لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which of the following would provide the HIGHEST level of confidence in the integrity of data when sent from one party to another?
A. Harden the communication infrastructure
B. Require files to be digitally signed before they are transmitted
C. Enforce multi-factor authentication on both ends of the communication
D. Require data to be transmitted over a secure connection
عرض الإجابة
اجابة صحيحة: B

View The Updated CISM Exam Questions

SPOTO Provides 100% Real CISM Exam Questions for You to Pass Your CISM Exam!

السؤال #2
Which of the following MOST commonly falls within the scope of an information security governance steering committee?
A. Interviewing candidates for information security specialist positions
B. Developing content for security awareness programs
C. Prioritizing information security initiatives
D. Approving access to critical financial systems
عرض الإجابة
اجابة صحيحة: C
السؤال #3
Which of the following is the MOST appropriate position to sponsor the design and implementation of a new security infrastructure in a large global enterprise?
A. Chief security officer (CSO)
B. Chief operating officer (COO)
C. Chief privacy officer (CPO)
D. Chief legal counsel (CLC)
عرض الإجابة
اجابة صحيحة: B
السؤال #4
Which of the following is MOST likely to be included in an enterprise security policy?
A. efinitions of responsibilities
B. etention schedules
C. ystem access specifications
D. rganizational risk
عرض الإجابة
اجابة صحيحة: A
السؤال #5
The PRIMARY advantage of performing black-box control tests as opposed to white-box control tests is that they:
A. cause fewer potential production issues
B. require less IT staff preparation
C. simulate real-world attacks
D. identify more threats
عرض الإجابة
اجابة صحيحة: C
السؤال #6
To ensure alignment between the disaster recovery plan (DRP) and incident response plan, which of the following is MOST important for the information security manager to verify?
A. he business impact analysis (BIA) has recently been updated
B. he same organizational department handles related testing
C. he plans document the handoff between various teams
D. he plans have similar requirements regarding escalations
عرض الإجابة
اجابة صحيحة: C
السؤال #7
Which of the following should a newly appointed information security manager do FIRST when evaluating the current incident notification and escalation processes?
A. eview findings from recent security incidents
B. est current incident-related communications plans
C. erify industry best practices are incorporated into processes
D. nterview key incident response stakeholders
عرض الإجابة
اجابة صحيحة: D
السؤال #8
Developing a successful business case for the acquisition of information security software products can BEST be assisted by:
A. assessing the frequency of incidents
B. quantifying the cost of control failures
C. calculating return on investment (ROI) projections
D. comparing spending against similar organizations
عرض الإجابة
اجابة صحيحة: C
السؤال #9
When identifying legal and regulatory issues affecting information security, which of the following would represent the BEST approach to developing information security policies?
A. Create separate policies to address each regulation
B. Develop policies that meet all mandated requirements
C. Incorporate policy statements provided by regulators
D. Develop a compliance risk assessment
عرض الإجابة
اجابة صحيحة: B
السؤال #10
Which of the following Is MOST useful to an information security manager when conducting a post-incident review of an attack?
A. ost of the attack to the organization
B. ocation of the attacker
C. ethod of operation used by the attacker
D. etails from intrusion detection system (IDS) logs
عرض الإجابة
اجابة صحيحة: C
السؤال #11
The MOST important component of a privacy policy is:
A. notifications
B. warranties
C. liabilities
D. geographic coverage
عرض الإجابة
اجابة صحيحة: A
السؤال #12
A business unit intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate action should an information security manager take?
A. Enforce the existing security standard
B. Change the standard to permit the deployment
C. Perform a risk analysis to quantify the risk
D. Perform research to propose use of a better technology
عرض الإجابة
اجابة صحيحة: C
السؤال #13
It is MOST important that information security architecture be aligned with which of the following?
A. Industry best practices
B. Information technology plans
C. Information security best practices
D. Business objectives and goals
عرض الإجابة
اجابة صحيحة: D
السؤال #14
Which of the following is MOST important to have in place as a basis for developing an effectiveinformation security program that supports the organization's business goals?
A. etrics to drive the information security program
B. nformation security policies
C. defined security organizational structure
D. n information security strategy
عرض الإجابة
اجابة صحيحة: D
السؤال #15
The MOST important factor in planning for the long-term retention of electronically stored business records is to take into account potential changes in:
A. storage capacity and shelf life
B. regulatory and legal requirements
C. business strategy and direction
D. application systems and media
عرض الإجابة
اجابة صحيحة: D
السؤال #16
Which of the following is the MOST effective way to increase security awareness in an organization?
A. Implement regularly scheduled information security audits
B. Require signed acknowledgment of information security policies
C. Conduct periodic simulated phishing exercises
D. Include information security requirements in job descriptions
عرض الإجابة
اجابة صحيحة: C
السؤال #17
A data discovery project uncovers an unclassified process document. Of the following, who is BEST suited to determine the classification?
A. Information security manager
B. Security policy author
C. Creator of the document
D. Data custodian
عرض الإجابة
اجابة صحيحة: C
السؤال #18
Conducting log analysis falls into which phase of the incident management life cycle?
A. Post-incident
B. Containment
C. Detection
D. Planning
عرض الإجابة
اجابة صحيحة: C
السؤال #19
When taking a risk-based approach to vulnerability management, which of the following is MOST important to consider when prioritizing a vulnerability?
A. The information available about the vulnerability
B. The sensitivity of the asset and the data it contains
C. IT resource availability and constraints
D. Whether patches have been developed and tested
عرض الإجابة
اجابة صحيحة: B
السؤال #20
Successful implementation of information security governance will FIRST require:
A. security awareness training
B. updated security policies
C. a computer incident management team
D. a security architecture
عرض الإجابة
اجابة صحيحة: B
السؤال #21
Which of the following would be the MOST important goal of an information security governance program?
A. Review of internal control mechanisms
B. Effective involvement in business decision making
C. Total elimination of risk factors
D. Ensuring trust in data
عرض الإجابة
اجابة صحيحة: D
السؤال #22
Security technologies should be selected PRIMARILY on the basis of their:
A. ability to mitigate business risks
B. evaluations in trade publications
C. use of new and emerging technologies
D. benefits in comparison to their costs
عرض الإجابة
اجابة صحيحة: A
السؤال #23
A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option? Verified Answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.3, 'The appropriate risk treatment option is decided by the chief information security officer (CISO) or the designated risk owner.'1 The CISO is the senior executive who is responsible for overseeing and managing the information security program of an organization. The CISO has the authority and expertise to assess the risks, determine the risk appetite and tolerance levels, and select the most suitable risk treatment options for each risk. The CISO also has the accountability and responsibility for implementing, monitoring, and reporting on the risk treatment activities.
A. Security manager
B. Chief information security officer (CISO)
C. System administrator
D. Business owner
عرض الإجابة
اجابة صحيحة: B
السؤال #24
Which of the following is MOST likely to be included in an enterprise security policy?
A. Definitions of responsibilities
B. Retention schedules
C. System access specifications
D. Organizational risk
عرض الإجابة
اجابة صحيحة: A
السؤال #25
To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information securitymanager should FIRST:
A. conduct a cost-benefit analysis
B. conduct a risk assessment
C. interview senior management
D. perform a gap analysis
عرض الإجابة
اجابة صحيحة: B
السؤال #26
Which of the following are likely to be updated MOST frequently?
A. Procedures for hardening database servers
B. Standards for password length and complexity
C. Policies addressing information security governance
D. Standards for document retention and destruction
عرض الإجابة
اجابة صحيحة: A
السؤال #27
Which of the following represents the MAJOR focus of privacy regulations?
A. Unrestricted data mining
B. Identity theft
C. Human rights protection
D. Identifiable personal data
عرض الإجابة
اجابة صحيحة: D
السؤال #28
Retention of business records should PRIMARILY be based on:
A. business strategy and direction
B. regulatory and legal requirements
C. storage capacity and longevity
D. business ease and value analysis
عرض الإجابة
اجابة صحيحة: B
السؤال #29
Which of the following is the BEST way to build a risk-aware culture?
A. Periodically change risk awareness messages
B. Ensure that threats are communicated organization-wide in a timely manner
C. Periodically test compliance with security controls and post results
D. Establish incentives and a channel for staff to report risks
عرض الإجابة
اجابة صحيحة: D
السؤال #30
When a security standard conflicts with a business objective, the situation should be resolved by:
A. changing the security standard
B. changing the business objective
C. performing a risk analysis
D. authorizing a risk acceptance
عرض الإجابة
اجابة صحيحة: C
السؤال #31
Acceptable levels of information security risk should be determined by:
A. legal counsel
B. security management
C. external auditors
D. die steering committee
عرض الإجابة
اجابة صحيحة: D
السؤال #32
An information security manager learns of a new standard related to an emerging technology the organization wants to implement. Which of the following should the information security manager recommend be done FIRST? = The first step that the information security manager should recommend when learning of a new standard related to an emerging technology is to determine whether the organization can benefit from adopting the new standard. This involves evaluating the business objectives, needs, and requirements of the organization, as well as the potential advantages, disadvantages, and challenges of implementing the new technology and the new standard. The information security manager should also consider the alignment of the new standard with the organization's existing policies, procedures, and standards, as well as the impact of the new standard on the organization's information security governance, risk management, program, and incident management. By conducting a preliminary analysis of the feasibility, suitability, and desirability of the new standard, the information security manager can provide a sound basis for further decision making and planning. Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Standards, page 391; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 43, page 412.
A. Determine whether the organization can benefit from adopting the new standard
B. Obtain legal counsel's opinion on the standard's applicability to regulations,
C. Perform a risk assessment on the new technology
D. Review industry specialists' analyses of the new standard
عرض الإجابة
اجابة صحيحة: A
السؤال #33
When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?
A. ccess control management
B. hange management
C. onfiguration management
D. isk management
عرض الإجابة
اجابة صحيحة: D
السؤال #34
Which of the following is the MOST essential task for a chief information security officer (CISO) to perform?
A. Update platform-level security settings
B. Conduct disaster recovery test exercises
C. Approve access to critical financial systems
D. Develop an information security strategy paper
عرض الإجابة
اجابة صحيحة: D
السؤال #35
When properly implemented, secure transmission protocols protect transactions:
A. rom eavesdropping
B. rom denial of service (DoS) attacks
C. n the client desktop
D. n the server's database
عرض الإجابة
اجابة صحيحة: A
السؤال #36
Which of the following would BEST ensure the success of information security governance within an organization?
A. Steering committees approve security projects
B. Security policy training provided to all managers
C. Security training available to all employees on the intranet
D. Steering committees enforce compliance with laws and regulations
عرض الإجابة
اجابة صحيحة: A
السؤال #37
Which of the following would be the MOST effective way to present quarterly reports to the board onthe status of the information security program?
A. capability and maturity assessment
B. etailed analysis of security program KPIs
C. n information security dashboard
D. n information security risk register
عرض الإجابة
اجابة صحيحة: C
السؤال #38
Information security governance is PRIMARILY driven by:
A. technology constraints
B. regulatory requirements
C. litigation potential
D. business strategy
عرض الإجابة
اجابة صحيحة: D
السؤال #39
What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identifyrequirements for safeguarding the organization's critical data?
A. Cancel the outsourcing contract
B. Transfer the risk to the provider
C. Create an addendum to the existing contract
D. Initiate an external audit of the provider's data center
عرض الإجابة
اجابة صحيحة: C
السؤال #40
Which of the following BEST informs the design of an information security framework?
A. Recent audit findings
B. Implementation cost
C. Risk appetite
D. Available skills
عرض الإجابة
اجابة صحيحة: C
السؤال #41
Which of the following provides an information security manager with the MOST useful information on new threats and emerging risks that could impact business objectives?
A. ndustry threat intelligence report
B. nternal threat analysis report
C. nternal vulnerability assessment report
D. xternal audit report
عرض الإجابة
اجابة صحيحة: A
السؤال #42
When building support for an information security program, which of the following elements is MOST important?
A. Identification of existing vulnerabilities
B. Information risk assessment
C. Business impact analysis (BIA)
D. Threat analysis
عرض الإجابة
اجابة صحيحة: C
السؤال #43
Which of the following is MOST important to the successful implementation of an information security program? The successful implementation of an information security program depends largely on the availability and allocation of adequate security resources, such as budget, staff, technology, and training. Without sufficient resources, the program may not be able to achieve its objectives, comply with the security strategy, or address the security risks. Key performance indicators (KPIs), a balanced scorecard, and global security standards are also important elements of an information security program, but they are not as critical as the resource allocation. Reference= CISM Review Manual, 16th Edition, page 69
A. Adequate security resources are allocated to the program
B. Key performance indicators (KPIs) are defined
C. A balanced scorecard is approved by the steering committee
D. The program is developed using global security standards
عرض الإجابة
اجابة صحيحة: A
السؤال #44
An information security risk analysis BEST assists an organization in ensuring that:
A. he infrastructure has the appropriate level of access control
B. ost-effective decisions are made with regard to which assets need protection
C. n appropriate level of funding is applied to security processes
D. he organization implements appropriate security technologies
عرض الإجابة
اجابة صحيحة: B
السؤال #45
In a multinational organization, local security regulations should be implemented over global security policy because:
A. business objectives are defined by local business unit managers
B. deploying awareness of local regulations is more practical than of global policy
C. global security policies include unnecessary controls for local businesses
D. requirements of local regulations take precedence
عرض الإجابة
اجابة صحيحة: D
السؤال #46
Which of the following situations must be corrected FIRST to ensure successful information security governance within an organization?
A. The information security department has difficulty filling vacancies
B. The chief information officer (CIO) approves security policy changes
C. The information security oversight committee only meets quarterly
D. The data center manager has final signoff on all security projects
عرض الإجابة
اجابة صحيحة: D
السؤال #47
An information security manager learns that a risk owner has approved exceptions to replace keycontrols with weaker compensating controls to improve process efficiency. Which of the followingshould be the GREATEST concern?
A. isk levels may be elevated beyond acceptable limits
B. ecurity audits may report more high-risk findings
C. he compensating controls may not be cost efficient
D. oncompliance with industry best practices may result
عرض الإجابة
اجابة صحيحة: A
السؤال #48
Which of the following should be the PRIMARY objective of an information security governance framework? According to the Certified Information Security Manager (CISM) Study Manual, 'The primary objective of information security governance is to provide a framework for managing and controlling information security practices and technologies at an enterprise level. Its goal is to manage and reduce risk through a process of identification, assessment, and management of those risks.' While demonstrating senior management commitment, compliance with industry best practices, and ensuring user compliance with policies are all important aspects of information security governance, they are not the primary objective. The primary objective is to manage and reduce risk by establishing a framework for managing and controlling information security practices and technologies at an enterprise level. Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 60.
A. Provide a baseline for optimizing the security profile of the organization
B. Demonstrate senior management commitment
C. Demonstrate compliance with industry best practices to external stakeholders
D. Ensure that users comply with the organization's information security policies
عرض الإجابة
اجابة صحيحة: A
السؤال #49
Which of the following should be the PRIMARY area of focus when mitigating security risksassociated with emerging technologies?
A. ompatibility with legacy systems
B. pplication of corporate hardening standards
C. ntegration with existing access controls
D. nknown vulnerabilities
عرض الإجابة
اجابة صحيحة: D
السؤال #50
In a multinational organization, local security regulations should be implemented over global security policy because:
A. usiness objectives are defined by local business unit managers
B. eploying awareness of local regulations is more practical than of global policy
C. lobal security policies include unnecessary controls for local businesses
D. equirements of local regulations take precedence
عرض الإجابة
اجابة صحيحة: D

View The Updated ISACA Exam Questions

SPOTO Provides 100% Real ISACA Exam Questions for You to Pass Your ISACA Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us