📘 Free CISM Sample Questions
An information security risk analysis BEST assists an organization in ensuring that
A
the infrastructure has the appropriate level of access control.
B
cost-effective decisions are made with regard to which assets need protection
C
an appropriate level of funding is applied to security processes.
D
the organization implements appropriate security technologies
Correct Answer:
B. cost-effective decisions are made with regard to which assets need protection
Explanation:
Correct answer is B:cost-effective decisions are made with regard to which assets need protection.
In a multinational organization, local security regulations should be implemented over global security policy because:
A
business objectives are defined by local business unit managers.
B
deploying awareness of local regulations is more practical than of global policy.
C
global security policies include unnecessary controls for local businesses.
D
requirements of local regulations take precedence.
Correct Answer:
D. requirements of local regulations take precedence.
Explanation:
Correct answer is D: requirements of local regulations take precedence.
To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information security manager should FIRST:
A
conduct a cost-benefit analysis.
B
conduct a risk assessment.
C
interview senior management.
D
perform a gap analysis.
Correct Answer:
B. conduct a risk assessment.
Explanation:
B. A risk assessment will identify any risks with adopting new policies and technologies.
A gap analysis is a method of assessing the performance of a business unit to determine whether business requirements or objectives are being met and, if not, what steps should be taken to meet them.
When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?
A
Access control management
B
Change management
C
Configuration management
D
Risk management
Correct Answer:
D. Risk management
Explanation:
Correct answer is D:Risk management.
Which of the following is the BEST way to build a risk-aware culture?
A
Periodically change risk awareness messages.
B
Ensure that threats are communicated organization-wide in a timely manner.
C
Periodically test compliance with security controls and post results.
D
Establish incentives and a channel for staff to report risks.
Correct Answer:
D. Establish incentives and a channel for staff to report risks.
Explanation:
D: "Establish incentives and a channel for staff to report risks," is the most effective approach for fostering a risk-aware culture within an organization. By establishing incentives, such as rewards or recognition, for employees to report risks, it encourages them to actively engage in identifying and communicating potential threats and vulnerabilities.
What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?
A
Cancel the outsourcing contract.
B
Transfer the risk to the provider.
C
Create an addendum to the existing contract.
D
Initiate an external audit of the provider's data center.
Correct Answer:
C. Create an addendum to the existing contract.
Explanation:
Correct answer is C:Create an addendum to the existing contract.
An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?
A
Controls to be monitored
B
Reporting capabilities
C
The contract with the SIEM vendor
D
Available technical support
Correct Answer:
A. Controls to be monitored
Explanation:
Correct answer is A:Controls to be monitored.
Which of the following is MOST likely to be included in an enterprise security policy?
A
Definitions of responsibilities
B
Retention schedules
C
System access specifications
D
Organizational risk
Correct Answer:
A. Definitions of responsibilities
Explanation:
Correct answer is A:Definitions of responsibilities.
Which of the following should an information security manager do FIRST when a legacy application is not compliant with a regulatory requirement, but the business unit does not have the budget for remediation?
A
Develop a business case for funding remediation efforts.
B
Advise senior management to accept the risk of noncompliance.
C
Notify legal and internal audit of the noncompliant legacy application.
D
Assess the consequences of noncompliance against the cost of remediation.
Correct Answer:
D. Assess the consequences of noncompliance against the cost of remediation.
Explanation:
D. Assess the consequences of noncompliance against the cost of remediation.
Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?
A
Review the third-party contract with the organization's legal department.
B
Communicate security policy with the third-party vendor.
C
Ensure security is involved in the procurement process.
D
Conduct an information security audit on the third-party vendor.
Correct Answer:
C. Ensure security is involved in the procurement process.
Explanation:
Ensuring security is involved in the procurement process is the most effective way to address an organization's security concerns during contract negotiations with a third party. Involving security personnel in the procurement process allows the organization to identify and address potential security risks early on, before a contract is signed. This helps ensure that security requirements are included in the contract and that the third-party vendor is aware of and committed to meeting the organization's security standards. By having security involved in the procurement process, the organization can also ensure that the third-party vendor has adequate security controls in place to protect sensitive information and critical assets. This can include reviewing the vendor's security policies, conducting security assessments, and verifying that the vendor is in compliance with relevant laws and regulations.
Questions: 1-10 out of 1432
Continue Full Practice..
GET ALL 1432 QUESTIONS