ExamGecko
Question list
Search
Search

Question 594 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST when a vulnerability has been disclosed?

A.
Perform a patch update.
Answers
A.
Perform a patch update.
B.
Conduct a risk assessment.
Answers
B.
Conduct a risk assessment.
C.
Perform a penetration test.
Answers
C.
Perform a penetration test.
D.
Conduct an impact assessment.
Answers
D.
Conduct an impact assessment.
Suggested answer: B

Explanation:

According to the CISM Review Manual, the first step an information security manager should take when a vulnerability has been disclosed is to conduct a risk assessment to determine the likelihood and impact of the vulnerability being exploited, and the appropriate response strategy. Performing a patch update, a penetration test or an impact assessment are possible subsequent steps, but not the first one.

Reference= CISM Review Manual, 27th Edition, Chapter 3, Section 3.3.2, page 1331.

asked 01/10/2024
Pedro Miguel Garcia Valdes
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first