100% Pass Guaranteed Accurate CISM Answers 365 Days Free Updates [Q102-Q125]

Share

100% Pass Guaranteed Accurate CISM Answers 365 Days Free Updates

CISM DUMPS Q&As with Explanations Verified & Correct Answers


The CISM exam is designed to assess the knowledge and skills of information security professionals who are responsible for managing, designing, and overseeing information security programs in organizations. CISM exam covers four domains: information security governance, risk management, information security program development and management, and information security incident management.

 

NEW QUESTION # 102
In order to protect a network against unauthorized external connections to corporate systems, the information security manager should BEST implement:

  • A. IP antispoofing filtering.
  • B. access lists of trusted devices.
  • C. a strong authentication.
  • D. network encryption protocol.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Strong authentication will provide adequate assurance on the identity of the users, while IP antispoofing is aimed at the device rather than the user. Encryption protocol ensures data confidentiality and authenticity while access lists of trusted devices are easily exploited by spoofed identity of the clients.


NEW QUESTION # 103
Which of the following defines the triggers within a business continuity plan (BCP)?

  • A. Gap analysis
  • B. Disaster recovery plan (DRP)
  • C. Information security policy
  • D. Needs of the organization

Answer: C


NEW QUESTION # 104
A risk analysis should:

  • A. address the potential size and likelihood of loss.
  • B. give more weight to the likelihood vs. the size of the loss.
  • C. include a benchmark of similar companies in its scope.
  • D. assume an equal degree of protection for all assets.

Answer: A

Explanation:
Explanation
A risk analysis should take into account the potential size and likelihood of a loss. It could include comparisons with a group of companies of similar size. It should not assume an equal degree of protection for all assets since assets may have different risk factors. The likelihood of the loss should not receive greater emphasis than the size of the loss; a risk analysis should always address both equally.


NEW QUESTION # 105
In order to protect a network against unauthorized external connections to corporate systems, the information security manager should BEST implement:

  • A. IP antispoofing filtering.
  • B. access lists of trusted devices.
  • C. a strong authentication.
  • D. network encryption protocol.

Answer: C

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Strong authentication will provide adequate assurance on the identity of the users, while IP antispoofing is aimed at the device rather than the user. Encryption protocol ensures data confidentiality and authenticity while access lists of trusted devices are easily exploited by spoofed identity of the clients.


NEW QUESTION # 106
Which of the following roles should be separated?

  • A. Firewall management and security operations
  • B. Help desk and security administration
  • C. Data security and database administration
  • D. Systems analysis and application programming

Answer: C


NEW QUESTION # 107
Which of the following is the MOST effective way for an information security manager to ensure that security is incorporated into an organization's project development processes?

  • A. Participate in project initiation, approval, and funding.
  • B. Conduct security reviews during design, testing, and implementation.
  • C. Integrate organization's security requirements into project
  • D. Develop good communications with the project management office (PMO).

Answer: C


NEW QUESTION # 108
An incident response team has determined there is a need to isolate a system that is communicating with a known malicious host on the Internet.
Which of the following stakeholders should be contacted FIRST?

  • A. Executive management
  • B. The business owner
  • C. Key customers
  • D. System administrator

Answer: D


NEW QUESTION # 109
The root cause of a successful cross site request forgery (XSRF) attack against an application is that the vulnerable application:

  • A. has implemented cookies as the sole authentication mechanism.
  • B. is hosted on a server along with other applications.
  • C. uses multiple redirects for completing a data commit transaction.
  • D. has been installed with a non-1egitimate license key.

Answer: A

Explanation:
XSRF exploits inadequate authentication mechanisms in web applications that rely only on elements such as cookies when performing a transaction. XSRF is related to an authentication mechanism, not to redirection. Option C is related to intellectual property rights, not to XSRF vulnerability. Merely hosting multiple applications on the same server is not the root cause of this vulnerability.


NEW QUESTION # 110
Meeting which of the following security objectives BEST ensures that information is protected against unauthorized disclosure?

  • A. Nonrepudiation
  • B. Confidentiality
  • C. Integrity
  • D. Authenticity

Answer: B


NEW QUESTION # 111
A successful risk management program should lead to:

  • A. optimization of risk reduction efforts against cost.
  • B. identification and removal of all man-made threats.
  • C. containment of losses to an annual budgeted amount.
  • D. elimination or transference of all organizational risks.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Successful risk management should lead to a breakeven point of risk reduction and cost. The other options listed are not achievable. Threats cannot be totally removed or transferred, while losses cannot be budgeted in advance with absolute certainty.


NEW QUESTION # 112
In risk assessment, after the identification of threats to organizational assets, the information security manager would:

  • A. determine threats to be reported to upper management.
  • B. request funding for the security program.
  • C. implement controls to achieve target risk levels.
  • D. evaluate the controls currently in place.

Answer: D

Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation/Reference:


NEW QUESTION # 113
Which of the following would BEST help to ensure an organization s security program is aligned with business objectives?

  • A. Security policies are reviewed and approved by the chief information officer.
  • B. Project managers receive annual information security awareness training.
  • C. The security strategy it reviewed and approved by the organization s executive committee.
  • D. The organization's board of directors includes a dedicated information security specialist

Answer: C


NEW QUESTION # 114
Which of the following actions should be taken when an online trading company discovers a network attack in progress?

  • A. Enable trace logging on all event
  • B. Dump all event logs to removable media
  • C. Isolate the affected network segment
  • D. Shut off all network access points

Answer: C

Explanation:
Explanation
Isolating the affected network segment will mitigate the immediate threat while allowing unaffected portions of the business to continue processing. Shutting off all network access points would create a denial of service that could result in loss of revenue. Dumping event logs and enabling trace logging, while perhaps useful, would not mitigate the immediate threat posed by the network attack.


NEW QUESTION # 115
An information security manager believes that a network file server was compromised by a hacker. Which of the following should be the FIRST action taken?

  • A. Shut down the network.
  • B. Unsure that critical data on the server are backed up.
  • C. Initiate the incident response process.
  • D. Shut down the compromised server.

Answer: C

Explanation:
Explanation
The incident response process will determine the appropriate course of action. If the data have been corrupted by a hacker, the backup may also be corrupted. Shutting down the server is likely to destroy any forensic evidence that may exist and may be required by the investigation. Shutting down the network is a drastic action, especially if the hacker is no longer active on the network.


NEW QUESTION # 116
An organization is considering the deployment of encryption software and systems organization-wide. The MOST important consideration should be whether:

  • A. the implementation supports the business strategy.
  • B. data can be recovered if the encryption keys are misplaced.
  • C. the business strategy includes exceptions to the encryption standard.
  • D. a classification policy has been developed to incorporate the need for encryption.

Answer: A


NEW QUESTION # 117
Before engaging outsourced providers, an information security manager should ensure that the organization's data classification requirements:

  • A. are compatible with the provider's own classification.
  • B. are communicated to the provider.
  • C. exceed those of the outsourcer.
  • D. are stated in the contract.

Answer: D

Explanation:
Explanation
The most effective mechanism to ensure that the organization's security standards are met by a third party, would be a legal agreement. Choices
A. B and C are acceptable options, but not as comprehensive or as binding as a legal contract.


NEW QUESTION # 118
An information security manager uses security metrics to measure the:

  • A. performance of the security baseline.
  • B. effectiveness of the incident response team.
  • C. performance of the information security program.
  • D. effectiveness of the security risk analysis.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The security metrics should be designed so that there is a relationship to the performance of the overall security program in terms of effectiveness measurement. Use of security metrics occurs after the risk assessment process and does not measure it. Measurement of the incident response team performance is included in the overall program performance, so this is an incomplete answer.


NEW QUESTION # 119
Management has announced the acquisition of a new company. The information security manager of parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies.
To BEST address this concern, the information security manager should:

  • A. review access rights as the acquisition integration occurs.
  • B. implement consistent access control standards.
  • C. perform a risk assessment of the access rights.
  • D. escalate concern for conflicting access rights to management.

Answer: B

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 120
Which of the following is the PRIMARY responsibility of the information security manager when an organization implements the use of personally-owned devices on the corporate network?

  • A. Encrypting the data on mobile devices
  • B. Enforcing defined policy and procedures
  • C. Requiring remote wipe capabilities
  • D. Conducting security awareness training

Answer: B


NEW QUESTION # 121
Which of the following is the MOST important reason for an information security review of contracts? To help ensure that:

  • A. appropriate controls are included.
  • B. the parties to the agreement can perform.
  • C. the right to audit is a requirement.
  • D. confidential data are not included in the agreement.

Answer: A

Explanation:
Agreements with external parties can expose an organization to information security risks that must be assessed and appropriately mitigated. The ability of the parties to perform is normally the responsibility of legal and the business operation involved. Confidential information may be in the agreement by necessity and. while the information security manager can advise and provide approaches to protect the information, the responsibility rests with the business and legal. Audit rights may be one of many possible controls to include in a third-party agreement, but is not necessarily a contract requirement, depending on the nature of the agreement.


NEW QUESTION # 122
When designing the technical solution for a disaster recovery site, the PRIMARY factor that should be taken into consideration is the:

  • A. maximum tolerable outage (MTO).
  • B. recovery window.
  • C. services delivery objective.
  • D. recovery time objective (RTO).

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The length of the recovery window is defined by business management and determines the acceptable time frame between a disaster and the restoration of critical services/applications. The technical implementation of the disaster recovery (DR) site will be based on this constraint, especially the choice between a hot, warm or cold site. The service delivery objective is supported during the alternate process mode until the normal situation is restored, which is directly related to business needs. The recovery time objective (RTO) is commonly agreed to be the time frame between a disaster and the return to normal operations. It is then longer than the interruption window and is very difficult to estimate in advance. The time frame between the reduced operation mode at the end of the interruption window and the return to normal operations depends on the magnitude of the disaster. Technical disaster recovery solutions alone will not be used for returning to normal operations. Maximum tolerable outage (MTO) is the maximum time acceptable by a company operating in reduced mode before experiencing losses. Theoretically, recovery time objectives (RTOs) equal the interruption window plus the maximum tolerable outage. This will not be the primary factor for the choice of the technical disaster recovery solution.


NEW QUESTION # 123
When recommending a preventive control against cross-site scripting in web applications, an information security manager is MOST likely to suggest:

  • A. coding standards and code review.
  • B. using https in place of http.
  • C. hardening of the web server s operating system.
  • D. consolidating multiple sites into a single portal.

Answer: A


NEW QUESTION # 124
An organization establishes an internal document collaboration site. To ensure data confidentiality of each project group, it is MOST important to:

  • A. enforce document lifecycle management.
  • B. prohibit remote access to the site.
  • C. periodically recertify access rights.
  • D. conduct a vulnerability assessment.

Answer: C


NEW QUESTION # 125
......

CISM dumps Exam Material with 417 Questions: https://www.free4dump.com/CISM-braindumps-torrent.html

CISM Questions and Answers Guarantee you Oass the Test Easily: https://drive.google.com/open?id=1Mk2PWcP7iVqJwg1aLe-bN9wA1xbiHT4j