Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Exactprep CISM Questions

Page: 12 / 86
Total 1191 questions

Certified Information Security Manager Questions and Answers

Question 45

Which of the following would be of GREATEST assistance in determining whether to accept residual risk of a critical security system?

Options:

A.

Available annual budget

B.

Cost-benefit analysis of mitigating controls

C.

Recovery time objective (RTO)

D.

Maximum tolerable outage (MTO)

Question 46

When a critical system incident is reported, the FIRST step of the incident handler should be to:

Options:

A.

Notify the appropriate parties

B.

Determine the scope of the incident

C.

Validate the incident

D.

Power off the system

Question 47

An information security manager has been asked to provide both one-year and five-year plans for the information security program. What is the PRIMARY purpose for the long-term plan?

Options:

A.

To facilitate the continuous improvement of the IT organization

B.

To ensure controls align with security needs

C.

To create and document required IT capabilities

D.

To prioritize security risks on a longer scale than the one-year plan

Question 48

The PRIMARY purpose for deploying information security metrics is to:

Options:

A.

compare program effectiveness to benchmarks.

B.

support ongoing security budget requirements.

C.

ensure that technical operations meet specifications.

D.

provide information needed to make decisions.

Page: 12 / 86
Total 1191 questions