UPDATED [Feb 24, 2025] Pass Certified Information Security Manager Exam with Latest Questions [Q130-Q146]

UPDATED [Feb 24, 2025] Pass Certified Information Security Manager Exam with Latest Questions

CISM Exam Practice Questions prepared by ISACA Professionals

新问题 130
An organization with a strict need-to-know information access policy is about to launch a knowledge management intranet. Which of the following is the MOST important activity to ensure compliance with existing security policies?

 
 
 
 

新问题 131
Which of the following is a potential indicator of inappropriate Internet use by staff?

 
 
 
 

新问题 132
When establishing metrics for an information security program, the BEST approach is to identify indicators that:

 
 
 
 

新问题 133
An organization’s CIO has tasked the information security manager with drafting the charter for an information security steering committee. The committee will be comprised of the CIO, the IT shared services manager, the vice president of marketing, and the information security manager.
Which of the following is the MOST significant issue with the development of this committee?

 
 
 
 

新问题 134
Which of the following is BEST used to determine the maturity of an information security program?

 
 
 
 

新问题 135
An intrusion detection system (IDS) should:

 
 
 
 

新问题 136
Which of the following BEST reduces the likelihood of leakage of private information via email?

 
 
 
 

新问题 137
Which of the following is the BEST way to ensure that organizational security policies comply with data security regulatory requirements?

 
 
 
 

新问题 138
Which of the following is the PRIMARY reason that an information security manager would contract with an external provider to perform penetration testing?

 
 
 
 

新问题 139
Recovery point objectives (RPOs) can be used to determine which of the following?

 
 
 
 

新问题 140
Which of the following is the BEST approach to incident response for an organization migrating to a cloud-based solution?

 
 
 
 

新问题 141
Which of the following is MOST important in increasing the effectiveness of incident responders?

 
 
 
 

新问题 142
When a proposed system change violates an existing security standard, the conflict would be BEST resolved by:

 
 
 
 

新问题 143
When electronically stored information is requested during a fraud investigation, which of the following should be the FIRST priority?

 
 
 
 

新问题 144
A risk assessment exercise has identified the threat of a denial of service (DoS) attack. Executive management has decided to take no further action related to this risk. The MOST likely reason for this decision is:

 
 
 
 

新问题 145
A software vendor has announced a zero-day vulnerability that exposes an organization’s critical business systems, following should be the information security manager’s PRIMARY concern?

 
 
 
 

新问题 146
Which of the following service offerings in a typical Infrastructure as a Service (IaaS) model will BEST enable a cloud service provider to assist customers when recovering from a security incident?

 
 
 
 

CISM Exam Practice Materials Collection: https://www.trainingdump.com/ISACA/CISM-practice-exam-dumps.html