
Quality CISM PDF Dumps - CISM Exam Questions
Most UptoDate ISACA CISM Exam Dumps PDF 2026
The CISM certification is recognized by many organizations around the world, including government agencies, financial institutions, and multinational corporations. Certified Information Security Manager certification is a valuable asset for professionals who want to advance their careers in information security management.
NEW QUESTION # 416
A third party was engaged to develop a business application. Which of the following would an information security manager BEST test for the existence of back doors?
- A. Security code reviews for the entire application
- B. Reverse engineering the application binaries
- C. System monitoring for traffic on network ports
- D. Running the application from a high-privileged account on a test system
Answer: A
Explanation:
Explanation
Security' code reviews for the entire application is the best measure and will involve reviewing the entire source code to detect all instances of back doors. System monitoring for traffic on network ports would not be able to detect all instances of back doors and is time consuming and would take a lot of effort. Reverse engineering the application binaries may not provide any definite clues. Back doors will not surface by running the application on high-privileged accounts since back doors are usually hidden accounts in the applications.
NEW QUESTION # 417
Which of the following is MOST important for the effectiveness of an incident response function?
- A. Enterprise security management system and forensic tools
- B. Automated modem tracking and reporting tools
- C. Training of all users on when and how to report
- D. Establishing prior contacts with law enforcement
Answer: C
NEW QUESTION # 418
An investigation of a recent security incident determined that the root cause was negligent handing of incident alerts by system admit manager to address this issue?
- A. Revise the incident response plan-to align with business processes.
- B. Provide incident response training to data custodians.
- C. Provide incident response training to data owners.
- D. Conduct a risk assessment and share the result with senior management.
Answer: B
Explanation:
The best action for the system admin manager to address the issue of negligent handling of incident alerts by system admins is to provide incident response training to data custodians because it helps to improve their awareness and skills in recognizing and reporting security incidents, and following the incident response procedures and protocols. Conducting a risk assessment and sharing the result with senior management is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Revising the incident response plan to align with business processes is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Providing incident response training to data owners is not a good action because data owners are not responsible for handling incident alerts or performing incident response tasks. References: https://www.isaca.org/resources
/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca- journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 419
Minimum standards for securing the technical infrastructure should be defined in a security:
- A. model.
- B. architecture.
- C. strategy.
- D. guidelines.
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Minimum standards for securing the technical infrastructure should be defined in a security architecture document. This document defines how components are secured and the security services that should be in place. A strategy is a broad, high-level document. A guideline is advisory in nature, while a security model shows the relationships between components.
NEW QUESTION # 420
The business continuity policy should contain which of the following?
- A. Critical backups inventory
- B. Emergency call trees
- C. Recovery criteria
- D. Business impact assessment (BIA)
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
Recovery criteria, indicating the circumstances under which specific actions are undertaken, should be contained within a business continuity policy. Telephone trees, business impact assessments (BIAs) and listings of critical backup files are too detailed to include in a policy document.
NEW QUESTION # 421
Which of the following is the MOST important prerequisite for establishing information security management within an organization?
- A. Senior management commitment
- B. Information security organizational structure
- C. Information security framework
- D. Information security policy
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Senior management commitment is necessary in order for each of the other elements to succeed. Without senior management commitment, the other elements will likely be ignored within the organization.
NEW QUESTION # 422
Which of the following is the GREATEST risk to consider when a rival organization purchases a business unit within an organization?
- A. Access and permissions to the corporate network from the business unit will remain after the sale.
- B. Loss of corporate knowledge.
- C. Senior business management will not understand technical risks.
- D. The business unit's confidential information will be transferred to the nval organization during the separation.
Answer: D
NEW QUESTION # 423
Which of the following is the MOST important consideration m a bring your own device (BYOD) program to protect company data in the event of a loss?
- A. The ability to classify types of devices
- B. The ability to centrally manage devices
- C. The ability to remotely locate devices
- D. The ability to restrict unapproved applications
Answer: C
NEW QUESTION # 424
When creating an incident response plan, the PRIMARY benefit of establishing a clear definition of a security incident is that it helps to:
- A. make tabletop testing more effective
- B. communicate the incident response process to stakeholders
- C. develop effective escalation and response procedures
- D. adequately staff and train incident response teams
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION # 425
Which of the following should be done FIRST after a ransomware incident has been successfully contained?
- A. Perform lessons learned.
- B. Notify relevant stakeholders.
- C. Restore impacted systems.
- D. Conduct forensic analysis.
Answer: B
NEW QUESTION # 426
After a ransomware incident an organization's systems were restored. Which of the following should be of MOST concern to the information security manager?
- A. The service level agreement (SLA) was not met.
- B. The root cause was not identified.
- C. The recovery time objective (RTO) was not met.
- D. Notification to stakeholders was delayed.
Answer: B
Explanation:
= After a ransomware incident, the most important concern for the information security manager is to identify the root cause of the incident and prevent it from happening again. The root cause analysis (RCA) is a systematic process of finding and eliminating the underlying factors that led to the incident, such as vulnerabilities, misconfigurations, human errors, or malicious actions. Without performing a RCA, the organization may not be able to address the root cause and may face the same or similar incidents in the future, which could result in more damage, costs, and reputational loss. Therefore, the information security manager should prioritize the RCA over other concerns, such as meeting the SLA, RTO, or notification requirements, which are important but secondary to the RCA.
References = CISM Review Manual 15th Edition, page 254-2551; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 4202
NEW QUESTION # 427
When implementing a security policy for an organization handling personally identifiable information (PlI). the MOST important objective should be:
- A. data availability.
- B. security awareness training.
- C. regulatory compliance.
- D. strong encryption.
Answer: C
NEW QUESTION # 428
Which of the following is the MOST appropriate method to protect a password that opens a confidential file?
- A. Digital signatures
- B. Out-of-band channels
- C. Delivery path tracing
- D. Reverse lookup translation
Answer: B
Explanation:
Out-of-band channels are useful when it is necessary, for confidentiality, to break a message into two parts that are then sent by different means. Digital signatures only provide nonrepudiation. Reverse lookup translation involves converting ;in Internet Protocol (IP) address to a username. Delivery path tracing shows the route taken but does not confirm the identity of the sender.
NEW QUESTION # 429
Which of the following is the PRIMARY product of a business impact analysis (BIA)?
- A. Well-defined incident escalation procedures
- B. A heat map of business risk scenarios
- C. Prioritization of assets for business recovery
- D. Prioritization of vulnerabilities for remediation
Answer: C
NEW QUESTION # 430
An organization has introduced a new bring your own device (BYOD) program. The security manager has determined that a small number of employees are utilizing free cloud storage services to store company data through their mobile devices. Which of the following is the MOST effective course of action?
- A. Allow the practice to continue temporarily for monitoring purposes.
- B. Initiate remote wipe of the devices
- C. Assess the business need to provide a secure solution
- D. Disable the employees' remote access to company email and data
Answer: C
Explanation:
Explanation
The most effective course of action when employees are using free cloud storage services to store company data through their mobile devices is to assess the business need to provide a secure solution, such as a corporate-approved cloud service or a virtual desktop environment. Assessing the business need can help understand why employees are using free cloud storage services, what kind of data they are storing, and what are the security risks and requirements. Based on the assessment, the security manager can propose a secure solution that meets the business needs and complies with the BYOD policy. The other options, such as allowing the practice to continue, disabling remote access, or initiating remote wipe, may not address the underlying business need or may cause disruption or data loss. References:
* https://www.digitalguardian.com/blog/byod-security-expert-tips-policy-mitigating-risks-preventing-breach
* https://news.microsoft.com/en-xm/2021/03/18/how-to-have-secure-remote-working-with-a-byod-policy/
* https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/-infosec-guide-bring-y
NEW QUESTION # 431
Which of the following devices should be placed within a DMZ?
- A. Authentication server
- B. Router
- C. Mail relay
- D. Firewall
Answer: C
Explanation:
Explanation/Reference:
Explanation:
A mail relay should normally be placed within a demilitarized zone (DMZ) to shield the internal network. An authentication server, due to its sensitivity, should always be placed on the internal network, never on a DMZ that is subject to compromise. Both routers and firewalls may bridge a DMZ to another network, but do not technically reside within the DMZ, network segment.
NEW QUESTION # 432
An information security manager is recommending an investment in a new security initiative to address recently published threats. Which of the following would be important to include in the business case?
- A. Threat information from reputable sources
- B. Alignment of the new initiative with the approved business strategy
- C. Availability of unused funds in the security budget
- D. Business impact if threats materialize
Answer: D
NEW QUESTION # 433
Which of the following is the BEST course of action for an information security manager to align security and business goals?
- A. Actively engaging with stakeholders
- B. Defining key performance indicators (KPIs)
- C. Reviewing the business strategy
- D. Conducting a business impact analysis (BIA)
Answer: A
Explanation:
= According to the CISM Review Manual, the information security manager should actively engage with stakeholders to align security and business goals. This means understanding the business needs, expectations, and risk appetite of the stakeholders, and communicating the value and benefits of security initiatives to them.
By engaging with stakeholders, the information security manager can also gain their support and commitment for security programs and projects, and ensure that security objectives are aligned with business strategy and priorities. References = CISM Review Manual, 16th Edition, ISACA, 2020, page 23.
NEW QUESTION # 434
Which of the following is MOST important when defining how an information security budget should be allocated?
- A. Business impact assessment
- B. Information security strategy
- C. Information security policy
- D. Regulatory compliance standards
Answer: B
Explanation:
Information security strategy is the most important factor when defining how an information security budget should be allocated because it helps to align the security objectives and initiatives with the business goals and priorities. An information security strategy is a high-level plan that defines the vision, mission, scope, and direction of the security program, as well as the roles and responsibilities, governance structures, policies and standards, risk management approaches, and performance measurement methods. An information security strategy helps to identify and prioritize the security needs and requirements of the organization, as well as to allocate the resources and funding accordingly. An information security strategy also helps to communicate the value and benefits of security to the stakeholders and justify the security investments. Therefore, information security strategy is the correct answer.
References:
* https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-breakdown-and-best-practices
* https://www.csoonline.com/article/3671108/how-2023-cybersecurity-budget-allocations-are-shaping-up.
html
* https://www.statista.com/statistics/1319677/companies-it-budget-allocated-to-security-worldwide/
NEW QUESTION # 435
An organization is already certified to an international security standard. Which mechanism would BEST help to further align the organization with other data security regulatory requirements as per new business needs?
- A. Business impact analysis (BIA)
- B. Gap analysis
- C. Technical vulnerability assessment
- D. Key performance indicators (KPIs)
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Gap analysis would help identify the actual gaps between the desired state and the current implementation of information security management. BIA is primarily used for business continuity planning. Technical vulnerability assessment is used for detailed assessment of technical controls, which would come later in the process and would not provide complete information in order to identify gaps.
NEW QUESTION # 436
When training an incident response team, the advantage of using tabletop exercises is that they:
- A. remove the need to involve senior managers in the response process.
- B. provide the team with practical experience in responding to incidents.
- C. ensure that the team can respond to any incident
- D. enable the team to develop effective response interactions.
Answer: C
NEW QUESTION # 437
......
100% Free Isaca Certification CISM Dumps PDF Demo Cert Guide Cover: https://examsboost.dumpstorrent.com/CISM-exam-prep.html