• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 25 páginas
Examen

CISM Domain 6 Questions and Answers Rated A+

Document preview thumbnail
Vista previa 3 fuera de 25 páginas

CISM Domain 6 Questions and Answers Rated A+

Vista previa del contenido

CISM Domain 6 Questions and Answers Rated A+


A. Validation checks are missing in data input pages. - ANSWER-ID.Which of the
following vulnerabilities allowing attackers access to the application database is the
MOST serious?

A. Validation checks are missing in data input pages.

B. Password rules do not allow sufficient complexity.

C. Application transaction log management is weak.

D. Application and database share a single access

B. Encryption of stored data - ANSWER-Which of the following is the MOST effective
security measure to protect data held on mobile computing devices?

A.Biometric access control

B. Encryption of stored data

C.Power-on passwords

D. Protection of data being transmitted

D. the threats and vulnerabilities - ANSWER-With regard to the implementation of
security awareness programs in an organization, it is MOST relevant to understand
that one of the following aspects can change?

A. The security culture

B. The information technology

C. The compliance requirements

D. the threats and vulnerabilities

D. the data owner - ANSWER-Who is in the BEST position to determine the level of
information security needed for a specific business application?

A.The system developer

B. The information security manager

C. The system custodian

,D. the data owner

B.Employ packet filtering to drop suspect packets. - ANSWER-What is the BEST
method for mitigating against network denial-of-service (DoS) attacks?

A.Ensure all servers are up-to-date on OS patches.

B.Employ packet filtering to drop suspect packets.

C. Implement network address translation to make internal addresses nonroutable.

D. Implement load balancing for Internet facing devices.

D. Reduces financial risk but leaves legal responsibility generally unchanged. -
ANSWER-Outsourcing combined with indemnification:
A.reduces legal responsibility but leaves financial risk relatively unchanged.

B.Is more cost-effective as a means of risk transfer than purchasing insurance.

C.Eliminates the reputational risk present when operations remain in-house.

D. Reduces financial risk but leaves legal responsibility generally unchanged.

B. Preserving the integrity of the evidence - ANSWER-What is the PRIMARY focus if
an organization considers taking legal action on a security incident?

A.Obtaining evidence as soon as possible

B. Preserving the integrity of the evidence

C. Disconnecting all IT equipment involved

D.Reconstructing the sequence of events

C. Define and monitor security metrics. - ANSWER-Which of the following is the
BEST approach for improving information security management processes?

A. Conduct periodic security audits.

B. Perform periodic penetration testing.

C. Define and monitor security metrics.

D. Survey business units for feedback.

C. Use third-party providers for low-risk activities. - ANSWER-Which of the following
is the BEST approach to deal with inadequate funding of the information security
program?

, A. Eliminate low-priority security services.

B. Require management to accept the increased risk.

C. Use third-party providers for low-risk activities.

D.Reduce monitoring and compliance enforcement activities.

B. Percent of control objectives accomplished - ANSWER-Which would be one of the
BEST metrics an information security manager can employ to effectively evaluate
the results of a security program?

A. Number of controls implemented

B. Percent of control objectives accomplished

C. Percent of compliance with the security policy

D. Reduction in the number of reported security incidents

D. The extent of data loss that is acceptable - ANSWER-Which of the following
items is MOST important to determine the recovery point objective for a critical
process in an enterprise?

A. The number of hours of acceptable downtime

B. The total cost of recovering critical systems

C. The acceptable reduction in the level of service

D. The extent of data loss that is acceptable

- ANSWER-An organization's IT change management process requires that all
change requests be approved by the asset owner and the information security
manager. The PRIMARY objective of getting the information security manager's
approval is to ensure that:

A. A change affecting a security policy is not handled by an IT change process.

B. Changes in the IT infrastructure may have an impact on existing risk. An
information security manager must ensure that the proposed changes do not
adversely affect the security posture.

C. Rollback to a current state may cause a security risk event and is normally part
of change management, but is not the primary reason that security is involved in
the review.

Información del documento

Subido en
31 de agosto de 2026
Número de páginas
25
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$12.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
CLOUNDLite
3.9
(128)
Vendido
659
Seguidores
389
Artículos
12325
Última venta
1 semana hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes