
Authentic Best resources for CISM Test Engine Practice Exam
[2023] CISM PDF Questions - Perfect Prospect To Go With TrainingQuiz Practice Exam
How to book the CISM Exam
These are following steps for registering the CISM exam. Step 1: Pass the CISM examination within the last five years Step 2: Candidate has a minimum of five years of professional Information Systems Security Manager work experience. Step3: Apply for CISA certification with $50 USD processing fee
For more detail visit this link Apply for certification
2. Information Risk Management – 30%
This is the largest topic out of the whole exam content. The theoretical knowledge that you should have covers the following:
- Knowledge of the changes to information security program elements and events that may require risk reassessments;
- Knowledge of risk reporting requirements;
- Knowledge of threats, reliability, and current sources of information;
- Knowledge of gap analysis related to information security.
NEW QUESTION 74
When a new key business application goes into production, the PRIMARY reason to update relevant business impact analysis (BIA) and business continuity/disaster recovery plans is because:
- A. software licenses may expire in the future without warning.
- B. service level agreements may not otherwise be met.
- C. the asset inventory must be maintained.
- D. this is a requirement of the security policy.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The key requirement is to preserve availability of business operations. Choice A is a correct compliance requirement, but is not the main objective in this case. Choices B and C are supplementary requirements for business continuity/disaster recovery planning.
NEW QUESTION 75
A business impact analysis should be periodically executed PRIMARILY to:
- A. validate vulnerabilities on environmental changes.
- B. check compliance with regulations.
- C. verify the effectiveness of controls.
- D. analyze the importance of assets.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation
NEW QUESTION 76
Embedding security responsibilities into jab descriptions is important PRIMARILY because it
- A. supports access management.
- B. aligns security to the human resources function.
- C. simplifies development of the security awareness program.
- D. strengthens employee accountability.
Answer: D
NEW QUESTION 77
The BEST way to encourage good security practices is to:
- A. recognize appropriate security behavior by individuals.
- B. discipline those who fail to comply with the security policy.
- C. schedule periodic compliance audits.
- D. publish the information security policy.
Answer: C
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION 78
Which of the following would BEST provide stakeholders with information to determine the appropriate response to a disaster?
- A. Risk assessment
- B. Vulnerability assessment
- C. Business impact analysis
- D. SWOT analysis
Answer: C
NEW QUESTION 79
Managing the life cycle of a digital certificate is a role of a(n):
- A. system administrator.
- B. system developer.
- C. independent trusted source.
- D. security administrator.
Answer: C
Explanation:
Explanation
Digital certificates must be managed by an independent trusted source in order to maintain trust in their authenticity. The other options are not necessarily entrusted with this capability.
NEW QUESTION 80
Who is responsible for ensuring that information is classified?
- A. Security manager
- B. Senior management
- C. Custodian
- D. Data owner
Answer: D
Explanation:
The data owner is responsible for applying the proper classification to the data. Senior management is ultimately responsible for the organization. The security officer is responsible for applying security protection relative to the level of classification specified by the owner. The technology group is delegated the custody of the data by the data owner, but the group does not classify the information.
NEW QUESTION 81
A customer credit card database has been breached by hackers. The FIRST step in dealing with this attack should be to:
- A. confirm the incident.
- B. notify law enforcement.
- C. start containment.
- D. notify senior management.
Answer: A
Explanation:
Asserting that the condition is a true security incident is the necessary first step in determining the correct response. The containment stage would follow. Notifying senior management and law enforcement could be part of the incident response process that takes place after confirming an incident.
NEW QUESTION 82
To minimize security exposure introduced by changes to the IT environment, which of the following is MOST important to implement as part of change management?
- A. Conducting a security risk assessment prior to go-live
- B. Requiring approval by senior management
- C. Performing a business impact analysis (BIA) prior to implementation
- D. Performing post-change reviews before closing change tickets
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 83
Which of the following actions should be taken when an online trading company discovers a network attack in progress?
- A. Shut off all network access points
- B. Isolate the affected network segment
- C. Dump all event logs to removable media
- D. Enable trace logging on all event
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Isolating the affected network segment will mitigate the immediate threat while allowing unaffected portions of the business to continue processing. Shutting off all network access points would create a denial of service that could result in loss of revenue. Dumping event logs and enabling trace logging, while perhaps useful, would not mitigate the immediate threat posed by the network attack.
NEW QUESTION 84
Which of the following will MOST likely reduce the chances of an unauthorized individual gaining access to computing resources by pretending to be an authorized individual needing to have his, her password reset?
- A. Implementing automatic password syntax checking
- B. Conducting security awareness programs
- C. Increasing the frequency of password changes
- D. Performing reviews of password resets
Answer: B
Explanation:
Social engineering can be mitigated best through periodic security awareness training for staff members who may be the target of such an attempt. Changing the frequency of password changes, strengthening passwords and checking the number of password resets may be desirable, but they will not be as effective in reducing the likelihood of a social engineering attack.
NEW QUESTION 85
Which of the following is the BEST way to determine if an organization's current risk is within the risk appetite?
- A. Implementing key risk indicators (KRIs)
- B. Implementing key performance indicators (KPIs)
- C. Developing additional mitigating controls
- D. Conducting a business impact analysis (BIA)
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 86
After assessing and mitigating the risks of a web application, who should decide on the acceptance of residual application risks?
- A. Chief information officer (CIO)
- B. Business owner
- C. Information security officer
- D. Chief executive officer (CF.O)
Answer: B
Explanation:
The business owner of the application needs to understand and accept the residual application risks.
NEW QUESTION 87
The FIRST step to create an internal culture that focuses on information security is to:
- A. actively monitor operations.
- B. conduct periodic awareness training.
- C. implement stronger controls.
- D. gain the endorsement of executive management.
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Endorsement of executive management in the form of policies provides direction and awareness. The implementation of stronger controls may lead to circumvention. Awareness training is important, but must be based on policies. Actively monitoring operations will not affect culture at all levels.
NEW QUESTION 88
After a security incident has been contained, which of the following should be done FIRST?
- A. Perform a complete wipe of the affected system.
- B. Conduct forensic analysis.
- C. Notify local authorities.
- D. Restore the affected system from backup.
Answer: A
NEW QUESTION 89
Which of the following BEST demonstrates effective information security management within an organization?
- A. Employees support decisions made by information security management.
- B. Information security governance is incorporated into organizational governance.
- C. Control ownership is assigned to parties who can accept losses related to control failure.
- D. Excessive risk exposure in one department can be absorbed by other departments.
Answer: B
NEW QUESTION 90
Which of the following is the MOST appropriate course of action when the risk occurrence rate is low but the impact is high?
- A. Risk transfer
- B. Risk mitigation
- C. Risk avoidance
- D. Risk acceptance
Answer: C
Explanation:
Section: INFORMATION RISK MANAGEMENT
NEW QUESTION 91
Which of the following is an information security manager's BEST course of action when a threat intelligence report indicates a large number of ransomware attacks targeting the industry?
- A. Increase the frequency of system backups.
- B. Review the mitigating security controls.
- C. Assess the risk to the organization.
- D. Notify staff members of the threat.
Answer: C
NEW QUESTION 92
Which of the following is MOST important when selecting a third-party security operations center?
- A. Business continuity plans
- B. Indemnity clauses
- C. Incident response plans
- D. Independent controls assessment
Answer: D
NEW QUESTION 93
Which of the following devices, when placed in a demilitarized zone (DMZ), would be considered the MOST significant exposure?
- A. Application server
- B. Database server
- C. Proxy server
- D. Mail relay server
Answer: B
NEW QUESTION 94
An internal security audit has reported that authentication controls are not operating effectively. Which of the following is MOST important to c management?
- A. A business case for implementing stronger authentication controls
- B. The impact of the control weakness on the risk profile of the organization
- C. An analysis of the impact of this type of control weakness on other organizations
- D. The results of a business impact analysis (BIA)
Answer: B
NEW QUESTION 95
An organization's operations have been significantly impacted by a cyber
attack resulting in data loss. Once the attack has been contained, what should the security team do NEXT?
- A. Implement compensating controls.
- B. Conduct a lessons learned exercise,
- C. Update the incident response plan.
- D. Perform a root cause analysis.
Answer: D
NEW QUESTION 96
Which of the following should be the MOST important consideration when reporting sensitive risk-related information to stakeholders?
- A. Ensuring nonrepudiation of communication
- B. Transmitting the internal communication securely
- C. Consulting with the public relations director
- D. Customizing the communication to the audience
Answer: D
NEW QUESTION 97
Over the last year, an information security manager has performed risk assessments on multiple third-party vendors. Which of the following criteria would be MOST helpful in determining the associated level of risk applied to each vendor?
- A. Criticality of the service to the organization
- B. Compliance requirements associated with the regulation
- C. Compensating controls in place to protect information security
- D. Corresponding breaches associated with each vendor
Answer: A
Explanation:
Associated level of risk applied to each vendor is the Residual Risk (the risk after applying vendor's controls). CRISC RM 6th, (Residual Risk = Inherent Risk - Cumulative Effect of Controls) Inherent risk is the current risk without applying any control (i.e. before vendor's controls), this risk is the same quantity in the equation for each vendor. Effect of controls (the value supplied by the vendor) will be different for each vendor. Ex. For vendor 1, Residual Risk1= Inherent/current Risk - Effect of controls of Vendor1 For vendor 2, Residual Risk2= Inherent/current Risk - Effect of controls of Vendor2
NEW QUESTION 98
......
Who should take the CISM exam
The ISACA Certified Information Security Manager CISM Exam certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled as Certified Information Security Manager. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The ISACA Certified Information Security Manager CISM Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge and skills that are required to pass the ISACA Certified Information Security Manager CISM Exam then he should take this exam.
Best updated resource for CISM Online Practice Exam: https://www.trainingquiz.com/CISM-practice-quiz.html
Realistic Practice CISM Certified Information Security Manager Exam Braindumps: https://drive.google.com/open?id=1Oo_Q_gaN-anvWBobJYma9FxnrF2FXOaA

