CISM Practice Questions and Answers (100% Pass)
How much security is enough? - Answer✔️✔️-Just enough
What is the role of the security professional? - Answer✔️✔️-Advise, not decide, on
security matters for the organization
Define confidentiality - Answer✔️✔️-Prevent unauthorized disclosure of data
(privacy, security)
Define integrity - Answer✔️✔️-Prevent/detect unauthorized modification of data
Define availability - Answer✔️✔️-Ensure timely access to resources
What is the opposite of confidentiality? - Answer✔️✔️-Disclosure of data
What is the opposite of integrity? - Answer✔️✔️-Alteration of data
What is the opposite of availbility? - Answer✔️✔️-Destruction of data
Identify ways to violate confidentiality - Answer✔️✔️-Sniffing, shoulder surfing,
social engineering, media reuse
Identify ways to violate integrity - Answer✔️✔️-intentional modification of database
files, accidental modification of database files, corruption of data
1
,©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM
Identify ways to violate availability - Answer✔️✔️-denial of service attack, physical
theft or vandalism
What is the biggest threat to confidentiality? - Answer✔️✔️-Social Engineering
Identify best practices to protect CIA - Answer✔️✔️-Separation of duties, mandatory
vacation, job rotation, least privilege, need to know, dual control
What is security governance? - Answer✔️✔️-Set of responsibilities and practices
exercised by the board and executive management with the goal of providing
strategic direction, ensuring objectives are achieved, ascertaining that risks are
managed appropriately, and verifying that the enterprise's resource are used
responsibly
What are the three components of data classification? - Answer✔️✔️-Cost, classify,
controls
What is data classification? - Answer✔️✔️-Development of sensitivity labels for
data and the assignment of those labels for the purpose fo configuing baseline
security based on value of data
What is the highest level of private and government classification? - Answer✔️✔️-
Confidential, Top Secret
2
, ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM
What is the second highest level of private and government classification? -
Answer✔️✔️-Private, Secret
What is the third highest level of private and government classification? -
Answer✔️✔️-Sensitive, Confidential
What is a switch? - Answer✔️✔️-Connects multiple devices and prvents data
collisions by using MAC addressing to determine where to forward traffic
What is a router? - Answer✔️✔️-Segments traffic into different networks (or
subnets). Routers can connect difference network addresses and can isolate
broadcast traffic
What is the difference between a switch and a router? - Answer✔️✔️-A router can
isolate broadcast traffic while a switch cannot
What is a vLAN? - Answer✔️✔️-Creates multiple broadcast domains on a single
switch so you do not have to worry about running out of port space
What is the advantage of a VLAN over a router? - Answer✔️✔️-A VLAN is much
cheaper than a router and takes up less physical space
What type of switch can connect different routers? - Answer✔️✔️-Layer 3 switch
3