Answers (Grade A+)
Who can BEST advocate the development of and ensure the
success of an information security program? -
correct answer ✅steering committee
When designing an intrusion detection system (IDS), the
information security manager should recommend that it be placed:
-
correct answer ✅on a screened subnet (=DMZ)
Which of the following is generally used to ensure that information
transmitted over the Internet is authentic and actually transmitted
by the named sender? -
correct answer ✅embedded digital signature
Where should a firewall be placed? -
correct answer ✅domain boundary (=security boundary)
A control policy is MOST likely to address which of the following
implementation requirements? -
correct answer ✅failure modes
,CISM 8ed domain 3 Exam Questions &
Answers (Grade A+)
Which of the following tools is MOST appropriate to assess whether
information security governance objectives are being met? -
correct answer ✅balanced scorecard (BSC)
Which of the following is MOST important to the success of an
information security program? -
correct answer ✅senior management sponsorship
Which of the following is the MOST effective solution for preventing
individual external to the organization from modifying sensitive
information on a corporate database? -
correct answer ✅screened subnets
Which of the following BEST accomplishes secure customer use of
an e-commerce application? -
correct answer ✅data encryption
Organizations implement ethics training PRIMARILY to provide
guidance to individuals engaged in:(*) -
correct answer ✅monitoring user activities
, CISM 8ed domain 3 Exam Questions &
Answers (Grade A+)
An outsourced service provider must handle sensitive customer
information. Which of the following is MOST important for an
information manager to know? -
correct answer ✅security in storage and transmission of sensitive
data
Which of the following security mechanism is MOST effective in
protecting classified data that have been encrypted to prevent
disclosure and transmission outside the organization's network? -
correct answer ✅safeguards over keys
What is the MOST important success factor to design an effective IT
security awareness program? -
correct answer ✅customize the content to the target audience
A certificate authority (CA) is required for a public key infrastructure
(PKI)(*) -
correct answer ✅except where users attest to each other's identity
Which of the following choices is the WEAKEST link in the
authorized user registration process?(*) -
correct answer ✅the registration authority's (RA's) private key