
CISM PDF Dumps Real 2021 Recently Updated Questions
Released ISACA CISM Updated Questions PDF
How to book the CISM Exam
These are following steps for registering the CISM exam. Step 1: Pass the CISM examination within the last five years Step 2: Candidate has a minimum of five years of professional Information Systems Security Manager work experience. Step3: Apply for CISA certification with $50 USD processing fee
For more detail visit this link Apply for certification
ISACA CISM: What career benefits can you get?
Holding the CISM certification will support your career growth. If you are an IT Security Architect, an Information Security Analyst, or a Chief Information Security Officer, this certificate will help you significantly get a promotion or find a new job. It demonstrates your knowledge in the information security sphere and makes finding a new job easier.
In addition, you will surely earn more. The average salary for those professionals who have the CISM certification ranges from $52,400 to $243,600 per year. Therefore, if you want to get a pay raise, this certificate is the right choice for you.
Who Is the Target Audience?
Now that you have an idea of the key topics of CISM, it's also relevant to know the main audience of the certification. First and foremost, it is created for individuals who have managerial roles. Their position allows them to design, supervise, and calculate the information security features of the organization. In addition, these professionals must have a minimum of 5 years of industry experience in managing information security. Isaca may allow a waiver of the number of working years for up to 2 years.
NEW QUESTION 599
A risk assessment and business impact analysis (BIA) have been completed for a major proposed purchase and new process for an organization. There is disagreement between the information security manager and the business department manager who will own the process regarding the results and the assigned risk. Which of the following would be the BES T approach of the information security manager?
- A. A new risk assessment and BIA are needed to resolve the disagreement
- B. Acceptance of the information security manager's decision on the risk to the corporation
- C. Acceptance of the business manager's decision on the risk to the corporation
- D. Review of the assessment with executive management for final input
Answer: D
Explanation:
Executive management must be supportive of the process and fully understand and agree with the results since risk management decisions can often have a large financial impact and require major changes. Risk management means different things to different people, depending upon their role in the organization, so the input of executive management is important to the process.
NEW QUESTION 600
Which of the following events generally has the highest information security impact?
- A. Relocating the data center
- B. Opening a new office
- C. Rewiring the network
- D. Merging with another organization
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Merging with or acquiring another organization causes a major impact on an information security management function because new vulnerabilities and risks are inherited. Opening a new office, moving the data center to a new site, or rewiring a network may have information security risks, but generally comply with corporate security policy and are easier to secure.
NEW QUESTION 601
Which of the following steps should be performed FIRST in the risk assessment process?
- A. Threat identification
- B. Asset identification and valuation
- C. Determination of the likelihood of identified risks
- D. Staff interviews
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The first step in the risk assessment methodology is a system characterization, or identification and valuation, of all of the enterprise's assets to define the boundaries of the assessment. Interviewing is a valuable tool to determine qualitative information about an organization's objectives and tolerance for risk.
Interviews are used in subsequent steps. Identification of threats comes later in the process and should not be performed prior to an inventory since many possible threats will not be applicable if there is no asset at risk. Determination of likelihood comes later in the risk assessment process.
NEW QUESTION 602
The MOST effective way to ensure that outsourced service providers comply with the organization's information security policy would be:
- A. service level monitoring.
- B. periodically auditing.
- C. penetration testing.
- D. security awareness training.
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Regular audit exercise can spot any gap in the information security compliance. Service level monitoring can only pinpoint operational issues in the organization's operational environment. Penetration testing can identify security vulnerability but cannot ensure information compliance Training can increase users' awareness on the information security policy, but is not more effective than auditing.
NEW QUESTION 603
When supporting an organization's privacy officer, which of the following is the information security managers PRIMARY role regarding privacy requirements?
- A. Monitoring the transfer of private data
- B. Ensuring appropriate controls are in place
- C. Conducting privacy awareness programs
- D. Determining data classification
Answer: B
NEW QUESTION 604
Which of the following outsourced services has the GREATEST need for security monitoring?
- A. Virtual private network (VPN) services
- B. Web site hosting
- C. Enterprise infrastructure
- D. Application development
Answer: C
NEW QUESTION 605
When a significant security breach occurs, what should be reported FIRST to senior management?
- A. A business case for implementing stronger logical access controls
- B. An explanation of the incident and corrective action taken
- C. A summary of the security logs that illustrates the sequence of events
- D. An analysis of the impact of similar attacks at other organizations
Answer: B
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
When reporting an incident to senior management, the initial information to be communicated should include an explanation of what happened and how the breach was resolved. A summary of security logs would be too technical to report to senior management. An analysis of the impact of similar attacks and a business case for improving controls would be desirable; however, these would be communicated later in the process.
NEW QUESTION 606
Reviewing which of the following would BEST ensure that security controls are effective?
- A. Security metrics
- B. Risk assessment policies
- C. Return on security investment
- D. User access rights
Answer: A
Explanation:
Reviewing security metrics provides senior management a snapshot view and trends of an organization's security posture. Choice A is incorrect because reviewing risk assessment policies would not ensure that the controls are actually working. Choice B is incorrect because reviewing returns on security investments provides business justifications in implementing controls, but does not measure effectiveness of the control itself. Choice D is incorrect because reviewing user access rights is a joint responsibility of the data custodian and the data owner, and does not measure control effectiveness.
NEW QUESTION 607
The PRIMARY goal of a corporate risk management program is to ensure that an organization's:
- A. IT assets in key business functions are protected.
- B. business risks are addressed by preventive controls.
- C. IT facilities and systems are always available.
- D. stated objectives are achievable.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Risk management's primary goal is to ensure an organization maintains the ability to achieve its objectives.
Protecting IT assets is one possible goal as well as ensuring infrastructure and systems availability.
However, these should be put in the perspective of achieving an organization's objectives. Preventive controls are not always possible or necessary; risk management will address issues with an appropriate mix of preventive and corrective controls.
NEW QUESTION 608
Which of the following would BEST assist an information security manager in measuring the existing level of development of security processes against their desired state?
- A. Balanced scorecard
- B. Security audit reports
- C. Capability maturity model (CMM)
- D. Systems and business security architecture
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The capability maturity model (CMM) grades each defined area of security processes on a scale of 0 to 5 based on their maturity, and is commonly used by entities to measure their existing state and then determine the desired one. Security audit reports offer a limited view of the current state of security.
Balanced scorecard is a document that enables management to measure the implementation of their strategy and assists in its translation into action. Systems and business security architecture explain the security architecture of an entity in terms of business strategy, objectives, relationships, risks, constraints and enablers, and provides a business-driven and business-focused view of security architecture.
NEW QUESTION 609
Which of the following ensures that newly identified security weaknesses in an operating system are mitigated in a timely fashion?
- A. Patch management
- B. Change management
- C. Acquisition management
- D. Security baselines
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Patch management involves the correction of software weaknesses and helps ensure that newly identified exploits are mitigated in a timely fashion. Change management controls the process of introducing changes to systems. Security baselines provide minimum recommended settings. Acquisition management controls the purchasing process.
NEW QUESTION 610
Which of the following provides the BEST justification for an information security investment when creating a business case
- A. The investment reduces the protected asset s inherent risk below the asset s residual risk
- B. The annualized loss expectancy (ALE) is greater than the annual cost of the investment.
- C. The investment can be managed using the organisation's established system development life cycle.
- D. Key risk indicators (KRIs) are available to measure the effectiveness and efficiency of the investment
Answer: B
NEW QUESTION 611
Which of the following incident response team (IRT) models is ideal for an organization that is regionally managed'
- A. Distributed IRT
- B. Central IRT
- C. Coordinating IRT
- D. Geographical IRT
Answer: A
NEW QUESTION 612
Which of the following, using public key cryptography, ensures authentication, confidentiality and nonrepudiation of a message?
- A. Encrypting first by sender's private key and second decrypting by sender's public key
- B. Encrypting first by receiver's private key and second by sender's public key
- C. Encrypting first by sender's public key and second by receiver's private key
- D. Encrypting first by sender's private key and second by receiver's public key
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
Encrypting by the sender's private key ensures authentication. By being able to decrypt with the sender's public key, the receiver would know that the message is sent by the sender only and the sender cannot deny/ repudiate the message. By encrypting with the sender's public key secondly, only the sender will be able to decrypt the message and confidentiality is assured. The receiver's private key is private to the receiver and the sender cannot have it for encryption. Similarly, the receiver will not have the private key of the sender to decrypt the second-level encryption. In the case of encrypting first by the sender's private key and. second, decrypting by the sender's public key, confidentiality is not ensured since the message can be decrypted by anyone using the sender's public key. The receiver's private key would not be available to the sender for second-level encryption. Similarly, the sender's private key would not be available to the receiver for decrypting the message.
NEW QUESTION 613
In the process of deploying a new e-mail system, an information security manager would like to ensure the confidentiality of messages while in transit. Which of the following is the MOST appropriate method to ensure data confidentiality in a new e-mail system implementation?
- A. I lashing algorithm
- B. Digital certificate
- C. Encryption
- D. Digital signature
Answer: C
Explanation:
To preserve confidentiality of a message while in transit, encryption should be implemented. Choices B and C only help authenticate the sender and the receiver. Choice D ensures integrity.
NEW QUESTION 614
An organization is considering whether to allow employees to use personal computing devices for business purposes To BEST facilitate senior management's decision, the information security manager should:
- A. map the strategy to business objectives.
D, perform a cost-benefit analysis. - B. conduct a risk assessment.
- C. develop a business case.
Answer: C
NEW QUESTION 615
What is the GREATEST risk when there is an excessive number of firewall rules?
- A. One rule may override another rule in the chain and create a loophole
- B. Performance degradation of the whole network
- C. The firewall may not support the increasing number of rules due to limitations
- D. The firewall may show abnormal behavior and may crash or automatically shut down
Answer: A
Explanation:
Explanation
If there are many firewall rules, there is a chance that a particular rule may allow an external connection although other associated rules are overridden. Due to the increasing number of rules, it becomes complex to test them and. over time, a loophole may occur.
NEW QUESTION 616
A company has a network of branch offices with local file/print and mail servers; each branch individually contracts a hot site. Which of the following would be the GREATEST weakness in recovery capability?
- A. The time of declaration determines site access priority
- B. The provider services all major companies in the area
- C. Exclusive use of the hot site is limited to six weeks
- D. The hot site may have to be shared with other customers
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Sharing a hot site facility is sometimes necessary in the case of a major disaster. Also, first come, first served usually determines priority of access based on general industry practice. Access to a hot site is not indefinite; the recovery plan should address a long-term outage. In case of a disaster affecting a localized geographical area, the vendor's facility and capabilities could be insufficient for all of its clients, which will all be competing for the same resource. Preference will likely be given to the larger corporations, possibly delaying the recovery of a branch that will likely be smaller than other clients based locally.
NEW QUESTION 617
The MOST important reason for formally documenting security procedures is to ensure:
- A. alignment with business objectives.
- B. objective criteria for the application of metrics.
- C. auditability by regulatory agencies.
- D. processes are repeatable and sustainable.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Without formal documentation, it would be difficult to ensure that security processes are performed in the proper manner every time that they are performed. Alignment with business objectives is not a function of formally documenting security procedures. Processes should not be formally documented merely to satisfy an audit requirement. Although potentially useful in the development of metrics, creating formal documentation to assist in the creation of metrics is a secondary objective.
NEW QUESTION 618
Which of the following is MOST likely to be discretionary?
- A. Policies
- B. Standards
- C. Procedures
- D. Guidelines
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Policies define security goals and expectations for an organization. These are defined in more specific terms within standards and procedures. Standards establish what is to be done while procedures describe how it is to be done. Guidelines provide recommendations that business management must consider in developing practices within their areas of control; as such, they are discretionary.
NEW QUESTION 619
When supporting an organization's privacy officer, which of the following is the information security manager's PRIMARY role regarding primacy requirements?
- A. Monitoring the transfer of private data
- B. Ensuring appropriate controls are in place
- C. Conducting privacy awareness programs
- D. Determining data classification
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 620
A message is being sent with a hash. The risk of an attacker changing the message and generating an authentic hash value can be mitigated by:
- A. requiring the recipient to use a different hash algorithm
- B. using a secret key in conjunction with the hash algorithm
- C. using the sender's public key to encrypt the message
- D. generating hash output that is the same size as the original message
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 621
Which of the following provides the linkage to ensure that procedures are correctly aligned with information security policy requirements?
- A. Security metrics
- B. IT governance
- C. Guidelines
- D. Standards
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Standards are the bridge between high-level policy statements and the "how to" detailed formal of procedures.
Security metrics and governance would not ensure correct alignment between policies and procedures.
Similarly, guidelines are not linkage documents but rather provide suggested guidance on best practices.
NEW QUESTION 622
An organization provides information to its supply chain partners and customers through an extranet infrastructure. Which of the following should be the GREATEST concern to an IS auditor reviewing the firewall security architecture?
- A. Firewall policies are updated on the basis of changing requirements.
- B. The firewall is placed on top of the commercial operating system with all installation options.
- C. Inbound traffic is blocked unless the traffic type and connections have been specifically permitted.
- D. A Secure Sockets Layer (SSL) has been implemented for user authentication and remote administration of the firewall.
Answer: B
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
The greatest concern when implementing firewalls on top of commercial operating systems is the potential presence of vulnerabilities that could undermine the security posture of the firewall platform itself. In most circumstances, when commercial firewalls are breached that breach is facilitated by vulnerabilities in the underlying operating system. Keeping all installation options available on the system further increases the risks of vulnerabilities and exploits. Using SSL for firewall administration (choice A) is important, because changes in user and supply chain partners' roles and profiles will be dynamic. Therefore, it is appropriate to maintain the firewall policies daily (choice B), and prudent to block all inbound traffic unless permitted (choice C).
NEW QUESTION 623
How would an information security manager balance the potentially conflicting requirements of an international organization's security standards and local regulation?
- A. Give organization standards preference over local regulations
- B. Negotiate a local version of the organization standards
- C. Make the organization aware of those standards where local regulations causes conflicts
- D. Follow local regulations only
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Adherence to local regulations must always be the priority. Not following local regulations can prove detrimental to the group organization. Following local regulations only is incorrect since there needs to be some recognition of organization requirements. Making an organization aware of standards is a sensible step, but is not a total solution. Negotiating a local version of the organization standards is the most effective compromise in this situation.
NEW QUESTION 624
......
CISM Dumps and Practice Test (1340 Exam Questions): https://www.prepawaytest.com/ISACA/CISM-practice-exam-dumps.html
Guide (New 2021) Actual ISACA CISM Exam Questions: https://drive.google.com/open?id=1S6OpwqnAMiYtF_zIBd-C77bQUpqGaRDf