Isaca CISM Practice Test - Questions Answers, Page 33
List of questions
Question 321
The PRIMARY advantage of performing black-box control tests as opposed to white-box control tests is that they:
Question 322
Which of the following is the BEST justification for making a revision to a password policy?
Question 323
Which of the following BEST enables an information security manager to obtain organizational support for the implementation of security controls?
Question 324
Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?
Question 325
Which of the following is the MOST important issue in a penetration test?
Question 326
Which of the following is the MOST important consideration when determining which type of failover site to employ?
Question 327
What should be an information security manager's FIRST step when developing a business case for a new intrusion detection system (IDS) solution?
Question 328
Of the following, who is MOST appropriate to own the risk associated with the failure of a privileged access control?
Question 329
Which of the following roles is MOST appropriate to determine access rights for specific users of an application?
Question 330
Which of the following metrics provides the BEST evidence of alignment of information security governance with corporate governance?
Question