Free Certified Information Security Manager (CISM) General Questions and Answers — Questions and Answers
Question 1: For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished. The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks. Which of the following would be the information security manager's BEST course of action?
- Acceptance of the information security manager’s decision on the risk to the corporation
- Acceptance of the business manager’s decision on the risk to the corporation
- Create a new risk assessment and BIA to resolve the disagreement
- Review of the risk assessment with executive management for final input (Correct answer)
Correct answer: Review of the risk assessment with executive management for final input
Executive management will be in the best position to consider the big picture and the trade-offs between security and functionality in the entire organization.
Question 2: Who is responsible for making sure that data is categorized and that particular security precautions are taken?
- Senior Management (Correct answer)
- The security Officer
- The custodian
- The end user
Correct answer: Senior Management
Routine administration of all aspects of security is delegated, but top management must retain overall accountability.
Question 3: Unusual server communication between internal and external parties may be observed to:
- Evaluate the process resiliency of server operations
- Record the trace of advanced persistent threats (Correct answer)
- Support a nonrepudiation framework in e-commerce
- Verify the effectiveness of an intrusion detection system
Correct answer: Record the trace of advanced persistent threats
The most important feature of target attacks as seen in advanced persistent threats is that malware secretly sends information back to a command and control server. Therefore, monitoring of outbound server communications that do not follow predefined routes will be the best control to detect such security events.
Question 4: What authentication technique stops authentication replay?
- Challenge/response mechanism (Correct answer)
- Password hash implementation
- Hypertext Transfer Protocol basic authentication
- Wired equivalent privacy encryption usage
Correct answer: Challenge/response mechanism
A challenge/response mechanism defeats replay attacks because the server issues a unique, one-time challenge each session, so a captured response is useless the next time. Password hashes, HTTP basic auth, and WEP all rely on static or reusable secrets that an attacker can intercept and replay.
Question 5: IT risk management initiatives are MOST successful when they:
- Conducted by the IT department
- Treated as distinct process
- Communicated to all employees
- Integrated within business processes (Correct answer)
Correct answer: Integrated within business processes
IT risk management is most successful when integrated within business processes, because the people who own the processes have the context and authority to make risk decisions that stick. Keeping it confined to the IT department or treating it as a separate process isolates it from where risk actually occurs, and merely communicating it to employees doesn't embed it into operations.
Question 6: Which of the following is the BEST technique to catch an intruder who breaks into a network without doing any damage?
- Establish minimum security baselines
- Perform periodic penetration testing
- Install a honeypot on the network (Correct answer)
- Implement vendor default settings
Correct answer: Install a honeypot on the network
A honeypot is the best tool to catch a non-destructive intruder because it's a decoy system designed to lure and observe attackers while keeping real assets safe. Baselines, penetration testing, and default settings are preventive or assessment measures—they don't actively detect or study an intruder already moving inside the network.
Question 7: Which of the following poses the BIGGEST risk to an enterprise resource planning (ERP) system's security?
- Network traffic is through a single switch
- User ad hoc reporting is not logged
- Database security defaults ti ERP settings
- Operating system security patches have not been applied (Correct answer)
Correct answer: Operating system security patches have not been applied
Missing operating system security patches pose the biggest risk because every application, including the ERP, depends on the OS layer, so an unpatched OS exposes the widest attack surface. A single switch, unlogged ad hoc reporting, and default database settings are concerns but far narrower in scope than a vulnerable underlying operating system.
For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished.
The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks.
Which of the following would be the information security manager's BEST course of action?