[Full-Version] 2023 New Preparation Guide of ISACA CISM-CN Exam [Q65-Q89]

Share

[Full-Version] 2023 New Preparation Guide of ISACA CISM-CN Exam

CISM-CN Practice Exam - 417 Unique Questions

NEW QUESTION # 65
以下哪项是帮助确保组织的风险偏好将被视为风险处理过程的一部分的最佳方式?

  • A. 要求指导委员会批准风险处理计划。
  • B. 使用定量风险评估方法。
  • C. 建立关键风险指标(KRIs)。
  • D. 定期向高级管理层报告风险处理情况

Answer: A


NEW QUESTION # 66
在恢復需要完全重建的受損系統時,應首先考慮以下哪項?

  • A. 補丁管理文件
  • B. 配置管理文件
  • C. 網絡系統日誌
  • D. 入侵檢測系統 (IDS) 日誌

Answer: B

Explanation:
When recovering a compromised system that needs a complete rebuild, the first step should be to restore configuration management files. Configuration management files are critical for identifying the system's original state and the changes that were made to it, and restoring them can help ensure that the system is rebuilt to its original state.
According to the Certified Information Security Manager (CISM) Study Manual, "The initial phase of the recovery process requires that configuration management files be restored. These files represent the foundation of the system and provide insight into the original state of the system, which is important for identifying changes that were made to the system as well as ensuring the recovery process can return the system to its original state." Patch management files, network system logs, and intrusion detection system (IDS) logs are also important in the recovery process, but they should be addressed after configuration management files have been restored.
Reference:
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 256.


NEW QUESTION # 67
當出現以下情況時,滲透測試是最合適的:

  • A. 正在製定安全策略。
  • B. 發生安全事件,
  • C. 新系統即將上線。
  • D. 新系統正在設計中。

Answer: C


NEW QUESTION # 68
以下哪一项 BEST 有助于有效执行事件响应计划?

  • A. 该计划基于行业最佳实践。
  • B. 事件响应计划与 IT 灾难恢复计划 (DRP) 保持一致。
  • C. 该计划基于风险评估结果。
  • D. 响应团队接受了计划培训

Answer: D

Explanation:
The best way to facilitate the effective execution of an incident response plan is to ensure that the response team is trained on the plan. An incident response plan is a set of instructions that defines the roles, responsibilities, procedures, and tools for detecting, responding to, and recovering from security incidents. An incident response team is a group of individuals that are assigned to perform specific tasks and activities during an incident response process. The response team may include security analysts, IT staff, legal counsel, public relations, and other stakeholders. To execute an incident response plan effectively, the response team needs to be trained on the plan, which means they need to be familiar with the following aspects of the plan: The scope and objectives of the plan The roles and responsibilities of each team member The communication and escalation protocols The incident classification and prioritization criteria The incident response procedures and tools The incident documentation and reporting requirements The incident review and improvement processes By training the response team on the plan, the organization can ensure that the team members are prepared and confident to handle any security incidents that may occur, and that they can perform their tasks efficiently and consistently. The other options are not the best way to facilitate the effective execution of an incident response plan, although they may be some steps or outcomes of the process. The plan being based on risk assessment results is a desirable practice, as it ensures that the plan is aligned with the organization's risk profile and addresses the most relevant and likely threats and vulnerabilities. However, it does not guarantee that the plan will be executed effectively unless the response team is trained on the plan. The plan being based on industry best practice is a desirable practice, as it ensures that the plan follows established standards and guidelines for incident response. However, it does not guarantee that the plan will be executed effectively unless the response team is trained on the plan. The incident response plan aligning with the IT disaster recovery plan (DRP) is a desirable practice, as it ensures that the plans are consistent and coordinated in terms of objectives, scope, roles, procedures, and tools. However, it does not guarantee that the plan will be executed effectively unless the response team is trained on the plan


NEW QUESTION # 69
以下哪項是防範新興高級持續威脅 (APT) 行為者的最佳方法?

  • A. 更新信息安全意識材料
  • B. 實現蜜罐環境
  • C. 實施主動系統監控
  • D. 為事件響應團隊提供持續培訓

Answer: C


NEW QUESTION # 70
信息安全控制的设计应主要基于:

  • A. 业务风险场景,
  • B. 脆弱性评估。
  • C. 法规要求。
  • D. 业务影响分析(BIA)。

Answer: A


NEW QUESTION # 71
以下哪項最有利於安全計劃的有效戰略調整?

  • A. 業務策略定期更新
  • B. 由第三方定期進行安全審核。
  • C. 組織單位對優先事項做出貢獻並達成一致
  • D. 程序和標準由部門負責人批准。

Answer: C

Explanation:
Organizational units contribute to and agree on priorities is the best way to facilitate effective strategic alignment of security initiatives because it ensures that the security initiatives are aligned with the business goals and objectives, supported by relevant stakeholders, and prioritized based on risk and value. The business strategy is periodically updated is not sufficient to facilitate effective strategic alignment of security initiatives because it does not involve collaboration or communication between different organizational units. Procedures and standards are approved by department heads is not sufficient to facilitate effective strategic alignment of security initiatives because it does not reflect the strategic direction or vision of the organization. Periodic security audits are conducted by a third-party is not sufficient to facilitate effective strategic alignment of security initiatives because it does not address the planning or implementation of security initiatives. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/how-to-align-security-initiatives-with-business-goals-and-objectives https://www.isaca.org/resources/isaca-journal/issues/2015/volume-1/how-to-measure-the-effectiveness-of-information-security-governance


NEW QUESTION # 72
以下哪一項是組織確保事件響應團隊做好適當準備的最佳方法?

  • A. 進行適合組織的桌面練習
  • B. 提供第三方取證公司的培訓
  • C. 響應團隊獲得行業認證
  • D. 記錄組織的多個場景和響應步驟

Answer: A

Explanation:
The BEST way for an organization to ensure that incident response teams are properly prepared is by conducting tabletop exercises appropriate for the organization.
Tabletop exercises are an effective way to test and validate an organization's incident response plan (IRP) and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan. By conducting regular tabletop exercises, the incident response team can stay current with changes in the threat landscape and ensure that they are prepared to respond to incidents effectively.
According to the Certified Information Security Manager (CISM) Study Manual, "Tabletop exercises are a valuable tool for testing and validating the effectiveness of the IRP and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan." While providing training from third-party forensics firms, obtaining industry certifications, and documenting multiple scenarios for the organization and response steps can all be useful in preparing incident response teams, they are not as effective as conducting tabletop exercises appropriate for the organization.
Reference:
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 324.


NEW QUESTION # 73
在商业提案中,潜在供应商提倡获得国际安全标准认证,以此作为衡量其安全能力的标准。
在依靠此认证之前,最重要的是信息安全经理确认:

  • A. 认证将在合同有效期内保持有效。
  • B. 认证可以扩展到涵盖客户的业务。
  • C. 认证范围与所提供的服务相关。
  • D. 当前的国际标准用于评估安全流程。

Answer: C


NEW QUESTION # 74
信息安全经理已收到影响组织内关键数据处理系统的新漏洞的通知,应首先执行以下哪项?

  • A. 通知高级管理层
  • B. 实施补偿控制
  • C. 重新评估风险
  • D. 向企业主索取新的整治方案

Answer: C

Explanation:
The first step when a new vulnerability is identified is to re-evaluate the risk associated with the vulnerability. This may require an update to the risk assessment and the implementation of additional controls. Informing senior management of the vulnerability is important, but should not be the first step. Implementing compensating controls may also be necessary, but again, should not be the first step. Asking the business owner for a remediation plan may be useful, but only after the risk has been re-evaluated.
The information security manager should first re-evaluate the risk posed by the new vulnerability to determine its impact and likelihood. Based on this assessment, appropriate actions can be taken such as informing senior management, implementing compensating controls, or requesting a remediation plan from the business owner. The other choices are possible actions but not necessarily the first one.
A vulnerability is a weakness that can be exploited by an attacker to compromise a system or network2. A vulnerability can affect key data processing systems within an organization if it exposes sensitive information, disrupts business operations, or damages assets2. A vulnerability assessment is a process of identifying and evaluating vulnerabilities and their potential consequences2


NEW QUESTION # 75
在网络监控中引入单点管理的主要好处是:

  • A. 允许行政人员做出管理决策。
  • B. 减少对系统的未授权访问。
  • C. 防止分布式环境中的信息不一致。
  • D. 提高环境控制效率。

Answer: A


NEW QUESTION # 76
當新推出的隱私法規影響業務時,信息安全經理應首先採取以下哪項行動?

  • A. 根據監管要求更新安全策略
  • B. 提出相關控制措施以確保業務符合法規
  • C. 識別和評估業務目標背景下的風險
  • D. 諮詢 IT 人員並根據他們的建議評估風險

Answer: C

Explanation:
Identify and assess the risk in the context of business objectives. Before making any changes to the security policy or introducing any new controls, the information security manager should first identify and assess the risk that the new privacy regulation poses to the business. This should be done in the context of the overall business objectives so that the security measures introduced are tailored to meet the specific needs of the organization.


NEW QUESTION # 77
单点登录 (SSO) 的主要优势在于它将:

  • A. 加强用户密码。
  • B. 增加相关应用的安全性。
  • C. 支持多种认证机制。
  • D. 提高访问管理效率

Answer: D

Explanation:
The primary advantage of single sign-on (SSO) is that it increases the efficiency of access management. With SSO, users only need to remember one set of credentials to access all of their applications, rather than having to remember multiple usernames and passwords for each application. This simplifies the user experience and helps to reduce the amount of time spent managing access to multiple applications. Additionally, SSO can also increase the security of related applications, as users are not sharing the same credentials across multiple applications, and it can also support multiple authentication mechanisms, such as biometric authentication.


NEW QUESTION # 78
組織的主要產品是使用軟件即服務 (SaaS) 交付的面向客戶的應用程序。首席安全工程師剛剛發現了主要雲提供商的一個重大安全漏洞。在組織內,誰主要負責相關任務?

  • A. 信息安全經理
  • B. 應用程序所有者
  • C. 安全工程師
  • D. 數據所有者

Answer: D


NEW QUESTION # 79
在定義如何分配信息安全預算時,以下哪一項最重要?

  • A. 監管合規標準
  • B. 業務影響評估
  • C. 信息安全政策
  • D. 信息安全策略

Answer: D

Explanation:
Information security strategy is the most important factor when defining how an information security budget should be allocated because it helps to align the security objectives and initiatives with the business goals and priorities. An information security strategy is a high-level plan that defines the vision, mission, scope, and direction of the security program, as well as the roles and responsibilities, governance structures, policies and standards, risk management approaches, and performance measurement methods. An information security strategy helps to identify and prioritize the security needs and requirements of the organization, as well as to allocate the resources and funding accordingly. An information security strategy also helps to communicate the value and benefits of security to the stakeholders and justify the security investments. Therefore, information security strategy is the correct answer.
Reference:
https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-breakdown-and-best-practices
https://www.csoonline.com/article/3671108/how-2023-cybersecurity-budget-allocations-are-shaping-up.html
https://www.statista.com/statistics/1319677/companies-it-budget-allocated-to-security-worldwide/


NEW QUESTION # 80
当出于分析目的授予供应商远程访问机密信息时,以下哪项是最重要的安全考虑因素?

  • A. 数据受定期访问日志审查。
  • B. 供应商必须能够修改数据。
  • C. 供应商必须同意组织的信息安全政策,
  • D. 数据在传输过程中加密,并在供应商站点处于静止状态。

Answer: C


NEW QUESTION # 81
网络隔离技术在安全漏洞发生后立即实施,以:

  • A. 为主要利益相关者的决策留出时间。
  • B. 执行零信任架构原则。
  • C. 根据取证需要保存证据
  • D. 减少进一步伤害的程度。

Answer: D


NEW QUESTION # 82
信息安全经理必须针对变更请求执行以下哪些活动?

  • A. 评估对信息安全风险的影响。
  • B. 对受影响的系统进行渗透测试。
  • C. 审查信息安全业务需求的变化。
  • D. 扫描 IT 系统以查找操作系统漏洞。

Answer: A


NEW QUESTION # 83
當威脅情報報告顯示針對該行業的大量勒索軟件攻擊時,以下哪一項是信息安全經理的最佳行動方案?

  • A. 增加系統備份的頻率。
  • B. 將威脅通知員工。
  • C. 檢查緩解安全控制措施。
  • D. 評估組織的風險。

Answer: D


NEW QUESTION # 84
如果在規定的期限內未遵守當地監管要求,組織將面臨嚴厲的罰款和處罰。高級管理層已要求信息安全經理準備一份行動計劃以實現合規性。
以下哪一項可為規劃目的提供最有用的信息?

  • A. 當前實施的安全控制清單
  • B. 業務影響分析 (BIA) 的結果
  • C. 差距分析的結果
  • D. 截止日期和違規處罰

Answer: C

Explanation:
Results from a gap analysis would provide the most useful information for planning purposes when preparing an action plan to achieve compliance with local regulatory requirements by an established deadline. A gap analysis is an assessment of the difference between an organization's current state of compliance and its desired level or standard. It is a process used to identify potential areas for improvement by comparing actual performance with expected performance. A gap analysis can help to prioritize the actions needed to close the gaps and comply with the regulatory requirements, as well as to estimate the resources and time required for each action1. The other options are not as useful as results from a gap analysis for planning purposes when preparing an action plan to achieve compliance with local regulatory requirements by an established deadline. Deadlines and penalties for noncompliance are important factors to consider, but they do not provide information on how to achieve compliance or what actions are needed2. Results from a business impact analysis (BIA) are useful for identifying the critical processes and assets that need to be protected, but they do not provide information on how to comply with the regulatory requirements or what actions are needed3. An inventory of security controls currently in place is useful for assessing the current state of compliance, but it does not provide information on how to comply with the regulatory requirements or what actions are needed4. Reference: 3: Business impact analysis (BIA) - Wikipedia 2: Compliance Gap Analysis & Effectiveness Evaluation | SMS 1: What is Gap Analysis in Compliance | Scytale 4: Gap Analysis & Risk Assessment - Riddle Compliance


NEW QUESTION # 85
随着对远程访问安全性需求的增加,组织发现有必要快速转变为在家工作模式。
应立即关注以下哪项?

  • A. 启用网络级身份验证
  • B. 增强网络响应能力
  • C. 加强端点安全
  • D. 转向零信任访问模型

Answer: C


NEW QUESTION # 86
組織的安全策略是禁止訪問筆記本電腦和台式機上的 USB 存儲設備。以下哪一項是給予政策例外的最有力的理由?

  • A. 收益大於潛在風險。
  • B. 根據用戶角色啟用USB存儲設備。
  • C. 用戶接受不合規的風險。
  • D. 訪問權限僅限於只讀。

Answer: A

Explanation:
The strongest justification for granting an exception to the security policy that disables access to USB storage devices on laptops and desktops is that the benefit is greater than the potential risk. A security policy is a document that defines the goals, objec-tives, principles, roles, responsibilities, and requirements for protecting information and systems in an organization. A security policy should be based on a risk assessment that identifies and evaluates the threats and vulnerabilities that affect the organiza-tion's assets, as well as the potential impact and likelihood of incidents. A security pol-icy should also be aligned with the organization's business objectives and risk appe-tite1. However, there may be situations where a security policy cannot be fully enforced or complied with due to technical, operational, or business reasons. In such cases, an exception to the policy may be requested and granted by an authorized person or body, such as a security manager or a policy committee. An exception to a security policy should be justified by a clear and compelling reason that outweighs the risk of non-compliance. An exception to a security policy should also be documented, approved, monitored, reviewed, and revoked as necessary2. The strongest justification for grant-ing an exception to the security policy that disables access to USB storage devices on laptops and desktops is that the benefit is greater than the potential risk. USB storage devices are portable devices that can store large amounts of data and can be easily connected to laptops and desktops via USB ports. They can provide several benefits for users and organizations, such as:
* Enhancing data mobility and accessibility
* Improving data backup and recovery
* Supporting data sharing and collaboration
* Enabling data encryption and authentication
However, USB storage devices also pose significant security risks for users and organi-zations, such as:
* Introducing malware or viruses to laptops and desktops
* Exposing sensitive data to unauthorized access or disclosure
* Losing or stealing data due to device loss or theft
* Violating security policies or regulations
Therefore, an exception to the security policy that disables access to USB storage de-vices on laptops and desktops should only be granted if the benefit of using them is greater than the potential risk of compromising them. For example, if a user needs to transfer a large amount of data from one laptop to another in a remote location where there is no network connection available, and the data is encrypted and protected by a strong password on the USB device, then the benefit of using the USB device may be greater than the risk of losing or exposing it. The other options are not the strongest justifications for granting an exception to the security policy that disables access to USB storage devices on laptops and desktops. Enabling USB storage devices based on user roles is not a justification, but rather a possible way of implementing a more gran-ular or flexible security policy that allows different levels of access for different types of users3. Users accepting the risk of noncompliance is not a justification, but rather a requirement for requesting an exception to a security policy that acknowledges their responsibility and accountability for any consequences of noncompliance4. Accessing being restricted to read-only is not a justification, but rather a possible control that can reduce the risk of introducing malware or viruses from USB devices to laptops and desktops5. Reference: 1: Information Security Policy - NIST 2: Policy Exception Man-agement - ISACA 3: Deploy and manage Removable Storage Access Control using In-tune - Microsoft Learn 4: Policy Exception Request Form - University of California 5: Re-movable Media Policy Writing Tips - CurrentWare


NEW QUESTION # 87
在企業中部署自帶設備 (BYOD) 移動程序時,以下哪一項是信息安全經理面臨的主要挑戰?

  • A. 移動應用程序控制
  • B. 配置管理
  • C. 最終用戶接受
  • D. 設備安全性不一致

Answer: D

Explanation:
Inconsistent device security is the primary challenge for an information security manager when deploying a bring your own device (BYOD) mobile program in an enterprise because it increases the risk of data breaches and compromises. A BYOD mobile program allows employees to use their personal devices, such as smartphones, tablets, or laptops, to access the organization's network, applications, and data. However, personal devices may have different operating systems, versions, configurations, and security settings than the organization's standard devices. Moreover, personal devices may not be updated regularly, may have unauthorized or malicious apps installed, or may not have adequate protection against malware or theft. Inconsistent device security makes it difficult for the information security manager to enforce and monitor the security policies and controls across all devices, as well as to ensure compliance with the regulatory requirements for data privacy and security. Therefore, inconsistent device security is the correct answer.
Reference:
https://simplemdm.com/blog/challenges-of-bring-your-own-device-byod-policy/
https://www.timedoctor.com/blog/byod-pros-and-cons/
https://www.ncsc.gov.uk/files/NCSC-Vendor-Security-Assessment.pdf


NEW QUESTION # 88
以下哪一項最能讓新的信息安全經理獲得高級管理層對信息安全治理計劃的支持?

  • A. 提供組織內信息安全事件的示例
  • B. 討論類似組織中的治理計劃
  • C. 展示該計劃對組織的價值
  • D. 提供外部審核結果

Answer: C

Explanation:
The best way to obtain senior management support for an information security governance program is to demonstrate the program's value to the organization, such as how it can help achieve business objectives, reduce operational risks, enhance resilience, and comply with regulations. Demonstrating the value of information security governance can help senior management understand the benefits and costs of the program, and motivate them to participate in the decision-making process. The other options, such as discussing governance programs in similar organizations, providing external audit results, or providing examples of incidents, may not be sufficient or persuasive enough to obtain senior management support, as they may not reflect the specific needs and goals of the organization. Reference:
https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/how-to-involve-senior-management-in-the-information-security-governance-process
https://www.sans.org/white-papers/992/
https://www.govtech.com/blogs/lohrmann-on-cybersecurity/how-to-get-management-support-for-your-security-program.html


NEW QUESTION # 89
......

Latest Questions CISM-CN Guide to Prepare Free Practice Tests: https://www.testinsides.top/CISM-CN-dumps-review.html