CISM TEST UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS
Question:
1. Administrative controls
Answer:
policies, processes, procedures, standards
Question:
2. Annualized Loss Expectancy
Answer:
ALE = SLExARO
Question:
3. architecture standard
Answer:
defines technology architecture at the database, system, or network level
Question:
4. assessment
Answer:
an examination that determines the effectiveness of a system or process
Question:
5. asset value
Answer:
the value of an IT asset - usually but not always the Replacement Value
Question:
6. Asynchronous Replication
Answer:
writing to data in a remote system is not synchronized with the local system.No guarantee that remote
system is identical to local systemMight be a time lag
Question:
7. Attestation of compliance
Answer:
assertion of compliance to a law, standard or requirement Typically signed by high ranking official
Question:
8. authentication
Answer:
asserting an identity and providing proof of ittypically requires an ID (assertion) and a password (proof)
,Question:
9. business email compromiseceo fraud
Answer:
perpetrator impersonates a CEO and gets company personnel to transfer large amounts of money, typically
for a "secret merger" or "acquisition"
Question:
10. Business Impact Analysis
Answer:
Study to identify the impact that different disaster scenarios will have on business operations
Question:
11. Business Recovery Plan
Answer:
activities required to recover and resume critical business processes and activities
Question:
12. capability maturity model
Answer:
measures relative maturity of an organization and its processes
Question:
13. capability maturity model for Development| CMMi-DEV
Answer:
maturity model used to measure software development process maturity
Question:
14. certification practicer statement (CPS)
Answer:
describes practices used by the CA to issue and manage digital certificates
Question:
15. Change Control BoardakaChange Advisory Board
Answer:
stakeholders from IT and Business who propose, discuss, approve changes to the IT systems
Question:
16. CIS Controls
Answer:
framework maintained by the Center for Internet Security (CIS)
Question:
17. COBIT
Answer:
published by ISACAcontrol framework for managing information systems and security
,Question:
18. COSO
Answer:
Committee of Sponsoring Organizations of the Treadway CommissionOrganization providing control
frameworks and guidance on enterprise risk management
Question:
19. COOP
Answer:
Continuity of Operations Planactivities required to continue critical and strategic business functions at
alternate site
Question:
20. Control
Answer:
Policy, Process or Procedure created to ensure desired outcomes or to avoid unwanted outcomes
Question:
21. Control Framework
Answer:
Collection of controls organized in logical categories
Question:
22. Covered Entity
Answer:
any organization that stores or processes information covered by HIPAA
Question:
23. Critical Path Methodology (CPM)
Answer:
Technique used to identify the most critical path in a project to understand which tasks are most likely to
affect the project schedule
Question:
24. Criticality Analysis (CA)
Answer:
Study of each system and process, a consideration of the impact on the organization if it's incapacitated,
the likelihood of incapacitation and the estimated cost of mitigating the impact (risk)
Question:
25. Digital envelope
Answer:
method of using two layers of encryptionsymmetric key is used to encrypt a message and a public or
private key is used to encrypt the symmetric key
Question:
26. Disaster
, Answer:
unexpected and unplanned event that results in the disruption of business operations
Question:
27. Dwell Time
Answer:
amount of time from the start of an incident to the organization's awareness of the incident
Question:
28. e-vaulting
Answer:
backing up information to an off-site location, usually a 3rd-party service provider
Question:
29. Exposure Factor
Answer:
financial loss resulting from realization of a threat.expressed as a percentage of the asset's total value
Question:
30. Facilities Classification
Answer:
methods for assigning risk levels to facilities based based on their operational criticality or other risk
factors
Question:
31. fiduciary
Answer:
person who has a legal trust relationship with another party
Question:
32. fiduciary duty
Answer:
highest standard of care that a fiduciary renders to a beneficiary
Question:
33. File Activity Monitoring (FAM)
Answer:
monitoring the use of files on a computer as a way to detect indicators of compromise
Question:
34. File Integrity Monitoring (FIM)
Answer:
periodically scanning file systems to detect changes to file contents or permissions that may indicate
compromise
Question:
35. HITRUST
CORRECT ANSWERS
Question:
1. Administrative controls
Answer:
policies, processes, procedures, standards
Question:
2. Annualized Loss Expectancy
Answer:
ALE = SLExARO
Question:
3. architecture standard
Answer:
defines technology architecture at the database, system, or network level
Question:
4. assessment
Answer:
an examination that determines the effectiveness of a system or process
Question:
5. asset value
Answer:
the value of an IT asset - usually but not always the Replacement Value
Question:
6. Asynchronous Replication
Answer:
writing to data in a remote system is not synchronized with the local system.No guarantee that remote
system is identical to local systemMight be a time lag
Question:
7. Attestation of compliance
Answer:
assertion of compliance to a law, standard or requirement Typically signed by high ranking official
Question:
8. authentication
Answer:
asserting an identity and providing proof of ittypically requires an ID (assertion) and a password (proof)
,Question:
9. business email compromiseceo fraud
Answer:
perpetrator impersonates a CEO and gets company personnel to transfer large amounts of money, typically
for a "secret merger" or "acquisition"
Question:
10. Business Impact Analysis
Answer:
Study to identify the impact that different disaster scenarios will have on business operations
Question:
11. Business Recovery Plan
Answer:
activities required to recover and resume critical business processes and activities
Question:
12. capability maturity model
Answer:
measures relative maturity of an organization and its processes
Question:
13. capability maturity model for Development| CMMi-DEV
Answer:
maturity model used to measure software development process maturity
Question:
14. certification practicer statement (CPS)
Answer:
describes practices used by the CA to issue and manage digital certificates
Question:
15. Change Control BoardakaChange Advisory Board
Answer:
stakeholders from IT and Business who propose, discuss, approve changes to the IT systems
Question:
16. CIS Controls
Answer:
framework maintained by the Center for Internet Security (CIS)
Question:
17. COBIT
Answer:
published by ISACAcontrol framework for managing information systems and security
,Question:
18. COSO
Answer:
Committee of Sponsoring Organizations of the Treadway CommissionOrganization providing control
frameworks and guidance on enterprise risk management
Question:
19. COOP
Answer:
Continuity of Operations Planactivities required to continue critical and strategic business functions at
alternate site
Question:
20. Control
Answer:
Policy, Process or Procedure created to ensure desired outcomes or to avoid unwanted outcomes
Question:
21. Control Framework
Answer:
Collection of controls organized in logical categories
Question:
22. Covered Entity
Answer:
any organization that stores or processes information covered by HIPAA
Question:
23. Critical Path Methodology (CPM)
Answer:
Technique used to identify the most critical path in a project to understand which tasks are most likely to
affect the project schedule
Question:
24. Criticality Analysis (CA)
Answer:
Study of each system and process, a consideration of the impact on the organization if it's incapacitated,
the likelihood of incapacitation and the estimated cost of mitigating the impact (risk)
Question:
25. Digital envelope
Answer:
method of using two layers of encryptionsymmetric key is used to encrypt a message and a public or
private key is used to encrypt the symmetric key
Question:
26. Disaster
, Answer:
unexpected and unplanned event that results in the disruption of business operations
Question:
27. Dwell Time
Answer:
amount of time from the start of an incident to the organization's awareness of the incident
Question:
28. e-vaulting
Answer:
backing up information to an off-site location, usually a 3rd-party service provider
Question:
29. Exposure Factor
Answer:
financial loss resulting from realization of a threat.expressed as a percentage of the asset's total value
Question:
30. Facilities Classification
Answer:
methods for assigning risk levels to facilities based based on their operational criticality or other risk
factors
Question:
31. fiduciary
Answer:
person who has a legal trust relationship with another party
Question:
32. fiduciary duty
Answer:
highest standard of care that a fiduciary renders to a beneficiary
Question:
33. File Activity Monitoring (FAM)
Answer:
monitoring the use of files on a computer as a way to detect indicators of compromise
Question:
34. File Integrity Monitoring (FIM)
Answer:
periodically scanning file systems to detect changes to file contents or permissions that may indicate
compromise
Question:
35. HITRUST