Isaca CISM Practice Test - Questions Answers, Page 59
List of questions
Question 581
An organization's information security team presented the risk register at a recent information security steering committee meeting. Which of the following should be of MOST concern to the committee?
Question 582
Which of the following BEST illustrates residual risk within an organization?
Question 583
After the occurrence of a major information security incident, which of the following will BEST help an information security manager determine corrective actions?
Question 584
Before approving the implementation of a new security solution, senior management requires a business case. Which of the following would BEST support the justification for investment?
Question 585
To inform a risk treatment decision, which of the following should the information security manager compare with the organization's risk appetite?
Question 586
The PRIMARY objective of timely declaration of a disaster is to:
Question 587
What should an information security manager verify FIRST when reviewing an information asset management program?
Question 588
Company A, a cloud service provider, is in the process of acquiring Company B to gain new benefits by incorporating their technologies within its cloud services.
Which of the following should be the PRIMARY focus of Company A's information security manager?
Question 589
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?
Question 590
During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:
Question