ExamGecko
Question list
Search
Search

Question 286 - CISM discussion

Report
Export

An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?

A.
Initiate incident response.
Answers
A.
Initiate incident response.
B.
Disable remote
Answers
B.
Disable remote
C.
Initiate a device reset.
Answers
C.
Initiate a device reset.
D.
Conduct a risk assessment.
Answers
D.
Conduct a risk assessment.
Suggested answer: A

Explanation:

Initiating incident response is the first course of action for an information security manager when an employee reports the loss of a personal mobile device containing corporate information. This will help to contain the incident, assess the impact, and take appropriate measures to prevent or mitigate further damage. According to ISACA, incident management is one of the key processes for information security governance. Initiating a device reset, disabling remote access, and conducting a risk assessment are possible subsequent actions, but they should be part of the incident response plan.

Reference: 1: Find, lock, or erase a lost Android device - Google Account Help 2: Find, lock, or erase a lost Android device - Android Help 3: Lost or Stolen Mobile Device Procedure - Information Security Office : CISM Practice Quiz | CISM Exam Prep | ISACA : 200 CISM Exam Prep Questions | Free Practice Test | Simplilearn : CISM practice questions to prep for the exam | TechTarget

asked 01/10/2024
max artusa
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first