Isaca CISM - Certified Information Security Manager Exam
Page: 3 / 250
Total 1250 questions
Question #11 (Topic: Single Topic)
Which of the following is the BEST method to protect consumer private information for an online public website?
A. Apply strong authentication to online accounts
B. Encrypt consumer data in transit and at rest
C. Use secure encrypted transport layer
D. Apply a masking policy to the consumer data
Answer: B
Question #12 (Topic: Single Topic)
Which of the following is the MOST important consideration in a bring your own device (BYOD) program to protect company data in the event of a loss?
A. The ability to remotely locate devices
B. The ability to centrally manage devices
C. The ability to restrict unapproved applications
D. The ability to classify types of devices
Answer: B
Question #13 (Topic: Single Topic)
An information security manager has been asked to determine whether an information security initiative has reduced risk to an acceptable level. Which of the
following activities would provide the BEST information for the information security manager to draw a conclusion?
following activities would provide the BEST information for the information security manager to draw a conclusion?
A. Initiating a cost-benefit analysis of the implemented controls
B. Performing a risk assessment
C. Reviewing the risk register
D. Conducting a business impact analysis (BIA)
Answer: B
Question #14 (Topic: Single Topic)
An organization that uses external cloud services extensively is concerned with risk monitoring and timely response. The BEST way to address this concern is to
ensure:
ensure:
A. the availability of continuous technical support.
B. appropriate service level agreements (SLAs) are in place.
C. a right-to-audit clause is included in contracts.
D. internal security standards are in place.
Answer: B
Question #15 (Topic: Single Topic)
Which of the following is the BEST way to ensure that organizational security policies comply with data security regulatory requirements?
A. Obtain annual sign-off from executive management.
B. Align the policies to the most stringent global regulations.
C. Send the policies to stakeholders for review.
D. Outsource compliance activities.
Answer: B