Isaca Certification CISM Practice Test Engine Try These 188 Exam Questions [Q11-Q30]

Share

Isaca Certification CISM Practice Test Engine: Try These 188 Exam Questions

Guaranteed Success in Isaca Certification CISM Exam Dumps


CISM (Certified Information Security Manager) is a certification intended for those professionals who are involved in the information security management. This certificate is issued by ISACA, and it will help you demonstrate your commitment to information security, identify critical issues within your company, enhance security programs, and bring you the credibility to support information security. This option can bring you the visibility you need.


Conclusion

Unlocking your potential becomes much easier when your tank is filled with the best CISM test prep materials. The knowledge you will find in each of the resources presented above is crucial to your success both in the exam process and in the actual field as a Certified Information Security Manager. Don’t get too caught up in reading and memorizing the concepts. Once you think you’ve gained mastery in each domain, try the practice quizzes. That is the surest way to know whether you have really understood the entirety of the exam and its tasks. Let these materials power you up so you can claim your deserved success very soon!


Why Is CISM Highly Recommended for Management Positions?

CISM is one of the best certifications needed by professionals in managerial roles in an information security domain. These may be security managers, IT managers, security administrators, senior system administrators, and so forth. By obtaining this Isaca certificate, you add value to your career because the exam coverage for CISM strategically highlights the entire aspects of IS management.

Therefore, if you want to level up your skills as well as your technical proficiency, this certification can help in reaching your objectives. Another thing that makes CISM famous among tech professionals is the fact that it serves as a salary booster. By having this on your profile, employers can distinguish your skills ahead of time. Thus, CISM certified individuals take home an average salary of more than $123,000+, as stated by PayScale, which is relatively higher than non-certified security professionals earn.

In addition, one can opt for other Isaca certifications. Although there is no further track related to CISM, applicant can choose alternatives such as CISA – Certified Information Systems Auditor, CSX-P – Cybersecurity Practitioner Certification, etc.

 

NEW QUESTION 11
An incident response team recently encountered an unfamiliar type of cyber event. Though the team was able to resalve the issue, it took a significant amount of time to identify, What is the BEST way to help ensure similar incidents are identified more quickly in the future?

  • A. Perform a post-incident review.
  • B. Establish performance metrics for the team.
  • C. Perform a threat analysis.
  • D. Implement a SIEM solution.

Answer: A

 

NEW QUESTION 12
Which of the following would be of GREATEST assistance in determining whether to accept residual risk of a critical security system?

  • A. Maximum tolerable outage (MTO)
  • B. Available annual budget
  • C. Recovery time objective (RTO)
  • D. Cost-benefit analysis of mitigating controls

Answer: D

 

NEW QUESTION 13
Which of the following mechanisms is the MOST secure way to implement a secure wireless network?

  • A. Filter media access control (MAC) addresses
  • B. Use a Wired Equivalent Privacy (WEP) key
  • C. Web-based authentication
  • D. Use a Wi-Fi Protected Access (WPA2) protocol

Answer: D

Explanation:
WPA2 is currently one of the most secure authentication and encryption protocols for mainstream wireless products. MAC address filtering by itself is not a good security mechanism since allowed MAC addresses can be easily sniffed and then spoofed to get into the network. WEP is no longer a secure encryption mechanism for wireless communications. The WEP key can be easily broken within minutes using widely available software. And once the WEP key is obtained, all communications of every other wireless client are exposed. Finally, a web-based authentication mechanism can be used to prevent unauthorized user access to a network, but it will not solve the wireless network's main security issues, such as preventing network sniffing.

 

NEW QUESTION 14
What is an appropriate frequency for updating operating system (OS) patches on production servers?

  • A. According to a fixed security patch management schedule
  • B. Concurrently with quarterly hardware maintenance
  • C. During scheduled rollouts of new applications
  • D. Whenever important security patches are released

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Patches should be applied whenever important security updates are released. They should not be delayed to coincide with other scheduled rollouts or maintenance. Due to the possibility of creating a system outage, they should not be deployed during critical periods of application activity such as month-end or quarter-end closing.

 

NEW QUESTION 15
When an organization is setting up a relationship with a third-party IT service provider, which of the following is one of the MOST important topics to include in the contract from a security standpoint?

  • A. Use of a two-factor authentication system.
  • B. Compliance with international security standards.
  • C. Compliance with the organization's information security requirements.
  • D. Existence of an alternate hot site in case of business disruption.

Answer: C

Explanation:
Explanation
Prom a security standpoint, compliance with the organization's information security requirements is one of the most important topics that should be included in the contract with third-party service provider. The scope of implemented controls in any ISO 27001-compliant organization depends on the security requirements established by each organization. Requiring compliance only with this security standard does not guarantee that a service provider complies with the organization's security requirements. The requirement to use a specific kind of control methodology is not usually stated in the contract with third- party service providers.

 

NEW QUESTION 16
Which of the following methods is the BEST way to demonstrate that an information security program provides appropriate coverage?

  • A. Security risk analysis
  • B. Gap assessment
  • C. Maturity assessment
  • D. Vulnerability scan report

Answer: B

 

NEW QUESTION 17
An information security manager learns of a new international standard related to information security. Which of the following would be the BEST course of action?

  • A. Consult with legal counsel on the standard's applicability to regulations
  • B. Perform a gap analysis between the new standard and existing practices.
  • C. Review industry peers responses to the new standard.
  • D. Determine whether the organization can benefit from adopting the new standard.

Answer: B

 

NEW QUESTION 18
What does a network vulnerability assessment intend to identify?

  • A. Misconfiguration and missing updates
  • B. 0-day vulnerabilities
  • C. Security design flaws
  • D. Malicious software and spyware

Answer: A

Explanation:
Explanation/Reference:
Explanation:
A network vulnerability assessment intends to identify known vulnerabilities based on common misconfigurations and missing updates. 0-day vulnerabilities by definition are not previously known and therefore are undetectable. Malicious software and spyware are normally addressed through antivirus and antispyware policies. Security design flaws require a deeper level of analysis.

 

NEW QUESTION 19
In a well-controlled environment, which of the following activities is MOST likely to lead to the introduction of weaknesses in security software?

  • A. Changing access rules
  • B. Backing up files
  • C. Applying patches
  • D. Upgrading hardware

Answer: A

Explanation:
Explanation
Security software will generally have a well-controlled process for applying patches, backing up files and upgrading hardware. The greatest risk occurs when access rules are changed since they are susceptible to being opened up too much, which can result in the creation of a security exposure.

 

NEW QUESTION 20
An emergency change was made to an IT system as a result of a failure. Which of the following should be of GREATEST concern to the organizations information security manager?

  • A. Documentation of the change was made after implementation.
  • B. The change did not include a proper assessment of nsk.
  • C. The operations team implemented the change without regression testing,
  • D. The information security manager did not review the change prior to implementation.

Answer: B

 

NEW QUESTION 21
Which is MOST important to enable a timely response to a security breach?

  • A. Knowledge sharing and collaboration
  • B. Security event logging
  • C. Forensic analysis
  • D. Roles and responsibilities

Answer: D

 

NEW QUESTION 22
Which of the following activities would BEST incorporate security into the software development life cycle {SOLO7

  • A. Minimize the use of open source software
  • B. Test applications before go-live
  • C. Include security training for the development team
  • D. Scan operating systems for vulnerabilities

Answer: C

 

NEW QUESTION 23
The MOST important element in achieving executive commitment to an information security governance program is:

  • A. identified business drivers
  • B. established security strategies
  • C. a defined security framework
  • D. a process improvement model

Answer: B

Explanation:
Section: INFORMATION SECURITY GOVERNANCE

 

NEW QUESTION 24
Which of the following measures would be MOST effective against insider threats to confidential information?

  • A. Audit trail monitoring
  • B. Defense-in-depth
  • C. Privacy policy
  • D. Role-based access control

Answer: D

Explanation:
Role-based access control provides access according to business needs; therefore, it reduces unnecessary- access rights and enforces accountability. Audit trail monitoring is a detective control, which is 'after the fact.' Privacy policy is not relevant to this risk. Defense-in-depth primarily focuses on external threats

 

NEW QUESTION 25
Which of the following practices completely prevents a man-in-the-middle (MitM) attack between two hosts?

  • A. Use https with a server-side certificate
  • B. Enforce static media access control (MAC) addresses
  • C. Use security tokens for authentication
  • D. Connect through an IPSec VPN

Answer: D

Explanation:
Explanation
IPSec effectively prevents man-in-the-middle (MitM) attacks by including source and destination IPs within the encrypted portion of the packet. The protocol is resilient to MitM attacks. Using token-based authentication does not prevent a MitM attack; however, it may help eliminate reusability of stolen cleartext credentials. An https session can be intercepted through Domain Name Server (DNS) or Address Resolution Protocol (ARP) poisoning. ARP poisoning - a specific kind of MitM attack - may be prevented by setting static media access control (MAC) addresses. Nevertheless, DNS and NetBIOS resolution can still be attacked to deviate traffic.

 

NEW QUESTION 26
Which of the following risks is represented in the risk appetite of an organization?

  • A. Residual
  • B. Control
  • C. Audit
  • D. Inherent

Answer: A

Explanation:
Residual risk is unmanaged, i.e., inherent risk which remains uncontrolled. This is key to the organization's risk appetite and is the amount of residual risk that a business is living with that affects its viability. Hence, inherent risk is incorrect. Control risk, the potential for controls to fail, and audit risk, which relates only to audit's approach to their work, are not relevant in this context.

 

NEW QUESTION 27
A post-incident review identified that user error resulted in a major breach. Which of the following is MOST important to determine during the review?

  • A. The underlying reason for the user error
  • B. The time and location that the breach occurred
  • C. Appropriate disciplinary procedures for user error
  • D. Evidence of previous incidents caused by the user

Answer: A

 

NEW QUESTION 28
An organization plans to allow employees to use their own devices on the organization's network. Which of the following is the information security manager's BEST course of action?

  • A. Update the security policy
  • B. Conduct awareness training
  • C. Assess associated risk
  • D. Implement automated software

Answer: C

 

NEW QUESTION 29
An information security organization should PRIMARILY:

  • A. ensure that the information security policies of the company are in line with global best practices and standards.
  • B. support the business objectives of the company by providing security-related support services.
  • C. be responsible for setting up and documenting the information security responsibilities of the information security team members.
  • D. ensure that the information security expectations are conveyed to employees.

Answer: B

Explanation:
The information security organization is responsible for options B and D within an organization, but they are not its primary mission. Reviewing and adopting appropriate standards (option C) is a requirement. The primary objective of an information security organization is to ensure that security supports the overall business objectives of the company.

 

NEW QUESTION 30
......

Test Engine to Practice CISM Test Questions: https://www.testkingpass.com/CISM-testking-dumps.html

ISACA CISM Daily Practice Exam New 2023 Updated 188 Questions: https://drive.google.com/open?id=1TZKVsIkG3Qdp4xStGFSCga2WYFmyLrQt