Rate this post

The Best Valid CISM Dumps for Helping Passing CISM Exam!

UPDATED ISACA CISM Exam Questions & Answer

ISACA CISM Exam Syllabus Topics:

Section Weight Objectives
Topic 1: Information Security Program Development and Management 33% – Align the information security program with the operational objectives of other business functions
– Develop and maintain a security awareness, training and education program for all stakeholders
– Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation
– Establish and maintain information security architectures (people, process, technology)
– Establish and/or maintain the information security program in alignment with the information security strategy
– Integrate information security requirements into organizational processes
– Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers)
– Monitor and manage the information security program
Topic 2: Information Security Risk Management 20% – Determine appropriate risk treatment options
– Integrate risk management into business and IT processes
– Monitor and communicate the information security risk posture
– Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership
– Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk
– Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk
– Identify legal, regulatory, organizational and other applicable compliance requirements
– Identify and/or recommend risk treatment options
Topic 3: Information Security Incident Management 30% – Develop and implement processes to ensure the timely identification of information security incidents
– Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents
– Establish and maintain communication plans and processes to manage communication with internal and external entities
– Establish and maintain processes to investigate and document information security incidents
– Establish and maintain incident escalation and notification processes
– Test, review and revise the incident response plan
– Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents
– Organize, train and equip teams to effectively respond to information security incidents
Topic 4: Information Security Governance 17% – Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization
– Obtain commitment from senior management and other stakeholders for the information security program
– Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives
– Identify internal and external influences to the organization that affect the information security strategy and program
– Establish, monitor, evaluate and report information security management metrics
– Define and communicate the roles and responsibilities for information security throughout the organization
– Develop business cases to support investments in information security

 

NO.317 Which of the following BEST indicates the effectiveness of the vendor risk management process?

 
 
 
 

NO.318 An information security manager recently received funding for a vulnerability scanning tool to replace manual assessment techniques and needs to justify the expense of the tool going forward. Which of the following metrics would BEST indicate the tool is effective?

 
 
 
 

NO.319 Which of the following principles BEST addresses the protection of data from unauthorized modification?

 
 
 
 

NO.320 When establishing metrics for an information security program, the BEST approach is to identify indicators that:

 
 
 
 

NO.321 An organization has received complaints from users that some of their files have been encrypted. These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?

 
 
 
 

NO.322 Which of the following is the MOST effective way to prevent information security incidents?

 
 
 
 

NO.323 After detecting an advanced persistent threat (APT), which of the following should be the information security manager’s FIRST step?

 
 
 
 

NO.324 Which of the following is CRITICAL to ensure the appropriate stakeholder makes decisions during a cybersecurity incident?

 
 
 
 

NO.325 Which of the following sources is MOST useful when planning a business-aligned information security program?

 
 
 
 

NO.326 Which of the following is the BEST method to ensure that data owners take responsibility for implementing information security processes’

 
 
 
 

NO.327 Which of the following is the GREATEST benefit of incorporating information security governance into the corporate governance framework?

 
 
 
 

NO.328 Executive leadership has decided to engage a consulting firm to develop and implement a comprehensive security framework for the organization to allow senior management to remain focused on business priorities.
Which of the following poses the GREATEST challenge to the successful implementation of a new security governance framework?

 
 
 
 

NO.329 An organization’s quality process can BEST support security management by providing:

 
 
 
 

NO.330 Which of the following BEST contributes to the successful management of security incidents?

 
 
 
 

NO.331 When introducing a new information asset, what is the MOST important responsibility of the asset owner?

 
 
 
 

NO.332 Which of the following should be an information security manager’s.
MOST important consideration when determining if an information asset has been classified appropriately?

 
 
 
 

NO.333 To determine how a security breach occurred on the corporate network, a security manager looks at the logs of various devices. Which of the following BEST facilitates the correlation and review of these logs?

 
 
 
 

NO.334 After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?

 
 
 

NO.335 Security technologies should be selected PRIMARILY on the basis of their:

 
 
 
 

NO.336 An information security manager wishing to establish security baselines would:

 
 
 
 

NO.337 Which of the following is the BEST metric for evaluating the effectiveness of an intrusion detection mechanism?

 
 
 
 

NO.338 Which of the following should be the FIRST step in developing an information security strategy?

 
 
 
 

Updated CISM Dumps Questions For ISACA Exam: https://www.pdf4test.com/CISM-dump-torrent.html

Related Links: www.slideshare.net myportal.utt.edu.tt myportal.utt.edu.tt scalar.usc.edu myportal.utt.edu.tt estar.jp

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below