[Feb 23, 2024] CISM-CN Dumps PDF and Test Engine Exam Questions - ActualVCE [Q131-Q152]

Share

[Feb 23, 2024] CISM-CN Dumps PDF and Test Engine Exam Questions - ActualVCE

Verified CISM-CN exam dumps Q&As with Correct 672 Questions and Answers

NEW QUESTION # 131
在進行全功能連續性測試之前,資安經理需要驗證下列哪一項最重要?

  • A. 事件回應和復原計畫以簡單的語言記錄
  • B. 復原和事件回應計畫的副本保存在異地
  • C. 已確定負責復原的團隊和個人
  • D. 企業接受的風險已記錄在案

Answer: C

Explanation:
Explanation
Before conducting full-functional continuity testing, an information security manager should verify that teams and individuals responsible for recovery have been identified and trained on their roles and responsibilities.
This will ensure that the testing can be executed effectively and efficiently, as well as identify any gaps or issues in the recovery process. Risk acceptance by the business, copies of plans kept offsite and plans documented in simple language are all good practices for continuity management, but they are not as important as having clear roles and responsibilities defined before testing.


NEW QUESTION # 132
一个组织计划利用流行的社交网络平台来推广其产品和服务。以下哪项是信息安全经理支持此计划的最佳行动方案?

  • A. 为社交网络的使用制定安全控制措施。
  • B. 评估与使用社交网络相关的安全风险。
  • C. 建立在社交网络上发布内容的流程。
  • D. 对社交网络平台进行漏洞评估。

Answer: B

Explanation:
The best course of action for the information security manager to support the initiative of leveraging popular social network platforms to promote the organization's products and services is to assess the security risk associated with the use of social networks. Security risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a security risk assessment, the information security manager can provide valuable input to the decision-making process regarding the benefits and costs of using social networks, as well as the appropriate security controls and mitigation strategies to reduce the risk to an acceptable level. The other options are not the best course of action, although they may be part of the security risk management process. Establishing processes to publish content on social networks is an operational task that should be performed after assessing the security risk and implementing the necessary controls. Conducting vulnerability assessments on social network platforms is a technical activity that may not be feasible or effective, as the organization does not have control over the platforms' infrastructure and configuration. Developing security controls for the use of social networks is a preventive measure that should be based on the results of the security risk assessment and aligned with the organization's risk appetite and tolerance


NEW QUESTION # 133
員工點擊釣魚郵件中的鏈接,引發勒索軟體攻擊 下列哪一項應該屬於資訊安全?

  • A. 通知高階管理層。
  • B. 通知內部法律顧問。
  • C. 隔離受影響的端點。
  • D. 擦除受影響的系統。

Answer: C

Explanation:
Explanation
Isolating the impacted endpoints is the best course of action for the information security manager after an employee clicked on a link in a phishing email, triggering a ransomware attack because it prevents the ransomware from spreading to other systems or devices on the network, and minimizes the damage or disruption caused by the attack. Wiping the affected system is not a good course of action because it may destroy any evidence or data that could be used for investigation or recovery. Notifying internal legal counsel is not a good course of action because it does not address the immediate threat or impact of the ransomware attack. Notifying senior management is not a good course of action because it does not address the immediate threat or impact of the ransomware attack. References:
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned
https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned


NEW QUESTION # 134
以下哪一项最好地确保信息安全治理与公司治理保持一致?

  • A. 包括 IT 代表在内的安全指导委员会
  • B. 将安全报告整合到公司报告中
  • C. 一致的风险管理方法
  • D. 信息安全风险登记册

Answer: B


NEW QUESTION # 135
在定義如何分配資訊安全預算時,下列何者最重要?

  • A. 監理合規標準
  • B. 資訊安全策略
  • C. 資訊安全政策
  • D. 業務影響評估

Answer: B

Explanation:
Explanation
Information security strategy is the most important factor when defining how an information security budget should be allocated because it helps to align the security objectives and initiatives with the business goals and priorities. An information security strategy is a high-level plan that defines the vision, mission, scope, and direction of the security program, as well as the roles and responsibilities, governance structures, policies and standards, risk management approaches, and performance measurement methods. An information security strategy helps to identify and prioritize the security needs and requirements of the organization, as well as to allocate the resources and funding accordingly. An information security strategy also helps to communicate the value and benefits of security to the stakeholders and justify the security investments. Therefore, information security strategy is the correct answer.
References:
* https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-breakdown-and-best-practices
* https://www.csoonline.com/article/3671108/how-2023-cybersecurity-budget-allocations-are-shaping-up.ht
* https://www.statista.com/statistics/1319677/companies-it-budget-allocated-to-security-worldwide/


NEW QUESTION # 136
在得知某些安全強化設定可能會對未來的業務活動產生負面影響後,資安經理應先執行下列哪項操作?

  • A. 執行風險評估。
  • B. 減少安全強化設定。
  • C. 記錄安全異常。
  • D. 向業務管理階層通報風險。

Answer: A

Explanation:
Explanation
Security hardening is the process of applying security configuration settings to systems and software to reduce their attack surface and improve their resistance to threats1. Security hardening settings are based on industry standards and best practices, such as the CIS Benchmarks2, which provide recommended security configurations for various software applications, operating systems, and network devices. However, security hardening settings may not always be compatible with the business requirements and objectives of an organization, and may negatively impact the functionality, performance, or usability of the systems and software3. Therefore, before applying any security hardening settings, an information security manager should perform a risk assessment to evaluate the potential benefits and drawbacks of the settings, and to identify and prioritize the risks associated with them. A risk assessment is a systematic process of identifying, analyzing, and evaluating the risks that an organization faces, and determining the appropriate risk responses. A risk assessment helps the information security manager to balance the security and business needs of the organization, and to communicate the risk level and impact to the relevant stakeholders. A risk assessment should be performed first, before taking any other actions, such as reducing security hardening settings, informing business management of the risk, or documenting a security exception, because it provides the necessary information and justification for making informed and rational decisions. References = 1: Basics of the CIS Hardening Guidelines | RSI Security 2: CIS Baseline Hardening and Security Configuration Guide | CalCom 3: CISM Review Manual 15th Edition, page 121 : CISM Review Manual 15th Edition, page 122 :
CISM Review Manual 15th Edition, page 145 : CISM Review Manual 15th Edition, page 146 : CISM Review Manual 15th Edition, page 147


NEW QUESTION # 137
及時宣布災難的主要目標是:

  • A. 確保業務管理階層參與恢復過程。
  • B. 評估並修正災難復原流程的缺陷。
  • C. 保護重要的實體資產免於進一步損失。
  • D. 確保組織基本服務的連續性。

Answer: D

Explanation:
Explanation
The primary objective of timely declaration of a disaster is to ensure the continuity of the organization's essential services, which are the services that are critical for the survival and operation of the organization, and that cannot be interrupted or delayed without causing severe consequences. By declaring a disaster, the organization can activate its disaster recovery plan (DRP), which is a set of documented procedures and resources to recover the essential services in the event of a disaster. The DRP should include the roles and responsibilities, the communication channels, the recovery strategies, the backup and restoration procedures, and the testing and maintenance activities for the disaster recovery process1.
References = CISM Review Manual, 16th Edition eBook2, Chapter 9: Business Continuity and Disaster Recovery, Section: Disaster Recovery Planning, Subsection: Disaster Declaration, Page 372.


NEW QUESTION # 138
高階管理層表示擔心組織的入侵防禦系統 (IPS) 可能會反覆擾亂業務運營 下列哪一項最能表明資訊安全經理已調整系統以解決此問題?

  • A. 減少漏報
  • B. 漏報率增加
  • C. 減少誤報
  • D. 誤報增加

Answer: C

Explanation:
Explanation
Decreasing false positives is the best indicator that the information security manager has tuned the system to address senior management's concern that the organization's intrusion prevention system (IPS) may repeatedly disrupt business operations. False positives are alerts generated by the IPS when it mistakenly blocks legitimate traffic or activity, causing disruption or downtime. Decreasing false positives means that the IPS has been configured to reduce such errors and minimize unnecessary interruptions. Increasing false negatives is not a good indicator because it means that the IPS has failed to detect or block malicious traffic or activity, increasing the risk of compromise or damage. Decreasing false negatives is not a good indicator because it does not affect business operations, but rather improves security detection or prevention. Increasing false positives is not a good indicator because it means that the IPS has increased its errors and interruptions, worsening senior management's concern. References:
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-6/the-value-of-penetration-testing
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing


NEW QUESTION # 139
创建事件响应计划时,以下哪项最重要?

  • A. 与风险评估过程保持一致
  • B. 识别事件的构成
  • C. 识别易受攻击的数据资产
  • D. 记录事件通知和升级流程

Answer: B


NEW QUESTION # 140
一個組織正在實施資訊安全治理框架。為了向利害關係人傳達該計劃的有效性,最重要的是建立:

  • A. 安全性策略的監控進程。
  • B. 每個里程碑的指標。
  • C. 控制自我評估 (CSA) 過程。
  • D. 向利害關係人自動報告。

Answer: B

Explanation:
Explanation
= Establishing metrics for each milestone is the best way to communicate the program's effectiveness to stakeholders, as it provides a clear and measurable way to track the progress, performance, and outcomes of the information security governance framework. Metrics are quantifiable indicators that can be used to evaluate the achievement of specific objectives, goals, or standards. Metrics can also help to demonstrate the value, benefits, and return on investment of the information security program, as well as to identify and address the gaps, issues, or risks. Metrics for each milestone should be aligned with the organization's strategy, vision, and mission, as well as with the expectations and needs of the stakeholders. Metrics for each milestone should also be SMART (specific, measurable, achievable, relevant, and time-bound), as well as consistent, reliable, and transparent.
The other options are not as important as establishing metrics for each milestone, as they do not provide a comprehensive and holistic way to communicate the program's effectiveness to stakeholders. A control self-assessment (CSA) process is a technique to involve the staff in assessing the design, implementation, and effectiveness of the information security controls. It can help to increase the awareness, ownership, and accountability of the staff, as well as to identify and mitigate the risks. However, a CSA process alone is not enough to communicate the program's effectiveness to stakeholders, as it does not measure the overall performance or maturity of the information security program. Automated reporting to stakeholders is a method to provide timely, accurate, and consistent information to the stakeholders about the status, results, and issues of the information security program. It can help to facilitate the communication, collaboration, and decision making among the stakeholders, as well as to ensure the compliance and transparency of the information security program. However, automated reporting alone is not enough to communicate the program's effectiveness to stakeholders, as it does not evaluate the achievement or impact of the information security program. A monitoring process for the security policy is a process to ensure that the security policy is implemented, enforced, and reviewed in accordance with the organization's objectives, standards, and regulations. It can help to maintain the relevance, adequacy, and effectiveness of the security policy, as well as to incorporate the feedback, changes, and improvements. However, a monitoring process alone is not enough to communicate the program's effectiveness to stakeholders, as it does not cover the other aspects of the information security program, such as governance, risk management, incident management, or business continuity. References = CISM Review Manual, 16th Edition, ISACA, 2022, pp. 211-212, 215-216, 233-234, 237-238.
CISM Questions, Answers & Explanations Database, ISACA, 2022, QID 1018.
CISM domain 1: Information security governance [Updated 2022], Infosec, 1.
Key Performance Indicators for Security Governance, Part 1, ISACA Journal, Volume 6, 2020, 2.


NEW QUESTION # 141
信息安全經理在選擇第三方取證提供商時需要驗證以下哪一項最重要?

  • A. 存在審計權條款
  • B. 提供商業務連續性測試的結果
  • C. 提供商的技術能力
  • D. 提供商的事件響應計劃的存在

Answer: C


NEW QUESTION # 142
云服务购买者在哪种云模型中承担最多的安全责任?

  • A. 基础架构即服务 (laaS)
  • B. 灾难恢复即服务 (DRaaS)
  • C. 软件即服务 (SaaS)
  • D. 平台即服务 (PaaS)

Answer: A


NEW QUESTION # 143
在調查資訊安全事件時,應分享事件的詳細資訊:

  • A. 廣泛地表現出正面的意圖。
  • B. 僅進行內部審核。
  • C. 僅根據需要,
  • D. 僅限管理。

Answer: C

Explanation:
Explanation
When investigating an information security incident, details of the incident should be shared only as needed, according to the principle of least privilege and the need-to-know basis. This means that only the authorized and relevant parties who have a legitimate purpose and role in the incident response process should have access to the incident information, and only to the extent that is necessary for them to perform their duties.
Sharing incident details only as needed helps to protect the confidentiality, integrity, and availability of the incident information, as well as the privacy and reputation of the affected individuals and the organization.
Sharing incident details only as needed also helps to prevent unauthorized disclosure, modification, deletion, or misuse of the incident information, which could compromise the investigation, evidence, remediation, or legal actions.
References = CISM Review Manual, 16th Edition, Chapter 4: Information Security Incident Management, Section: Incident Response Process, page 2311; CISM Review Questions, Answers & Explanations Manual,
10th Edition, Question 49, page 462.


NEW QUESTION # 144
下列哪一項是資訊資產分類的最大好處?

  • A. 定義資源所有權
  • B. 協助確定復原點目標 (RPO)
  • C. 支援職責分離
  • D. 為實施需要了解的政策提供基礎

Answer: D

Explanation:
Explanation
The greatest benefit of information asset classification is providing a basis for imple-menting a need-to-know policy. Information asset classification is a process of catego-rizing information based on its level of sensitivity and importance, and applying appro-priate security controls based on the level of risk associated with that information1. A need-to-know policy is a principle that states that access to information should be granted only to those individuals who require it to perform their official duties or tasks2. The purpose of a need-to-know policy is to limit the exposure of sensitive information to unauthorized or unnecessary parties, and to reduce the risk of data breaches, leaks, or misuse. Information asset classification provides a basis for implementing a need-to-know policy by:
*Defining the value and protection requirements of different types of information
*Labeling the information with the appropriate classification level, such as public, internal, confidential, secret, or top secret
*Establishing the roles and responsibilities of information owners, custodians, and users
*Enforcing access controls and encryption for the information
*Documenting the security policies and procedures for the information
By providing a basis for implementing a need-to-know policy, information asset classi-fication can help organizations to protect their sensitive information, comply with rele-vant laws and regulations, and achieve their business objectives. The other options are not the greatest benefits of information asset classification.
Helping to determine the recovery point objective (RPO) is not a benefit, but rather a consequence of applying security controls based on the classification level. RPO is the acceptable amount of data loss in case of a disruption3. Supporting segregation of duties is not a benefit, but rather a prerequisite for implementing a need-to-know policy. Segregation of duties is a principle that states that no single individual should have control over two or more phases of a business process or transaction that are susceptible to errors or fraud4.
De-fining resource ownership is not a benefit, but rather a component of information asset classification.
Resource ownership is the assignment of accountability and authority for an information asset to an individual or a group5. References: 1: Information Classifi-cation - Advisera 2: Need-to-Know Principle - NIST 3:
Recovery Point Objective - NIST 4: Segregation of Duties - NIST 5: Resource Ownership - NIST :
Information Classification in Information Security - GeeksforGeeks : Information Asset Classification Policy - UCI


NEW QUESTION # 145
以下哪一項應該是信息安全事件分類的嚴重性層次結構的主要基礎?

  • A. 根本原因分析結果
  • B. 資源的可用性
  • C. 對業務的不利影響
  • D. 法律和監管要求

Answer: C

Explanation:
The severity hierarchy for information security incident classification should be based on the potential or actual impact of the incident on the business objectives, operations, reputation, and stakeholders. The adverse effects on the business can be measured by criteria such as financial loss, operational disruption, legal liability, regulatory compliance, customer satisfaction, and public confidence. The other options are not the primary basis for a severity hierarchy, although they may be considered as secondary factors or consequences of an incident


NEW QUESTION # 146
以下哪一項最適合用來確定信息安全計劃的成熟度?

  • A. 風險評估結果
  • B. 組織風險偏好
  • C. 安全預算分配
  • D. 安全指標

Answer: D

Explanation:
Security metrics are the best way to determine the maturity of an information security program because they are quantifiable indicators of the performance and effectiveness of the security controls and processes. Security metrics help to evaluate the current state of security, identify gaps and weaknesses, measure progress and improvement, and communicate the value and impact of security to stakeholders. Therefore, security metrics are the correct answer.
Reference:
https://www.isaca.org/resources/isaca-journal/issues/2020/volume-6/key-performance-indicators-for-security-governance-part-1
https://www.gartner.com/en/publications/protect-your-business-assets-with-roadmap-for-maturing-information-security


NEW QUESTION # 147
在通過大眾媒體了解到組織的託管薪資服務提供商發生數據洩露事件後,信息安全經理應首先執行以下哪項操作?

  • A. 與提供商驗證違規情況
  • B. 暫停與提供商的數據交換
  • C. 將違規行為通知適當的監管機構。
  • D. 啟動業務連續性計劃 (BCP)

Answer: A

Explanation:
The first thing an information security manager should do after learning through mass media of a data breach at the organization's hosted payroll service provider is to validate the breach with the provider, which means contacting the provider directly and confirming the details and scope of the breach, such as when it occurred, what data was compromised, and what actions the provider is taking to mitigate the impact. Validating the breach with the provider can help the information security manager assess the situation accurately and plan the next steps accordingly. The other options, such as suspending the data exchange, notifying regulatory authorities, or initiating the business continuity plan, may be premature or unnecessary before validating the breach with the provider. Reference:
https://www.wired.com/story/sequoia-hr-data-breach/
https://cybernews.com/news/kronos-major-hr-and-payroll-service-provider-hit-with-ransomware-warns-of-a-long-outage/
https://www.afr.com/work-and-careers/workplace/pay-in-crisis-as-major-payroll-company-hacked-20211117-p599mr


NEW QUESTION # 148
组织允许在员工拥有的智能手机上存储和使用其关键和敏感信息。以下哪一项是最好的安全控制?

  • A. 开展安全意识培训
  • B. 建立远程擦除的权限
  • C. 要求用户备份组织数据
  • D. 监控智能手机的使用频率

Answer: B

Explanation:
The best security control for an organization that permits the storage and use of its critical and sensitive information on employee-owned smartphones is establishing the authority to remote wipe. Remote wipe is a feature that allows an authorized administrator or user to remotely erase the data on a device in case of loss, theft, or compromise1. Remote wipe can help prevent unauthorized access or disclosure of the organization's information on employee-owned smartphones, as well as protect the privacy of the employee's personal dat a. Remote wipe can be implemented through various methods, such as mobile device management (MDM) software, native device features, or third-party applications2. However, remote wipe requires the consent and cooperation of the employee, as well as a clear policy that defines the conditions and procedures for its use. The other options are not the best security controls for an organization that permits the storage and use of its critical and sensitive information on employee-owned smartphones. Developing security awareness training is an important measure to educate employees about the security risks and responsibilities associated with using their own smartphones for work purposes, but it does not provide a technical or physical protection for the data on the devices3. Requiring the backup of the organization's data by the user is a good practice to ensure data availability and recovery in case of device failure or loss, but it does not prevent unauthorized access or disclosure of the data on the devices4. Monitoring how often the smartphone is used is a possible way to detect abnormal or suspicious activities on the devices, but it does not prevent or mitigate the impact of a data breach on the devices. Reference: 4: Mobile Device Backup - NIST 3: Security Awareness Training - NIST 1: Remote Wipe - Lifewire 2: How Businesses with a BYOD Policy Can Secure Employee Devices - IBM : Mobile Device Security Policy - SANS


NEW QUESTION # 149
當安全人員發生組織變動時,下列何者最能支援資訊安全管理?

  • A. 正式製定安全策略和計劃
  • B. 確保安全流程的最新記錄
  • C. 為員工製定意識計劃
  • D. 在安全營運團隊內建立流程

Answer: B


NEW QUESTION # 150
基于异常的入侵检测系统 (IDS) 通过收集以下方面的数据来运行:

  • A. 异常网络行为并将其用作衡量正常活动的基线
  • B. 正常网络行为并将其用作测量异常活动的基线
  • C. 异常网络行为并向防火墙发出指令以丢弃流氓连接
  • D. 来自历史数据的攻击模式签名

Answer: B

Explanation:
An anomaly-based intrusion detection system (IDS) operates by gathering data on normal network behavior and using it as a baseline for measuring abnormal activity. This is important because it allows the IDS to detect any activity that is outside of the normal range of usage for the network, which can help to identify potential malicious activity or security threats. Additionally, the IDS will monitor for any changes in the baseline behavior and alert the administrator if any irregularities are detected. By contrast, signature-based IDSs operate by gathering attack pattern signatures from historical data and comparing them against incoming traffic in order to identify malicious activity.


NEW QUESTION # 151
下列何者最有​​利於制定全面的資訊安全政策?

  • A. 既定的內部稽核計劃
  • B. 安全關鍵績效指標 (KPI)
  • C. 近期資訊安全事件回顧
  • D. 與已建立的資訊安全框架保持一致

Answer: D

Explanation:
Explanation
Alignment with an established information security framework is the BEST way to facilitate the development of a comprehensive information security policy, because it provides a consistent and structured approach to define, implement, and maintain the policy across the organization. An information security framework is a set of best practices, standards, and guidelines that help to ensure the effectiveness, efficiency, and compliance of the information security policy.
References =
CISM Review Manual, 16th Edition, ISACA, 2020, p. 35: "An information security framework is a set of best practices, standards, and guidelines that provide a consistent and structured approach to information security governance." CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: "The information security policy should be aligned with an established information security framework to ensure its effectiveness, efficiency, and compliance."


NEW QUESTION # 152
......

ISACA CISM-CN Test Engine PDF - All Free Dumps: https://learningtree.actualvce.com/ISACA/CISM-CN-valid-vce-dumps.html