Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISM Exam Dumps - Certified Information Security Manager

Searching for workable clues to ace the Isaca CISM Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISM PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 337

Which of the following BEST provides an information security manager with sufficient assurance that a service provider complies with the organization ' s information security requirements?

A.

Alive demonstration of the third-party supplier ' s security capabilities

B.

The ability to i third-party supplier ' s IT systems and processes

C.

Third-party security control self-assessment (CSA) results

D.

An independent review report indicating compliance with industry standards

Full Access
Question # 338

Which of the following is MOST helpful for aligning security operations with the IT governance framework?

A.

Security risk assessment

B.

Security operations program

C.

Information security policy

D.

Business impact analysis (BIA)

Full Access
Question # 339

Which of the following has the GREATEST impact on the ability to successfully execute a disaster recovery plan (DRP)?

A.

Conducting tabletop exercises of the plan

B.

Updating the plan periodically

C.

Communicating the plan to all stakeholders

D.

Reviewing escalation procedures

Full Access
Question # 340

An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information about the effectiveness of compensating controls?

A.

Threat assessment

B.

Intrusion detection system logs

C.

Penetration testing

D.

Firewall rules

Full Access
Question # 341

Which of the following is the BEST method to protect against emerging advanced persistent threat (APT) actors?

A.

Providing ongoing training to the incident response team

B.

Implementing proactive systems monitoring

C.

Implementing a honeypot environment

D.

Updating information security awareness materials

Full Access
Question # 342

Which of the following should include contact information for representatives of equipment and software vendors?

A.

Information security program charter

B.

Business impact analysis (BIA)

C.

Service level agreements (SLAs)

D.

Business continuity plan (BCP)

Full Access
Question # 343

Which of the following is the GREATEST concern with implementing all controls recommended by a security framework?

A.

Increased time for implementation

B.

Lack of approval from senior management

C.

Negative return on investment

D.

Increased risk levels

Full Access
Question # 344

Which of the following is the MOST effective approach to communicate general information security responsibilities across an organization?

A.

Provide regular security awareness training

B.

Require staff to sign confidentiality agreements

C.

Publish the information security policy on the corporate intranet

D.

Develop a RACI matrix for the organization

Full Access
Go to page: