100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CISM Practice Exam Questions and Answers (100% Pass)

Rating
-
Sold
-
Pages
477
Grade
A+
Uploaded on
16-08-2024
Written in
2024/2025

CISM Practice Exam Questions and Answers (100% Pass) Which of the following should be the FIRST step in developing an information security plan? A. Perform a technical vulnerabilities assessment B. Analyze the current business strategy C. Perform a business impact analysis D. Assess the current levels of security awareness - Answer️️ -Answer: B Explanation: Prior to assessing technical vulnerabilities or levels of security awareness, an information security manager needs to gain an understanding of the current business strategy and direction. A ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM 2 business impact analysis should be performed prior to developing a business continuity plan, but this would not be an appropriate first step in developing an information security strategy because it focuses on availability. Senior management commitment and support for information security can BEST be obtained through presentations that: A. use illustrative examples of successful attacks. B. explain the technical risks to the organization. C. evaluate the organization against best security practices. D. tie security risks to key business objectives. - Answer️️ -Answer: D Explanation: ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM 3 Senior management seeks to understand the business justification for investing in security. This can best be accomplished by tying security to key business objectives. Senior management will not be as interested in technical risks or examples of successful attacks if they are not tied to the impact on business environment and objectives. Industry best practices are important to senior management but, again, senior management will give them the right level of importance when they are presented in terms of key business objectives. QUESTION NO: 4 Which of the following would BEST ensure the success of information security governance within an organization? A. Steering committees approve security projects B. Security policy training provided to all managers C. Security training available to all employees on the intranet D. ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM 4 Steering committees enforce compliance with laws and regulations - Answer️️ - Answer: A Explanation: The existence of a steering committee that approves all security projects would be an indication of the existence of a good governance program. Compliance with laws and regulations is part of the responsibility of the steering committee but it is not a full answer. Awareness training is important at all levels in any medium, and also an indicator of good governance. However, it must be guided and approved as a security project by the steering committee. QUESTION NO: 8 Retention of business records should PRIMARILY be based on: A. business strategy and direction. B. regulatory and legal requirements. C. storage capacity and longevity. ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM 5 D. business ease and value analysis. - Answer️️ -Answer: B Explanation: Retention of business records is generally driven by legal and regulatory requirements. Business strategy and direction would not normally apply nor would they override legal and regulatory requirements. Storage capacity and longevity are important but secondary issues. Business case and value analysis would be secondary to complying with legal and regulatory requirements

Show more Read less
Institution
CISM
Course
CISM











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CISM
Course
CISM

Document information

Uploaded on
August 16, 2024
Number of pages
477
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM



CISM Practice Exam Questions and Answers (100% Pass)


Which of the following should be the FIRST step in developing an information

security plan?

A.

Perform a technical vulnerabilities assessment

B.

Analyze the current business strategy

C.

Perform a business impact analysis

D.


Assess the current levels of security awareness - Answer✔️✔️-Answer: B


Explanation:

Prior to assessing technical vulnerabilities or levels of security awareness, an

information security

manager needs to gain an understanding of the current business strategy and

direction. A



1

,©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM


business impact analysis should be performed prior to developing a business

continuity plan, but

this would not be an appropriate first step in developing an information security

strategy because it

focuses on availability.

Senior management commitment and support for information security can BEST

be obtained through presentations that:

A.

use illustrative examples of successful attacks.

B.

explain the technical risks to the organization.

C.

evaluate the organization against best security practices.

D.


tie security risks to key business objectives. - Answer✔️✔️-Answer: D


Explanation:




2

,©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM


Senior management seeks to understand the business justification for investing in

security. This can best be accomplished by tying security to key business

objectives. Senior management will not be as interested in technical risks or

examples of successful attacks if they are not tied to the impact on business

environment and objectives. Industry best practices are important to senior

management but, again, senior management will give them the right level of

importance when they

are presented in terms of key business objectives.

QUESTION NO: 4

Which of the following would BEST ensure the success of information security

governance within an organization?

A.

Steering committees approve security projects

B.

Security policy training provided to all managers

C.

Security training available to all employees on the intranet

D.


3

, ©PREP4EXAMS 2024/2025 REAL EXAM DUMPS Tuesday, August 6, 2024 10,57 AM


Steering committees enforce compliance with laws and regulations - Answer✔️✔️-

Answer: A

Explanation:

The existence of a steering committee that approves all security projects would be

an indication of the existence of a good governance program. Compliance with

laws and regulations is part of the responsibility of the steering committee but it is

not a full answer. Awareness training is important at all levels in any medium, and

also an indicator of good governance. However, it must be guided and approved as

a security project by the steering committee.

QUESTION NO: 8

Retention of business records should PRIMARILY be based on:

A.

business strategy and direction.

B.

regulatory and legal requirements.

C.

storage capacity and longevity.




4

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
OliviaWest Teachme2-tutor
View profile
Follow You need to be logged in order to follow users or courses
Sold
105
Member since
1 year
Number of followers
17
Documents
8528
Last sold
6 days ago
Pure Orchid Haven.

All Documents,and package deals offered by seller Olivia West.

2.8

22 reviews

5
6
4
2
3
4
2
1
1
9

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions