
[Jan 01, 2024] CISM-CN Practice Exam Dumps - 99% Marks In ISACA Exam
Updated Verified CISM-CN Q&As - Pass Guarantee or Full Refund
NEW QUESTION # 184
以下哪一項是監控與信息安全相關的關鍵風險指標 (KRI) 的主要原因?
- A. 重新評估風險偏好
- B. 控制性能基準測試
- C. 警告不可接受的風險
- D. 識別殘餘風險
Answer: B
NEW QUESTION # 185
託管組織的數據中心容納服務器、應用程序
為組織製定物理訪問控制策略的最佳方法?
- A. 進行風險評估以確定安全風險和緩解控制措施。
- B. 設計單點登錄 (SSO) 或聯合訪問。
- C. 審查客戶的安全策略。
- D. 為每個系統和應用程序制定訪問控制要求。
Answer: A
NEW QUESTION # 186
部署以下哪種技術後,安全管理工作將大大減少?
- A. 分佈式訪問控制
- B. 基於角色的訪問控制
- C. 訪問控制列表
- D. 自主訪問控制
Answer: B
NEW QUESTION # 187
以下哪项应该是信息安全策略的主要基础?
- A. 信息安全政策
- B. 全面差距分析的结果
- C. 组织的愿景和使命
- D. 审计和监管要求
Answer: C
Explanation:
The primary basis for an information security strategy should be the organization's vision and mission. The organization's vision and mission should be the foundation for the security strategy, and should inform and guide the security policies, procedures, and practices that are implemented. The results of a comprehensive gap analysis, information security policies, and audit and regulatory requirements should all be taken into consideration when developing the security strategy, but should not be the primary basis.
NEW QUESTION # 188
某员工点击钓鱼邮件中的链接,引发勒索软件攻击 信息安全应具备以下哪项?
- A. 通知高级管理层。
- B. 擦除受影响的系统。
- C. 隔离受影响的端点。
- D. 通知内部法律顾问。
Answer: C
Explanation:
Isolating the impacted endpoints is the best course of action for the information security manager after an employee clicked on a link in a phishing email, triggering a ransomware attack because it prevents the ransomware from spreading to other systems or devices on the network, and minimizes the damage or disruption caused by the attack. Wiping the affected system is not a good course of action because it may destroy any evidence or data that could be used for investigation or recovery. Notifying internal legal counsel is not a good course of action because it does not address the immediate threat or impact of the ransomware attack. Notifying senior management is not a good course of action because it does not address the immediate threat or impact of the ransomware attack. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 189
當出現以下情況時,滲透測試是最合適的:
- A. 新系統正在設計中。
- B. 新系統即將上線。
- C. 正在製定安全策略。
- D. 發生安全事件,
Answer: B
NEW QUESTION # 190
以下哪一項可以向高級管理層提供安全控制績效已改善的最佳證據?
- A. 新興威脅分析的結果
- B. 降低固有風險
- C. 安全指標趨勢回顧
- D. 已證明的安全投資回報
Answer: C
Explanation:
Review of security metrics trends is the best evidence to senior management that security control performance has improved because it helps to measure and demonstrate the effectiveness and efficiency of the security controls over time. Security metrics are quantitative or qualitative indicators that provide information about the security status or performance of an organization, system, process, or activity. Security metrics can be used to evaluate the implementation, operation, and outcome of security controls, such as the number of vulnerabilities detected and remediated, the time to respond and recover from incidents, the compliance level with security policies and standards, or the return on security investment. Review of security metrics trends helps to identify and communicate the progress, achievements, and challenges of the security program, as well as to support decision making and continuous improvement. Therefore, review of security metrics trends is the correct answer.
Reference:
https://www.bitsight.com/blog/importance-continuous-improvement-security-performance-management
https://www.isaca.org/resources/isaca-journal/issues/2020/volume-6/key-performance-indicators-for-security-governance-part-2
https://www.nist.gov/news-events/news/2021/09/dhs-nist-coordinate-releasing-preliminary-cybersecurity-performance-goals.
NEW QUESTION # 191
组织越来越多地使用软件即服务 (SaaS) 来取代 IT 应用程序的内部托管和支持。以下哪项是帮助确保采购决策考虑信息安全问题的最有效方法?
- A. 邀请 IT 成员参加定期的采购团队会议以影响最佳实践。
- B. 将信息安全风险评估纳入采购流程。
- C. 在与 SaaS 供应商的采购合同中强制执行审计权。
- D. 为采购团队提供定期的信息安全培训。
Answer: B
NEW QUESTION # 192
以下哪項對於獲得高級管理層對網絡基礎設施安全投資的批准最有效?
- A. 突出競爭對手在網絡最佳安全實踐方面的表現
- B. 提供來自多個供應商的可比較的安全實施評估
- C. 證明有針對性的安全控制與業務目標相關
- D. 針對網絡執行滲透測試以證明業務漏洞
Answer: C
Explanation:
The most effective way to gain senior management approval of security investments in network infrastructure is by demonstrating that targeted security controls tie to business objectives.
Security investments should be tied to business objectives and should support the overall goals of the organization. By demonstrating that the security controls will directly support the organization's business objectives, senior management will be more likely to approve the investment.
According to the Certified Information Security Manager (CISM) Study Manual, "To gain senior management's approval for investments in security, it is essential to show how the security controls tie to business objectives and are in support of the overall goals of the organization." While performing penetration tests against the network, highlighting competitor performance, and presenting comparable security implementation estimates from vendors are all useful in presenting the value of security investments, they are not as effective as demonstrating how the security controls will support the organization's business objectives.
Reference:
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 305.
NEW QUESTION # 193
以下哪个角色最能影响组织内的安全文化?
- A. 首席运营官(COO)
- B. 首席信息安全官(CISO)
- C. 首席信息官(CIO)
- D. 首席执行官(CEO)
Answer: B
Explanation:
The Chief Information Security Officer (CISO) is responsible for leading and coordinating an organization's information security program, and as such, is in a prime position to influence the security culture within the organization. The CISO is responsible for setting policies and standards, educating employees about security risks and best practices, and ensuring that the organization is taking appropriate measures to mitigate security risks. By demonstrating a strong commitment to information security, the CISO can help to create a security-aware culture within the organization.
NEW QUESTION # 194
以下哪一項最能體現信息安全計劃的附加價值?
- A. 差距分析
- B. 安全基線
- C. SWOT 分析
- D. 平衡計分卡
Answer: D
Explanation:
A balanced scorecard is a tool that can be used to demonstrate the added value of an information security program by measuring and reporting on key performance indicators (KPIs) and key risk indicators (KRIs) aligned with strategic objectives. Security baselines, a gap analysis and a SWOT analysis are all useful for assessing and improving security posture, but they do not necessarily show how security contributes to business value.
NEW QUESTION # 195
對組織內部網絡的定期漏洞掃描發現許多用戶工作站都有未打補丁的軟件版本。信息安全經理幫助高級管理層了解相關風險的最佳方法是什麼?
- A. 建議安全指導委員會進行審查。
- B. 將風險的影響納入常規指標中。
- C. 直接向高級管理人員發送定期通知
- D. 定期更新風險評估
Answer: B
Explanation:
Including the impact of the risk as part of regular metrics is the best way for the information security manager to help senior management understand the related risk of having many user workstations with unpatched versions of software because it quantifies and communicates the potential consequences and likelihood of such a risk in terms of business objectives and performance indicators. Recommending the security steering committee conduct a review is not a good way because it does not provide any specific information or analysis about the risk or its impact. Updating the risk assessment at regular intervals is not a good way because it does not ensure that senior management is aware or informed about the risk or its impact. Sending regular notifications directly to senior managers is not a good way because it may be perceived as intrusive or annoying, and may not convey the severity or urgency of the risk or its impact. Reference: https://www.isaca.org/resources/isaca-journal/issues/2015/volume-6/measuring-the-value-of-information-security-investments https://www.isaca.org/resources/isaca-journal/issues/2017/volume-3/how-to-measure-the-effectiveness-of-your-information-security-management-system
NEW QUESTION # 196
一家拥有多家商店的零售商新任命的信息安全经理发现 HVAC(供暖、通风和空调)供应商可以远程访问商店以实现实时监控和设备诊断。以下哪项应该是信息安全经理的首要行动方案?
- A. 审查供应商的技术安全控制
- B. 断开实时访问
- C. 对供应商进行渗透测试。
- D. 审查供应商合同
Answer: D
Explanation:
Reviewing the vendor contract should be the information security manager's first course of action when discovering an HVAC vendor has remote access to the stores to enable real-time monitoring and equipment diagnostics. The vendor contract should specify the terms and conditions of the vendor's access to the retailer's network, such as the scope, purpose, duration, frequency, and method of access. The vendor contract should also define the roles and responsibilities of both parties regarding security, privacy, compliance, liability, and incident response. Reviewing the vendor contract will help the information security manager to understand the contractual obligations and expectations of both parties, and to identify any gaps or issues that need to be addressed or resolved1. The other options are not the first course of action for the information security manager when discovering an HVAC vendor has remote access to the stores. Conducting a penetration test of the vendor may be a useful way to assess the vendor's security posture and potential vulnerabilities, but it should be done with the vendor's consent and cooperation, and after reviewing the vendor contract2. Reviewing the vendor's technical security controls may be a necessary step to verify the vendor's compliance with security standards and best practices, but it should be done after reviewing the vendor contract and in accordance with the agreed-upon audit procedures3. Disconnecting the real-time access may be a drastic measure that could disrupt the vendor's service delivery and violate the vendor contract, unless there is a clear and imminent threat or breach that warrants such action. Reference: 1: Vendor Access: Addressing the Security Challenge with Urgency - BeyondTrust 2: Penetration Testing - NIST 3: Reduce Risk from Third Party Access | BeyondTrust : Third-Party Vendor Security Risk Management & Prevention
NEW QUESTION # 197
應防止欺騙,因為它可能用於:
- A. 通過偽造發件人地址非法進入安全系統,
- B. 收集信息、跟踪流量並識別網絡漏洞。
- C. 預測出現選項時程序將分支的方式
- D. 捕獲通過網絡傳輸的密碼等信息
Answer: A
Explanation:
Gaining illegal entry to a secure system by faking the sender's address is one of the reasons why spoofing should be prevented. Spoofing is a technique that involves impersonating someone or something else to deceive or manipulate the recipient or target. Spoofing can be applied to various communication channels, such as emails, websites, phone calls, IP addresses, or DNS servers. One of the common goals of spoofing is to gain unauthorized access to a secure system by faking the sender's address, such as an email address or an IP address. For example, an attacker may spoof an email address of a trusted person or organization and send a phishing email that contains a malicious link or attachment. If the recipient clicks on the link or opens the attachment, they may be redirected to a fake website that asks for their credentials or downloads malware onto their device. Alternatively, an attacker may spoof an IP address of a trusted source and send packets to a secure system that contains malicious code or commands. If the system accepts the packets as legitimate, it may execute the code or commands and compromise its security. Therefore, gaining illegal entry to a secure system by faking the sender's address is one of the reasons why spoofing should be prevented.
Reference:
https://www.kaspersky.com/resource-center/definitions/spoofing
https://www.cisa.gov/resources-tools/resources/business-case-security
https://www.avast.com/c-spoofing
NEW QUESTION # 198
让最终用户参与连续性规划的主要优势在于他们:
- A. 对具体的业务需求有更好的理解。
- B. 可以看到对业务的整体影响。
- C. 可以平衡技术风险和业务风险。
- D. 比信息安全管理更客观。
Answer: A
NEW QUESTION # 199
組織的災難恢復計劃 (DRP) 被記錄並保存在災難恢復站點。以下哪項是確保計劃在緊急情況下得以執行的最佳方法?
- A. 將災難恢復文檔存儲在公共雲中。
- B. 向適當的員工提供年度災難恢復培訓。
- C. 要求所有關鍵決策者都存儲災難恢復文檔。
- D. 在另一個國家/地區維護一個外包聯絡中心。
Answer: C
NEW QUESTION # 200
以下哪一項是保護高價值資產或處理存在信任問題的環境的最佳縱深防禦實施?
- A. 劃分
- B. 持續監控
- C. 重疊冗餘
- D. 多重身份驗證
Answer: A
Explanation:
Compartmentalization is the best defense-in-depth implementation for protecting high value assets or for handling environments that have trust concerns because it is a strategy that divides the network or system into smaller segments or compartments, each with its own security policies, controls, and access rules. Compartmentalization helps to isolate and protect the most sensitive or critical data and functions from unauthorized or malicious access, as well as to limit the damage or impact of a breach or compromise. Compartmentalization also helps to enforce the principle of least privilege, which grants users or processes only the minimum access rights they need to perform their tasks. Therefore, compartmentalization is the correct answer.
Reference:
https://www.csoonline.com/article/3667476/defense-in-depth-explained-layering-tools-and-processes-for-better-security.html
https://www.fortinet.com/resources/cyberglossary/defense-in-depth
https://sciencepublishinggroup.com/journal/paperinfo?journalid=542&doi=10.11648/j.ajai.20190302.11
NEW QUESTION # 201
這違反了禁止在辦公室使用攝像頭的政策,向員工發放了配備網絡攝像頭的智能手機和平板電腦。以下哪一項應該是信息安全經理的首要行動方案?
- A. 傳達可接受的使用政策。
- B. 修改政策。
- C. 進行風險評估,
- D. 執行根本原因分析。
Answer: C
NEW QUESTION # 202
一家医院的关键服务器已被勒索软件加密。如果没有此服务器,医院将无法有效运作 以下哪项最有效地让医院避免支付赎金?
- A. 关于勒索软件的员工培训
- B. 经过适当测试的离线备份系统
- C. 正确配置的防火墙
- D. 持续的服务器复制过程
Answer: B
Explanation:
The most effective way to avoid paying the ransom in a ransomware attack is to have a properly tested offline backup system. A ransomware attack is a type of cyberattack that encrypts the victim's data or systems and demands a payment for the decryption key. A properly tested offline backup system is a method of storing copies of the data or systems in a separate location that is not connected to the network or the internet. By having a properly tested offline backup system, the hospital can restore its critical server from the backup without paying the ransom or losing any data. The other options are not the most effective way to avoid paying the ransom in a ransomware attack, although they may be some preventive or detective measures. Employee training on ransomware is a preventive measure that can help raise awareness and reduce the likelihood of falling victim to phishing or other social engineering techniques that may deliver ransomware. However, it does not guarantee that employees will always follow best practices or that ransomware will not enter the network through other means. A continual server replication process is a method of creating copies of the server data or systems in real time or near real time. However, it may not be effective against ransomware, as the replication process may also copy the encrypted data or systems, making them unusable. A properly configured firewall is a preventive measure that can help block malicious network traffic and prevent unauthorized access to the server. However, it does not guarantee that ransomware will not bypass the firewall through other channels, such as email attachments or removable media.
NEW QUESTION # 203
對最近發生的安全事件的調查確定,根本原因是系統准入管理員為解決此問題而疏忽處理事件警報?
- A. 向數據所有者提供事件響應培訓。
- B. 進行風險評估並與高級管理層分享結果。
- C. 修改事件響應計劃-以與業務流程保持一致。
- D. 為數據保管人提供事件響應培訓。
Answer: D
Explanation:
The best action for the system admin manager to address the issue of negligent handling of incident alerts by system admins is to provide incident response training to data custodians because it helps to improve their awareness and skills in recognizing and reporting security incidents, and following the incident response procedures and protocols. Conducting a risk assessment and sharing the result with senior management is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Revising the incident response plan to align with business processes is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Providing incident response training to data owners is not a good action because data owners are not responsible for handling incident alerts or performing incident response tasks. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 204
渗透测试最适合以下情况:
- A. 发生安全事件,
- B. 新系统即将上线。
- C. 正在设计新系统。
- D. 正在制定安全政策。
Answer: B
NEW QUESTION # 205
信息安全團隊正在計劃對現有供應商進行安全評估。以下哪種方法對於正確確定評估範圍最有幫助?
- A. 確定供應商是否遵循所選的安全框架規則
- B. 審查供應商的安全策略
- C. 審查供應商合同中列出的控制措施
- D. 重點審查風險最高的基礎設施
Answer: C
Explanation:
Reviewing controls listed in the vendor contract is the most helpful approach for properly scoping the security assessment of an existing vendor because it helps to determine the security requirements and expectations that the vendor has agreed to meet. A vendor contract is a legal document that defines the terms and conditions of the business relationship between the organization and the vendor, including the scope, deliverables, responsibilities, and obligations of both parties. A vendor contract should also specify the security controls that the vendor must implement and maintain to protect the organization's data and systems, such as encryption, authentication, access control, backup, monitoring, auditing, etc. Reviewing controls listed in the vendor contract helps to ensure that the security assessment covers all the relevant aspects of the vendor's security posture, as well as to identify any gaps or discrepancies between the contract and the actual practices. Therefore, reviewing controls listed in the vendor contract is the correct answer.
Reference:
https://medstack.co/blog/vendor-security-assessments-understanding-the-basics/
https://www.ncsc.gov.uk/files/NCSC-Vendor-Security-Assessment.pdf
https://securityscorecard.com/blog/how-to-conduct-vendor-security-assessment
NEW QUESTION # 206
......
CISM-CN Real Valid Brain Dumps With 417 Questions: https://prep4sure.dumpsfree.com/CISM-CN-valid-exam.html