لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which of the following should an information security manager do FIRST when a legacy application is not compliant with a regulatory requirement, but thebusiness unit does not have the budget for remediation?
A. Develop a business case for funding remediation efforts
B. Advise senior management to accept the risk of noncompliance
C. Notify legal and internal audit of the noncompliant legacy application
D. Assess the consequences of noncompliance against the cost of remediation
عرض الإجابة
اجابة صحيحة: D

View The Updated CISM Exam Questions

SPOTO Provides 100% Real CISM Exam Questions for You to Pass Your CISM Exam!

السؤال #2
Which of the following messages would be MOST effective in obtaining senior management's commitment to information security management?
A. Effective security eliminates risk to the business
B. Adopt a recognized framework with metrics
C. Security is a business product and not a process
D. Security supports and protects the business
عرض الإجابة
اجابة صحيحة: D
السؤال #3
When an organization hires a new information security manager, which of the following goals should this individual pursue FIRST?
A. Develop a security architecture
B. Establish good communication with steering committee members
C. Assemble an experienced staff
D. Benchmark peer organizations
عرض الإجابة
اجابة صحيحة: B
السؤال #4
Which of the following is the MOST important information to include in a strategic plan for information security?
A. Information security staffing requirements
B. Current state and desired future state
C. IT capital investment requirements
D. information security mission statement
عرض الإجابة
اجابة صحيحة: B
السؤال #5
Which of the following is MOST important to include in a post-incident review following a databreach?
A. n evaluation of the effectiveness of the information security strategy
B. valuations of the adequacy of existing controls
C. ocumentation of regulatory reporting requirements
D. review of the forensics chain of custom
عرض الإجابة
اجابة صحيحة: B
السؤال #6
Which of the following presents the GREATEST challenge to a large multinational organization using an automated identity and access management (IAM) system?
A. taff turnover rates that significantly exceed industry averages
B. requent changes to user roles during employment
C. naccurate workforce data from human resources (HR)
D. arge number of applications in the organization
عرض الإجابة
اجابة صحيحة: C
السؤال #7
Which of the following BEST indicates that information assets are classified accurately?
A. ppropriate prioritization of information risk treatment
B. ncreased compliance with information security policy
C. ppropriate assignment of information asset owners
D. n accurate and complete information asset catalog
عرض الإجابة
اجابة صحيحة: A
السؤال #8
An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider beforeimplementation?
A. Controls to be monitored
B. Reporting capabilities
C. The contract with the SIEM vendor
D. Available technical support
عرض الإجابة
اجابة صحيحة: A
السؤال #9
Senior management commitment and support for information security can BEST be obtained through presentations that:
A. use illustrative examples of successful attacks
B. explain the technical risks to the organization
C. evaluate the organization against best security practices
D. tie security risks to key business objectives
عرض الإجابة
اجابة صحيحة: D
السؤال #10
The cost of implementing a security control should not exceed the:
A. annualized loss expectancy
B. cost of an incident
C. asset value
D. implementation opportunity costs
عرض الإجابة
اجابة صحيحة: C
السؤال #11
Which of the following is the MOST important factor when designing information security architecture?
A. Technical platform interfaces
B. Scalability of the network
C. Development methodologies
D. Stakeholder requirements
عرض الإجابة
اجابة صحيحة: D
السؤال #12
To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information security manager should FIRST:
A. onduct a cost-benefit analysis
B. onduct a risk assessment
C. nterview senior management
D. erform a gap analysis
عرض الإجابة
اجابة صحيحة: D
السؤال #13
Which of the following characteristics is MOST important when looking at prospective candidates for the role of chief information security officer (CISO)?
A. Knowledge of information technology platforms, networks and development methodologies
B. Ability to understand and map organizational needs to security technologies
C. Knowledge of the regulatory environment and project management techniques
D. Ability to manage a diverse group of individuals and resources across an organization
عرض الإجابة
اجابة صحيحة: B
السؤال #14
Which of the following should be the PRIMARY goal of information security?
A. Information management
B. Regulatory compliance
C. Data governance
D. Business alignment
عرض الإجابة
اجابة صحيحة: D
السؤال #15
The chief information security officer (CISO) should ideally have a direct reporting relationship to the:
A. head of internal audit
B. chief operations officer (COO)
C. chief technology officer (CTO)
D. legal counsel
عرض الإجابة
اجابة صحيحة: B
السؤال #16
The MOST appropriate role for senior management in supporting information security is the:
A. evaluation of vendors offering security products
B. assessment of risks to the organization
C. approval of policy statements and funding
D. monitoring adherence to regulatory requirements
عرض الإجابة
اجابة صحيحة: C
السؤال #17
Which of the following should an information security manager do FIRST when a legacy application is not compliant with a regulatory requirement, but the business unit does not have the budget for remediation?
A. evelop a business case for funding remediation efforts
B. dvise senior management to accept the risk of noncompliance
C. otify legal and internal audit of the noncompliant legacy application
D. ssess the consequences of noncompliance against the cost of remediation
عرض الإجابة
اجابة صحيحة: D
السؤال #18
Which of the following is the PRIMARY benefit of implementing a vulnerability assessment process?
A. hreat management is enhanced
B. ompliance status is improved
C. ecurity metrics are enhanced
D. roactive risk management is facilitated
عرض الإجابة
اجابة صحيحة: D
السؤال #19
During which of the following development phases is it MOST challenging to implement security controls? The development phase is the stage of the system development life cycle (SDLC) where the system requirements, design, architecture, and implementation are performed. The development phase is most challenging to implement security controls because it involves complex and dynamic processes that may not be well understood or documented. Security controls are essential for ensuring the confidentiality, integrity, and availability of the system and its data, as well as for complying with regulatory and contractual obligations. However, security controls may also introduce additional costs, risks, and constraints to the development process, such as: Increased complexity and overhead of testing, verification, validation, and maintenance Reduced flexibility and agility of changing requirements or design Increased dependency on external vendors or third parties for security services or products Increased vulnerability to errors, defects, or vulnerabilities in the code or configuration Increased difficulty in measuring and reporting on security performance or effectiveness Therefore, implementing security controls in the development phase requires careful planning, coordination, communication, and collaboration among all stakeholders involved in the SDLC. It also requires a clear understanding of the security objectives, scope, criteria, standards, policies, procedures, roles, responsibilities, and resources for the system. Moreover, it requires a proactive approach to identifying and mitigating potential threats or risks that may affect the security of the system. Reference= CISM Manual1, Chapter 3: Information Security Program Development (ISPD), Section 3.1: System Development Life Cycle (SDLC)2 1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles
A. Post-implementation phase
B. Implementation phase
C. Development phase
D. Design phase
عرض الإجابة
اجابة صحيحة: C
السؤال #20
Investments in information security technologies should be based on:
A. vulnerability assessments
B. value analysis
C. business climate
D. audit recommendations
عرض الإجابة
اجابة صحيحة: B
السؤال #21
An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?
A. ontrols to be monitored
B. eporting capabilities
C. he contract with the SIEM vendor
D. vailable technical support
عرض الإجابة
اجابة صحيحة: A
السؤال #22
When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information securitycontrols as well as to select new information security controls?
A. Access control management
B. Change management
C. Configuration management
D. Risk management
عرض الإجابة
اجابة صحيحة: D
السؤال #23
Relationships among security technologies are BEST defined through which of the following?
A. Security metrics
B. Network topology
C. Security architecture
D. Process improvement models
عرض الإجابة
اجابة صحيحة: C
السؤال #24
An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?
A. eedback from the vendor's previous clients
B. enetration testing against the vendor's network
C. lignment of the vendor's business objectives with enterprise security goals
D. he maturity of the vendor's internal control environment
عرض الإجابة
اجابة صحيحة: C
السؤال #25
Minimum standards for securing the technical infrastructure should be defined in a security:
A. strategy
B. guidelines
C. model
D. architecture
عرض الإجابة
اجابة صحيحة: D
السؤال #26
Senior management commitment and support for information security will BEST be attained by an information security manager by emphasizing:
A. organizational risk
B. organization wide metrics
C. security needs
D. the responsibilities of organizational units
عرض الإجابة
اجابة صحيحة: A
السؤال #27
Senior management commitment and support for information security can BEST be enhanced through:
A. a formal security policy sponsored by the chief executive officer (CEO)
B. regular security awareness training for employees
C. periodic review of alignment with business management goals
D. senior management signoff on the information security strategy
عرض الإجابة
اجابة صحيحة: C
السؤال #28
Implementing the principle of least privilege PRIMARILY requires the identification of:
A. job duties
B. data owners
C. primary risk factors
D. authentication controls
عرض الإجابة
اجابة صحيحة: A
السؤال #29
Which of the following should be the FIRST step in developing an information security plan?
A. Perform a technical vulnerabilities assessment
B. Analyze the current business strategy
C. Perform a business impact analysis
D. Assess the current levels of security awareness
عرض الإجابة
اجابة صحيحة: B
السؤال #30
The MOST important reason for an information security manager to be involved in the change management process is to ensure that:
A. security controls drive technology changes
B. risks have been evaluated
C. security controls are updated regularly
D. potential vulnerabilities are identified
عرض الإجابة
اجابة صحيحة: B
السؤال #31
What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?
A. ancel the outsourcing contract
B. ransfer the risk to the provider
C. reate an addendum to the existing contract
D. nitiate an external audit of the provider's data center
عرض الإجابة
اجابة صحيحة: C
السؤال #32
The PRIMARY goal in developing an information security strategy is to:
A. establish security metrics and performance monitoring
B. educate business process owners regarding their duties
C. ensure that legal and regulatory requirements are met
D. support the business objectives of the organization
عرض الإجابة
اجابة صحيحة: D
السؤال #33
Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
A. To define security roles and responsibilities
B. To determine return on investment (ROI)
C. To establish incident severity levels
D. To determine the criticality of information assets
عرض الإجابة
اجابة صحيحة: D
السؤال #34
Which of the following roles would represent a conflict of interest for an information security manager?
A. Evaluation of third parties requesting connectivity
B. Assessment of the adequacy of disaster recovery plans
C. Final approval of information security policies
D. Monitoring adherence to physical security controls
عرض الإجابة
اجابة صحيحة: C
السؤال #35
An information security risk analysis BEST assists an organization in ensuring that:
A. the infrastructure has the appropriate level of access control
B. cost-effective decisions are made with regard to which assets need protection
C. an appropriate level of funding is applied to security processes
D. the organization implements appropriate security technologies
عرض الإجابة
اجابة صحيحة: B
السؤال #36
Which of the following is characteristic of centralized information security management?
A. More expensive to administer
B. Better adherence to policies
C. More aligned with business unit needs
D. Faster turnaround of requests
عرض الإجابة
اجابة صحيحة: B
السؤال #37
An employee who is a remote user has copied financial data from the corporate server to a laptop using virtual private network (VPN) connectivity.
A. Review of the audit logs
B. Ownership of the data
C. Employee's job role
D. Valid use case
عرض الإجابة
اجابة صحيحة: D
السؤال #38
A new risk has been identified in a high availability system. The BEST course of action is to:
A. ecommend risk acceptance to the business owner
B. valuate and prioritize the identified risk
C. evelop and implement a plan to mitigate the identified risk
D. erform a cost-benefit analysis for mitigating controls
عرض الإجابة
اجابة صحيحة: B
السؤال #39
When an information security manager is developing a strategic plan for information security, the timeline for the plan should be:
A. aligned with the IT strategic plan
B. based on the current rate of technological change
C. three-to-five years for both hardware and software
D. aligned with the business strategy
عرض الإجابة
اجابة صحيحة: D
السؤال #40
Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?
A. Review the third-party contract with the organizationג€™s legal department
B. Communicate security policy with the third-party vendor
C. Ensure security is involved in the procurement process
D. Conduct an information security audit on the third-party vendor
عرض الإجابة
اجابة صحيحة: C
السؤال #41
An organization that conducts business globally is planning to utilize a third-party service provider to process payroll information.
A. The third party does not have an independent assessment of controls available for review
B. The third party has not provided evidence of compliance with local regulations where data is generated
C. The third-party contract does not include an indemnity clause for compensation in the event of a breach
D. The third party's service level agreement (SLA) does not include guarantees of uptime
عرض الإجابة
اجابة صحيحة: B
السؤال #42
Which of the following is the MOST important consideration when establishing an organization'sinformation security governance committee?
A. embers have knowledge of information security controls
B. embers are business risk owners
C. embers are rotated periodically
D. embers represent functions across the organization
عرض الإجابة
اجابة صحيحة: D
السؤال #43
Which of the following are seldom changed in response to technological changes?
A. Standards
B. Procedures
C. Policies
D. Guidelines
عرض الإجابة
اجابة صحيحة: C
السؤال #44
A business unit has designed a mobile app to provide services to customers. Which of the following is an information security manager's BEST approach when the business resists implementing a strong password policy due to concerns about the user experience?
A. eview the security risk with the business unit
B. resent the risk and user impact to senior management
C. equire the business unit to adhere to the policy
D. valuate the costs and benefits of improving the user experience
عرض الإجابة
اجابة صحيحة: A
السؤال #45
Which of the following requirements would have the lowest level of priority in information security?
A. Technical
B. Regulatory
C. Privacy
D. Business
عرض الإجابة
اجابة صحيحة: A
السؤال #46
Which of the following is characteristic of decentralized information security management across a geographically dispersed organization?
A. More uniformity in quality of service
B. Better adherence to policies
C. Better alignment to business unit needs
D. More savings in total operating costs
عرض الإجابة
اجابة صحيحة: C
السؤال #47
Which of the following is the BEST way to build a risk-aware culture?
A. eriodically change risk awareness messages
B. nsure that threats are communicated organization-wide in a timely manner
C. eriodically test compliance with security controls and post results
D. stablish incentives and a channel for staff to report risks
عرض الإجابة
اجابة صحيحة: D
السؤال #48
Which of the following is MOST likely to be discretionary?
A. Policies
B. Procedures
C. Guidelines
D. Standards
عرض الإجابة
اجابة صحيحة: C
السؤال #49
Who should be responsible for enforcing access rights to application data?
A. Data owners
B. Business process owners
C. The security steering committee
D. Security administrators
عرض الإجابة
اجابة صحيحة: D
السؤال #50
Which of the following is MOST important to complete during the recovery phase of an incident response process before bringing affected systems back online?
A. est and verify that compromised systems are clean
B. ecord and close security incident tickets
C. ocument recovery steps for senior management reporting
D. apture and preserve forensic images of affected systems
عرض الإجابة
اجابة صحيحة: A
السؤال #51
Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?
A. eview the third-party contract with the organization's legal department
B. ommunicate security policy with the third-party vendor
C. nsure security is involved in the procurement process
D. onduct an information security audit on the third-party vendor
عرض الإجابة
اجابة صحيحة: C
السؤال #52
Which of the following is the BEST metric to measure the efficiency of an information security program?
A. ercentage of systems with defined control baselines
B. atio of risk assessments to vulnerability scans over time
C. verage mitigation cost per identified risk
D. umber of completed lessons learned activities
عرض الإجابة
اجابة صحيحة: A
السؤال #53
Which of the following individuals would be in the BEST position to sponsor the creation of an information security steering group?
A. Information security manager
B. Chief operating officer (COO)
C. Internal auditor
D. Legal counsel
عرض الإجابة
اجابة صحيحة: B
السؤال #54
Which of the following is MOST appropriate for inclusion in an information security strategy?
A. Business controls designated as key controls
B. Security processes, methods, tools and techniques
C. Firewall rule sets, network defaults and intrusion detection system (IDS) settings
D. Budget estimates to acquire specific security tools
عرض الإجابة
اجابة صحيحة: B
السؤال #55
An information security manager is assisting in the development of the request for proposal (RFP) for a new outsourced service. This will require the third party to have access to critical business information. The security manager should focus
A. service level agreements (SLAs)
B. security requirements for the process being outsourced
C. risk-reporting methodologies
D. security metrics
عرض الإجابة
اجابة صحيحة: B
السؤال #56
The PRIMARY purpose for conducting cybersecurity risk assessments is to:
A. Assist in security reporting to senior management
B. Provide metrics to indicate cybersecurity program effectiveness
C. Verify compliance across multiple sectors
D. Understand the organization's current security posture
عرض الإجابة
اجابة صحيحة: D

View The Updated ISACA Exam Questions

SPOTO Provides 100% Real ISACA Exam Questions for You to Pass Your ISACA Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us