
Get Apr-2024 updated Exam CISM Dumps with New Questions
100% Pass Guarantee for CISM Exam Dumps with Actual Exam Questions
NEW QUESTION # 342
Threat and vulnerability assessments are important PRIMARILY because they are:
- A. used to establish security investments
- B. the basis for setting control objectives.
- C. needed to estimate risk.
- D. elements of the organization's security posture.
Answer: B
Explanation:
Explanation
Threat and vulnerability assessments are important primarily because they are the basis for setting control objectives. Control objectives are the desired outcomes of implementing security controls, and they should be aligned with the organization's risk appetite and business objectives. Threat and vulnerability assessments help to identify the potential sources and impacts of security incidents, and to prioritize the mitigation actions based on the likelihood and severity of the risks. By conducting threat and vulnerability assessments, the organization can establish the appropriate level and type of security controls to protect its information assets and reduce the residual risk to an acceptable level. References = CISM Review Manual (Digital Version), Chapter 3: Information Security Risk Management, Section 3.1: Risk Identification, p. 115-1161. CISM Review Manual (Print Version), Chapter 3: Information Security Risk Management, Section 3.1: Risk Identification, p. 115-1162. CISM ITEM DEVELOPMENT GUIDE, Domain 3: Information Security Program Development and Management, Task Statement 3.1, p. 193.
Threat and vulnerability assessments are important PRIMARILY because they are the basis for setting control objectives. Control objectives are the desired outcomes or goals of implementing security controls in an information system. They are derived from the risk assessment process, which identifies and evaluates the threats and vulnerabilities that could affect the system's confidentiality, integrity and availability. By conducting threat and vulnerability assessments, an organization can determine the level of risk it faces and establish the appropriate control objectives to mitigate those risks.
NEW QUESTION # 343
Who should be responsible for determining the classification of data within a database used in conjunction with an enterprise application?
- A. Information security manager
- B. Data owner
- C. Database architect
- D. Database administrator
Answer: B
NEW QUESTION # 344
Over the last year, an information security manager has performed risk assessments on multiple third-party vendors. Which of the following criteria would be MOST helpful in determining the associated level of risk applied to each vendor?
- A. Cnticahty of the service to the organization
- B. Compliance requirements associated with the regulation
- C. Compensating controls tn place to protect information security
- D. Corresponding breaches associated with each vendor
Answer: A
NEW QUESTION # 345
When developing an incident response plan, which of the following is the MOST -effective way to ensure incidents common to the organization are handled properly?
- A. Conducting awareness training
- B. Rehearsing response scenarios
- C. Adopting industry standard response procedures
- D. Creating and distributing a personnel call tree
Answer: C
NEW QUESTION # 346
Which of the following is MOST critical when creating an incident response plan?
- A. Aligning with the risk assessment process
- B. Identifying vulnerable data assets
- C. Documenting incident notification and escalation processes
- D. Identifying what constitutes an incident
Answer: C
NEW QUESTION # 347
Which of the following is MOST appropriate to communicate to senior management regarding information risk?
- A. Vulnerability scanning progress
- B. Emerging security technologies
- C. Defined risk appetite
- D. Risk profile changes
Answer: A
NEW QUESTION # 348
The return on investment of information security can BEST be evaluated through which of the following?
- A. Security deliverables
- B. Security metrics
- C. Process improvement models
- D. Support of business objectives
Answer: D
Explanation:
Explanation
One way to determine the return on security investment is to illustrate how information security supports the achievement of business objectives. Security metrics measure improvement and effectiveness within the security practice but do not tie to business objectives. Similarly, listing deliverables and creating process improvement models does not necessarily tie into business objectives.
NEW QUESTION # 349
Risk scenarios simplify the risk assessment process by:
- A. reducing the need for subsequent risk evaluation.
- B. focusing on important and relevant risk.
- C. covering the full range of possible risk.
- D. ensuring business risk is mitigated.
Answer: B
NEW QUESTION # 350
What should be an information security manager's BEST course of action if funding for a security-related initiative is denied by a steering committee?
- A. Provide information from industry benchmarks
- B. Document the accepted risk
- C. Discuss the initiative with senior management.
- D. Look for other ways to fund the initiative.
Answer: B
NEW QUESTION # 351
Which of the following devices should be placed within a DMZ?
- A. Departmental server
- B. Proxy server
- C. Data warehouse server
- D. Application server
Answer: D
Explanation:
Explanation
An application server should normally be placed within a demilitarized zone (DMZ) to shield the internal network. Data warehouse and departmental servers may contain confidential or valuable data and should always be placed on the internal network, never on a DMZ that is subject to compromise. A proxy server forms the inner boundary of the DMZ but is not placed within it.
NEW QUESTION # 352
A test plan to validate the security controls of a new system should be developed during which phase of the project?
- A. Development
- B. Testing
- C. Design
- D. Initiation
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
In the design phase, security checkpoints are defined and a test plan is developed. The testing phase is too late since the system has already been developed and is in production testing. In the initiation phase, the basic security objective of the project is acknowledged. Development is the coding phase and is too late to consider test plans.
NEW QUESTION # 353
The data access requirements for an application should be determined by the:
- A. information security manager.
- B. compliance officer.
- C. business owner.
- D. legal department.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Business owners are ultimately responsible for their applications. The legal department, compliance officer and information security manager all can advise, but do not have final responsibility.
NEW QUESTION # 354
Which is the MOST important to enable a timely response to a security breach?
- A. Security event logging
- B. Forensic analysis
- C. Knowledge sharing and collaboration
- D. Roles and responsibilities
Answer: A
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION # 355
Which of the following is MOST helpful in determining an organization's current capacity to mitigate risks?
- A. Capability maturity model
- B. Business impact analysis (BIA)
- C. Vulnerability assessment
- D. IT security risk and exposure
Answer: A
Explanation:
Explanation
A capability maturity model (CMM) is a framework that helps organizations assess and improve their processes and capabilities in various domains, such as software development, project management, information security, and others1. A CMM defines a set of levels or stages that represent the degree of maturity or effectiveness of an organization's processes and capabilities in a specific domain. Each level has a set of criteria or characteristics that an organization must meet to achieve that level of maturity. A CMM also provides guidance and best practices on how to progress from one level to another, and how to measure and monitor the performance and improvement of the processes and capabilities2.
A CMM is most helpful in determining an organization's current capacity to mitigate risks, because it provides a systematic and objective way to evaluate the strengths and weaknesses of the organization's processes and capabilities related to risk management. A CMM can help an organization identify the gaps and opportunities for improvement in its risk management practices, and prioritize the actions and resources needed to address them. A CMM can also help an organization benchmark its risk management maturity against industry standards or best practices, and demonstrate its compliance with regulatory or contractual requirements3.
The other options are not as helpful as a CMM in determining an organization's current capacity to mitigate risks, because they are either more specific, limited, or dependent on a CMM. A vulnerability assessment is a process of identifying and analyzing the vulnerabilities in an organization's systems, networks, or applications, and their potential impact on the organization's assets, operations, or reputation. A vulnerability assessment can help an organization identify the sources and levels of risk, but it does not provide a comprehensive or holistic view of the organization's risk management maturity or effectiveness4. IT security risk and exposure is a measure of the likelihood and impact of a security breach or incident on an organization's IT assets, operations, or reputation. IT security risk and exposure can help an organization quantify and communicate the level of risk, but it does not provide a framework or guidance on how to improve the organization's risk management processes or capabilities5. A business impact analysis (BIA) is a process of identifying and evaluating the potential effects of a disruption or disaster on an organization's critical business functions, processes, or resources. A BIA can help an organization determine the priorities and requirements for business continuity and disaster recovery, but it does not provide a method or standard for assessing or enhancing the organization's risk management maturity or effectiveness. References = 1: CMMI Institute - What is CMMI? - Capability Maturity Model Integration 2: Capability Maturity Model and Risk Register Integration:
The Right ... 3: Performing Risk Assessments of Emerging Technologies - ISACA 4: CISM Review Manual
15th Edition, Chapter 4, Section 4.2 5: CISM Review Manual 15th Edition, Chapter 4, Section 4.3 : CISM Review Manual 15th Edition, Chapter 4, Section 4.4
NEW QUESTION # 356
Ensuring that an organization can conduct security reviews within third-party facilities is PRIMARILY enabled by:
- A. contractual agreements.
- B. audit guidelines.
- C. acceptance of the organization s security policies.
- D. service level agreements (SLAs).
Answer: A
NEW QUESTION # 357
Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?
- A. Projected increase in maturity level
- B. Estimated increase in efficiency
- C. Projected costs over time
- D. Estimated reduction in risk
Answer: D
NEW QUESTION # 358
Which of the following is the MOST appropriate individual to ensure that new exposures have not been introduced into an existing application during the change management process?
- A. Data security officer
- B. System analyst
- C. System user
- D. Operations manager
Answer: C
Explanation:
Explanation/Reference:
Explanation:
System users, specifically the user acceptance testers, would be in the best position to note whether new exposures are introduced during the change management process. The system designer or system analyst, data security officer and operations manager would not be as closely involved in testing code changes.
NEW QUESTION # 359
Priority should be given to which of the following to ensure effective implementation of information security governance?
- A. Consultation
- B. Negotiation
- C. Planning
- D. Facilitation
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Planning is the key to effective implementation of information security governance. Consultation, negotiation and facilitation come after planning.
NEW QUESTION # 360
Which of the following BEST supports effective information security governance"*
- A. The information security manager develops the strategy
- B. Compliance with regulations is demonstrated.
- C. A baseline risk assessment is performed.
- D. A steering committee is established
Answer: D
NEW QUESTION # 361
While implementing information security governance an organization should FIRST:
- A. determine security baselines.
- B. adopt security standards.
- C. define the security strategy.
- D. establish security policies.
Answer: C
Explanation:
The first step in implementing information security governance is to define the security strategy based on which security baselines are determined. Adopting suitable security- standards, performing risk assessment and implementing security policy are steps that follow the definition of the security strategy.
NEW QUESTION # 362
......
ISACA CISM: What requirements should you meet?
The ISACA CISM certificate is available for those individuals who have technical and IS/IT experience and are ready to become a Manager. It validates your expertise in risk management, incident management, security governance, as well as program management and development. This certification proves your knowledge in the following domains:
- Information Security Governance.
- Information Security Incident Management;
- Information Security Program Development & Management;
- Information Risk Management;
ISACA recommends all the potential candidates to have at least 5 years of experience in the IS management. To become eligible for this certification, you also need to pass one exam.
To be eligible for the CISM certification exam, candidates must meet certain requirements. They must hold at least five years of experience in information security, with a minimum of three years in information security management. Alternatively, they can substitute two years of general information security experience with a relevant degree or other certification. Additionally, candidates must adhere to the ISACA Code of Professional Ethics and pass the CISM exam.
CISM exam dumps with real ISACA questions and answers: https://www.itcertmagic.com/ISACA/real-CISM-exam-prep-dumps.html
Today Updated CISM Exam Dumps Actual Questions: https://drive.google.com/open?id=12XdFF-QX3On26b8lP82MUqnbVfssIaNq