Isaca CISM Practice Test - Questions Answers, Page 41
List of questions
Question 401
Which of the following is MOST important when defining how an information security budget should be allocated?
Question 402
An information security manager is working to incorporate media communication procedures into the security incident communication plan. It would be MOST important to include:
Question 403
Which of the following is the PRIMARY benefit of an information security awareness training program?
Question 404
A business requires a legacy version of an application to operate but the application cannot be patched. To limit the risk exposure to the business, a firewall is implemented in front of the legacy application. Which risk treatment option has been applied?
Question 405
Which of the following is a viable containment strategy for a distributed denial of service (DDoS) attack?
Question 406
Which of the following is the BEST way to determine if an information security profile is aligned with business requirements?
Question 407
Which of the following is the GREATEST challenge with assessing emerging risk in an organization?
Question 408
Which of the following would BEST enable a new information security manager to obtain senior management support for an information security governance program?
Question 409
An organization has introduced a new bring your own device (BYOD) program. The security manager has determined that a small number of employees are utilizing free cloud storage services to store company data through their mobile devices. Which of the following is the MOST effective course of action?
Question 410
An employee of an organization has reported losing a smartphone that contains sensitive information The BEST step to address this situation is to:
Question