
Pass Your CISM-CN Dumps as PDF Updated on 2024 With 672 Questions
ISACA CISM-CN Real Exam Questions and Answers FREE
NEW QUESTION # 254
在收購的盡職調查階段,資訊安全經理最重要的行動方針是:
- A. 執行風險評估。
- B. 執行差距分析。
- C. 檢視資訊安全策略。
- D. 回顧安全意識狀況。
Answer: A
Explanation:
Explanation
According to the CISM Review Manual, performing a risk assessment is the most important course of action for an information security manager during the due diligence phase of an acquisition, as it helps to identify and evaluate the potential threats, vulnerabilities and impacts that may affect the information assets of the target organization. A risk assessment also provides the basis for performing a gap analysis, reviewing the information security policies and awareness, and developing a remediation plan.
References = CISM Review Manual, 27th Edition, Chapter 3, Section 3.4.1, page 1411.
NEW QUESTION # 255
某個組織正在經歷與網路釣魚訊息相關的事件急劇增加。根本原因是供應商不再支援過時的電子郵件過濾系統。下列哪一項應該是資訊安全經理的首要行動方案?
- A. 開發一個業務案例來替換系統。
- B. 暫時將電子郵件系統外包給雲端供應商。
- C. 監控防火牆上的傳出流量。
- D. 加強最終使用者的安全意識實踐。
Answer: A
Explanation:
Explanation
Developing a business case to replace the system is the FIRST course of action that the information security manager should take, because it helps to justify the need for a new and effective email filtering system that can prevent or reduce phishing incidents. A business case should include the problem statement, the proposed solution, the costs and benefits, the risks and assumptions, and the expected outcomes and metrics.
References =
CISM Review Manual, 16th Edition, ISACA, 2020, p. 42: "A business case is a document that provides the rationale and justification for an information security investment. It should include the problem statement, the proposed solution, the costs and benefits, the risks and assumptions, and the expected outcomes and metrics." Email Filtering Explained: What Is It and How Does It Work: "Email filtering is a process used to sort emails and identify unwanted messages such as spam, malware, and phishing attempts. The goal is to ensure that they don't reach the recipient's primary inbox. It is an essential security measure that helps protect users from unwanted or malicious messages." Cloud-based email phishing attack using machine and deep learning ...: "This attack is used to attack your email account and hack sensitive data easily."
NEW QUESTION # 256
以下哪一項是成功的安全計劃最重要的要求?
- A. 關鍵系統滲透測試
- B. 資產價值的管理決策
- C. 與員工簽訂的保密協議 (NDA)
- D. 將安全流程映射到基線安全標準
Answer: B
Explanation:
"A successful security program requires management support and involvement. One of the key aspects of management support is to decide on the value of assets and the acceptable level of risk for them. This will help define the security objectives and priorities for the program. The other options are possible activities within a security program, but they are not as important as management decision on asset value."
NEW QUESTION # 257
下列哪一個角色主要負責根據業務需求開發資訊分類架構?
- A. 高階管理層
- B. 資訊擁有者
- C. 資訊安全經理
- D. 資訊安全指導委員會
Answer: B
Explanation:
Explanation
According to the CISM Review Manual (Digital Version), Chapter 3, Section 3.2.1, Information owners are responsible for developing an information classification framework based on business needs1. They are also responsible for defining and maintaining the classification scheme, policies, and procedures for their information assets1.
The CISM Review Manual (Digital Version) also states that information owners should collaborate with other stakeholders, such as information security managers, information security steering committees, senior management, and legal counsel, to ensure that the classification framework is aligned with the organization's objectives and complies with applicable laws and regulations1.
The CISM Exam Content Outline also covers the topic of information classification frameworks in Domain 3
- Information Security Program Development and Management (27% exam weight)2. The subtopics include:
3.2.1 Information Classification Frameworks
3.2.2 Information Classification Policies
3.2.3 Information Classification Procedures
3.2.4 Information Classification Training
I hope this answer helps you prepare for your CISM exam. Good luck!
NEW QUESTION # 258
下列哪项应作为确定资产价值的主要依据?
- A. 总拥有成本 (TCO)
- B. 更换资产的成本
- C. 资产的原始成本减去折旧
- D. 资产不可用时的业务成本
Answer: D
NEW QUESTION # 259
一個組織即將實施基於雲的應用程序。已收到的獨立滲透測試結果顯示存在高評級漏洞。以下哪一項是最好的繼續方式?
- A. 實施應用程序並請求雲服務提供商修復漏洞。
- B. 委託進一步的滲透測試來驗證初始測試結果,
- C. 推遲實施,直到漏洞得到修復。
- D. 評估漏洞是否在組織的風險承受範圍內。
Answer: C
NEW QUESTION # 260
以下哪项是在实施控制时征求风险负责人意见的最重要原因?
- A. 解决企业架构(EA)中的漏洞
- B. 降低风险缓解成本
- C. 将风险控制在可接受的水平
- D. 消除影响业务的威胁
Answer: C
Explanation:
According to the Certified Information Security Manager (CISM) Study Manual, risk owners are responsible for managing a risk, including taking corrective action to reduce the risk to an acceptable level. When implementing controls, it is essential to obtain input from risk owners to ensure that the controls are effective in managing the risk to an acceptable level.
By obtaining input from risk owners, the organization can ensure that the controls are tailored to the specific risks and are effective in reducing the risk to an acceptable level. This can help to minimize the impact of the risk on the organization and reduce the potential for financial or reputational damage.
NEW QUESTION # 261
在呼叫中心,进行社会工程学的最佳理由是:
- A. 改进密码策略。
- B. 最小化攻击成功的可能性。
- C. 为信息安全计划获得资金。
- D. 确定接受额外安全培训的候选人。
Answer: D
Explanation:
The best reason to conduct a social engineering test in a call center is to identify candidates for additional security training because it helps to assess the level of awareness and skills of the call center staff in recognizing and resisting social engineering attacks, and provide them with the necessary training or education to improve their security posture. Minimizing the likelihood of successful attacks is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Gaining funding for information security initiatives is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Improving password policy is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-6/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 262
下列何者最能決定安全事件回應期間的資源分配?
- A. 高階管理層承諾
- B. 定義的嚴重級別
- C. 業務連續性計劃 (BCP)
- D. 既定的升級流程
Answer: B
Explanation:
Explanation
= The allocation of resources during a security incident response depends on the defined levels of severity, which indicate the potential impact and urgency of the incident. The levels of severity help prioritize the response activities and assign the appropriate roles and responsibilities. Senior management commitment, a business continuity plan (BCP), and an established escalation process are important factors for an effective incident response, but they do not directly determine the allocation of resources. References = CISM Review Manual, 16th Edition, page 3011; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 1462 Learn more:
1. isaca.org2. amazon.com3. gov.uk
Defined levels of severity is the best determinant of the allocation of resources during a security incident response. Having defined levels of severity allows organizations to plan for and allocate resources for each level of incident, depending on the severity of the incident. This ensures that the right resources are allocated in a timely manner and that incidents are addressed appropriately.
NEW QUESTION # 263
下列哪一項是修改密碼原則的最佳理由?
- A. 供應商推薦
- B. 業界最佳實踐
- C. 稽核建議
- D. 風險評估
Answer: D
Explanation:
Explanation
The best justification for making a revision to a password policy is a risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a risk assessment, the organization can determine the appropriate level of security controls and measures to protect its information assets and systems, including password policies. A risk assessment can also help identify any gaps or weaknesses in the existing password policy, and provide recommendations for improvement based on the organization's risk appetite and tolerance. The other options are not the best justification for making a revision to a password policy, although they may be some inputs or outputs of the risk assessment process. A vendor recommendation is an external source of advice or guidance that may or may not be relevant or applicable to the organization's specific context and needs. A vendor recommendation should not be followed blindly without conducting a risk assessment to evaluate its suitability and effectiveness. An audit recommendation is an internal source of feedback or suggestion that may or may not be accurate or complete. An audit recommendation should not be implemented without conducting a risk assessment to verify its validity and feasibility. An industry best practice is a general standard or guideline that may or may not reflect the organization's unique characteristics and requirements. An industry best practice should not be adopted without conducting a risk assessment to customize it according to the organization's goals and priorities
NEW QUESTION # 264
以下哪一項最能有效地確保新服務器得到適當的保護?
- A. 執行技術安全標準
- B. 執行安全代碼審查
- C. 啟動安全掃描
- D. 進行滲透測試
Answer: A
Explanation:
Enforcing technical security standards is the most effective way to ensure that a new server is appropriately secured because it ensures that the server complies with the organization's security policies and best practices, such as encryption, authentication, patching, and hardening. Performing secure code reviews is not relevant for securing a new server, unless it is running custom applications that need to be verified for security flaws. Conducting penetration testing is not sufficient for securing a new server, because it only identifies vulnerabilities that can be exploited by attackers, but does not fix them. Initiating security scanning is not sufficient for securing a new server, because it only detects known vulnerabilities or misconfigurations, but does not enforce security standards or remediate issues. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-3/secure-code-review https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 265
以下哪项变更管理程序最有可能引起信息安全经理的关注?
- A. 使用手动而非自动过程来比较程序版本。
- B. 开发经理将程序迁移到生产中
- C. 用户不会收到计划的系统更改通知
- D. 在进行更改之前的周末测试回退流程
Answer: B
Explanation:
According to the Certified Information Security Manager (CISM) Study Guide, one of the primary responsibilities of an information security manager is to ensure that changes to systems and processes are managed in a secure and controlled manner. The change management procedure that is most likely to cause concern for an information security manager is when the development manager migrates programs into production without proper oversight or control. This can increase the risk of unauthorized changes being made to systems and data, and can also increase the risk of configuration errors or other issues that can negatively impact the security and availability of systems. To mitigate these risks, it is important for the information security manager to work closely with the development team to establish and enforce change management procedures that ensure that all changes are properly approved, tested, and implemented in a controlled manner.
NEW QUESTION # 266
當決定遷移到基於雲的模型時,首先考慮的因素應該是:
- A. 共享環境中的存儲。
- B. 數據的物理位置。
- C. 數據的可用性。
- D. 數據分類。
Answer: D
NEW QUESTION # 267
以下哪项是确保在勒索软件攻击后能够恢复干净数据的最佳方法?
- A. 加密敏感生产数据
- B. 维护多个离线备份
- C. 购买网络保险
- D. 对备份执行完整性检查
Answer: B
Explanation:
Maintaining multiple offline backups is the best way to ensure the capability to restore clean data after a ransomware attack. This is because offline backups are not connected to the network and thus cannot be compromised by the ransomware. Additionally, performing integrity checks on backups will help to ensure that any backups that have been potentially corrupted by the ransomware can be identified and discarded. Encrypting sensitive production data and purchasing cyber insurance can help to protect against a ransomware attack, but are not the best way to ensure the capability to restore clean data after an attack.
NEW QUESTION # 268
一家線上銀行發現正在進行的成功網路攻擊。銀行應該首先:
- A. 評估個人識別資訊 (Pll) 是否受到洩漏。
- B. 關閉整個網路。
- C. 向董事會報告根本原因。
- D. 隔離受影響的網段。
Answer: D
Explanation:
Explanation
The online bank should first isolate the affected network segment, as this is the most effective way to contain the attack and prevent it from spreading to other parts of the network or compromising more data or systems.
Isolating the affected network segment also helps to preserve the evidence and facilitate the investigation and recovery process. Reporting the root cause to the board of directors, assessing whether personally identifiable information (Pll) is compromised, and shutting down the entire network are not the first actions that the online bank should take, as they may not be feasible or appropriate at the time of the attack, and may cause more disruption, confusion, or damage to the business operations and reputation. References = CISM Review Manual 2023, page 1641; CISM Review Questions, Answers & Explanations Manual 2023, page 362; ISACA CISM - iSecPrep, page 213
NEW QUESTION # 269
以下哪一项 BEST 有助于安全计划的有效战略调整?
- A. 业务策略定期更新
- B. 程序和标准由部门负责人批准。
- C. 定期安全审计由第三方进行。
- D. 组织单位对优先事项做出贡献并就优先事项达成一致
Answer: D
Explanation:
Organizational units contribute to and agree on priorities is the best way to facilitate effective strategic alignment of security initiatives because it ensures that the security initiatives are aligned with the business goals and objectives, supported by relevant stakeholders, and prioritized based on risk and value. The business strategy is periodically updated is not sufficient to facilitate effective strategic alignment of security initiatives because it does not involve collaboration or communication between different organizational units. Procedures and standards are approved by department heads is not sufficient to facilitate effective strategic alignment of security initiatives because it does not reflect the strategic direction or vision of the organization. Periodic security audits are conducted by a third-party is not sufficient to facilitate effective strategic alignment of security initiatives because it does not address the planning or implementation of security initiatives. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/how-to-align-security-initiatives-with-business-goals-and-objectives https://www.isaca.org/resources/isaca-journal/issues/2015/volume-1/how-to-measure-the-effectiveness-of-information-security-governance
NEW QUESTION # 270
下列哪一項最能顯示資訊資產已被準確分類?
- A. 資訊風險處理的適當優先級
- B. 資訊資產所有者的適當分配
- C. 準確、完整的資訊資產目錄
- D. 增強對資訊安全策略的遵守
Answer: A
NEW QUESTION # 271
以下哪一項是修改密碼策略的最佳理由?
- A. 供應商推薦
- B. 審計建議
- C. 行業最佳實踐
- D. 風險評估
Answer: D
Explanation:
The best justification for making a revision to a password policy is a risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a risk assessment, the organization can determine the appropriate level of security controls and measures to protect its information assets and systems, including password policies. A risk assessment can also help identify any gaps or weaknesses in the existing password policy, and provide recommendations for improvement based on the organization's risk appetite and tolerance. The other options are not the best justification for making a revision to a password policy, although they may be some inputs or outputs of the risk assessment process. A vendor recommendation is an external source of advice or guidance that may or may not be relevant or applicable to the organization's specific context and needs. A vendor recommendation should not be followed blindly without conducting a risk assessment to evaluate its suitability and effectiveness. An audit recommendation is an internal source of feedback or suggestion that may or may not be accurate or complete. An audit recommendation should not be implemented without conducting a risk assessment to verify its validity and feasibility. An industry best practice is a general standard or guideline that may or may not reflect the organization's unique characteristics and requirements. An industry best practice should not be adopted without conducting a risk assessment to customize it according to the organization's goals and priorities
NEW QUESTION # 272
恢復點目標(RPO)對災難恢復的貢獻是:
- A. 消除單點故障。
- B. 盡量減少停電時間。
- C. 減少平均故障間隔時間 (MTBF)。
- D. 定義備份策略
Answer: D
Explanation:
The contribution of recovery point objective (RPO) to disaster recovery is to define backup strategy because it determines the maximum amount of data loss that is acceptable to an organization after a disruption, and guides the frequency and type of backups needed to restore the data to a usable format1. Minimize outage periods is not a contribution of RPO, but rather a contribution of recovery time objective (RTO), which defines the maximum amount of time that is acceptable to restore normal operations after a disruption2. Eliminate single points of failure is not a contribution of RPO, but rather a goal of high availability (HA), which ensures that systems or services are continuously operational and resilient3. Reduce mean time between failures (MTBF) is not a contribution of RPO, but rather a measure of reliability, which indicates the average time that a system or component operates without failure4. Reference: 1 https://www.druva.com/glossary/what-is-a-recovery-point-objective-definition-and-related-faqs 2 https://www.druva.com/glossary/what-is-a-recovery-time-objective-definition-and-related-faqs 3 https://www.fortinet.com/resources/cyberglossary/high-availability 4 https://www.fortinet.com/resources/cyberglossary/mean-time-between-failures
NEW QUESTION # 273
下列哪一項對於確定組織目前降低風險的能力最有幫助?
- A. IT 安全風險與暴露
- B. 業務影響分析 (BIA)
- C. 能力成熟度模型
- D. 漏洞評估
Answer: C
NEW QUESTION # 274
下列哪一項為資訊安全經理提供了有關組織回應網路攻擊的能力的最準確指示?
- A. 模擬網路釣魚練習
- B. 黑盒滲透測試
- C. 事件響應計畫的演練
- D. 紅隊演習
Answer: D
Explanation:
Explanation
A red team exercise is a simulated cyber attack conducted by a group of ethical hackers or security experts (the red team) against an organization's network, systems, and staff (the blue team) to test the organization's ability to detect, respond, and recover from a real cyber attack. A red team exercise provides an information security manager with the most accurate indication of the organization's ability to respond to a cyber attack, because it mimics the tactics, techniques, and procedures of real threat actors, and challenges the organization's security posture, incident response plan, and security awareness in a realistic and adversarial scenario12. A red team exercise can measure the following aspects of the organization's cyber attack response capability3:
The effectiveness and efficiency of the security controls and processes in preventing, detecting, and mitigating cyber attacks The readiness and performance of the incident response team and other stakeholders in following the incident response plan and procedures The communication and coordination among the internal and external parties involved in the incident response process The resilience and recovery of the critical assets and functions affected by the cyber attack The lessons learned and improvement opportunities identified from the cyber attack simulation The other options, such as a walk-through of the incident response plan, a black box penetration test, or a simulated phishing exercise, are not as accurate as a red team exercise in indicating the organization's ability to respond to a cyber attack, because they have the following limitations4 :
A walk-through of the incident response plan is a theoretical and hypothetical exercise that involves reviewing and discussing the incident response plan and procedures with the relevant stakeholders, without actually testing them in a live environment. A walk-through can help to familiarize the participants with the incident response roles and responsibilities, and to identify any gaps or inconsistencies in the plan, but it cannot measure the actual performance and effectiveness of the incident response process under a real cyber attack scenario.
A black box penetration test is a technical and targeted exercise that involves testing the security of a specific system or application, without any prior knowledge or access to its internal details or configuration. A black box penetration test can help to identify the vulnerabilities and weaknesses of the system or application, and to simulate the perspective and behavior of an external attacker, but it cannot test the security of the entire network or organization, or the response of the incident response team and other stakeholders to a cyber attack.
A simulated phishing exercise is a social engineering and awareness exercise that involves sending fake emails or messages to the organization's staff, to test their ability to recognize and report phishing attempts. A simulated phishing exercise can help to measure the level of security awareness and training of the staff, and to simulate one of the most common cyber attack vectors, but it cannot test the security of the network or systems, or the response of the incident response team and other stakeholders to a cyber attack.
References = 1: What is a Red Team Exercise? | Redscan 2: Red Team vs Blue Team: How They Differ and Why You Need Both | CISA 3: Red Team Exercises: What They Are and How to Run Them | Rapid7 4: What is a Walkthrough Test? | Definition and Examples | ISACA : Penetration Testing Types: Black Box, White Box, and Gray Box | CISA
NEW QUESTION # 275
......
Pass ISACA CISM-CN Exam Info and Free Practice Test: https://www.testkingpass.com/CISM-CN-testking-dumps.html
New 2024 Latest Questions CISM-CN Dumps - Use Updated ISACA Exam: https://drive.google.com/open?id=1AljzOtDU5RNVvQMlnA1xZIjVeoOtzaYo