Isaca CISM Practice Test - Questions Answers, Page 55

List of questions
Question 541

Which of the following is the BEST indicator of the maturity level of a vendor risk management process?
Question 542

Which of the following should be the PRIMARY focus of a status report on the information security program to senior management?
Question 543

Which of the following is the BEST indication that an organization has integrated information security governance with corporate governance?
Question 544

Which of the following is the PRIMARY objective of a cyber resilience strategy?
Question 545

Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?
Question 546

When testing an incident response plan for recovery from a ransomware attack, which of the following is MOST important to verify?
Question 547

Which of the following elements of a service contract would BEST enable an organization to monitor the information security risk associated with a cloud service provider?
Question 548

The PRIMARY purpose for continuous monitoring of security controls is to ensure:
Question 549

Which of the following is the MOST effective way to ensure the security of services and solutions delivered by third-party vendors?
Question 550

Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?
Question