Exit demo CISM Certified Information Security Manager PDF format · free preview

Isaca CISM - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/cism.html

Question 1
Single choice

Which of the following is MOST important to include in an information security policy?

A.

Best practices

B.

Management objectives

C.

Baselines

D.

Maturity levels

Question 2
Single choice

How does an incident response team BEST leverage the results of a business impact analysis (BIA)?

A.

Assigning restoration priority during incidents

B.

Determining total cost of ownership (TCO)

C.

Evaluating vendors critical to business recovery

D.

Calculating residual risk after the incident recovery phase

Question 3
Single choice

Which of the following is MOST important when designing an information security governance framework?

A.

Aligning with the information security strategy

B.

Assessing the availability of information security resources

C.

Aligning with industry best practice frameworks

D.

Assessing the current state of information security

Question 4
Single choice

A global organization is planning to expand its operations into a new country with stricter data protection regulations than those in the headquarters' home country.

Which of the following is the BEST approach for adopting these new requirements?

A.

Adjust organization-wide security polices to align with regulations of the new country.

B.

Ensure local operations comply with geographical data protection laws of the headquarters.

C.

Work with legal to interpret the local regulatory requirements and implement applicable controls.

D.

Procure cybersecurity insurance that covers potential breaches and incidents in the new country.

Question 5
Single choice

Which of the following is an information security manager's MOST important course of action after receiving information about a new cybersecurity threat?

A.

Assess the impact of the new threat on the organization in the event of materialization.

B.

Update correlation rules for log monitoring to detect the possible emerging threat.

C.

Report the threat to senior management immediately to enable an informed decision.

D.

Review the enterprise architecture (EA) for vulnerabilities exploited by the threat.

Question 6
Single choice

Which of the following presents the GREATEST challenge when assessing the impact of emerging risk?

A.

Complexity of the emerging risk

B.

Insufficient data related to the emerging risk

C.

Outdated risk management strategy

D.

Lack of resources to perform risk assessments

Question 7
Single choice

Which of the following MUST happen immediately following the identification of a malware incident?

A.

Preparation

B.

Recovery

C.

Containment

D.

Eradication

Question 8
Single choice

The BEST way to integrate information security governance with corporate governance is to ensure:

A.

the information security steering committee monitors compliance with security policies.

B.

management teams embed information security into business processes.

C.

awareness programs include industry best practice for information security governance.

D.

the information security program is included in regular external audits.

Question 9
Single choice

An information security manager learns that business unit leaders are encouraging increased use of social media platforms to reach customers.

Which of the following should be done FIRST to help mitigate the risk of confidential information being disclosed by employees on social media?

A.

Establish an organization-wide social media policy.

B.

Develop sanctions for misuse of social media sites.

C.

Monitor social media sites visited by employees.

D.

Restrict social media access on corporate devices.

Question 10
Single choice

Which of the following processes BEST supports the evaluation of incident response effectiveness?

A.

Root cause analysis

B.

Post-incident review

C.

Chain of custody

D.

Incident logging

Showing 10 of 1,583 questions · Unlock the full set