Isaca CISM Practice Test - Questions Answers, Page 59

List of questions
Question 581

An organization's information security team presented the risk register at a recent information security steering committee meeting. Which of the following should be of MOST concern to the committee?
Question 582

Which of the following BEST illustrates residual risk within an organization?
Question 583

After the occurrence of a major information security incident, which of the following will BEST help an information security manager determine corrective actions?
Question 584

Before approving the implementation of a new security solution, senior management requires a business case. Which of the following would BEST support the justification for investment?
Question 585

To inform a risk treatment decision, which of the following should the information security manager compare with the organization's risk appetite?
Question 586

The PRIMARY objective of timely declaration of a disaster is to:
Question 587

What should an information security manager verify FIRST when reviewing an information asset management program?
Question 588

Company A, a cloud service provider, is in the process of acquiring Company B to gain new benefits by incorporating their technologies within its cloud services.
Which of the following should be the PRIMARY focus of Company A's information security manager?
Question 589

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?
Question 590

During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:
Question