy (ALE)
- C. Cost of replacing the asset
- D. Annual rate of occurrence (ARO)
Answer: C
NEW QUESTION 68
......
CISM Dumps and Exam Test Engine: https://lead2pass.troytecdumps.com/CISM-troytec-exam-dumps.html