
[2022] Use Valid New CISM Questions - Top choice Help You Gain Success
CISM Exam Practice Materials Collection
NEW QUESTION 229
The MOST effective control to detect fraud inside an organization's network is to:
- A. implement C (IDS).
- B. segregate duties
- C. apply two-factor authentication
- D. review access logs.
Answer: D
NEW QUESTION 230
What is the MOST effective access control method to prevent users from sharing files with unauthorized users?
- A. Mandatory
- B. Role-based
- C. Walled garden
- D. Discretionary
Answer: A
Explanation:
Explanation
Mandatory access controls restrict access to files based on the security classification of the file. This prevents users from sharing files with unauthorized users. Role-based access controls grant access according to the role assigned to a user; they do not prohibit file sharing. Discretionary and lattice-based access controls are not as effective as mandatory access controls in preventing file sharing. A walled garden is an environment that controls a user's access to web content and services. In effect, the walled garden directs the user's navigation within particular areas, and does not necessarily prevent sharing of other material.
NEW QUESTION 231
Managing the life cycle of a digital certificate is a role of a(n):
- A. independent trusted source.
- B. security administrator.
- C. system developer.
- D. system administrator.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Digital certificates must be managed by an independent trusted source in order to maintain trust in their authenticity. The other options are not necessarily entrusted with this capability.
NEW QUESTION 232
Which of the following is the BEST mechanism to determine the effectiveness of the incident response process?
- A. Post incident review
- B. Action recording and review
- C. Incident response metrics
- D. Periodic auditing of the incident response process
Answer: A
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Post event reviews are designed to identify gaps and shortcomings in the actual incident response process so that these gaps may be improved over time. The other choices will not provide the same level of feedback in improving the process.
NEW QUESTION 233
Which of the following is the MOST important element to ensure the success of a disaster recovery test at a vendor-provided hot site?
- A. Business management actively participates
- B. Network IP addresses are predefined
- C. Equipment at the hot site is identical
- D. Tests are scheduled on weekends
Answer: A
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Disaster recovery testing requires the allocation of sufficient resources to be successful. Without the support of management, these resources will not be available, and testing will suffer as a result. Testing on weekends can be advantageous but this is not the most important choice. As vendor-provided hot sites are in a state of constant change, it is not always possible to have network addresses defined in advance.
Although it would be ideal to provide for identical equipment at the hot site, this is not always practical as multiple customers must be served and equipment specifications will therefore vary.
NEW QUESTION 234
Which of the following should be the FIRST step when creating an organization's bring your own device (BYOD) program?
- A. Pretest approved devices
- B. Develop an acceptable use policy.
- C. identify data to be stored on the device
- D. Develop employee training.
Answer: B
NEW QUESTION 235
A regulatory compliance issue has been identified in a critical business application, but remediating the issue would significantly impact business operations. Vyhat information would BEST enable senior management to make an informed decision?
- A. Risk assessment results and recommendations
- B. Costs associated with compensating controls
- C. Industry benchmarks and best practices
- D. Impact analysis and treatment options
Answer: A
NEW QUESTION 236
Which of the following is the MOST important action when using a web application that has recognized vulnerabilities?
- A. Deploy host-based intrusion detection.
- B. Install anti-spyware software.
- C. Monitor application level logs.
- D. Deploy an application firewall.
Answer: D
NEW QUESTION 237
A test plan to validate the security controls of a new system should be developed during which phase of the project?
- A. Testing
- B. Development
- C. Initiation
- D. Design
Answer: D
Explanation:
Explanation
In the design phase, security checkpoints are defined and a test plan is developed. The testing phase is too late since the system has already been developed and is in production testing. In the initiation phase, the basic security objective of the project is acknowledged. Development is the coding phase and is too late to consider test plans.
NEW QUESTION 238
The management staff of an organization that does not have a dedicated security function decides to use its IT manager to perform a security review. The MAIN job requirement in this arrangement is that the IT manager
- A. obtain support from other departments.
- B. have knowledge of security standards.
- C. report significant security risks.
- D. report risks in other departments.
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The IT manager needs to report the security risks in the environment pursuant to the security review, including risks in the IT implementation. Choices A, B and D are important, but not the main responsibilities or job requirements.
NEW QUESTION 239
Before engaging outsourced providers, an information security manager should ensure that the organization's data classification requirements:
- A. exceed those of the outsourcer.
- B. are communicated to the provider.
- C. are compatible with the provider's own classification.
- D. are stated in the contract.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The most effective mechanism to ensure that the organization's security standards are met by a third party, would be a legal agreement. Choices A.
B and C are acceptable options, but not as comprehensive or as binding as a legal contract.
NEW QUESTION 240
What does a network vulnerability assessment intend to identify?
- A. Malicious software and spyware
- B. Security design flaws
- C. Misconfiguration and missing updates
- D. 0-day vulnerabilities
Answer: C
Explanation:
Explanation/Reference:
Explanation:
A network vulnerability assessment intends to identify known vulnerabilities based on common misconfigurations and missing updates. 0-day vulnerabilities by definition are not previously known and therefore are undetectable. Malicious software and spyware are normally addressed through antivirus and antispyware policies. Security design flaws require a deeper level of analysis.
NEW QUESTION 241
The PRIMARY reason to classify information assets should be to ensure
- A. Insurance valuation is appropriate.
- B. proper ownership is established
- C. proper access control
- D. senior management buy-in
Answer: C
NEW QUESTION 242
When a new key business application goes into production, the PRIMARY reason to update relevant business impact analysis (BIA) and business continuity/disaster recovery plans is because:
- A. the asset inventory must be maintained.
- B. software licenses may expire in the future without warning.
- C. service level agreements may not otherwise be met.
- D. this is a requirement of the security policy.
Answer: C
Explanation:
The key requirement is to preserve availability of business operations. Choice A is a correct compliance requirement, but is not the main objective in this case. Choices B and C are supplementary requirements for business continuity/disaster recovery planning.
NEW QUESTION 243
Which of the following methods BEST ensures that a comprehensive approach is used to direct information security activities?
- A. Creating communication channels
- B. Promoting security training
- C. Molding periodic meetings with business owners
- D. Establishing a steering committee
Answer: D
Explanation:
Explanation
NEW QUESTION 244
When application-level security controlled by business process owners is found to be poorly managed, which of the following could BEST improve current practices?
- A. Policy enforcement by IT management
- B. Centralizing security management
- C. Implementing sanctions for noncompliance
- D. Periodic compliance reviews
Answer: B
Explanation:
By centralizing security management, the organization can ensure that security standards are applied to all systems equally and in line with established policy. Sanctions for noncompliance would not be the best way to correct poor management practices caused by work overloads or insufficient knowledge of security practices. Enforcement of policies is not solely the responsibility of IT management. Periodic compliance reviews would not correct the problems, by themselves, although reports to management would trigger corrective action such as centralizing security management.
NEW QUESTION 245
......
Maximum Grades By Making ready With CISM Dumps: https://www.braindumpsvce.com/CISM_exam-dumps-torrent.html
Get Latest and 100% Accurate CISM Exam Questions: https://drive.google.com/open?id=10jMKnb3qzmPKPVQoeidG2R1AG0d6W9Vd