Christian Haller
Quiz por , criado more than 1 year ago

Quiz sobre CISM Quiz, criado por Christian Haller em 21-06-2014.

2263
0
0
Christian Haller
Criado por Christian Haller mais de 10 anos atrás
Fechar

CISM Quiz

Questão 1 de 30

1

A security strategy is important for an organization PRIMARILY because it provides

Selecione uma das seguintes:

  • basis for determining the best logical security architecture for the organization

  • management intent and direction for security activities

  • provides users guidance on how to operate securely in everyday tasks

  • helps IT auditors ensure compliance

Explicação

Questão 2 de 30

1

The MOST important reason to make sure there is good communication about security throughout the organization is:

Selecione uma das seguintes:

  • to make security more palatable to resistant employees

  • because people are the biggest security risk

  • to inform business units about security strategy

  • to conform to regulations requiring all employees are informed about security

Explicação

Questão 3 de 30

1

The regulatory environment for most organizations mandates a variety of security-related activities. It is MOST important that the information security manager:

Selecione uma das seguintes:

  • rely on corporate counsel to advise which regulations are relevant

  • stay current with all relevant regulations and request legal interpretation

  • involve all impacted departments and treat regulations as just another risk

  • ignore many of the regulations that have no teeth

Explicação

Questão 4 de 30

1

The MOST important consideration in developing security policies is that:

Selecione uma das seguintes:

  • they are based on a threat profile

  • they are complete and no detail is let out

  • management signs off on them

  • all employees read and understand them

Explicação

Questão 5 de 30

1

The PRIMARY security objective in creating good procedures is

Selecione uma das seguintes:

  • to make sure they work as intended

  • that they are unambiguous and meet the standards

  • that they be written in plain language

  • that compliance can be monitored

Explicação

Questão 6 de 30

1

The assignment of roles and responsibilities will be MOST effective if:

Selecione uma das seguintes:

  • there is senior management support

  • the assignments are consistent with proficiencies

  • roles are mapped to required competencies

  • responsibilities are undertaken on a voluntary basis

Explicação

Questão 7 de 30

1

The PRIMARY benefit organizations derive from effective information security governance is:

Selecione uma das seguintes:

  • ensuring appropriate regulatory compliance

  • ensuring acceptable levels of disruption

  • prioritizing allocation of remedial resources

  • maximizing return on security investments

Explicação

Questão 8 de 30

1

From an information security manager’s perspective, the MOST important factors regarding data retention are:

Selecione uma das seguintes:

  • business and regulatory requirements

  • document integrity and destruction

  • media availability and storage

  • data confidentiality and encryption

Explicação

Questão 9 de 30

1

Which role is in the BEST position to review and confirm the appropriateness of a user access list?

Selecione uma das seguintes:

  • data owner

  • information security manager

  • domain administrator

  • business manager

Explicação

Questão 10 de 30

1

In implementing information security governance, the information security manager is PRIMARILY responsible for:

Selecione uma das seguintes:

  • developing the security strategy

  • reviewing the security strategy

  • communicating the security strategy

  • approving the security strategy

Explicação

Questão 11 de 30

1

The overall objective of risk management is to:

Selecione uma das seguintes:

  • eliminate all vulnerabilities, if possible

  • determine the best way to transfer risk

  • reduce risks to an acceptable level

  • implement effective countermeasures

Explicação

Questão 12 de 30

1

The statement „risk = value x vulnerability x threat“ indicates that:

Selecione uma das seguintes:

  • risk can be quantified using annual loss expectancy (ALE)

  • approximate risk can be estimated, provided probability is computed

  • the level of risk is greater when more threats meet more vulnerabilities

  • without knowing value, risk cannot be calculated

Explicação

Questão 13 de 30

1

To address changes in risk, an effective risk management program should:

Selecione uma das seguintes:

  • ensure that continuous monitoring processes are in place

  • establish proper security baselines for all information resources

  • implement a complete data classification process

  • change security policies on a timely basis to address changing risks

Explicação

Questão 14 de 30

1

Information classification is important to properly manage risk PRIMARILY because:

Selecione uma das seguintes:

  • it ensures accountability for information resources as required by roles and responsibilities

  • it is legal requirement under various regulations

  • there is no other way to meet the requirements for availability, integrity and auditability

  • it is used to identify the sensitivity and criticality of information to the organization

Explicação

Questão 15 de 30

1

Vulnerabilities discovered during an assessment should be:

Selecione uma das seguintes:

  • handled as a risk, even though there is no threat

  • prioritized for remediation solely based on impact

  • a basis for analyzing the effectiveness of controls

  • evaluated for threat and impact in addition to cost of mitigation

Explicação

Questão 16 de 30

1

Indemnity (Schadensersatz) agreements can be used to:

Selecione uma das seguintes:

  • ensure an agreed-upon level of service

  • reduce impacts on critical resources

  • transfer responsibility to a third party

  • provide an effective countermeasure to threats

Explicação

Questão 17 de 30

1

Residual risks can be determined by:

Selecione uma das seguintes:

  • determining remaining vulnerabilities after countermeasures are in place

  • a threat analysis

  • a risk assessment

  • transferring all risks

Explicação

Questão 18 de 30

1

Data owners are PRIMARILY responsible for creating risk mitigation strategies to address which of the following areas?

Selecione uma das seguintes:

  • platform security

  • entitlement changes

  • intrusion detection

  • antivirus controls

Explicação

Questão 19 de 30

1

A risk analysis should:

Selecione uma das seguintes:

  • limit the scope to a benchmark of similar companies

  • assume an equal degree of protection for all assets

  • address the potential size and likelihood of loss

  • give more weight to the likelihood vs. the size of the loss

Explicação

Questão 20 de 30

1

Which of the following is BEST for preventing an external attack?

Selecione uma das seguintes:

  • static IP addresses

  • network address translation

  • background checks for temporary employees

  • writing computer logs to removable media

Explicação

Questão 21 de 30

1

Who is in the BEST position to develop the priorities and identify what risks and impacts would occur if there were a loss or corruption of the organization‘s information resources?

Selecione uma das seguintes:

  • internal auditors

  • security management

  • business process owners

  • external regulatory agencies

Explicação

Questão 22 de 30

1

The MOST important single concept for an information security architect to keep in mind is:

Selecione uma das seguintes:

  • plan do check act

  • confidentiality, integrity, availablility

  • prevention, detection, correction

  • tone at the top

Explicação

Questão 23 de 30

1

Which of the following is the BEST method of limiting the impact of vulnerabilities inherent to wireless networks?

Selecione uma das seguintes:

  • require private, key based encryption to connect to the wireless network

  • enable auditing on every host that connects to a wireless network

  • require that every host that connects to this network is have a well tested recovery plan

  • enable auditing on every connection to the wireless network

Explicação

Questão 24 de 30

1

In an environment that practises defense in depth, an Internet application that requires a login for a user to access it would also require which of the following additional controls?

Selecione uma das seguintes:

  • user authentication

  • user audit trails

  • network load balancing

  • network authentication

Explicação

Questão 25 de 30

1

If an information security manager has responsibility for application security review, which of the following additional responsibilities present a conflict of interest in performing the review?

Selecione uma das seguintes:

  • operation system recovery

  • application administration

  • network change control

  • host based intrusion detection

Explicação

Questão 26 de 30

1

Which of the following BEST promotes accountability?

Selecione uma das seguintes:

  • compliance monitoring

  • awareness training

  • secure implementation

  • documented policy

Explicação

Questão 27 de 30

1

Which of the following conclusions render the sentence MOST accurate? Vulnerabilities combined with threats:

Selecione uma das seguintes:

  • always results in damage

  • require controls to avoid damage

  • allow exploits that may cause damage

  • always results in exploits

Explicação

Questão 28 de 30

1

In which state of the systems development life cycle (SDLC) should the information security manager create a list of security issues presented by the functional description of a newly planned system?

Selecione uma das seguintes:

  • feasibility

  • requirements

  • design

  • development

Explicação

Questão 29 de 30

1

What is the FIRST step in designing a secure client server environment?

Selecione uma das seguintes:

  • identify all data access points

  • establish operating system security on all platforms

  • require hard passwords

  • place a firewall between the server and clients

Explicação

Questão 30 de 30

1

What BEST represents the hierarchy of access control strength, from weakest to strongest?

Selecione uma das seguintes:

  • what you have, what you are, what you know

  • what you know, what you have, what you are

  • what you are, what you have, what you know

  • what you are, what you know, what you have information Security Program

Explicação