2022 CISM Question Bank Free PDF Download Recently Updated Questions [Q250-Q275]

Share

2022 CISM Question Bank: Free PDF Download Recently Updated Questions

CISM Certification Exam Dumps with 1340 Practice Test Questions


ISACA CISM: What exam details should you know?

The CISM certification exam usually lasts about 4 hours and contains 150 questions. The test has the multiple-choice format, and there are no negative points if you choose an incorrect answer. However, the correct ones are nullified within the same question. Thus, you should choose only the answers you are sure about. Each of the questions has a different score, depending on how difficult it is. You need to have the score of more than 450 points out of 800 to pass the exam successfully. The test is available in Simplified Chinese, English, Japanese, and Spanish. The exam voucher will cost you $760 or $575 if you enroll for membership.

 

NEW QUESTION 250
Which of the following would be the BEST way for a company to reduce the risk of data loss resulting from employee-owned devices accessing the corporate email system?

  • A. Require employees to install a reputable mobile anti-virus solution on their personal devices.
  • B. Link the bring-your-own-device (BYOD) policy to the existing staff disciplinary policy.
  • C. Require employees to undergo training before permitting access to the corporate email service.
  • D. Use a mobile device management (MDM) solution to isolate the local corporate email storage.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 251
The MOST important reason to have a well-documented and tested incident response plan in place is to:

  • A. promote a coordinated effort.
  • B. outline external communications
  • C. facilitate the escalation process
  • D. standardize the chain of custody procedure

Answer: A

 

NEW QUESTION 252
Which of the following is the MOST important consideration when securing customer credit card data acquired by a point-of-sale (POS) cash register?

  • A. Hardening
  • B. Authentication
  • C. Nonrepudiation
  • D. Encryption

Answer: D

Explanation:
Cardholder data should be encrypted using strong encryption techniques. Hardening would be secondary in importance, while nonrepudiation would not be as relevant. Authentication of the point-of-sale (POS) terminal is a previous step to acquiring the card information.

 

NEW QUESTION 253
When an information security manager presents an information security program status report to senior management, the MAIN focus should be:

  • A. key performance indicators (KPIs).
  • B. critical risks indicators.
  • C. net present value (NPV).
  • D. key controls evaluation.

Answer: A

 

NEW QUESTION 254
Which of the following is the BEST way for an information security manager to protect against a zero-day attack?

  • A. Implement heuristic-based monitoring tools
  • B. Perform a business impact analysis (BIA).
  • C. Conduct vulnerability scans on a daily basis.
  • D. Configure daily runs of the virus protection software.

Answer: A

 

NEW QUESTION 255
A legacy application does not comply with new regulatory requirements to encrypt sensitive data at rest, and remediating this issue would require significant investment. What should the information security manager do FIRST?

  • A. Present the noncompliance risk to senior management.
  • B. Investigate alternative options to remediate the noncompliance.
  • C. Determine the cost to remediate the noncompliance.
  • D. Assess the business impact to the organization.

Answer: B

 

NEW QUESTION 256
What is the PRIMARY purpose of communicating business impact to an incident response team?

  • A. To provide monetary values for post-incident review
  • B. To provide information for communication of incidents
  • C. To facilitate resource allocation tor preventive measures
  • D. To enable effective prioritization of incidents

Answer: A

 

NEW QUESTION 257
Risk assessment should be built into which of the following systems development phases to ensure that risks are addressed in a development project?

  • A. User testing
  • B. Feasibility
  • C. Programming
  • D. Specification

Answer: B

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Risk should be addressed as early as possible in the development cycle. The feasibility study should include risk assessment so that the cost of controls can be estimated before the project proceeds. Risk should also be considered in the specification phase where the controls are designed, but this would still be based on the assessment carried out in the feasibility study. Assessment would not be relevant in choice A or C.

 

NEW QUESTION 258
Which of the following is the PRIMARY advantage of desk checking a business continuity plan (BCP)?

  • A. Allows for greater participation be management and the IT department
  • B. Assesses the availability and compatibility a backup hardware
  • C. Ensures that appropriate follow-up work is performed on noted issues
  • D. Provides a low-cost method of assessing the BCP's completeness

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:

 

NEW QUESTION 259
Priority should be given to which of the following to ensure effective implementation of information security governance?

  • A. Consultation
  • B. Planning
  • C. Facilitation
  • D. Negotiation

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Planning is the key to effective implementation of information security governance. Consultation, negotiation and facilitation come after planning.

 

NEW QUESTION 260
Which of the following ensures that newly identified security weaknesses in an operating system are mitigated in a timely fashion?

  • A. Patch management
  • B. Change management
  • C. Acquisition management
  • D. Security baselines

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Patch management involves the correction of software weaknesses and helps ensure that newly identified exploits are mitigated in a timely fashion. Change management controls the process of introducing changes to systems. Security baselines provide minimum recommended settings. Acquisition management controls the purchasing process.

 

NEW QUESTION 261
The MOST important objective of a post incident review is to:

  • A. develop a process for continuous improvement.
  • B. capture lessons learned to improve the process.
  • C. identify new incident management tools.
  • D. develop a business case for the security program budget.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The main purpose of a post incident review is to identify areas of improvement in the process. Developing a process for continuous improvement is not true in every case. Developing a business case for the security program budget and identifying new incident management tools may come from the analysis of the incident, but are not the key objectives.

 

NEW QUESTION 262
The PRIMARY objective of periodically testing an incident response plan should be to:

  • A. improve internal processes and procedures,
  • B. improve employee awareness of the incident response process,
  • C. harden the technical infrastructure.
  • D. highlight the importance of incident response and recovery.

Answer: D

 

NEW QUESTION 263
Which of the following is the MOST appropriate method to protect a password that opens a confidential file?

  • A. Digital signatures
  • B. Delivery path tracing
  • C. Out-of-band channels
  • D. Reverse lookup translation

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Out-of-band channels are useful when it is necessary, for confidentiality, to break a message into two parts that are then sent by different means. Digital signatures only provide nonrepudiation. Reverse lookup translation involves converting ;in Internet Protocol (IP) address to a username. Delivery path tracing shows the route taken but does not confirm the identity of the sender.

 

NEW QUESTION 264
Which of the following is the GREATEST benefit of information asset classification to an organization?

  • A. It helps to optimize the investment in protecting information assets.
  • B. It measures qualitative value of the information.
  • C. It helps to minimize the cost of regulatory compliance efforts
  • D. It demonstrates the value of information assets for financial reporting.

Answer: A

 

NEW QUESTION 265
To justify the need to invest in a forensic analysis tool, an information security manager should FIRST:

  • A. provide examples of situations where such a tool would be useful.
  • B. review comparison reports of tool implementation in peer companies.
  • C. substantiate the investment in meeting organizational needs.
  • D. review the functionalities and implementation requirements of the solution.

Answer: C

Explanation:
Explanation
Any investment must be reviewed to determine whether it is cost effective and supports the organizational strategy. It is important to review the features and functionalities provided by such a tool, and to provide examples of situations where the tool would be useful, but that comes after substantiating the investment and return on investment to the organization.

 

NEW QUESTION 266
The PRIMARY purpose of aligning information security with corporate governance objectives is to:

  • A. consistently manage significant areas of risk.
  • B. re-align roles and responsibilities.
  • C. identify an organization's tolerance for risk.
  • D. build capabilities to improve security processes.

Answer: D

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 267
After a risk assessment, it is determined that the cost to mitigate the risk is much greater than the benefit to be derived. The information security manager should recommend to business management that the risk be:

  • A. transferred.
  • B. accepted.
  • C. terminated.
  • D. treated.

Answer: B

Explanation:
When the cost of control is more than the cost of the risk, the risk should be accepted. Transferring, treating or terminating the risk is of limited benefit if the cost of that control is more than the cost of the risk itself.

 

NEW QUESTION 268
Risk identification, analysis, and mitigation activities can BEST be integrated into business life cycle processes by linking them to:

  • A. compliance testing
  • B. continuity planning
  • C. configuration management
  • D. change management

Answer: C

Explanation:
Section: INFORMATION RISK MANAGEMENT

 

NEW QUESTION 269
Which of the following is the BEST

  • A. Managing user profiles for accessing the operating system
  • B. Provisioning users to access the operating system
  • C. Logging unauthorized access to the operating system
  • D. Approving standards for accessing the operating system

Answer: A

 

NEW QUESTION 270
Which of the following would help management determine the resources needed to mitigate a risk to the organization?

  • A. Business impact analysis (BIA)
  • B. Risk-based audit program
  • C. Risk management balanced scorecard
  • D. Risk analysis process

Answer: A

Explanation:
The business impact analysis (BIA) determines the possible outcome of a risk and is essential to determine the appropriate cost of control. The risk analysis process provides comprehensive data, but does not determine definite resources to mitigate the risk as does the BIA. The risk management balanced scorecard is a measuring tool for goal attainment. A risk-based audit program is used to focus the audit process on the areas of greatest importance to the organization.

 

NEW QUESTION 271
Which of the following is the MOST effective method for assessing the effectiveness of a security awareness program?

  • A. Post-incident review
  • B. Vulnerability scan
  • C. Tabletop test
  • D. Social engineering test

Answer: D

 

NEW QUESTION 272
Which of the following metrics would provide management with the MOST useful information about the progress of a security awareness program?

  • A. Increased reported of security incidents
  • B. Completion rate of user awareness training within each business unit
  • C. Decreased number of security incidents
  • D. Increased number of downloads of the organization's security policy

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT

 

NEW QUESTION 273
Which of the following is the BEST way to integrate information security into corporate governance?

  • A. Conduct comprehensive information security management training for key stakeholders.
  • B. Require periodic security risk assessments be performed.
  • C. Ensure information security processes are part of the existing management processes.
  • D. Engage external security consultants in security initiatives.

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 274
What is the BEST technique to determine which security controls to implement with a limited budget?

  • A. Annualized loss expectancy (ALE) calculations
  • B. Cost-benefit analysis
  • C. Risk analysis
  • D. Impact analysis

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Cost-benefit analysis is performed to ensure that the cost of a safeguard does not outweigh it's benefit and that the best safeguard is provided for the cost of implementation. Risk analysis identifies the risks and suggests appropriate mitigation. The annualized loss expectancy (ALE) is a subset of a cost-benefit analysis. Impact analysis would indicate how much could be lost if a specific threat occurred.

 

NEW QUESTION 275
......


Certification Path

The Certified Information Security Manager CISM certification includes only one CISM exams.

 

New CISM Exam Dumps with High Passing Rate: https://www.pass4suresvce.com/CISM-pass4sure-vce-dumps.html

ISACA CISM Actual Questions and Braindumps: https://drive.google.com/open?id=1St-J81eH8eg5k2IFfR4h0W_BQGbroxKQ