• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 25 pages
Exam (elaborations)

CISM Domain 6 Questions and Answers Rated A+

Document preview thumbnail
Preview 3 out of 25 pages

CISM Domain 6 Questions and Answers Rated A+

Content preview

CISM Domain 6 Questions and Answers Rated A+


A. Validation checks are missing in data input pages. - ANSWER-ID.Which of the
following vulnerabilities allowing attackers access to the application database is the
MOST serious?

A. Validation checks are missing in data input pages.

B. Password rules do not allow sufficient complexity.

C. Application transaction log management is weak.

D. Application and database share a single access

B. Encryption of stored data - ANSWER-Which of the following is the MOST effective
security measure to protect data held on mobile computing devices?

A.Biometric access control

B. Encryption of stored data

C.Power-on passwords

D. Protection of data being transmitted

D. the threats and vulnerabilities - ANSWER-With regard to the implementation of
security awareness programs in an organization, it is MOST relevant to understand
that one of the following aspects can change?

A. The security culture

B. The information technology

C. The compliance requirements

D. the threats and vulnerabilities

D. the data owner - ANSWER-Who is in the BEST position to determine the level of
information security needed for a specific business application?

A.The system developer

B. The information security manager

C. The system custodian

,D. the data owner

B.Employ packet filtering to drop suspect packets. - ANSWER-What is the BEST
method for mitigating against network denial-of-service (DoS) attacks?

A.Ensure all servers are up-to-date on OS patches.

B.Employ packet filtering to drop suspect packets.

C. Implement network address translation to make internal addresses nonroutable.

D. Implement load balancing for Internet facing devices.

D. Reduces financial risk but leaves legal responsibility generally unchanged. -
ANSWER-Outsourcing combined with indemnification:
A.reduces legal responsibility but leaves financial risk relatively unchanged.

B.Is more cost-effective as a means of risk transfer than purchasing insurance.

C.Eliminates the reputational risk present when operations remain in-house.

D. Reduces financial risk but leaves legal responsibility generally unchanged.

B. Preserving the integrity of the evidence - ANSWER-What is the PRIMARY focus if
an organization considers taking legal action on a security incident?

A.Obtaining evidence as soon as possible

B. Preserving the integrity of the evidence

C. Disconnecting all IT equipment involved

D.Reconstructing the sequence of events

C. Define and monitor security metrics. - ANSWER-Which of the following is the
BEST approach for improving information security management processes?

A. Conduct periodic security audits.

B. Perform periodic penetration testing.

C. Define and monitor security metrics.

D. Survey business units for feedback.

C. Use third-party providers for low-risk activities. - ANSWER-Which of the following
is the BEST approach to deal with inadequate funding of the information security
program?

, A. Eliminate low-priority security services.

B. Require management to accept the increased risk.

C. Use third-party providers for low-risk activities.

D.Reduce monitoring and compliance enforcement activities.

B. Percent of control objectives accomplished - ANSWER-Which would be one of the
BEST metrics an information security manager can employ to effectively evaluate
the results of a security program?

A. Number of controls implemented

B. Percent of control objectives accomplished

C. Percent of compliance with the security policy

D. Reduction in the number of reported security incidents

D. The extent of data loss that is acceptable - ANSWER-Which of the following
items is MOST important to determine the recovery point objective for a critical
process in an enterprise?

A. The number of hours of acceptable downtime

B. The total cost of recovering critical systems

C. The acceptable reduction in the level of service

D. The extent of data loss that is acceptable

- ANSWER-An organization's IT change management process requires that all
change requests be approved by the asset owner and the information security
manager. The PRIMARY objective of getting the information security manager's
approval is to ensure that:

A. A change affecting a security policy is not handled by an IT change process.

B. Changes in the IT infrastructure may have an impact on existing risk. An
information security manager must ensure that the proposed changes do not
adversely affect the security posture.

C. Rollback to a current state may cause a security risk event and is normally part
of change management, but is not the primary reason that security is involved in
the review.

Document information

Uploaded on
August 31, 2026
Number of pages
25
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CLOUNDLite
3.9
(128)
Sold
659
Followers
389
Items
12325
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions