ExamGecko
Question list
Search
Search

Question 246 - CISM discussion

Report
Export

Data entry functions for a web-based application have been outsourced to a third-party service provider who will work from a remote site Which of the following issues would be of GREATEST concern to an information security manager?

A.
The application does not use a secure communications protocol
Answers
A.
The application does not use a secure communications protocol
B.
The application is configured with restrictive access controls
Answers
B.
The application is configured with restrictive access controls
C.
The business process has only one level of error checking
Answers
C.
The business process has only one level of error checking
D.
Server-based malware protection is not enforced
Answers
D.
Server-based malware protection is not enforced
Suggested answer: D

Explanation:

Server-based malware protection is not enforced is the issue that would be of GREATEST concern to an information security manager, as it exposes the web-based application and its data to potential threats from malicious software that can compromise the confidentiality, integrity, and availability of the information. Server-based malware protection is a security control that monitors and blocks malicious activities on the server where the application runs, such as viruses, worms, trojans, ransomware, etc. Without server-based malware protection, the web-based application may be vulnerable to attacks that can damage or destroy the data stored on the server, or disrupt the normal functioning of the application. The other issues are also important, but not as critical as server-based malware protection. The application does not use a secure communications protocol may expose sensitive data in transit to eavesdropping or interception by unauthorized parties. The application is configured with restrictive access controls may limit the access rights of legitimate users to authorized resources, but it does not prevent unauthorized users from accessing them through other means.The business process has only one level of error checking may result in incorrect or inconsistent data entry or processing, but it does not guarantee data quality or accuracy.Reference= CISM Review Manual, 16th Edition, page 1751; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 812

asked 01/10/2024
Carlos Augusto Quintal
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first