
Latest CISM-CN Actual Free Exam Questions Updated 672 Questions
Free CISM-CN Exam Braindumps certification guide Q&A
NEW QUESTION # 132
下列哪一項應該是資訊安全計畫的主要結果?
- A. 風險消除
- B. 減少威脅
- C. 降低成本
- D. 策略調整
Answer: D
Explanation:
Explanation
According to the CISM Review Manual (Digital Version), Chapter 3, Section 3.2.1, strategic alignment is the primary outcome of an information security program1. Strategic alignment means that the information security program supports and is tailored to the organization's objectives and business strategy1. It also means that the information security program is aligned with other assurance functions, such as physical, human resources, quality, and IT1.
The CISM Review Manual (Digital Version) also states that strategic alignment is essential for achieving a competitive advantage, enhancing customer trust, reducing legal and regulatory risks, and improving organizational performance1. Strategic alignment requires effective communication and collaboration among all stakeholders, including senior management, information owners, information security managers, information security steering committees, and external partners1.
The CISM Exam Content Outline also covers the topic of strategic alignment in Domain 3 - Information Security Program Development and Management (33% exam weight)2. The subtopics include:
3.2.1 Information Security Strategy
3.2.2 Information Security Governance
3.2.3 Information Security Risk Management
3.2.4 Information Security Compliance
I hope this answer helps you prepare for your CISM exam. Good luck!
NEW QUESTION # 133
某組織使用的雲應用程序被發現存在嚴重漏洞。評估風險後,以下哪一項是信息安全經理的最佳行動方案?
- A. 向應用程序的業務所有者報告情況。
- B. 啟動組織的事件響應流程。
- C. 暫停與防火牆中應用程序的連接
- D. 指示供應商進行滲透測試。
Answer: A
NEW QUESTION # 134
在網路監控中引入單點管理的主要好處是:
- A. 防止分散式環境中資訊不一致。
- B. 減少對系統的未經授權的存取。
- C. 提高環境控制效率。
- D. 允許管理人員做出管理決策。
Answer: D
NEW QUESTION # 135
影響管理層對信息安全支持的最重要信息是:
- A. 組織風險的識別。
- B. 與業務戰略保持一致的證明。
- C. 總體威脅態勢的識別。
- D. 成功攻擊競爭對手的報告。
Answer: B
Explanation:
The most important information for influencing management's support of information security is an demonstration of alignment with the business strategy because it shows how information security contributes to the achievement of the organization's goals and objectives, and adds value to the organization's performance and competitiveness. An identification of the overall threat landscape is not very important because it does not indicate how information security addresses or mitigates the threats or risks. A report of a successful attack on a competitor is not very important because it does not indicate how information security prevents or responds to such attacks. An identification of organizational risks is not very important because it does not indicate how information security manages or reduces the risks. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/how-to-align-security-initiatives-with-business-goals-and-objectives
NEW QUESTION # 136
事件響應團隊已確定應用程序已被破壞。接下來應該執行以下哪項操作?
- A. 將受影響的系統維持在取證可接受的狀態
- B. 對受影響的應用程序進行風險評估
- C. 將受影響的系統與網絡的其餘部分隔離
- D. 將違規情況通知高級管理層。
Answer: C
Explanation:
The next thing an incident response team should do after establishing that an application has been breached is to isolate the impacted systems from the rest of the network, which means disconnecting them from the internet or other network connections to prevent further spread of the attack or data exfiltration. Isolating the impacted systems can help to contain the breach and limit its impact on the organization. The other options, such as maintaining the affected systems in a forensically acceptable state, conducting a risk assessment, or informing senior management, may be done later in the incident response process, after isolating the impacted systems. Reference:
https://www.crowdstrike.com/cybersecurity-101/incident-response/
https://learn.microsoft.com/en-us/security/operations/incident-response-playbooks
https://www.invicti.com/blog/web-security/incident-response-steps-web-application-security/
NEW QUESTION # 137
下列哪一項最能幫助及時執行事件回應計畫?
- A. 觸發事件定義
- B. 集中服務台
- C. 決策支援工具的引入
- D. 明確定義的資料分類過程
Answer: A
Explanation:
Explanation
Definition of trigger events is the best way to enable the timely execution of an incident response plan because it helps to specify the conditions or criteria that initiate the incident response process. Trigger events are predefined scenarios or indicators that signal the occurrence or potential occurrence of a security incident, such as a ransomware attack, a data breach, a denial-of-service attack, or an unauthorized access attempt.
Definition of trigger events helps to ensure that the incident response team is alerted and activated as soon as possible, as well as to determine the appropriate level and scope of response based on the severity and impact of the incident. Therefore, definition of trigger events is the correct answer.
References:
* https://www.atlassian.com/incident-management/kpis/common-metrics
* https://www.varonis.com/blog/incident-response-plan/
* https://holierthantao.com/2023/05/03/minimizing-disruptions-a-comprehensive-guide-to-incident-response
NEW QUESTION # 138
组织正在收购一家新公司 以下哪一项是确定如何在集成之前保护新收购的数据资产的最佳方法?
- A. 审查数据架构。
- B. 在合同中包含安全要求
- C. 评估安全控制。
- D. 执行风险评估
Answer: D
Explanation:
The best approach to determine how to protect newly acquired data assets prior to integration is to perform a risk assessment. A risk assessment will identify the various threats and vulnerabilities associated with the data assets and help the organization develop an appropriate security strategy. This risk assessment should include an assessment of the security controls in place to protect the data, a review of the data architecture, and a review of any contractual requirements related to security.
NEW QUESTION # 139
識別與社會工程攻擊相關的風險的最佳方法是:
- A. 監控入侵偵測系統(IDS),
- B. 對電子郵件過濾系統進行業務風險評估。
- C. 檢查單一登入 (SSO) 驗證延遲。
- D. 測試使用者對資訊安全實務的了解。
Answer: D
NEW QUESTION # 140
下列何者最能實現風險和控制所有權的分配?
- A. 採用風險管理框架
- B. 制定資訊安全策略
- C. 與業界認可的控制框架保持一致
- D. 獲得高階管理層的支持
Answer: D
Explanation:
Explanation
Obtaining senior management buy-in is the best way to enable the assignment of risk and control ownership because it helps to establish the authority and accountability of the risk and control owners, as well as to provide them with the necessary resources and support to perform their roles. Risk and control ownership refers to the assignment of specific responsibilities and accountabilities for managing risks and controls to individuals or groups within the organization. Obtaining senior management buy-in helps to ensure that risk and control ownership is aligned with the organizational objectives, structure, and culture, as well as to communicate the expectations and benefits of risk and control ownership to all stakeholders. Therefore, obtaining senior management buy-in is the correct answer.
References:
* https://www.protechtgroup.com/en-au/blog/risk-control-management
* https://www.mckinsey.com/~/media/mckinsey/dotcom/client_service/risk/working%20papers/23_getting_
* https://www.linkedin.com/pulse/risk-controls-who-owns-them-david-tattam
NEW QUESTION # 141
下列哪一項是組織選擇關鍵風險指標 (KRI) 時最重要的因素?
- A. 訊息的重要性
- B. 投資報酬率(ROI)
- C. 合規要求
- D. 目標受眾
Answer: A
Explanation:
Explanation
A key risk indicator (KRI) is a metric that provides an early warning of potential exposure to a risk. A KRI should be relevant, measurable, timely, and actionable. The most important factor in an organization's selection of a KRI is the criticality of information, which means that the KRI should reflect the value and sensitivity of the information assets that are exposed to the risk. For example, a KRI for data breach risk could be the number of unauthorized access attempts to a database that contains confidential customer data. The criticality of information helps to prioritize the risks and focus on the most significant ones. References:
https://www.isaca.org/credentialing/cism
https://www.wiley.com/en-us/CISM+Certified+Information+Security+Manager+Study+Guide-p-978111980194
NEW QUESTION # 142
從成功的惡意軟體攻擊中恢復後,惡意軟體的實例會繼續被發現。哪個階段的事件回應不成功?
- A. 事件聲明
- B. 根除
B恢復 - C. 經驗教訓回顧
Answer: B
Explanation:
Explanation
Eradication is the phase of incident response where the incident team removes the threat from the affected systems and restores them to a secure state. If this phase is not successful, the malware may persist or reappear on the systems, causing further damage or compromise. Therefore, eradication is the correct answer.
References:
* https://www.securitymetrics.com/blog/6-phases-incident-response-plan
* https://www.atlassian.com/incident-management/incident-response
* https://eccouncil.org/cybersecurity-exchange/incident-handling/what-is-incident-response-life-cycle/
NEW QUESTION # 143
資訊安全經理了解到 IT 人員沒有遵守資訊安全策略,因為這會導致流程效率低落。資訊安全經理首先該做什麼?
- A. 要求內部稽核對政策制定流程進行審查,
- B. 確定與不遵守政策相關的風險。
- C. 建議 IT 更新資訊安全策略和程序。
- D. 在 IT 職能部門內進行使用者意識培訓。
Answer: B
Explanation:
Explanation
The information security manager should first determine the risk related to noncompliance with the policy, as this will help to understand the impact and likelihood of the policy violation and the potential consequences for the organization. The information security manager can then use the risk assessment results to communicate the importance of the policy to the IT personnel, propose any necessary changes to the policy or the processes, or request an audit of the policy development process, depending on the situation. Conducting user awareness training, updating policies and procedures, or requesting an audit are possible actions that the information security manager can take after determining the risk, but they are not the first step. References = CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Assessment, page 86; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 59, page 60.
NEW QUESTION # 144
实现对信息安全治理计划的执行承诺的最重要因素是:
- A. 已建立的安全策略。
- B. 确定的业务驱动因素。
- C. 过程改进模型
- D. 定义的安全框架。
Answer: B
Explanation:
The most important element in achieving executive commitment to an information security governance program is to align the program with the identified business drivers of the organization. Business drivers are the factors that influence the strategic objectives, goals, and priorities of the organization. They reflect the needs and expectations of the stakeholders, customers, regulators, and other parties that are relevant to the organization's mission and vision. By aligning the information security governance program with the business drivers, the executive can demonstrate the value and benefits of information security to the organization's performance, reputation, and competitiveness. The other options are not the most important element, although they may be part of an information security governance program. A defined security framework is a set of standards, guidelines, and best practices that provide a structure and direction for implementing information security. A process improvement model is a methodology that helps to identify, analyze, and improve the processes related to information security. Established security strategies are the plans and actions that define how information security supports and enables the business objectives and goals. These elements are important for developing and executing an information security governance program, but they do not necessarily ensure executive commitment unless they are aligned with the business drivers
NEW QUESTION # 145
以下哪一項是向董事會提交有關信息安全計劃狀況的季度報告的最有效方法?
- A. 信息安全儀表板
- B. 安全計劃KPI詳細分析
- C. 信息安全風險登記冊
- D. 能力和成熟度評估
Answer: A
Explanation:
An information security dashboard is an effective way to present quarterly reports to the board on the status of the information security program. It allows the board to quickly view key metrics and trends at a glance and to drill down into more detailed information as needed. The dashboard should include metrics such as total incidents, patching compliance, vulnerability scanning results, and more. It should also include high-level overviews of the security program and its components, such as the security policy, security architecture, and security controls.
NEW QUESTION # 146
一家組織計劃向客戶提供一項受法規約束的新服務。在製定支持這項新服務的安全策略時,組織首先應該做什麼?
- A. 建立合規計劃,
- B. 確定新服務的安全控制。
- C. 針對目前狀態執行差距分析
- D. 僱用新資源來支援服務。
Answer: C
Explanation:
Explanation
A gap analysis is a process of comparing the current state of an organization's security posture with the desired or required state, and identifying the gaps or discrepancies that need to be addressed. A gap analysis helps to determine the current level of compliance with relevant regulations, standards, and best practices, and to prioritize the actions and resources needed to achieve the desired level of compliance1. A gap analysis should be performed first when developing a security strategy in support of a new service that is subject to regulations, because it provides the following benefits2:
It helps to understand the scope and impact of the new service on the organization's security objectives, risks, and controls.
It helps to identify the legal, regulatory, and contractual requirements that apply to the new service, and the potential penalties or consequences of non-compliance.
It helps to assess the effectiveness and efficiency of the existing security controls, and to identify the gaps or weaknesses that need to be remediated or enhanced.
It helps to align the security strategy with the business goals and objectives of the new service, and to ensure the security strategy is consistent and coherent across the organization.
It helps to communicate the security requirements and expectations to the stakeholders involved in the new service, and to obtain their support and commitment.
The other options, such as determining security controls for the new service, establishing a compliance program, or hiring new resources to support the service, are not the first steps when developing a security strategy in support of a new service that is subject to regulations, because they depend on the results and recommendations of the gap analysis. Determining security controls for the new service requires a clear understanding of the security requirements and risks associated with the new service, which can be obtained from the gap analysis. Establishing a compliance program requires a systematic and structured approach to implement, monitor, and improve the security controls and processes that ensure compliance, which can be based on the gap analysis. Hiring new resources to support the service requires a realistic and justified estimation of the human and financial resources needed to achieve the security objectives and compliance, which can be derived from the gap analysis. References = 1: What is a Gap Analysis? | Smartsheet 2: CISM Review Manual 15th Edition, page 121 : CISM Review Manual 15th Edition, page 122 : CISM Review Manual 15th Edition, page 123 : CISM Review Manual 15th Edition, page 124 : CISM Review Manual 15th Edition, page 125 Learn more:
1. infosectrain.com2. resources.infosecinstitute.com3. resources.infosecinstitute.com4.
resources.infosecinstitute.com+2 more
NEW QUESTION # 147
当出于分析目的授予供应商远程访问机密信息时,以下哪项是最重要的安全考虑因素?
- A. 数据在传输过程中加密,并在供应商站点处于静止状态。
- B. 数据受定期访问日志审查。
- C. 供应商必须同意组织的信息安全政策,
- D. 供应商必须能够修改数据。
Answer: C
NEW QUESTION # 148
下列哪一項應該是製定資訊安全策略的第一步?
- A. 確定關鍵利害關係人以維護資訊安全
- B. 根據當前狀態進行差距分析
- C. 建立路線圖來確定安全基線和控制措施
- D. 確定可接受的資訊安全風險級別
Answer: A
Explanation:
Explanation
The first step in developing an information security strategy is to identify key stakeholders who can provide support, guidance and resources for information security initiatives. These stakeholders may include senior management, business unit leaders, legal counsel, audit and compliance officers and other relevant parties. By engaging these stakeholders early on, an information security manager can ensure that the strategy aligns with business objectives and expectations, as well as gain buy-in and commitment from them. Determining acceptable levels of risk, creating a roadmap and performing a gap analysis are all important steps in developing an information security strategy, but they should follow after identifying key stakeholders.
NEW QUESTION # 149
供應鏈攻擊最有可能出現以下哪種風險場景?
- A. 供應商提供的硬件和軟件資源不可靠
- B. 由於產品缺貨而失去客戶
- C. 通過第三方資源損害關鍵資產
- D. 供應商無法提供服務
Answer: B
NEW QUESTION # 150
以下哪一项是信息安全经理使安全和业务目标保持一致的最佳行动方案?
- A. 定义关键绩效指标 (KPI)
- B. 进行业务影响分析 (BIA)
- C. 积极与利益相关者接触
- D. 审查业务战略
Answer: C
NEW QUESTION # 151
在製定資訊安全策略的背景下,以下哪一項提供了最有用的輸入來確定或
- A. 風險登記冊
- B. 法律法規
- C. 風險評分
- D. 安全預算
Answer: B
Explanation:
Explanation
Laws and regulations provide the most useful input to determine the organization's information security strategy because they define the legal and compliance requirements and obligations that the organization must adhere to, and guide the development and implementation of the security policies and controls that support them. Security budget is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security needs or goals, but rather a resource to enable the security activities and initiatives. Risk register is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security vision or mission, but rather a tool to identify and manage the security risks. Risk score is not a useful input to determine the organization's information security strategy because it does not reflect the organization's security priorities or objectives, but rather a measure of the level of risk exposure or performance. References:
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/how-to-align-security-initiatives-with-busin
NEW QUESTION # 152
以下哪項需要恢復點目標 (RPO)?
- A. 災難恢復計劃 (DRP)
- B. 業務連續性計劃 (BCP)
- C. 事件響應計劃
- D. 信息安全計劃
Answer: A
NEW QUESTION # 153
以下哪一項是在業務影響分析 (BIA) 流程中進行訪談的最重要原因?
- A. 促進 BIA 後的定性風險評估
- B. 提高主要利益相關者的信息安全意識
- C. 確保提供意見的利益相關者承擔相關風險
- D. 獲取盡可能多的相關利益相關者的意見
Answer: C
NEW QUESTION # 154
在选择第三方取证提供商时,信息安全经理需要验证以下哪项最重要?
- A. 审计权条款的存在
- B. 提供商的事件响应计划的存在
- C. 提供商业务连续性测试的结果
- D. 提供商的技术能力
Answer: D
NEW QUESTION # 155
在網路監控中引入單點管理的主要好處是:
- A. 防止分散式環境中資訊不一致。
- B. 允許管理人員做出管理決策。
- C. 提高環境控制效率。
- D. 減少對系統的未經授權的存取。
Answer: C
Explanation:
Explanation
A single point of administration in network monitoring is a centralized system that allows network administrators to manage and monitor the entire network from one location. A single point of administration can provide several benefits, such as:
Promoting efficiency in control of the environment: A single point of administration can simplify and streamline the network management tasks, such as configuration, troubleshooting, performance optimization, security updates, backup and recovery, etc. It can also reduce the time and cost of network maintenance and administration, as well as improve the consistency and quality of network services.
Reducing unauthorized access to systems: A single point of administration can enhance the network security by implementing centralized authentication, authorization and auditing mechanisms. It can also enforce consistent security policies and standards across the network, and detect and respond to any unauthorized or malicious activities.
Preventing inconsistencies in information in the distributed environment: A single point of administration can ensure the data integrity and availability by synchronizing and replicating the data across the network nodes. It can also provide a unified view of the network status and performance, and facilitate the analysis and reporting of network data.
Allowing administrative staff to make management decisions: A single point of administration can support the decision-making process by providing relevant and timely information and feedback to the network administrators. It can also enable the administrators to implement changes and improvements to the network based on the business needs and objectives.
Therefore, the primary benefit of introducing a single point of administration in network monitoring is that it promotes efficiency in control of the environment, as it simplifies and streamlines the network management tasks and improves the network performance and quality. References = CISM Review Manual, 16th Edition eBook | Digital | English1, Chapter 4: Information Security Program Development and Management, Section
4.3: Information Security Program Resources, Subsection 4.3.1: Information Security Infrastructure and Architecture, Page 205.
NEW QUESTION # 156
......
CISM-CN Certification Overview Latest CISM-CN PDF Dumps: https://www.examboosts.com/ISACA/CISM-CN-practice-exam-dumps.html