CISM Certification - Valid Exam Dumps Questions Study Guide! (Updated 964 Questions) [Q239-Q263]

Share

CISM Certification – Valid Exam Dumps Questions Study Guide! (Updated 964 Questions)

CISM Dumps are Available for Instant Access using Exams-boost


The CISM certification exam is a rigorous test that requires significant preparation and dedication from candidates. CISM exam consists of 150 multiple-choice questions that must be completed within a four-hour time limit. To be eligible to take the CISM exam, candidates must have a minimum of five years of experience in information security management, with three of those years being in a leadership role. Alternatively, candidates may substitute up to two years of experience with a relevant degree or other certifications.

 

NEW QUESTION # 239
A risk assessment and business impact analysis (BIA) have been completed for a major proposed purchase and new process for an organization. There is disagreement between the information security manager and the business department manager who will own the process regarding the results and the assigned risk. Which of the following would be the BES T approach of the information security manager?

  • A. Review of the assessment with executive management for final input
  • B. A new risk assessment and BIA are needed to resolve the disagreement
  • C. Acceptance of the business manager's decision on the risk to the corporation
  • D. Acceptance of the information security manager's decision on the risk to the corporation

Answer: A

Explanation:
Executive management must be supportive of the process and fully understand and agree with the results since risk management decisions can often have a large financial impact and require major changes. Risk management means different things to different people, depending upon their role in the organization, so the input of executive management is important to the process.


NEW QUESTION # 240
An organization's marketing department wants to use an online collaboration service which is not in compliance with the information security policy. A risk assessment is performed, and risk acceptance is being pursued. Approval of risk acceptance should be provided by:

  • A. business senior management
  • B. the information security manager
  • C. the compliance officer.
  • D. the chief risk officer

Answer: C


NEW QUESTION # 241
The MOST appropriate time to conduct a disaster recovery test would be after:

  • A. the security risk profile has been reviewed
  • B. the business continuity plan (BCP) has been updated.
  • C. noncompliance incidents have been filed.
  • D. major business processes have been redesigned.

Answer: B

Explanation:
The most appropriate time to conduct a disaster recovery test would be after the business continuity plan (BCP) has been updated, as it ensures that the disaster recovery plan (DRP) is aligned with the current business requirements, objectives, and priorities. The BCP should be updated regularly to reflect any changes in the business environment, such as new threats, risks, processes, technologies, or regulations. The disaster recovery test should validate the effectiveness and efficiency of the DRP, as well as identify any gaps, issues, or improvement opportunities123. References =
* 1: CISM Review Manual 15th Edition, page 2114
* 2: CISM Practice Quiz, question 1042
* 3: Business Continuity Planning and Disaster Recovery Testing, section "Testing the Plan"


NEW QUESTION # 242
In the course of responding 10 an information security incident, the BEST way to treat evidence for possible legal action is defined by:

  • A. local regulations.
  • B. organizational security policies.
  • C. international standards.
  • D. generally accepted best practices.

Answer: A

Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation/Reference:
Explanation:
Legal follow-up will most likely be performed locally where the incident took place; therefore, it is critical that the procedure of treating evidence is in compliance with local regulations. In certain countries, there are strict regulations on what information can be collected. When evidence collected is not in compliance with local regulations, it may not be admissible in court. There are no common regulations to treat computer evidence that are accepted internationally. Generally accepted best practices such as a common chain-of-custody concept may have different implementation in different countries, and thus may not be a good assurance that evidence will be admissible. Local regulations always take precedence over organizational security policies.


NEW QUESTION # 243
Security awareness training should be provided to new employees:

  • A. during system user training.
  • B. along with department staff.
  • C. before they have access to data.
  • D. on an as-needed basis.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Security awareness training should occur before access is granted to ensure the new employee understands that security is part of the system and business process. All other choices imply that security awareness training is delivered subsequent to the granting of system access, which may place security as a secondary step.


NEW QUESTION # 244
Which of the following BEST facilitates recovery of data lost as a result of a cybersecurity incident?

  • A. Offsite data backups
  • B. Disaster recovery plan (DRP)
  • C. Encrypted data drives
  • D. Removable storage media

Answer: A

Explanation:
The best option to facilitate recovery of data lost as a result of a cybersecurity incident is offsite data backups.
This is because offsite data backups provide a secure and reliable way to restore data that may have been corrupted, deleted, or encrypted by malicious actors. Offsite data backups also reduce the risk of data loss due to physical damage, theft, or natural disasters that may affect the primary data storage location. Offsite data backups should be part of a comprehensive disaster recovery plan (DRP) that defines the roles, responsibilities, procedures, and resources for restoring normal operations after a cyber incident.


NEW QUESTION # 245
The MOST appropriate owner of customer data stored in a central database, used only by an organization's sales department, would be the:

  • A. database administrator.
  • B. chief information officer (CIO).
  • C. head of the sales department.
  • D. sales department.

Answer: C

Explanation:
Explanation
The owner of the information asset should be the person with the decision-making power in the department deriving the most benefit from the asset. In this case, it would be the head of the sales department. The organizational unit cannot be the owner of the asset because that removes personal responsibility. The database administrator is a custodian. The chief information officer (CIO) would not be an owner of this database because the CIO is less likely to be knowledgeable about the specific needs of sales operations and security concerns.


NEW QUESTION # 246
Which of the following would BEST ensure that security is integrated during application development?

  • A. Providing training on secure development practices to programmers
  • B. Introducing security requirements during the initiation phase
  • C. Performing application security testing during acceptance testing
  • D. Employing global security standards during development processes

Answer: B

Explanation:
Introducing security requirements during the initiation phase would BEST ensure that security is integrated during application development because it would allow the security objectives and controls to be defined and aligned with the business needs and risk appetite before any design or coding is done. This would also facilitate the security by design approach, which is the most effective method to enhance the security of applications and application development activities1. Introducing security requirements early would also enable the collaboration between security professionals and developers, the identification and specification of security architectures, and the integration and testing of security controls throughout the development life cycle2. Employing global security standards during development processes (A) would help to ensure the consistency and quality of security practices, but it would not necessarily ensure that security is integrated during application development. Providing training on secure development practices to programmers (B) would help to raise the awareness and skills of developers, but it would not ensure that security is integrated during application development. Performing application security testing during acceptance testing © would help to verify the security of the application before deployment, but it would not ensure that security is integrated during application development. It would also be too late to identify and remediate any security issues that could have been prevented or mitigated earlier in the development process. References = 1: Five Key Components of an Application Security Program - ISACA1; 2: CISM Domain - Information Security Program Development | Infosec2


NEW QUESTION # 247
What would be the MOST significant security risks when using wireless local area network (LAN) technology?

  • A. Man-in-the-middle attack
  • B. Spoofing of data packets
  • C. Session hijacking
  • D. Rogue access point

Answer: D

Explanation:
Explanation/Reference:
Explanation:
A rogue access point masquerades as a legitimate access point The risk is that legitimate users may connect through this access point and have their traffic monitored. All other choices are not dependent on the use of a wireless local area network (LAN) technology.


NEW QUESTION # 248
Information classification is a fundamental step in determining:

  • A. whether risk analysis objectives are met.
  • B. who has ownership of information.
  • C. the security strategy that should be used.
  • D. the type of metrics that should be captured.

Answer: B


NEW QUESTION # 249
Which of the following is an important criterion for developing effective key risk indicators (KRIs) to monitor information security risk?

  • A. The indicator should focus on IT and accurately represent risk variances.
  • B. The indicator should align with key performance indicators and measure root causes of process performance issues.
  • C. The indicator should provide a retrospective view of risk impacts and be measured annually.
  • D. The indicator should possess a high correlation with a specific risk and be measured on a regular basis.

Answer: D

Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT


NEW QUESTION # 250
Data owners are normally responsible for which of the following?

  • A. Applying emergency changes to application data
  • B. Determining the level of application security required
  • C. Migrating application code changes to production
  • D. Administering security over database records

Answer: B

Explanation:
Explanation
Data owners approve access to data and determine the degree of protection that should be applied (data classification). Administering database security, making emergency changes to data and migrating code to production are infrastructure tasks performed by custodians of the data.


NEW QUESTION # 251
Which of the following sources is MOST useful when planning a business-aligned information security program?

  • A. Enterprise architecture (EA)
  • B. Information security policy
  • C. Business impact analysis (BIA)
  • D. Security risk register

Answer: A


NEW QUESTION # 252
Which of the following is the PRIMARY purpose of implementing information security standards?

  • A. To provide step-by-step instructions for performing security-related tasks
  • B. To provide management direction with a specific security objective
  • C. To provide a basis for developing information security policies
  • D. To establish a minimum acceptable security baseline

Answer: D


NEW QUESTION # 253
Acceptable levels of information security risk should be determined by:

  • A. die steering committee.
  • B. external auditors.
  • C. legal counsel.
  • D. security management.

Answer: A

Explanation:
Senior management, represented in the steering committee, has ultimate responsibility for determining what levels of risk the organization is willing to assume. Legal counsel, the external auditors and security management are not in a position to make such a decision.


NEW QUESTION # 254
In order to highlight to management the importance of network security, the security manager should FIRST:

  • A. conduct a risk assessment.
  • B. develop a network security policy.
  • C. develop a security architecture.
  • D. install a network intrusion detection system (NIDS) and prepare a list of attacks.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
A risk assessment would be most helpful to management in understanding at a very high level the threats, probabilities and existing controls. Developing a security architecture, installing a network intrusion detection system (NIDS) and preparing a list of attacks on the network and developing a network security policy would not be as effective in highlighting the importance to management and would follow only after performing a risk assessment.


NEW QUESTION # 255
When performing an information risk analysis, an information security manager should FIRST:

  • A. establish the ownership of assets.
  • B. take an asset inventory.
  • C. evaluate the risks to the assets.
  • D. categorize the assets.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Assets must be inventoried before any of the other choices can be performed.


NEW QUESTION # 256
Which of the following is the BEST way to achieve compliance with new global regulations related to the protection of personal information?

  • A. Execute a risk treatment plan.
  • B. Determine current and desired state of controls.
  • C. Implement data regionalization controls.
  • D. Review contracts and statements of work (SOWs) with vendors.

Answer: B

Explanation:
Explanation
The best way to achieve compliance with new global regulations related to the protection of personal information is to determine the current and desired state of controls, as this helps the information security manager to identify the gaps and requirements for compliance, and to prioritize and implement the necessary actions and measures to meet the regulatory standards. The current state of controls refers to the existing level of protection and compliance of the personal information, while the desired state of controls refers to the target level of protection and compliance that is required by the new regulations. By comparing the current and desired state of controls, the information security manager can assess the maturity and effectiveness of the information security program, and plan and execute a risk treatment plan to address the risks and issues related to the protection of personal information. Executing a risk treatment plan, reviewing contracts and statements of work (SOWs) with vendors, and implementing data regionalization controls are also important, but not as important as determining the current and desired state of controls, as they are dependent on the outcome of the gap analysis and the risk assessment, and may not be sufficient or appropriate to achieve compliance with the new regulations. References = CISM Review Manual 2023, page 491; CISM Review Questions, Answers & Explanations Manual 2023, page 352; ISACA CISM - iSecPrep, page 203


NEW QUESTION # 257
An information security team has started work to mitigate findings from a recent penetration test.
Which of the following presents the GREATEST risk to the organization?

  • A. The penetration testing report did not contain any high-risk findings
  • B. Some findings were reclassified to low risk after evaluation
  • C. Not all findings from the penetration test report were fixed
  • D. Risk classification of penetration test findings was not performed

Answer: D

Explanation:
The greatest risk comes from not performing risk classification on the findings. Without classification, the organization cannot prioritize remediation efforts, allocate resources effectively, or understand the business impact of the vulnerabilities.
"Risk classification helps determine the priority for mitigating vulnerabilities and enables risk-informed decisions."
- CISM Review Manual 15th Edition, Chapter 2: Risk Assessment and Analysis* Even if some findings are unfixed or reclassified, the lack of any classification process undermines the whole risk management effort.


NEW QUESTION # 258
Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?

  • A. Results of a recent external audit
  • B. Information security program metrics
  • C. Changes to information security risks
  • D. The information security operations matrix

Answer: B

Explanation:
Information security program metrics are the best way to demonstrate the status of an organization's information security program to the board of directors, as they provide relevant and meaningful information on the performance, effectiveness, and value of the program, as well as the current and emerging risks and the corresponding mitigation strategies. Information security program metrics should be aligned with the business objectives and risk appetite of the organization, and should be presented in a clear and concise manner that enables the board of directors to make informed decisions and provide oversight. (From CISM Review Manual 15th Edition) References: CISM Review Manual 15th Edition, page 37, section 1.3.2.2.


NEW QUESTION # 259
Which of the following is the MOST effective way to detect security incidents?

  • A. Analyze penetration test results.
  • B. Analyze vulnerability assessments.
  • C. Analyze security anomalies.
  • D. Analyze recent security risk assessments.

Answer: C

Explanation:
Explanation
Analyzing security anomalies is the most effective way to detect security incidents, as it involves comparing the current state of the information system and network with the expected or normal state, and identifying any deviations or irregularities that may indicate a security breach or compromise. Security anomalies can be detected by using various tools and techniques, such as security information and event management (SIEM) systems, intrusion detection and prevention systems (IDS/IPS), log analysis, network traffic analysis, and behavioral analysis. (From CISM Review Manual 15th Edition) References: CISM Review Manual 15th Edition, page 181, section 4.3.2.4; CISM: Information Security Incident Management Part 11, section recognize security anomalies.


NEW QUESTION # 260
Which of the following BEST ensures that security risks will be reevaluated when modifications in application developments are made?

  • A. Background screening
  • B. A change control process
  • C. Business impact analysis (BIA)
  • D. A problem management process

Answer: B

Explanation:
Explanation
A change control process is the methodology that ensures that anything that could be impacted by a development change will be reevaluated. Problem management is the general process intended to manage all problems, not those specifically related to security. Background screening is the process to evaluate employee references when they are hired. BIA is the methodology used to evaluate risks in the business continuity process.


NEW QUESTION # 261
In violation of a policy prohibiting the use of cameras at the office, employees have been issued smartphones and tablet computers with enabled web cameras. Which of the following should be the information security manager's FIRST course of action?

  • A. Conduct a risk assessment,
  • B. Communicate the acceptable use policy.
  • C. Revise the policy.
  • D. Perform a root cause analysis.

Answer: A


NEW QUESTION # 262
What is the MOST important reason to regularly report information security risk to relevant stakeholders?

  • A. To ensure information security controls are effective
  • B. To enable risk-informed decision making
  • C. To achieve compliance with regulatory requirements
  • D. To reduce the impact of information security risk

Answer: B


NEW QUESTION # 263
......

ISACA CISM Exam Practice Test Questions: https://www.exams-boost.com/CISM-valid-materials.html

CISM Dumps 2026 - New ISACA CISM Exam Questions: https://drive.google.com/open?id=1pPS7pb4_CETdcCLuYZ1Khu9xUcRcHRGr