Answers (Grade A+)
Which of the following practices completely prevents a man-in-the-
middle attack between two hosts? -
correct answer ✅Connect through an IP Security v6 virtual private
network
Which of the following considerations is the MOST important one in
the use of a vulnerability scanning tool? -
correct answer ✅Regular updates
Which of the following should the information security manager
implement to protect a network against unauthorized external
connections to corporate systems? -
correct answer ✅Strong authentication
Obtaining another party's public key is required to initiate which of
the following activities? -
correct answer ✅Authentication
Which of the following devices could potentially stop a structured
query language injection attack? -
correct answer ✅An intrusion prevention system
, ISACA CISM Exam Questions &
Answers (Grade A+)
When a user employs a client-side digital certificate to authenticate
to a web server through Secure Sockets Layer, confidentiality is
MOST vulnerable to which of the following? -
correct answer ✅Trojan
What is an advantage of sending messages using steganographic
techniques as opposed to using encryption? -
correct answer ✅The existence of messages is hidden in another
file, such as a JPEG image, when using steganography.
Which of the following BEST ensures nonrepudiation? -
correct answer ✅Digital signatures
How does the development of an information security program
begin? -
correct answer ✅Required outcomes are defined.
What is the BEST policy for securing data on mobile universal serial
bus (USB) drives? -
correct answer ✅Encryption