Check the Available CISM Exam Dumps with 672 QA's UPDATED 2024 [Q365-Q387]

Share

Check the Available CISM Exam Dumps with 672 QA's UPDATED 2024

Download CISM Exam Dumps Questions to get 100% Success in ISACA 


The CISM exam is recognized by many organizations worldwide and is considered an essential certification for professionals seeking to advance their careers in information security management. Certified Information Security Manager certification is particularly relevant for information security managers, IT security professionals, risk management professionals, and compliance officers. The CISM certification is designed to demonstrate a professional's ability to effectively manage information security risks and provide value to their organization.


ISACA CISM (Certified Information Security Manager) exam is a globally recognized certification for professionals who manage, design, and oversee an organization's information security. CISM exam is designed to test the candidate's knowledge and understanding of information security management, risk management, incident management, and governance. Certified Information Security Manager certification is highly valued by employers as it validates the candidate's expertise in the field of information security.

 

NEW QUESTION # 365
A data leakage prevention (DLP) solution has identified that several employees are sending confidential company data to their personal email addresses in violation of company policy. The information security manager should FIRST:

  • A. notify senior management that employees are breaching policy
  • B. contact the employees involved to retake security awareness training
  • C. limit access to the Internet for employees involved
  • D. initiate an investigation to determine the full extent of noncompliance

Answer: D


NEW QUESTION # 366
Which of the following is the MOST important requirement for a successful security program?

  • A. Nondisclosure agreements (NDA) with employees
  • B. Penetration testing on key systems
  • C. Management decision on asset value
  • D. Mapping security processes to baseline security standards

Answer: C

Explanation:
"A successful security program requires management support and involvement. One of the key aspects of management support is to decide on the value of assets and the acceptable level of risk for them. This will help define the security objectives and priorities for the program. The other options are possible activities within a security program, but they are not as important as management decision on asset value."


NEW QUESTION # 367
Which of the following will MOST likely reduce the chances of an unauthorized individual gaining access to computing resources by pretending to be an authorized individual needing to have his, her password reset?

  • A. Increasing the frequency of password changes
  • B. Performing reviews of password resets
  • C. Conducting security awareness programs
  • D. Implementing automatic password syntax checking

Answer: C

Explanation:
Explanation
Social engineering can be mitigated best through periodic security awareness training for staff members who may be the target of such an attempt. Changing the frequency of password changes, strengthening passwords and checking the number of password resets may be desirable, but they will not be as effective in reducing the likelihood of a social engineering attack.


NEW QUESTION # 368
Risk assessment should be built into which of the following systems development phases to ensure that risks are addressed in a development project?

  • A. User testing
  • B. Programming
  • C. Feasibility
  • D. Specification

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Risk should be addressed as early as possible in the development cycle. The feasibility study should include risk assessment so that the cost of controls can be estimated before the project proceeds. Risk should also be considered in the specification phase where the controls are designed, but this would still be based on the assessment carried out in the feasibility study. Assessment would not be relevant in choice A or C.


NEW QUESTION # 369
Risk assessment is MOST effective when performed:

  • A. at the beginning of security program development.
  • B. during the business change process.
  • C. while developing the business case for the security program.
  • D. on a continuous basis.

Answer: D

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Risk assessment needs to be performed on a continuous basis because of organizational and technical changes. Risk assessment must take into account all significant changes in order to be effective.


NEW QUESTION # 370
Which of the following is the MOST important security consideration when developing an incident response strategy with a cloud provider?

  • A. Escalation processes
  • B. Technological capabilities
  • C. Security audit reports
  • D. Recovery time objective (RTO)

Answer: D


NEW QUESTION # 371
A security manager is preparing a report to obtain the commitment of executive management to a security program. Inclusion of which of the following would be of MOST value?

  • A. Examples of genuine incidents at similar organizations
  • B. Statement of generally accepted best practices
  • C. Associating realistic threats to corporate objectives
  • D. Analysis of current technological exposures

Answer: C

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Linking realistic threats to key business objectives will direct executive attention to them. All other options are supportive but not of as great a value as choice C when trying to obtain the funds for a new program.


NEW QUESTION # 372
Which of the following is the MOST effective solution for preventing internal users from modifying sensitive and classified information?

  • A. Role-based access controls
  • B. System access violation logs
  • C. Exit routines
  • D. Baseline security standards

Answer: A

Explanation:
Explanation
Role-based access controls help ensure that users only have access to files and systems appropriate for their job role. Violation logs are detective and do not prevent unauthorized access. Baseline security standards do not prevent unauthorized access. Exit routines are dependent upon appropriate role-based access.


NEW QUESTION # 373
Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?

  • A. Consistent execution of information security strategy
  • B. Optimized information security resources
  • C. Increased influence of security management
  • D. Improved accountability to shareholders

Answer: D


NEW QUESTION # 374
Which of the following is the MOST important reason to conduct interviews as part of the business impact analysis (BIA) process?

  • A. To increase awareness of information security among key stakeholders
  • B. To obtain input from as many relevant stakeholders as possible
  • C. To facilitate a qualitative risk assessment following the BIA
  • D. To ensure the stakeholders providing input own the related risk

Answer: B

Explanation:
Explanation
The most important reason to conduct interviews as part of the business impact analysis (BIA) process is to obtain input from as many relevant stakeholders as possible. A BIA is a process of identifying and analyzing the potential effects of disruptive events on the organization's critical business functions, processes, and resources. A BIA helps to determine the recovery priorities, objectives, and strategies for the organization's continuity planning. Interviews are one of the methods to collect data and information for the BIA, and they involve direct and interactive communication with the stakeholders who are involved in or affected by the business functions, processes, and resources. By conducting interviews, the information security manager can obtain input from as many relevant stakeholders as possible, such as business owners, managers, users, customers, suppliers, regulators, and partners. This can help to ensure that the BIA covers the full scope and complexity of the organization's business activities, and that the BIA reflects the accurate, current, and comprehensive views and expectations of the stakeholders. Interviews can also help to validate, clarify, and supplement the data and information obtained from other sources, such as surveys, questionnaires, documents, or systems. Interviews can also help to build rapport, trust, and collaboration among the stakeholders, and to increase their awareness, involvement, and commitment to the information security and continuity planning.
References = CISM Review Manual, 16th Edition, Chapter 3: Information Security Program Development and Management, Section: Business Impact Analysis (BIA), pages 178-1801; CISM Review Questions, Answers
& Explanations Manual, 10th Edition, Question 65, page 602.


NEW QUESTION # 375
Which of the following is the MOST appropriate method to protect a password that opens a confidential file?

  • A. Out-of-band channels
  • B. Reverse lookup translation
  • C. Delivery path tracing
  • D. Digital signatures

Answer: A

Explanation:
Explanation
Out-of-band channels are useful when it is necessary, for confidentiality, to break a message into two parts that are then sent by different means. Digital signatures only provide nonrepudiation. Reverse lookup translation involves converting; in Internet Protocol (IP) address to a username. Delivery path tracing shows the route taken but does not confirm the identity of the sender.


NEW QUESTION # 376
Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?

  • A. Security standards
  • B. Security policy
  • C. Risk appetite
  • D. Risk management framework

Answer: B


NEW QUESTION # 377
The FIRST step to create an internal culture that focuses on information security is to:

  • A. actively monitor operations.
  • B. conduct periodic awareness training.
  • C. gain the endorsement of executive management.
  • D. implement stronger controls.

Answer: C

Explanation:
Explanation
Endorsement of executive management in the form of policies provides direction and awareness. The implementation of stronger controls may lead to circumvention. Awareness training is important, but must be based on policies. Actively monitoring operations will not affect culture at all levels.


NEW QUESTION # 378
A risk assessment exercise has identified the threat of a denial of service (DoS) attack Executive management has decided to take no further action related to this risk. The MO ST likely reason for this decision is

  • A. executive management is not aware of the impact potential
  • B. the cost of implementing controls exceeds the potential financial losses.
  • C. the risk assessment has not defined the likelihood of occurrence
  • D. the reported vulnerability has not been validated

Answer: B

Explanation:
Executive management may not take action related to a risk if they have determined that the cost of implementing necessary controls to mitigate the risk exceeds the potential financial losses that the organization may incur if the risk were to materialize. In cases such as this, it is important for the information security team to provide the executive team with thorough cost-benefit analysis that outlines the cost of implementing the controls versus the expected losses from the risk.


NEW QUESTION # 379
Which of the following is the BEST reason for reevaluating an information security program?

  • A. Change in senior management
  • B. Ineffectiveness of the information security strategy execution
  • C. Misalignment between information security priorities and business objectives
  • D. Noncompliance with information security policies and procedures

Answer: C


NEW QUESTION # 380
Prior to implementing a bring your own device (BYOD) program, it is MOST important to:

  • A. survey employees for requested applications.
  • B. develop an acceptable use policy.
  • C. review currently utilized applications.
  • D. select mobile device management (MDM) software.

Answer: B

Explanation:
Explanation
Before implementing a BYOD program, it is most important to develop an acceptable use policy that defines the roles and responsibilities of the organization and the employees, the security requirements and controls for the devices, the acceptable and unacceptable behaviors and activities, and the consequences of non-compliance. This policy will help to establish a clear and consistent framework for managing the risks and benefits of BYOD.
References = CISM Review Manual, 16th Edition, page 197


NEW QUESTION # 381
The PRIMARY objective of a risk management program is to:

  • A. minimize inherent risk.
  • B. minimize residual risk.
  • C. implement effective controls.
  • D. eliminate business risk.

Answer: B

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
The goal of a risk management program is to ensure that residual risk remains within manageable levels.
Management of risk does not always require the removal of inherent risk nor is this always possible. A possible benefit of good risk management is to reduce insurance premiums, but this is not its primary intention.
Effective controls are naturally a clear objective of a risk management program, but with the choices given, choice C is an incomplete answer.


NEW QUESTION # 382
What should the information security manager do FIRST when end users express that new security controls are too restrictive?

  • A. Obtain process owner buy-in to remove the controls
  • B. Perform a cost-benefit analysis on modifying the control environment
  • C. Conduct a business impact analysis (BIA)
  • D. Perform a risk assessment on modifying the control environment

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation/Reference:


NEW QUESTION # 383
The MOST effective way to ensure that outsourced service providers comply with the organization's information security policy would be:

  • A. periodically auditing.
  • B. security awareness training.
  • C. service level monitoring.
  • D. penetration testing.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Regular audit exercise can spot any gap in the information security compliance. Service level monitoring can only pinpoint operational issues in the organization's operational environment. Penetration testing can identify security vulnerability but cannot ensure information compliance Training can increase users' awareness on the information security policy, but is not more effective than auditing.


NEW QUESTION # 384
The MOST important element in achieving executive commitment to an information security governance program is:

  • A. a defined security framework.
  • B. a process improvement model
  • C. established security strategies.
  • D. identified business drivers.

Answer: D

Explanation:
The most important element in achieving executive commitment to an information security governance program is to align the program with the identified business drivers of the organization. Business drivers are the factors that influence the strategic objectives, goals, and priorities of the organization. They reflect the needs and expectations of the stakeholders, customers, regulators, and other parties that are relevant to the organization's mission and vision. By aligning the information security governance program with the business drivers, the executive can demonstrate the value and benefits of information security to the organization's performance, reputation, and competitiveness. The other options are not the most important element, although they may be part of an information security governance program. A defined security framework is a set of standards, guidelines, and best practices that provide a structure and direction for implementing information security. A process improvement model is a methodology that helps to identify, analyze, and improve the processes related to information security. Established security strategies are the plans and actions that define how information security supports and enables the business objectives and goals. These elements are important for developing and executing an information security governance program, but they do not necessarily ensure executive commitment unless they are aligned with the business drivers


NEW QUESTION # 385
In the context of developing an information security strategy, which of the following provides the MOST useful input to determine the or

  • A. Laws and regulations
  • B. Risk register
  • C. Security budget
  • D. Risk score

Answer: A

Explanation:
Explanation
Laws and regulations provide the most useful input to determine the organization's information security strategy because they define the legal and compliance requirements and obligations that the organization must adhere to, and guide the development and implementation of the security policies and controls that support them. Security budget is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security needs or goals, but rather a resource to enable the security activities and initiatives. Risk register is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security vision or mission, but rather a tool to identify and manage the security risks. Risk score is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security priorities or objectives, but rather a measure of the level of risk exposure or performance. References:
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/how-to-align-security-initiatives-with-busin


NEW QUESTION # 386
A newly hired information security manager for a small organization has been tasked with improving data security. The BEST way to understand the organizations security postuie would be to:

  • A. perform a gap analysis based on Industry best practices.
  • B. identify and classify business processes.
  • C. engage a thud party to perform a security assessment.
  • D. review previous vulnerabilities.

Answer: C


NEW QUESTION # 387
......


The CISM certification is targeted at professionals who are involved in designing, managing, and assessing the information security policies and procedures of an organization. Certified Information Security Manager certification exam covers four domains: Information Security Governance, Risk Management, Information Security Program Development and Management, and Information Security Incident Management.

 

Best Value Available! 2024 Realistic Verified Free CISM Exam Questions: https://www.pass4suresvce.com/CISM-pass4sure-vce-dumps.html

100% Accurate Answers! CISM Actual Real Exam Questions: https://drive.google.com/open?id=1WPec07IegPf2knHMMTquKlBg_-08lEvL