
CISM Dumps with Practice Exam Questions Answers
CISM by Isaca Certification Actual Free Exam Practice Test
ISACA Certified Information Security Manager CISM Exam
ISACA Certified Information Security Manager CISM Exam is related to Certified Information Security Manager CISM certification. This CISM Exam validates the ability to maintain and establish an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives. Candidate must have the ability to manage information risk appropriately and program resources are managed responsibly. It also deals with the ability to ensure that organizational goals and objectives are supported by the information security program communicate managements directives and guide the development of standards, procedures, and guidelines and develop business cases to support investments in information security. Security Managers Industry Leaders and Industry Practitioners usually hold or pursue this certification and you can expect the same job roles after completion of this certification.
Important requirements
The IT consultants, information security managers, and aspiring managers are the target audience for the CISM certification exam that supports InfoSec program management. These specialists are expected to have an understanding of the relationship between information security and business objectives, as well as manage information security of a company, and develop policies and practices.
NEW QUESTION 387
What should be an information security manager's FIRST step when developing a business case for a new intrusion detection system (IDS) solution?
- A. Perform a cost-benefit analysis.
- B. Define the issues to be addressed.
- C. Calculate the total cost of ownership (TCO).
- D. Conduct a feasibility study.
Answer: D
NEW QUESTION 388
When performing a quantitative risk analysis, which of the following is MOST important to estimate the potential loss?
- A. Calculate the value of the information or asset
- B. Assess the impact of confidential data disclosure
- C. Evaluate productivity losses
- D. Measure the probability of occurrence of each threat
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Calculating the value of the information or asset is the first step in a risk analysis process to determine the impact to the organization, which is the ultimate goal. Determining how much productivity could be lost and how much it would cost is a step in the estimation of potential risk process. Knowing the impact if confidential information is disclosed is also a step in the estimation of potential risk. Measuring the probability of occurrence for each threat identified is a step in performing a threat analysis and therefore a partial answer.
NEW QUESTION 389
A core business unit relies on an effective legacy system that does not meet the current security standards and threatens the enterprise network. Which of the following is the BEST course of action to address the situation?
- A. Develop processes to compensate for the deficiencies.
- B. Require that new systems that can meet the standards be implemented.
- C. Disconnect the legacy system from the rest of the network.
- D. Document the deficiencies in the risk register.
Answer: D
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation
NEW QUESTION 390
An organization is developing a disaster recovery plan for a data center that hosts multiple applications. The application recovery sequence would BEST be determined through an analysis of:
- A. Key performance indicators (KPIs)
- B. Recovery point objectives (RPOs)
- C. Recovery time objectives (RTOs)
- D. The data classification scheme
Answer: C
NEW QUESTION 391
Which of the following is the MOST likely outcome of a well-designed information security awareness course?
- A. Increased reporting of security incidents to the incident response function
- B. Decreased reporting of security incidents to the incident response function
- C. Decrease in the number of password resets
- D. Increase in the number of identified system vulnerabilities
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
A well-organized information security awareness course informs all employees of existing security policies, the importance of following safe practices for data security anil the need to report any possible security incidents to the appropriate individuals in the organization. The other choices would not be the likely outcomes.
NEW QUESTION 392
The BEST strategy for risk management is to:
- A. reduce risk to an acceptable level.
- B. ensure that policy development properly considers organizational risks.
- C. ensure that all unmitigated risks are accepted by management.
- D. achieve a balance between risk and organizational goals.
Answer: A
Explanation:
The best strategy for risk management is to reduce risk to an acceptable level, as this will take into account the organization's appetite for risk and the fact that it would not be practical to eliminate all risk. Achieving balance between risk and organizational goals is not always practical. Policy development must consider organizational risks as well as business objectives. It may be prudent to ensure that management understands and accepts risks that it is not willing to mitigate, but that is a practice and is not sufficient to l>e considered a strategy.
NEW QUESTION 393
Which of the following would BEST enable effective decision-making?
- A. A consistent process to analyze new and historical information risk
- B. A universally applied list of generic threats, impacts, and vulnerabilities
- C. Formalized acceptance of risk analysis by business management
- D. Annualized loss estimates determined from past security events
Answer: A
NEW QUESTION 394
When conducting a post-incident review, the GREATEST benefit of collecting mean time to resolution (MTTR) data is the ability to:
- A. verify compliance with the service level agreement (SLA).
- B. learn of potential areas of improvement
- C. reduce the costs of future preventive controls.
- D. provide metrics for reporting to senior management
Answer: A
NEW QUESTION 395
An organization is entering into an agreement with a new business partner to conduct customer mailings. What is the MOST important action that the information security manager needs to perform?
- A. A due diligence security review of the business partner's security controls
- B. Ensuring that the business partner has an effective business continuity program
- C. Talking to other clients of the business partner to check references for performance
- D. Ensuring that the third party is contractually obligated to all relevant security requirements
Answer: D
Explanation:
The key requirement is that the information security manager ensures that the third party is contractually bound to follow the appropriate security requirements for the process being outsourced. This protects both organizations. All other steps are contributory to the contractual agreement, but are not key.
NEW QUESTION 396
Penetration testing is MOST appropriate when a:
- A. security incident has occurred.
- B. new system is about to go live.
- C. new system is being designed.
- D. security policy is being developed
Answer: D
NEW QUESTION 397
A threat intelligence report indicates there has been a significant rise in the number of attacks targeting the industry. What should the information security manager do NEXT?
- A. Update the organization s security awareness campaign.
- B. Conduct penetration testing to identity vulnerabilities.
- C. Discuss the risk with senior management.
- D. Allocate additional resources to monitor perimeter secunty systems,
Answer: C
NEW QUESTION 398
The business continuity policy should contain which of the following?
- A. Recovery criteria
- B. Emergency call trees
- C. Business impact assessment (BIA)
- D. Critical backups inventory
Answer: A
Explanation:
Explanation
Recovery criteria, indicating the circumstances under which specific actions are undertaken, should be contained within a business continuity policy. Telephone trees, business impact assessments (BIAs) and listings of critical backup files are too detailed to include in a policy document.
NEW QUESTION 399
The MAIN reason for having the Information Security Steering Committee review a new security controls implementation plan is to ensure that:
- A. regulatory oversight requirements are met.
- B. departmental budgets are allocated appropriately to pay for the plan.
- C. the plan aligns with the organization's business plan.
- D. the impact of the plan on the business units is reduced.
Answer: C
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The steering committee controls the execution of the information security strategy according to the needs of the organization and decides on the project prioritization and the execution plan. The steering committee does not allocate department budgets for business units. While ensuring that regulatory oversight requirements are met could be a consideration, it is not the main reason for the review. Reducing the impact on the business units is a secondary concern but not the main reason for the review.
NEW QUESTION 400
Which of the following is the BEST method for ensuring that security procedures and guidelines are known and understood?
- A. Periodic focus group meetings
- B. Computer-based certification training (CBT)
- C. Employee's signed acknowledgement
- D. Periodic compliance reviews
Answer: B
Explanation:
Explanation
Using computer-based training (CBT) presentations with end-of-section reviews provides feedback on how well users understand what has been presented. Periodic compliance reviews are a good tool to identify problem areas but do not ensure that procedures are known or understood. Focus groups may or may not provide meaningful detail. Although a signed employee acknowledgement is good, it does not indicate whether the material has been read and/or understood.
NEW QUESTION 401
Internal audit has reported a number of information security issues which are not in compliance with regulatory requirements. What should the information security manager do FIRST?
- A. Assess the risk to business operations
- B. Perform a gap analysis to determine needed resources
- C. Perform a vulnerability assessment
- D. Create a security exception
Answer: B
NEW QUESTION 402
Which of the following is the MOST likely to change an organization's culture to one that is more security conscious?
- A. Security steering committees
- B. Adequate security policies and procedures
- C. Security awareness campaigns
- D. Periodic compliance reviews
Answer: C
Explanation:
Explanation
Security awareness campaigns will be more effective at changing an organizational culture than the creation of steering committees and security policies and procedures. Compliance reviews are helpful; however, awareness by all staff is more effective because compliance reviews are focused on certain areas groups and do not necessarily educate.
NEW QUESTION 403
Authorization can BEST be accomplished by establishing:
- A. whether users are who they say they are.
- B. the ownership of the data.
- C. how users identify themselves to information systems.
- D. what users can do when they are granted system access.
Answer: D
NEW QUESTION 404
Logging is an example of which type of defense against systems compromise?
- A. Containment
- B. Detection
- C. Reaction
- D. Recovery
Answer: B
Explanation:
Explanation
Detection defenses include logging as well as monitoring, measuring, auditing, detecting viruses and intrusion.
Examples of containment defenses are awareness, training and physical security defenses. Examples of reaction defenses are incident response, policy and procedure change, and control enhancement. Examples of recovery defenses are backups and restorations, failover and remote sites, and business continuity plans and disaster recovery plans.
NEW QUESTION 405
When an organization hires a new information security manager, which of the following goals should this individual pursue FIRST?
- A. Assemble an experienced staff
- B. Establish good communication with steering committee members
- C. Benchmark peer organizations
- D. Develop a security architecture
Answer: B
Explanation:
Explanation
New information security managers should seek to build rapport and establish lines of communication with senior management to enlist their support. Benchmarking peer organizations is beneficial to better understand industry best practices, but it is secondary to obtaining senior management support. Similarly, developing a security architecture and assembling an experienced staff are objectives that can be obtained later.
NEW QUESTION 406
The MAIN reason for deploying a public key infrastructure (PKI) when implementing an information security program is to:
- A. allow deployment of the active directory.
- B. ensure the confidentiality of sensitive material.
- C. implement secure sockets layer (SSL) encryption.
- D. provide a high assurance of identity.
Answer: D
Explanation:
Explanation
The primary purpose of a public key infrastructure (PKI) is to provide strong authentication. Confidentiality is a function of the session keys distributed by the PKI. An active directory can use PKI for authentication as well as using other means. Even though secure sockets layer (SSL) encryption requires keys to authenticate, it is not the main reason for deploying PKI.
NEW QUESTION 407
......
Career Growth
After getting the CISM certificate, one can become an Information System Security Officer, an Information Risk Consultant, or an Information Security Manager. Furthermore, there are different levels starting from the Entry one, which involves a System Analyst, Security Auditor Trainee, etc. Besides that, you can become a Technical Specialist, a Technical Manager, or go for the expert-level positions, which include a Senior IT Systems Professional, a Senior IT Architect, a Development Engineer, etc. Obtaining this ISACA certification can also cause a huge salary bump of around $128,000 per year, but your salary may vary according to the job title you choose.
Free Isaca Certification CISM Exam Question: https://www.examcost.com/CISM-practice-exam.html
CISM dumps & Isaca Certification sure practice dumps: https://drive.google.com/open?id=1cpUw6AVKaGCYh4thr1xzHiWN80GR9d6G

