
CISM-CN Dumps 2023 - New ISACA CISM-CN Exam Questions
Free CISM-CN Braindumps Download Updated on Nov 30, 2023 with 417 Questions
NEW QUESTION # 145
以下哪一方应负责确定处理客户信息的应用程序的访问级别?
- A. 商业客户
- B. 身份和访问管理团队
- C. 业务单元管理
- D. 信息安全撕裂
Answer: C
NEW QUESTION # 146
在制定多年计划时,信息安全经理最重要的考虑因素是什么?
- A. 确保与其他业务部门的计划保持一致
- B. 确保为潜在的信息安全风险制定应急计划
- C. 展示预计预算逐年增加
- D. 允许信息安全程序扩展其功能
Answer: A
NEW QUESTION # 147
對最近發生的安全事件的調查確定,根本原因是系統准入管理員為解決此問題而疏忽處理事件警報?
- A. 為數據保管人提供事件響應培訓。
- B. 向數據所有者提供事件響應培訓。
- C. 修改事件響應計劃-以與業務流程保持一致。
- D. 進行風險評估並與高級管理層分享結果。
Answer: A
Explanation:
The best action for the system admin manager to address the issue of negligent handling of incident alerts by system admins is to provide incident response training to data custodians because it helps to improve their awareness and skills in recognizing and reporting security incidents, and following the incident response procedures and protocols. Conducting a risk assessment and sharing the result with senior management is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Revising the incident response plan to align with business processes is not a good action because it does not address the root cause of the issue or provide any solutions or improvements. Providing incident response training to data owners is not a good action because data owners are not responsible for handling incident alerts or performing incident response tasks. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 148
以下哪項是降低針對性電子郵件攻擊帶來的安全事件風險的最佳方法?
- A. 禁用所有傳入雲郵件服務
- B. 實施數據丟失防護 (DLP) 系統
- C. 需要確認可接受的使用政策
- D. 在整個組織內進行意識培訓
Answer: D
Explanation:
Conducting awareness training across the organization is the best way to reduce the risk of security incidents from targeted email attacks because it helps to educate and empower the employees to recognize and avoid falling for such attacks. Targeted email attacks, such as phishing, spear phishing, or business email compromise, rely on social engineering techniques to deceive and manipulate the recipients into clicking on malicious links, opening malicious attachments, or disclosing sensitive information. Awareness training can help to raise the level of security culture and behavior among the employees, as well as to provide them with practical tips and best practices to protect themselves and the organization from targeted email attacks. Therefore, conducting awareness training across the organization is the correct answer.
Reference:
https://almanac.upenn.edu/articles/one-step-ahead-dont-get-caught-by-targeted-email-attacks
https://www.microsoft.com/en-us/security/business/security-101/what-is-business-email-compromise-bec
https://www.csoonline.com/article/3334617/what-is-spear-phishing-examples-tactics-and-techniques.html
NEW QUESTION # 149
一个组织计划利用流行的社交网络平台来推广其产品和服务。以下哪项是信息安全经理支持此计划的最佳行动方案?
- A. 建立在社交网络上发布内容的流程。
- B. 为社交网络的使用制定安全控制措施。
- C. 评估与使用社交网络相关的安全风险。
- D. 对社交网络平台进行漏洞评估。
Answer: C
Explanation:
The best course of action for the information security manager to support the initiative of leveraging popular social network platforms to promote the organization's products and services is to assess the security risk associated with the use of social networks. Security risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a security risk assessment, the information security manager can provide valuable input to the decision-making process regarding the benefits and costs of using social networks, as well as the appropriate security controls and mitigation strategies to reduce the risk to an acceptable level. The other options are not the best course of action, although they may be part of the security risk management process. Establishing processes to publish content on social networks is an operational task that should be performed after assessing the security risk and implementing the necessary controls. Conducting vulnerability assessments on social network platforms is a technical activity that may not be feasible or effective, as the organization does not have control over the platforms' infrastructure and configuration. Developing security controls for the use of social networks is a preventive measure that should be based on the results of the security risk assessment and aligned with the organization's risk appetite and tolerance
NEW QUESTION # 150
以下哪种风险情景最有可能从供应链攻击中出现?
- A. 供应商提供的硬件和软件资源不可靠
- B. 通过第三方资源危及关键资产
- C. 由于产品不可用而导致客户流失
- D. 供应商提供的服务不可用
Answer: C
NEW QUESTION # 151
创建事件响应计划时,以下哪项最重要?
- A. 与风险评估过程保持一致
- B. 记录事件通知和升级流程
- C. 识别事件的构成
- D. 识别易受攻击的数据资产
Answer: C
NEW QUESTION # 152
以下哪一项最有效地防止引入可能破坏关键业务应用程序可用性的漏洞?
- A. 补丁管理进程
- B. 版本控制
- C. 变更管理控制
- D. 逻辑访问控制
Answer: A
NEW QUESTION # 153
在呼叫中心,进行社会工程学的最佳理由是:
- A. 改进密码策略。
- B. 为信息安全计划获得资金。
- C. 确定接受额外安全培训的候选人。
- D. 最小化攻击成功的可能性。
Answer: C
Explanation:
The best reason to conduct a social engineering test in a call center is to identify candidates for additional security training because it helps to assess the level of awareness and skills of the call center staff in recognizing and resisting social engineering attacks, and provide them with the necessary training or education to improve their security posture. Minimizing the likelihood of successful attacks is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Gaining funding for information security initiatives is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Improving password policy is not a reason to conduct a social engineering test, but rather a possible outcome or benefit of conducting such a test. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-6/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 154
信息安全控制的设计应主要基于:
- A. 脆弱性评估。
- B. 业务风险场景,
- C. 法规要求。
- D. 业务影响分析(BIA)。
Answer: B
NEW QUESTION # 155
实现对信息安全治理计划的执行承诺的最重要因素是:
- A. 已建立的安全策略。
- B. 定义的安全框架。
- C. 过程改进模型
- D. 确定的业务驱动因素。
Answer: D
Explanation:
The most important element in achieving executive commitment to an information security governance program is to align the program with the identified business drivers of the organization. Business drivers are the factors that influence the strategic objectives, goals, and priorities of the organization. They reflect the needs and expectations of the stakeholders, customers, regulators, and other parties that are relevant to the organization's mission and vision. By aligning the information security governance program with the business drivers, the executive can demonstrate the value and benefits of information security to the organization's performance, reputation, and competitiveness. The other options are not the most important element, although they may be part of an information security governance program. A defined security framework is a set of standards, guidelines, and best practices that provide a structure and direction for implementing information security. A process improvement model is a methodology that helps to identify, analyze, and improve the processes related to information security. Established security strategies are the plans and actions that define how information security supports and enables the business objectives and goals. These elements are important for developing and executing an information security governance program, but they do not necessarily ensure executive commitment unless they are aligned with the business drivers
NEW QUESTION # 156
事件响应过程中根除阶段的主要目标是:
- A. 移除威胁并恢复受影响的系统
- B. 从受影响的系统获取取证证据。
- C. 保持严格的监管链。
- D. 提供有效的事件分类和遏制。
Answer: A
Explanation:
The primary goal of the eradication phase in an incident response process is to remove the threat and restore affected systems because it eliminates any traces or remnants of malicious activity or compromise from the systems or network, and returns them to their normal or secure state. Maintaining a strict chain of custody is not a goal of the eradication phase, but rather a requirement for preserving and documenting digital evidence throughout the incident response process. Providing effective triage and containment of the incident is not a goal of the eradication phase, but rather a goal of the containment phase, which isolates and stops the spread of malicious activity or compromise. Obtaining forensic evidence from the affected system is not a goal of the eradication phase, but rather a goal of the identification phase, which collects and analyzes data or artifacts related to malicious activity or compromise. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 157
向董事会提交的月度信息安全报告中包含以下哪项最重要?
- A. 安全事件根源分析
- B. 安全指标趋势分析
- C. 风险评估结果
- D. 威胁情报
Answer: B
NEW QUESTION # 158
一个组织正在制定一项风险缓解计划,该计划考虑冗余电源以降低与关键系统中断相关的业务风险。正在考虑哪种类型的控制?
- A. 威慑
- B. 预防
- C. 纠正
- D. 侦探
Answer: B
NEW QUESTION # 159
信息安全經理已確定特權員工對生產服務器的訪問請求已獲得批准;但不會記錄用戶操作。對於這種情況,以下哪一項應該是最令人擔憂的?
- A. 授權不當
- B. 缺乏可用性
- C. 缺乏問責制
- D. 身份驗證不充分
Answer: C
Explanation:
The greatest concern with the situation of privileged employee access requests to production servers being approved but not logged is the lack of accountability, which means the inability to trace or verify the actions and decisions of the privileged users. Lack of accountability can lead to security risks such as unauthorized changes, data breaches, fraud, or misuse of privileges. Logging user actions is a key component of privileged access management (PAM), which helps to monitor, detect, and prevent unauthorized privileged access to critical resources. The other options, such as lack of availability, improper authorization, or inadequate authentication, are not directly related to the situation of not logging user actions. Reference:
https://www.microsoft.com/en-us/security/business/security-101/what-is-privileged-access-management-pam
https://www.ekransystem.com/en/blog/privileged-user-monitoring-best-practices
https://www.beyondtrust.com/resources/glossary/privileged-access-management-pam
NEW QUESTION # 160
一位信息安全经理发现,即将部署的在线应用程序会增加风险,超出可接受的水平,并且没有包括必要的控制措施。以下哪项是信息安全经理的最佳行动方案?
- A. 向高级管理层介绍额外控制的业务案例。
- B. 指示 IT 根据紧急业务需求部署控制措施。
- C. 对补偿控制产品进行招标。
- D. 推荐不同的应用程序。
Answer: A
NEW QUESTION # 161
以下哪项是风险缓解的示例?
- A. 购买保险
- B. 进行成本效益分析
- C. 改进安全控制
- D. 停止与风险相关的活动
Answer: C
Explanation:
Risk mitigation refers to the processes and strategies that organizations use to reduce the likelihood or impact of potential risks. Improving security controls is a classic example of risk mitigation. By implementing or enhancing security controls, organizations can reduce the risk of security incidents or breaches, such as data theft or unauthorized access. For example, implementing strong passwords, regularly updating software and systems, and training employees on security best practices are all ways to improve security controls and mitigate risk. Other examples of risk mitigation include implementing disaster recovery and business continuity plans, conducting regular security assessments and audits, and purchasing insurance.
NEW QUESTION # 162
這違反了禁止在辦公室使用攝像頭的政策,向員工發放了配備網絡攝像頭的智能手機和平板電腦。以下哪一項應該是信息安全經理的首要行動方案?
- A. 進行風險評估,
- B. 修改政策。
- C. 執行根本原因分析。
- D. 傳達可接受的使用政策。
Answer: A
NEW QUESTION # 163
由于事件分类中缺乏严重性标准,以下哪项是最令人担忧的问题?
- A. 服务台人员配置不正确。
- B. 统计报告会不正确。
- C. 升级程序将无效。
- D. 不可能及时发现攻击。
Answer: C
Explanation:
The greatest concern resulting from the lack of severity criteria in incident classification is that escalation procedures will be ineffective because they rely on severity criteria to determine when and how to escalate an incident to higher levels of authority or responsibility, and what actions or resources are required for resolving an incident. Statistical reports will be incorrect is not a great concern because they do not affect the incident response process directly, but rather provide information or analysis for improvement or evaluation purposes. The service desk will be staffed incorrectly is not a great concern because it does not affect the incident response process directly, but rather affects the availability or efficiency of one of its components. Timely detection of attacks will be impossible is not a great concern because it does not depend on severity criteria, but rather on monitoring and alerting mechanisms. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
NEW QUESTION # 164
以下哪一項是信息安全經理協調安全和業務目標的最佳行動方案?
- A. 審查業務策略
- B. 進行業務影響分析 (BIA)
- C. 定義關鍵績效指標 (KPI)
- D. 積極與利益相關者互動
Answer: D
NEW QUESTION # 165
以下哪一項是降低實施應用程序安全控製成本的最佳選擇?
- A. 在開發環境中進行安全測試。
- B. 包括標準應用程序安全要求
- C. 項目完成後進行風險分析。
- D. 將安全活動集成到開發過程中
Answer: D
Explanation:
Integrating security activities within the development process is the best option to lower the cost to implement application security controls because it ensures that security is considered and addressed throughout the software development life cycle (SDLC), from design to deployment, and reduces the likelihood and impact of security flaws or vulnerabilities that may require costly fixes or patches later on. Performing security tests in the development environment is not the best option because it may not detect or prevent all security issues that may arise in different environments or scenarios. Performing a risk analysis after project completion is not a good option because it may be too late to identify or mitigate security risks that may have been introduced during the project. Including standard application security requirements is not a good option because it may not account for specific or unique security needs or challenges of different applications or projects. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/secure-software-development-lifecycle https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems
NEW QUESTION # 166
以下哪项是信息资产分类的最大好处?
- A. 为实施需要知道的政策提供基础
- B. 定义资源所有权
- C. 支持职责分离
- D. 帮助确定恢复点目标 (RPO)
Answer: A
Explanation:
The greatest benefit of information asset classification is providing a basis for imple-menting a need-to-know policy. Information asset classification is a process of catego-rizing information based on its level of sensitivity and importance, and applying appro-priate security controls based on the level of risk associated with that information1. A need-to-know policy is a principle that states that access to information should be granted only to those individuals who require it to perform their official duties or tasks2. The purpose of a need-to-know policy is to limit the exposure of sensitive information to unauthorized or unnecessary parties, and to reduce the risk of data breaches, leaks, or misuse. Information asset classification provides a basis for implementing a need-to-know policy by:
* Defining the value and protection requirements of different types of information
* Labeling the information with the appropriate classification level, such as public, internal, confidential, secret, or top secret
* Establishing the roles and responsibilities of information owners, custodians, and users
* Enforcing access controls and encryption for the information
* Documenting the security policies and procedures for the information By providing a basis for implementing a need-to-know policy, information asset classi-fication can help organizations to protect their sensitive information, comply with rele-vant laws and regulations, and achieve their business objectives. The other options are not the greatest benefits of information asset classification. Helping to determine the recovery point objective (RPO) is not a benefit, but rather a consequence of applying security controls based on the classification level. RPO is the acceptable amount of data loss in case of a disruption3. Supporting segregation of duties is not a benefit, but rather a prerequisite for implementing a need-to-know policy. Segregation of duties is a principle that states that no single individual should have control over two or more phases of a business process or transaction that are susceptible to errors or fraud4. De-fining resource ownership is not a benefit, but rather a component of information asset classification. Resource ownership is the assignment of accountability and authority for an information asset to an individual or a group5. Reference: 1: Information Classifi-cation - Advisera 2: Need-to-Know Principle - NIST 3: Recovery Point Objective - NIST 4: Segregation of Duties - NIST 5: Resource Ownership - NIST : Information Classification in Information Security - GeeksforGeeks : Information Asset Classification Policy - UCI
NEW QUESTION # 167
以下哪一項是成功信息安全文化的最佳標誌?
- A. 最終用戶知道如何識別和報告事件。
- B. 分配給信息安全的預算是充足的。
- C. 定期進行滲透測試並修復發現的結果。
- D. 根據工作職能為個人分配角色。
Answer: A
NEW QUESTION # 168
以下哪一項可以最全面地洞察組織面臨的持續威脅?
- A. 漏洞評估
- B. 滲透測試
- C. 業務影響分析 (BIA)
- D. 風險登記冊
Answer: D
Explanation:
A risk register provides the MOST comprehensive insight into ongoing threats facing an organization. This is because a risk register is a document that records and tracks the identified risks, their likelihood, impact, mitigation strategies, and status. A risk register helps an organization to monitor and manage the threats that could affect its objectives, assets, and operations. A risk register also helps an organization to prioritize its response efforts and allocate its resources accordingly.
NEW QUESTION # 169
以下哪項變更管理程序最有可能引起信息安全經理的關注?
- A. 使用手動而不是自動過程來比較程序版本。
- B. 在進行更改之前的周末測試後備流程
- C. 用戶不會收到有關計劃的系統更改的通知
- D. 開發經理將程序遷移到生產中
Answer: D
Explanation:
According to the Certified Information Security Manager (CISM) Study Guide, one of the primary responsibilities of an information security manager is to ensure that changes to systems and processes are managed in a secure and controlled manner. The change management procedure that is most likely to cause concern for an information security manager is when the development manager migrates programs into production without proper oversight or control. This can increase the risk of unauthorized changes being made to systems and data, and can also increase the risk of configuration errors or other issues that can negatively impact the security and availability of systems. To mitigate these risks, it is important for the information security manager to work closely with the development team to establish and enforce change management procedures that ensure that all changes are properly approved, tested, and implemented in a controlled manner.
NEW QUESTION # 170
......
ISACA CISM-CN Exam Practice Test Questions: https://www.premiumvcedump.com/ISACA/valid-CISM-CN-premium-vce-exam-dumps.html
Updated Certification Exam CISM-CN Dumps - Practice Test Questions: https://drive.google.com/open?id=11feb6WAMrkfmqwRnGJZ8PYE9nh0GCqoz