CISM: Certified Information Security Manager Isaca Practice Exam
An organization is concerned about the possibility that vulnerabilities in its server systems could be exploited. Which of the following is the BEST control for mitigating the related risk?
AEnforcing standard system configurations based on secure configuration benchmarks
BImplementing network and system-based anomaly monitoring software for server systems
CEnforcing configurations for secure logging and audit trails on server systems
DImplementing host-based intrusion detection systems (IDS) on server systems
Which of the following is the first step in developing a business continuity plan (BCP)?
AIdentify critical business processes.
BDetermine the business recovery strategy
CDetermine available resources
DIdentify the applications with the shortest recovery time objectives (RTOs)
Which of the following is the MOST important outcome of effective risk treatment?
AImplementation of corrective actions
BElimination of risk
CTimely reporting of incidents
DReduced cost of acquiring controls
An organization’s marketing department wants to use an online collaboration service that does not comply with the information security policy. A risk assessment has been performed, and risk acceptance is being sought. Who should approve the risk acceptance?
Abusiness senior management.
Bthe compliance officer.
Cthe information security manager.
Dthe chief risk officer (CRO).
QuestionQ6
Information Security Risk Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Information Security Program
QuestionQ8
Information Security Risk Management
QuestionQ9
Incident Management
QuestionQ10
Information Security Risk Management
QuestionQ11
Incident Management
QuestionQ12
Information Security Risk Management
QuestionQ13
Information Security Risk Management
QuestionQ14
Information Security Program
QuestionQ15
Information Security Risk Management
QuestionQ16
Information Security Program
QuestionQ17
Information Security Governance
QuestionQ18
Information Security Risk Management
QuestionQ19
Information Security Risk Management
QuestionQ20
Information Security Program
QuestionQ21
Information Security Program
QuestionQ22
Information Security Risk Management
QuestionQ23
Information Security Program
QuestionQ24
Information Security Risk Management
QuestionQ25
Information Security Risk Management
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which of the following is MOST useful for determining the criticality of an organization’s business functions?
ADisaster recovery plan (DRP)
BBusiness continuity plan (BCP)
CSecurity assessment report (SAR)
DBusiness impact analysis (BIA)
What is the BEST way for an information security manager to make sure that critical assets are prioritized in a new information security program?
AUpdate operating procedures to include new requirements.
BConduct security awareness training.
CConduct an inventory of information assets.
DBackup information assets and store them offsite.
Which of the following protects the confidentiality of data transmitted across the Internet?
AMessage digests
BEncrypting file system
CNetwork address translation
DIPsec protocol
Which of the following is essential for ensuring effective incident response?
ABusiness continuity plan (BCP)
BCost-benefit analysis
CClassification scheme
DSenior management support
An information security manager has determined that the organization does not comply with new legislation that will soon take effect. Which of the following is MOST important to consider when deciding which additional controls to implement?
AThe information security strategy
BThe organization's risk appetite
CThe cost of noncompliance
DThe information security policy
Which of the following BEST supports the incident-management process for attacks on an organization’s supply chain?
ARequiring security awareness training for vendor staff
BIncluding service level agreements (SLAs) in vendor contracts
CPerforming integration testing with vendor systems
DEstablishing communication paths with vendors
An organization has identified a heightened risk of external brute-force attacks in its environment. Which option is the MOST effective method to mitigate this risk to the organization’s critical systems?
AIncrease the frequency of log monitoring and analysis.
BImplement a security information and event management system (SIEM).
CIncrease the sensitivity of intrusion detection systems.
DImplement multi-factor authentication.
The relationships among critical systems are BEST understood by:
Aperforming a business impact analysis (BIA).
Bdeveloping a system classification scheme.
Cevaluating key performance indicators (KPIs).
Devaluating the recovery time objectives (RTOs).
An organization has implemented a bring your own device (BYOD) program. Which of the following is the MOST important security consideration when permitting employees to use personal devices remotely for corporate applications?
AMandatory controls for maintaining security policy
BMobile operating systems support
CSecurity awareness training
DSecure application development
A critical vulnerability is discovered on a server that hosts multiple applications owned by different business units. One business unit determines that its hosted application will not work with the patch applied and elects to accept the risk. What should the information security manager do NEXT?
AUpdate the risk register
BDevelop a business case for compensating controls
CUpdate the information security policy
DConsult the incident management process
An organization has acquired a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementing it?
AControls to be monitored
BReporting capabilities
CThe contract with the SIEM vendor
DAvailable technical support
Which of the following would be MOST helpful in enabling senior management to understand the status of information security compliance?
AKey performance indicators (KPIs)
BRisk assessment results
CIndustry benchmarks
DBusiness impact analysis (BIA) results
When selecting the most appropriate controls to reduce risk to acceptable levels, an information security manager’s decision should be MAINLY driven by:
Aregulatory requirements.
Bcontrol framework.
Cbest practices.
Dcost-benefit analysis.
An information security manager recommends investing in a new security initiative to address recently published threats. Which of the following is MOST important to include in the business case?
AAlignment with the approved IT strategy
BPotential impact of threat realization
CAvailability of resources to implement the initiative
DPeer group threat intelligence report
Which option is the BEST method for determining the gap between an information security program’s current state and its desired state?
ADetermine whether critical success factors (CSFs) have been defined.
BReview and update current operational procedures.
CPerform a risk analysis for critical applications.
DConduct a capability maturity model evaluation.
Which of the following activities MUST an information security manager perform for change requests?
AAssess impact on information security risk.
BPerform penetration testing on affected systems.
CScan IT systems for operating system vulnerabilities.
DReview change in business requirements for information security.
Which of the following is MOST helpful in determining priorities when developing a long-term information security roadmap?
AThe organization's information security framework
BInformation security steering committee input
CEnterprise architecture (EA)
DIndustry best practices
Which of the following metrics BEST measures the effectiveness of a security awareness program?
AVariance of program cost to allocated budget
BThe number of security breaches
CMean time between incident detection and remediation
DThe number of reported security incidents
What should a global information security manager do first after learning that a new regulation with significant impact will take effect soon?
APerform a vulnerability assessment.
BPerform a business impact analysis (BIA).
CPerform a privacy impact assessment.
DPerform a gap analysis.
Which of the following is the BEST way to help ensure that an organization’s risk appetite is considered during the risk treatment process?
AEstablish key risk indicators (KRIs).
BProvide regular reporting on risk treatment to senior management.
CRequire steering committee approval of risk treatment plans.
Community Discussion