2023 Latest CISM Exam Dumps Recently Updated 672 Questions [Q161-Q178]

Share

2023 Latest CISM Exam Dumps Recently Updated 672 Questions

ISACA CISM Real 2023 Braindumps Mock Exam Dumps


What Are the Important Exam Requirements You Need to Know?

Just like all other Isaca certification exams, CISM consists of 150 questions. These are structured in multiple-choice type, with a time limit of up to 4 hours or 240 minutes. The converted scale scores range from 200 to 800. In order to pass the test, you have to get at least 450 points. On the other hand, the exam fee differs for members and non-members. If you're a member, you only have to pay $575 while the non-members have to shell out $760.

Before taking the test, you will be given two delivery options. The first one is by in-person at a testing site. The second one is via a remote set-up in an online setting. Both options allow you to choose your preferred language options. As of this writing, there are 4 selections, including English, Japanese, Chinese Simplified, and Spanish.

Another thing to remember is the exam registration. You cannot take the CISM test if you will not register with Isaca and schedule it ahead. But don't worry because it doesn't mean that you have to sit for the exam as soon as possible after registration. You are given 12 months from the date of enrollment to take it. Henceforth, you have to take into account the eligibility period.


ISACA CISM Exam Certification Details:

Books / TrainingVirtual Instructor-Led Training
In-Person Training & Conferences
Customized, On-Site Corporate Training
CISM Planning Guide
Exam CodeCISM
Passing Score450/800
Exam NameISACA Certified Information Security Manager (CISM)
Exam Price ISACA Nonmember$760 (USD)
Sample QuestionsISACA CISM Sample Questions

 

NEW QUESTION # 161
Which of the following is the MOST appropriate method for deploying operating system (OS) patches to production application servers?

  • A. Automatically push all patches to the servers
  • B. Batch patches into frequent server updates
  • C. Set up servers to automatically download patches
  • D. Initially load the patches on a test machine

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Some patches can conflict with application code. For this reason, it is very important to first test all patches in a test environment to ensure that there are no conflicts with existing application systems. For this reason, choices C and D are incorrect as they advocate automatic updating. As for frequent server updates, this is an incomplete (vague) answer from the choices given.


NEW QUESTION # 162
Which of the following is the PRIMARY role of the information security manager in application development?
To ensure:

  • A. enterprise security controls are implemented.
  • B. security is integrated into the system development life cycle (SDLC).
  • C. compliance with industry best practice.
  • D. control procedures address business risk.

Answer: B


NEW QUESTION # 163
An intrusion detection system (IDS) should:

  • A. ignore anomalies
  • B. be located on the network
  • C. require a stable, rarely changed environment
  • D. run continuously

Answer: D

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
If an intrusion detection system (IDS) does not run continuously the business remains vulnerable. An IDS should detect, not ignore anomalies. An IDS should be flexible enough to cope with a changing environment. Both host and network based IDS are recommended for adequate detection.


NEW QUESTION # 164
Which of the following would BEST assist an IS manager in gaining strategic support from executive management?

  • A. Risk analysis specific to the organization
  • B. Research on trends in global information security breaches
  • C. Annual report of security incidents within the organization
  • D. Rating of the organization's security, based on international standards

Answer: A

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 165
Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:

  • A. prepare to adapt the controls for future system upgrades.
  • B. ensure the controls are regularly tested for ongoing effectiveness.
  • C. perform testing to compare control performance against industry levels.
  • D. hand over the controls to the relevant business owners.

Answer: B


NEW QUESTION # 166
Which of the following is the MOST effective at preventing an unauthorized individual from following an authorized person through a secured entrance (tailgating or piggybacking)?

  • A. Photo identification
  • B. Card-key door locks
  • C. Biometric scanners
  • D. Awareness training

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Awareness training would most likely result in any attempted tailgating being challenged by the authorized employee. The other choices are physical controls which by themselves would not be effective against tailgating.


NEW QUESTION # 167
Of the following, who is MOST appropriate to own the risk associated with the failure of a privileged access control?

  • A. Compliance manager
  • B. Data owner
  • C. Information security manager
  • D. Business owner

Answer: D

Explanation:
The business owner is the most appropriate person to own the risk associated with the failure of a privileged access control because they are ultimately responsible for the protection and use of the information in their business unit1. The data owner is responsible for determining the access rights for specific data sets, but not for the access control mechanisms2. The information security manager is responsible for implementing and enforcing the security policies and standards, but not for owning the risk3. The compliance manager is responsible for ensuring that the organization meets the regulatory requirements, but not for owning the risk3. Reference: 1 https://www.cyberark.com/resources/blog/how-do-you-prioritize-risk-for-privileged-access-management 3 https://www.isaca.org/resources/isaca-journal/issues/2017/volume-1/capability-framework-for-privileged-access-management 2 https://security.stackexchange.com/questions/218049/what-is-the-difference-between-data-owner-data-custodian-and-system-owner


NEW QUESTION # 168
Which of the following is the MOST effective approach of delivering security incident response training?

  • A. Provide on-the-job training and mentoring for the incident response team.
  • B. Include incident response training within new staff orientation.
  • C. Engage external consultants to present real-world examples within the industry.
  • D. Perform role-playing exercises to simulate real-world incident response scenarios.

Answer: D


NEW QUESTION # 169
An organization is considering a self-service solution for the deployment of virtualized development servers.
Which of the following should be the information security manager's PRIMARY concern?

  • A. Ability to remain current with patches
  • B. Segregation of servers from the production environment
  • C. Ability to maintain server security baseline
  • D. Generation of excessive security event logs

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 170
Which of the following characteristics is MOST important when looking at prospective candidates for the role of chief information security officer (CISO)?

  • A. Ability to understand and map organizational needs to security technologies
  • B. Ability to manage a diverse group of individuals and resources across an organization
  • C. Knowledge of the regulatory environment and project management techniques
  • D. Knowledge of information technology platforms, networks and development methodologies

Answer: A

Explanation:
Explanation
Information security will be properly aligned with the goals of the business only with the ability to understand and map organizational needs to enable security technologies. All of the other choices are important but secondary to meeting business security needs.


NEW QUESTION # 171
The chief information security officer (CISO) has developed an information security strategy, but is struggling to obtain senior management commitment for funds to implement the strategy. Which of the following is the MOST likely reason?

  • A. The strategy does not include a cost-benefit analysis.
  • B. There was a lack of engagement with the business during development.
  • C. The CISO reports to the CIO.
  • D. The strategy does not comply with security standards.

Answer: A


NEW QUESTION # 172
An organization is about to purchase a rival organization. The PRIMARY reason for performing information security due diligence prior to making the purchase is to:

  • A. assess the ability to integrate the security department operations.
  • B. ensure compliance with international standards.
  • C. evaluate the security policy and standards.
  • D. determine the security exposures.

Answer: D

Explanation:
Explanation
Information security due diligence is the process of assessing the current state of information security in an organization, identifying any gaps, risks, or vulnerabilities, and estimating the costs and efforts required to remediate them. Performing information security due diligence prior to making the purchase is important to determine the security exposures that may affect the value, reputation, or liability of the organization, as well as the feasibility and compatibility of integrating the security systems and processes of the two organizations.
References = CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.22; Information Security Due Diligence Questionnair


NEW QUESTION # 173
An internal review of a web-based application system finds the ability to gain access to all employees' accounts by changing the employee's ID on the URL used for accessing the account. The vulnerability identified is:

  • A. cross-site scripting.
  • B. broken authentication.
  • C. structured query language (SQL) injection.
  • D. unvalidated input.

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
The authentication process is broken because, although the session is valid, the application should reauthenticate when the input parameters are changed. The review provided valid employee IDs, and valid input was processed. The problem here is the lack of reauthentication when the input parameters are changed.
Cross-site scripting is not the problem in this case since the attack is not transferred to any other user's browser to obtain the output. Structured query language (SQL) injection is not a problem since input is provided as a valid employee ID and no SQL queries are injected to provide the output.


NEW QUESTION # 174
An email digital signature will:

  • A. prevent unauthorized modification of an email message.
  • B. protect the confidentiality of an email message.
  • C. automatically correct unauthorized modification of an email message.
  • D. verify to recipient the integrity of an email message.

Answer: D

Explanation:
An email digital signature will verify to recipient the integrity of an email message because it ensures that the message has not been altered or tampered with during transit, and confirms that the message originated from the sender and not an imposter. An email digital signature will not protect the confidentiality of an email message because it does not encrypt or hide the message content from unauthorized parties. An email digital signature will not automatically correct unauthorized modification of an email message because it does not change or restore the message content if it has been altered or tampered with. An email digital signature will not prevent unauthorized modification of an email message because it does not block or stop any attempts to alter or tamper with the message content. Reference: https://support.microsoft.com/en-us/office/secure-messages-by-using-a-digital-signature-549ca2f1-a68f-4366-85fa-b3f4b5856fc6 https://www.techtarget.com/searchsecurity/definition/digital-signature


NEW QUESTION # 175
An information security manager is implementing a bring your own device (BYOD) program. Which of the following would BEST ensure that users adhere to the security standards?

  • A. Deploy a device management solution
  • B. Publish the standards on the intranet landing page
  • C. Establish an acceptable use policy
  • D. Monitor user activities on the network

Answer: A


NEW QUESTION # 176
The MOST important characteristic of good security policies is that they:

  • A. are aligned with organizational goals.
  • B. state only one general security mandate.
  • C. govern the creation of procedures and guidelines.
  • D. state expectations of IT management.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The most important characteristic of good security policies is that they be aligned with organizational goals.
Failure to align policies and goals significantly reduces the value provided by the policies. Stating expectations of IT management omits addressing overall organizational goals and objectives. Stating only one general security mandate is the next best option since policies should be clear; otherwise, policies may be confusing and difficult to understand. Governing the creation of procedures and guidelines is most relevant to information security standards.


NEW QUESTION # 177
What would be the PRIMARY reason for an organization to conduct a simulated phishing attack on its employees as part of a social engineering assessment?

  • A. Test the effectiveness of the incident response plan.
  • B. Measure the effectiveness of the anti-spam solution.
  • C. Identify the need for mitigating security controls.
  • D. Measure the effectiveness of security awareness training.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT


NEW QUESTION # 178
......

Verified CISM Exam Dumps Q&As - Provide CISM with Correct Answers: https://www.torrentvalid.com/CISM-valid-braindumps-torrent.html

CISM Exam Questions | Real CISM Practice Dumps: https://drive.google.com/open?id=1lffOQg9YHbmHGJ_AgvLnn1RQ1PBtHEgE