
[Dec 26, 2023] 100% Pass Guarantee for CISM Dumps with Actual Exam Questions
Today Updated CISM Exam Dumps Actual Questions
The CISM certification exam is a rigorous four-hour exam that consists of 150 multiple-choice questions. CISM exam is designed to assess an individual’s knowledge and understanding of information security management, including information security governance, risk management, program development and management, incident management, and information security incident response. To earn the CISM certification, candidates must pass the exam and meet the experience and education requirements set forth by ISACA. Certified Information Security Manager certification is valid for three years, and individuals must earn continuing education credits to maintain their certification.
NEW QUESTION # 38
Minimum standards for securing the technical infrastructure should be defined in a security:
- A. strategy.
- B. guidelines.
- C. architecture.
- D. model.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Minimum standards for securing the technical infrastructure should be defined in a security architecture document. This document defines how components are secured and the security services that should be in place. A strategy is a broad, high-level document. A guideline is advisory in nature, while a security model shows the relationships between components.
NEW QUESTION # 39
Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?
- A. Improved accountability to shareholders
- B. Increased influence of security management
- C. Optimized information security resources
- D. Consistent execution of information security strategy
Answer: A
NEW QUESTION # 40
When establishing classifications of security incidents for the development of an incident response plan, which of the following provides the MOST valuable input?
- A. The business continuity plan (BCP)
- B. Vulnerability assessment results
- C. Business impact analysis (BIA) results
- D. Recommendations from senior management
Answer: C
Explanation:
Section: MIXED QUESTIONS
NEW QUESTION # 41
The likelihood of a successful intrusion is a function of:
- A. opportunity and asset value.
- B. threat and vulnerability levels.
- C. configuration and maintenance of log monitoring system.
- D. value and desirability to the intruder.
Answer: B
NEW QUESTION # 42
The MOST effective way to continuously monitor an organization's cybersecurity posture is to evaluate its:
- A. level of support from senior management.
- B. key performance indicators (KPIs).
- C. timeliness in responding to attacks.
- D. compliance with industry regulations.
Answer: B
NEW QUESTION # 43
Which of the following activities is MOST likely to increase the difficulty of totally eradicating malicious code that is not immediately detected?
- A. Backing up files
- B. Upgrading hardware
- C. Applying patches
- D. Changing access rules
Answer: A
Explanation:
Explanation/Reference:
Explanation:
If malicious code is not immediately detected, it will most likely be backed up as a part of the normal tape backup process. When later discovered, the code may be eradicated from the device but still remain undetected ON a backup tape. Any subsequent restores using that tape may reintroduce the malicious code. Applying patches, changing access rules and upgrading hardware does not significantly increase the level of difficulty.
NEW QUESTION # 44
An internal audit has found that critical patches were not implemented within the timeline established by policy without a valid reason. Which of the following is the BEST course of action to address the audit findings?
- A. Evaluate patch management training.
- B. Perform regular audits on the implementation of critical patches.
- C. Monitor and notify IT staff of critical patches
- D. Assess the patch management process
Answer: B
NEW QUESTION # 45
What is the BEST method to confirm that all firewall rules and router configuration settings are adequate?
- A. Daily review of server logs for evidence of hacker activity
- B. Periodically perform penetration tests
- C. Review intrusion detection system (IDS) logs for evidence of attacks
- D. Periodic review of network configuration
Answer: B
Explanation:
Due to the complexity of firewall rules and router tables, plus the sheer size of intrusion detection systems (IDSs) and server logs, a physical review will be insufficient. The best approach for confirming the adequacy of these configuration settings is to periodically perform attack and penetration tests.
NEW QUESTION # 46
The BEST way to ensure that information security policies are followed is to:
- A. perform periodic reviews for compliance.
- B. include escalating penalties for noncompliance.
- C. establish an anonymous hotline to report policy abuses.
- D. distribute printed copies to all employees.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The best way to ensure that information security policies are followed is to periodically review levels of compliance. Distributing printed copies, advertising an abuse hotline or linking policies to an international standard will not motivate individuals as much as the consequences of being found in noncompliance.
Escalating penalties will first require a compliance review.
NEW QUESTION # 47
Which of the following types of controls would be MOST important to implement when digitizing human resource (HR) records?
- A. Access management controls
- B. Change management controls
- C. Project management controls
- D. Software development controls
Answer: B
NEW QUESTION # 48
A message is being sent with a hash. The risk of an attacker changing the message and generating an authentic hash value can be mitigated by:
- A. generating hash output that is the same size as the original message
- B. using a secret key in conjunction with the hash algorithm
- C. requiring the recipient to use a different hash algorithm
- D. using the sender's public key to encrypt the message
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 49
When an organization and its IT-hosting service provider are establishing a contract with each other, it is MOST important that the contract includes:
- A. recovery time objectives (RTOs).
- B. each party's security responsibilities.
- C. details of expected security metrics.
- D. penalties for noncompliance with security policy.
Answer: B
NEW QUESTION # 50
Which of the following contributes MOST to the effective implementation of an information security strategy?
- A. Reporting of security metrics
- B. Endorsement by senior management
- C. Implementation of security standards
- D. Regular security awareness training
Answer: B
NEW QUESTION # 51
What is the BEST way for an information security manager to ensure critical assets are prioritized in a new information security program?
- A. Backup information assets and store them offsite
- B. Conduct security awareness training.
- C. Conduct an inventory of information assets.
- D. Update operating procedures to include new requirements.
Answer: D
NEW QUESTION # 52
In designing a backup strategy that will be consistent with a disaster recovery strategy, the PRIMARY factor to be taken into account will be the:
- A. interruption window.
- B. volume of sensitive data.
- C. recovery point objective (RPO).
- D. recovery' time objective (RTO).
Answer: C
Explanation:
Explanation
The recovery point objective (RPO) defines the maximum loss of data (in terms of time) acceptable by the business (i.e., age of data to be restored). It will directly determine the basic elements of the backup strategy frequency of the backups and what kind of backup is the most appropriate (disk-to-disk, on tape, mirroring).
The volume of data will be used to determine the capacity of the backup solution. The recovery time objective (RTO) - the time between disaster and return to normal operation - will not have any impact on the backup strategy. The availability to restore backups in a time frame consistent with the interruption window will have to be checked and will influence the strategy (e.g., full backup vs. incremental), but this will not be the primary factor.
NEW QUESTION # 53
After completing a full IT risk assessment, who can BEST decide which mitigating controls should be implemented?
- A. IT audit manager
- B. Senior management
- C. Information security officer (ISO)
- D. Business manager
Answer: D
Explanation:
Explanation
The business manager will be in the best position, based on the risk assessment and mitigation proposals. to decide which controls should/could be implemented, in line with the business strategy and with budget. Senior management will have to ensure that the business manager has a clear understanding of the risk assessed but in no case will be in a position to decide on specific controls. The IT audit manager will take part in the process to identify threats and vulnerabilities, and to make recommendations for mitigations. The information security officer (ISO) could make some decisions regarding implementation of controls. However, the business manager will have a broader business view and full control over the budget and, therefore, will be in a better position to make strategic decisions.
NEW QUESTION # 54
Which of the following is MOST likely to reduce the effectiveness of a signature-based intrusion detection system (IDS)?
- A. The environment is complex.
- B. The activities being monitored deviate from what is considered normal.
- C. The pattern of normal behavior changes quickly and dramatically.
- D. The information regarding monitored activities becomes stale.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 55
After a server has been attacked, which of the following is the BEST course of action?
- A. Initiate incident response
- B. Isolate the system
- C. Conduct a security audit
- D. Review vulnerability assessment
Answer: A
NEW QUESTION # 56
The PRIMARY objective of a risk response strategy should be:
- A. threat reduction.
- B. regulatory compliance.
- C. senior management buy-in.
- D. appropriate control selection.
Answer: D
NEW QUESTION # 57
When developing an incident response plan, which of the following is the MOST effective way to ensure incidents common to the organization are handled properly?
- A. Creating and distributing a personnel call tree
- B. Conducting awareness training
- C. Rehearsing response scenarios
- D. Adopting industry standard response procedures
Answer: D
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
NEW QUESTION # 58
......
CISM exam dumps with real ISACA questions and answers: https://www.torrentvalid.com/CISM-valid-braindumps-torrent.html
CISM Exam in First Attempt Guaranteed: https://drive.google.com/open?id=1sWWTh0M0mi8VxwBLLdvahTnt6r68J1xt