Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Vce CISM Questions Latest

Page: 51 / 86
Total 1191 questions

Certified Information Security Manager Questions and Answers

Question 201

Which type of system is MOST effective for prioritizing cyber incidents based on impact and tracking them until they are closed?

Options:

A.

Security information and event management (SIEM)

B.

Extended detection and response (XDR)

C.

Endpoint detection and response (EDR)

D.

Network intrusion detection system (NIDS)

Question 202

An organization recently identified a significant risk related to data exfiltration, and the information security manager is asked to quickly address this issue. The security team suggests a number of different security controls. Which of the following is the BEST approach for selecting controls to manage the risk?

Options:

A.

Implement controls recommended by an industry-recognized security framework.

B.

Assess the effectiveness of each control in reducing residual risk.

C.

Prioritize the controls based on ease of implementation and resource availability.

D.

Choose the most economical controls for risk mitigation based on a cost-benefit analysis.

Question 203

Which of the following should an information security manager do FIRST when there is a conflict between the organization ' s information security policy and a local regulation?

Options:

A.

Enforce the local regulation.

B.

Obtain legal guidance.

C.

Enforce the organization ' s information security policy.

D.

Obtain an independent assessment of the regulation.

Question 204

Which of the following should be the PRIMARY basis for an information security strategy?

Options:

A.

The organization ' s vision and mission

B.

Results of a comprehensive gap analysis

C.

Information security policies

D.

Audit and regulatory requirements

Page: 51 / 86
Total 1191 questions