ExamGecko
Question list
Search
Search

Question 202 - CISM discussion

Report
Export

A financial company executive is concerned about recently increasing cyberattacks and needs to take action to reduce risk. The organization would BEST respond by:

A.
increasing budget and staffing levels for the incident response team.
Answers
A.
increasing budget and staffing levels for the incident response team.
B.
implementing an intrusion detection system (IDS).
Answers
B.
implementing an intrusion detection system (IDS).
C.
revalidating and mitigating risks to an acceptable level.
Answers
C.
revalidating and mitigating risks to an acceptable level.
D.
testing the business continuity plan (BCP).
Answers
D.
testing the business continuity plan (BCP).
Suggested answer: C

Explanation:

The best response for the organization to reduce risk from increasing cyberattacks is to revalidate and mitigate risks to an acceptable level. This means that the organization should review its current risk profile, identify any new or emerging threats, vulnerabilities, or impacts, and evaluate the effectiveness of its existing controls and countermeasures. Based on this analysis, the organization should implement appropriate risk treatment strategies, such as avoiding, transferring, accepting, or reducing the risks, to achieve its desired risk appetite and tolerance. The organization should also monitor and review the risk situation and the implemented controls on a regular basis, and update its risk management plan accordingly.This approach is consistent with the ISACA Risk IT Framework, which provides guidance on how to align IT risk management with business objectives and value12.

The other options are not the best responses because they are either too narrow or too reactive. Increasing budget and staffing levels for the incident response team may improve the organization's ability to respond to and recover from cyberattacks, but it does not address the root causes or the prevention of the attacks. Implementing an intrusion detection system (IDS) may enhance the organization's detection and analysis capabilities, but it does not guarantee the protection or mitigation of the attacks. Testing the business continuity plan (BCP) may verify the organization's readiness and resilience to continue its critical operations in the event of a cyberattack, but it does not reduce the likelihood or the impact of the attack.Reference=

Risk IT Framework1

CISM Review Manual, 16th Edition | Print | English2, Chapter 3: Information Risk Management, pages 97-98, 103-104, 107-108, 111-112.

asked 01/10/2024
Juan Gonzalez
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first