[Q662-Q687] Tested Material Used To CISM Test Engine Exam Questions in here [Sep-2021]

Share

Tested Material Used To CISM Test Engine Exam Questions in here [Sep-2021]

Penetration testers simulate CISM exam PDF

NEW QUESTION 662
The PRIMARY purpose of asset valuation for the management of information security is to:

  • A. determine the value of each asset
  • B. provide a basis for asset classification.
  • C. prioritize risk management activities.
  • D. eliminate the least significant assets.

Answer: C

 

NEW QUESTION 663
Which of the following steps in conducting a risk assessment should be performed FIRST?

  • A. Identity business assets
  • B. Assess vulnerabilities
  • C. Evaluate key controls
  • D. Identify business risks

Answer: A

Explanation:
Risk assessment first requires one to identify the business assets that need to be protected before identifying the threats. The next step is to establish whether those threats represent business risk by identifying the likelihood and effect of occurrence, followed by assessing the vulnerabilities that may affect the security of the asset. This process establishes the control objectives against which key controls can be evaluated.

 

NEW QUESTION 664
Which of the following should be the PRIMARY factor in prioritizing responses to a security incident?

  • A. Asset classification
  • B. Cost of mitigation
  • C. Incident location
  • D. Inherent cost of assets

Answer: A

 

NEW QUESTION 665
What is the BEST policy for securing data on mobile universal serial bus (USB) drives?

  • A. Authentication
  • B. Encryption
  • C. Prohibit employees from copying data to l)SB devices
  • D. Limit the use of USB devices

Answer: B

Explanation:
Encryption provides the most effective protection of data on mobile devices. Authentication on its own is not very secure. Prohibiting employees from copying data to USB devices and limiting the use of USB devices are after the fact.

 

NEW QUESTION 666
Which of the following is the MOST important consideration for an organization interacting with the media during a disaster?

  • A. Referring the media to the authorities
  • B. Communicating specially drafted messages by an authorized person
  • C. Reporting the losses and recovery strategy to the media
  • D. Refusing to comment until recovery

Answer: B

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Proper messages need to be sent quickly through a specific identified person so that there are no rumors or statements made that may damage reputation. Choices B, C and D are not recommended until the message to be communicated is made clear and the spokesperson has already spoken to the media.

 

NEW QUESTION 667
Which of the following is MOST important to the success of an information security program?

  • A. Adequate start-up budget and staffing
  • B. Security' awareness training
  • C. Achievable goals and objectives
  • D. Senior management sponsorship

Answer: D

Explanation:
Sufficient senior management support is the most important factor for the success of an information security program. Security awareness training, although important, is secondary. Achievable goals and objectives as well as having adequate budgeting and staffing are important factors, but they will not ensure success if senior management support is not present.

 

NEW QUESTION 668
Which of the following should be the information security manager's NEXT step following senior management approval of the information security strategy?

  • A. Form a steering committee
  • B. Develop a security pokey.
  • C. Develop a budget
  • D. Perform a gap analysis.

Answer: A

 

NEW QUESTION 669
The MOST important factor in ensuring the success of an information security program is effective:

  • A. formulation of policies and procedures for information security.
  • B. monitoring compliance with information security policies and procedures.
  • C. communication of information security requirements to all users in the organization.
  • D. alignment with organizational goals and objectives.

Answer: D

Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The success of security programs is dependent upon alignment with organizational goals and objectives.
Communication is a secondary step. Effective communication and education of users is a critical determinant of success but alignment with organizational goals and objectives is the most important factor for success. Mere formulation of policies without effective communication to users will not ensure success.
Monitoring compliance with information security policies and procedures can be, at best, a detective mechanism that will not lead to success in the midst of uninformed users.

 

NEW QUESTION 670
An extranet server should be placed:

  • A. outside the firewall.
  • B. on the external router.
  • C. on the firewall server.
  • D. on a screened subnet.

Answer: D

Explanation:
Explanation
An extranet server should be placed on a screened subnet, which is a demilitarized zone (DMZ). Placing it on the Internet side of the firewall would leave it defenseless. The same would be true of placing it on the external router, although this would not be possible. Since firewalls should be installed on hardened servers with minimal services enabled, it would be inappropriate to store the extranet on the same physical device.

 

NEW QUESTION 671
Which of the following is the BEST reason for delaying the application of a critical security patch?

  • A. Conflicts with software development life cycle
  • B. Lack of vulnerability management
  • C. Resource limitations
  • D. Technology interdependences

Answer: D

 

NEW QUESTION 672
A risk management program should reduce risk to:

  • A. an acceptable level.
  • B. an acceptable percent of revenue.
  • C. zero.
  • D. an acceptable probability of occurrence.

Answer: A

Explanation:
Risk should be reduced to an acceptable level based on the risk preference of the organization. Reducing risk to zero is impractical and could be cost-prohibitive. Tying risk to a percentage of revenue is inadvisable since there is no direct correlation between the two. Reducing the probability of risk occurrence may not always be possible, as in the ease of natural disasters. The focus should be on reducing the impact to an acceptable level to the organization, not reducing the probability of the risk.

 

NEW QUESTION 673
A benefit of using a full disclosure (white box) approach as compared to a blind (black box) approach to penetration testing is that:

  • A. human intervention is not required for this type of test.
  • B. less time is spent on reconnaissance and information gathering.
  • C. critical infrastructure information is not revealed to the tester.
  • D. it simulates the real-life situation of an external security attack.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Data and information required for penetration are shared with the testers, thus eliminating time that would otherwise have been spent on reconnaissance and gathering of information. Blind (black box) penetration testing is closer to real life than full disclosure (white box) testing. There is no evidence to support that human intervention is not required for this type of test. A full disclosure (white box) methodology requires the knowledge of the subject being tested.

 

NEW QUESTION 674
Which of the following would be an information security manager's PRIMARY challenge when deploying a Bring Your Own Device (BYOD) mobile program in an enterprise?

  • A. Mobile application control
  • B. End user acceptance
  • C. Disparate device security
  • D. Configuration management

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT

 

NEW QUESTION 675
An organization has announced new initiatives to establish a big data platform and develop mobile apps. What is the FIRST step when defining new human resource requirements?

  • A. Benchmark to an industry peer
  • B. Analyze the skills necessary to support the new initiatives.
  • C. Determine the security technology requirements for the initiatives
  • D. Request additional funding for recruiting and training

Answer: B

 

NEW QUESTION 676
Segregation of duties is a security control PRIMARILY used to:

  • A. establish hierarchy.
  • B. decentralize operations.
  • C. limit malicious behavior.
  • D. establish dual check.

Answer: C

 

NEW QUESTION 677
Which of the following is the PRIMARY reason for implementing a risk management program?

  • A. Is a necessary part of management's due diligence
  • B. Assists in incrementing the return on investment (ROD
  • C. Satisfies audit and regulatory requirements
  • D. Allows the organization to eliminate risk

Answer: A

Explanation:
Explanation
The key reason for performing risk management is that it is part of management's due diligence. The elimination of all risk is not possible. Satisfying audit and regulatory requirements is of secondary importance.
A risk management program may or may not increase the return on investment (ROD.

 

NEW QUESTION 678
An organization is implementing an information security governance framework. To communicate the program's effectiveness to stakeholders, it is MOST important to establish:

  • A. a monitoring process for the security policy.
  • B. automated reporting to stakeholders.
  • C. metrics for each milestone.
  • D. a control self-assessment process.

Answer: C

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE

 

NEW QUESTION 679
When implementing effective security governance within the requirements of the company's security strategy, which of the following is the MOST important factor to consider?

  • A. Establishing international security standards for data sharing
  • B. Preserving the confidentiality of sensitive data
  • C. Adhering to corporate privacy standards
  • D. Establishing system manager responsibility for information security

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The goal of information security is to protect the organization's information assets. International security standards are situational, depending upon the company and its business. Adhering to corporate privacy standards is important, but those standards must be appropriate and adequate and are not the most important factor to consider. All employees are responsible for information security, but it is not the most important factor to consider.

 

NEW QUESTION 680
One way to determine control effectiveness is by determining:

  • A. the test results of intended objectives.
  • B. the evaluation and analysis of reliability.
  • C. whether it is preventive, detective or compensatory.
  • D. the capability of providing notification of failure.

Answer: A

Explanation:
Control effectiveness requires a process to verify that the control process worked as intended. Examples such as dual-control or dual-entry bookkeeping provide verification and assurance that the process operated as intended. The type of control is not relevant, and notification of failure is not determinative of control strength. Reliability is not an indication of control strength; weak controls can be highly reliable, even if they are ineffective controls.

 

NEW QUESTION 681
The security responsibility of data custodians in an organization will include:

  • A. assuming overall protection of information assets.
  • B. implementing security controls in products they install.
  • C. ensuring security measures are consistent with policy.
  • D. determining data classification levels.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Security responsibilities of data custodians within an organization include ensuring that appropriate security measures are maintained and are consistent with organizational policy. Executive management holds overall responsibility for protection of the information assets. Data owners determine data classification levels for information assets so that appropriate levels of controls can be provided to meet the requirements relating to confidentiality, integrity and availability. Implementation of information security in products is the responsibility of the IT developers.

 

NEW QUESTION 682
What is the MOST effective access control method to prevent users from sharing files with unauthorized users?

  • A. Mandatory
  • B. Walled garden
  • C. Role-based
  • D. Discretionary

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Mandatory access controls restrict access to files based on the security classification of the file. This prevents users from sharing files with unauthorized users. Role-based access controls grant access according to the role assigned to a user; they do not prohibit file sharing. Discretionary and lattice-based access controls are not as effective as mandatory access controls in preventing file sharing. A walled garden is an environment that controls a user's access to web content and services. In effect, the walled garden directs the user's navigation within particular areas, and does not necessarily prevent sharing of other material.

 

NEW QUESTION 683
An e-commerce order fulfillment web server should generally be placed on which of the following?

  • A. Domain controller
  • B. Database server
  • C. Demilitarized zone (DMZ)
  • D. Internal network

Answer: C

Explanation:
Explanation
An e-commerce order fulfillment web server should be placed within a DMZ to protect it and the internal network from external attack. Placing it on the internal network would expose the internal network to potential attack from the Internet. Since a database server should reside on the internal network, the same exposure would exist. Domain controllers would not normally share the same physical device as a web server.

 

NEW QUESTION 684
When personal information is transmitted across networks, there MUST be adequate controls over:

  • A. encryption devices.
  • B. consent to data transfer.
  • C. change management.
  • D. privacy protection.

Answer: D

Explanation:
Privacy protection is necessary to ensure that the receiving party has the appropriate level of protection of personal data. Change management primarily protects only the information, not the privacy of the individuals. Consent is one of the protections that is frequently, but not always, required. Encryption is a method of achieving the actual control, but controls over the devices may not ensure adequate privacy protection and. therefore, is a partial answer.

 

NEW QUESTION 685
An information security manager is planning to purchase a mobile device management (MDM) system to manage personal devices used by employees to access corpor Which of the following is MOST important to include in the business case?

  • A. Identified risks and mitigating controls
  • B. Cost-benefit analysis
  • C. Industry best practice benchmarking results
  • D. Information security-related metrics

Answer: A

 

NEW QUESTION 686
Of the following, who should have responsibility for assessing the security risk associated with an outsourced cloud provider contract?

  • A. Chief information officer
  • B. Service delivery manager
  • C. Compliance manager
  • D. Information security manager

Answer: B

 

NEW QUESTION 687
......

Authentic Best resources for CISM Online Practice Exam: https://www.testkingpass.com/CISM-testking-dumps.html

Get the superior quality CISM Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1zOzCqHbM9BmQeN2l7AQuxH-91s2V13ti