Free Certified Information Security Manager (CISM) ISACA Questions and Answers — Questions and Answers
Question 1: The following conditions lead to the MOST successful IT risk management activities:
- Conducted by the IT department
- Treated as a distinct process
- Integrated within business processes (Correct answer)
- Communicated to all employees
Correct answer: Integrated within business processes
Effective IT-related risk management activities are most effective when they are integrated within business processes.
Question 2: For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished. The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks. <br> <br> Which of the following would be the information security manager's BEST course of action?
- Acceptance of the information security manager’s decision on the risk to the corporation
- Acceptance of the business manager’s decision on the risk to the corporation
- Create a new risk assessment and BIA to resolve the disagreement
- Review of the risk assessment with executive management for final input (Correct answer)
Correct answer: Review of the risk assessment with executive management for final input
The best approach for the information security manager in this situation would be to review the risk assessment with executive management for final input.
Question 3: Who is responsible for making sure that data is categorized and that particular security precautions are taken?
- Senior management (Correct answer)
- The security officer
- The custodian
- The end user
Correct answer: Senior management
Senior management is accountable for ensuring that information is categorized and that specific protective measures are taken. As the highest level of management within an organization, senior management holds the ultimate responsibility for information security and the protection of organizational assets. This includes establishing policies and procedures for information classification and ensuring that appropriate protective measures are implemented.
Question 4: It is possible to monitor unusual server traffic between internal and external parties to:
- Evaluate the process resiliency of server operations
- Record the trace of advanced persistent threats (Correct answer)
- Support a nonrepudiation framework in e-commerce
- Verify the effectiveness of an intrusion detection system
Correct answer: Record the trace of advanced persistent threats
Monitoring abnormal server communication from inside the organization to external parties can serve the purpose of recording the trace of advanced persistent threats (APTs).
Question 5: Which of the following is the BEST technique to catch an intruder who breaks into a network without doing any damage?
- Establish minimum security baselines
- Perform periodic penetration testing
- Install a honeypot on the network (Correct answer)
- Implement vendor default settings
Correct answer: Install a honeypot on the network
A honeypot is the best technique to catch an intruder who breaks in without doing damage because it's a deceptive system that attracts attackers and lets you observe their behavior without risking production assets. Security baselines, periodic penetration testing, and vendor defaults are preventive or testing measures, not active intruder-detection tools.
Question 6: A security manager examines the logs of numerous devices to ascertain how a security breach on the business network happened. <br> <br> Which of the following BEST makes it easier to compare and analyze these logs?
- Domain name server
- Database server
- Proxy server
- Time server (Correct answer)
Correct answer: Time server
A time server best enables log comparison because synchronized, consistent timestamps across all devices are required before events from different sources can be sequenced and correlated. DNS, database, and proxy servers serve other functions and do nothing to ensure the time alignment needed to reconstruct the order of a breach.
Question 7: What authentication technique stops authentication replay?
- Challenge/response mechanism (Correct answer)
- Password hash implementation
- Hypertext Transfer Protocol basic authentication
- Wired equivalent privacy encryption usage
Correct answer: Challenge/response mechanism
The challenge/response mechanism is an authentication method that effectively prevents authentication replay attacks.
The following conditions lead to the MOST successful IT risk management activities: