
Latest CISM-CN exam dumps with real ISACA questions and answers
CISM-CN Exam in First Attempt Guaranteed
NEW QUESTION # 267
下列哪一項對於幫助高階管理層了解資訊安全合規狀況最有用?
- A. 業務影響分析 (BIA) 結果
- B. 關鍵績效指標 (KPI)
- C. 風險評估結果
- D. 產業基準
Answer: B
Explanation:
Explanation
Key performance indicators (KPIs) are metrics that measure the effectiveness and ef-ficiency of information security processes and activities. They help senior manage-ment understand the status of information security compliance by providing relevant, timely and accurate information on the performance of security controls, the level of risk exposure, the return on security investment and the progress toward security ob-jectives. KPIs can also be used to benchmark the organization's security performance against industry standards or best practices. KPIs should be aligned with the organiza-tion's strategic goals and risk appetite, and should be reported regularly to senior man-agement and other stakeholders.
References:
*1 Key Performance Indicators for Security Governance, Part 1 - ISACA
*2 Key Performance Indicators for Security Governance, Part 2 - ISACA
*3 Compliance Metrics and KPIs For Measuring Compliance Effectiveness - Reciprocity
*4 14 Cybersecurity Metrics + KPIs You Must Track in 2023 - UpGuard
NEW QUESTION # 268
響應勒索軟件攻擊時的主要考慮因素應是確保:
- A. 企業可以經營
- B. 勒索軟件攻擊已被遏制
- C. 備份可用。
- D. 已應用最新補丁。
Answer: A
Explanation:
Ensuring the business can operate is the primary consideration when responding to a ransomware attack because it helps to minimize the disruption and impact of the attack on the organization's mission-critical functions and services. Ransomware is a type of malware that encrypts the files or systems of the victims and demands payment for their decryption. Ransomware attacks can cause significant operational, financial, and reputational damage to organizations, especially if they affect their core business processes or customer data. Therefore, ensuring the business can operate is the primary consideration when responding to a ransomware attack.
Reference:
https://www.cisa.gov/stopransomware/ransomware-guide
https://csrc.nist.gov/Projects/ransomware-protection-and-response
https://learn.microsoft.com/en-us/azure/security/fundamentals/ransomware-detect-respond
NEW QUESTION # 269
需要對 PC 進行取證檢查,但 PC 已關閉。應首先執行以下哪項操作?
- A. 使用備份實用程序執行硬盤驅動器備份。
- B. 使用CD-ROM驅動器中的第三方取證軟件重新啟動系統
- C. 使用網絡執行計算機備份
- D. 使用寫阻止設備對硬盤執行逐位備份
Answer: D
Explanation:
Performing a bit-by-bit backup of the hard disk using a write-blocking device is the first step to do when a forensic examination of a PC is required, but the PC has been switched off because it helps to create a forensically sound copy of the original evidence without altering or damaging it. A bit-by-bit backup, also known as a physical or raw image, is a complete copy of every bit on the hard disk, including the unallocated or deleted data. A write-blocking device is a hardware or software tool that prevents any write operations to the hard disk, such as updating timestamps or changing file attributes. Performing a bit-by-bit backup of the hard disk using a write-blocking device ensures the integrity and authenticity of the evidence and allows the forensic analysis to be conducted on the duplicate image rather than the original source. Therefore, performing a bit-by-bit backup of the hard disk using a write-blocking device is the correct answer.
Reference:
https://en.wikipedia.org/wiki/Computer_forensics
https://resources.infosecinstitute.com/topic/computer-forensics-forensic-analysis-examination-planning/
https://www.computer-forensics-recruiter.com/topics/examination_steps/
NEW QUESTION # 270
以下哪項最能幫助信息安全經理獲得實施安全控制的組織支持?
- A. 傳達業務影響分析 (BIA) 結果
- B. 定義組織的風險管理框架
- C. 建立有效的利益相關者關係
- D. 定期進行漏洞評估
Answer: C
Explanation:
The best way to obtain organizational support for the implementation of security controls is to establish effective stakeholder relationships. Stakeholders are the individuals or groups that have an interest or influence in the organization's information security objectives, activities, and outcomes. They may include senior management, business owners, users, customers, regulators, auditors, vendors, and others. By establishing effective stakeholder relationships, the information security manager can communicate the value and benefits of security controls to the organization's performance, reputation, and competitiveness. The information security manager can also solicit feedback and input from stakeholders to ensure that the security controls are aligned with the organization's needs and expectations. The information security manager can also foster collaboration and cooperation among stakeholders to facilitate the implementation and operation of security controls. The other options are not the best way to obtain organizational support for the implementation of security controls, although they may be some steps or outcomes of the process. Conducting periodic vulnerability assessments is a technical activity that can help identify and prioritize the security weaknesses and gaps in the organization's information assets and systems. However, it does not necessarily obtain organizational support for the implementation of security controls unless the results are communicated and justified to the stakeholders. Communicating business impact analysis (BIA) results is a reporting activity that can help demonstrate the potential consequences of disruptions or incidents on the organization's critical business processes and functions. However, it does not necessarily obtain organizational support for the implementation of security controls unless the results are linked to the organization's risk appetite and tolerance. Defining the organization's risk management framework is a strategic activity that can help establish the policies, procedures, roles, and responsibilities for managing information security risks in a consistent and effective manner. However, it does not necessarily obtain organizational support for the implementation of security controls unless the framework is endorsed and enforced by the stakeholders
NEW QUESTION # 271
以下哪項最能確保及時、可靠地訪問服務?
- A. 真實性
- B. 可用性
- C. 恢復時間目標 (RTO)
- D. 不可否認性
Answer: B
NEW QUESTION # 272
威胁和脆弱性评估很重要,主要是因为它们是:
- A. 组织安全态势的要素。
- B. 设定控制目标的依据。
- C. 用于建立安全投资
- D. 需要评估风险。
Answer: B
Explanation:
Threat and vulnerability assessments are important PRIMARILY because they are the basis for setting control objectives. Control objectives are the desired outcomes or goals of implementing security controls in an information system. They are derived from the risk assessment process, which identifies and evaluates the threats and vulnerabilities that could affect the system's confidentiality, integrity and availability. By conducting threat and vulnerability assessments, an organization can determine the level of risk it faces and establish the appropriate control objectives to mitigate those risks.
NEW QUESTION # 273
以下哪项最有助于确定组织应实施哪些信息安全策略?
- A. 风险评估
- B. 业务影响分析(BIA)
- C. 漏洞评估
- D. 行业最佳实践
Answer: A
NEW QUESTION # 274
以下哪项是组织确保事件响应团队做好适当准备的最佳方式?
- A. 提供第三方取证公司的培训
- B. 进行适合组织的桌面练习
- C. 为响应团队获得行业认证
- D. 记录组织和响应步骤的多个场景
Answer: B
Explanation:
The BEST way for an organization to ensure that incident response teams are properly prepared is by conducting tabletop exercises appropriate for the organization.
Tabletop exercises are an effective way to test and validate an organization's incident response plan (IRP) and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan. By conducting regular tabletop exercises, the incident response team can stay current with changes in the threat landscape and ensure that they are prepared to respond to incidents effectively.
According to the Certified Information Security Manager (CISM) Study Manual, "Tabletop exercises are a valuable tool for testing and validating the effectiveness of the IRP and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan." While providing training from third-party forensics firms, obtaining industry certifications, and documenting multiple scenarios for the organization and response steps can all be useful in preparing incident response teams, they are not as effective as conducting tabletop exercises appropriate for the organization.
Reference:
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 324.
NEW QUESTION # 275
如果滿足以下條件,資訊安全治理框架的有效性將得到最好的增強:
- A. 風險管理融入營運和策略活動。
- B. 顧問審查資訊安全治理框架。
- C. 管理階層提倡遵守法規的文化。
- D. 資訊系統審計員有權評估治理活動
Answer: A
Explanation:
Explanation
The effectiveness of an information security governance framework will best be enhanced if risk management is built into operational and strategic activities. This is because risk management is a key component of information security governance, which is the process of establishing and maintaining a framework to provide assurance that information security strategies are aligned with and support business objectives, are consistent with applicable laws and regulations, and are effectively managed and measured. Risk management involves identifying, analyzing, evaluating, treating, monitoring, and communicating information security risks that may affect the organization's objectives, assets, and stakeholders. By integrating risk management into operational and strategic activities, the organization can ensure that information security risks are considered and addressed in every decision and action, and that the information security governance framework is aligned with the organization's risk appetite and tolerance. This also helps to optimize the allocation of resources, enhance the performance and value of information security, and improve the accountability and transparency of information security governance.
References = CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section:
Information Security Governance Framework, page 181; CISM Review Manual, 16th Edition, Chapter 2:
Information Risk Management, Section: Risk Management, page 812; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 53, page 493.
NEW QUESTION # 276
信息安全经理了解到 IT 人员没有遵守信息安全策略,因为这导致流程效率低下。信息安全经理应该首先做什么?
- A. 确定与不遵守政策相关的风险。
- B. 建议 IT 更新信息安全政策和程序。
- C. 要求内部审计对政策制定过程进行审查,
- D. 在 IT 职能部门内进行用户意识培训。
Answer: A
NEW QUESTION # 277
以下哪项是有效信息安全治理的最佳指标?
- A. 信息安全被认为是整个信息安全团队的责任。
- B. 信息安全控制分配给风险负责人。
- C. 信息安全治理基于外部安全框架。
- D. 信息安全融入公司治理。
Answer: D
NEW QUESTION # 278
依安全等級標註資訊:
- A. 如果資訊處理不安全,會影響後果。
- B. 減少所需對策的數量和種類。
- C. 減少為每個分類確定基線控制的需要。
- D. 提高人們安全處理資訊的可能性。
Answer: D
Explanation:
Explanation
Labeling information according to its security classification enhances the likelihood of people handling information securely. Security classification is a process of categoriz-ing information based on its level of sensitivity and importance, and applying appropri-ate security controls based on the level of risk associated with that infor-mation1. Labeling is a process of marking the information with the appropriate classifi-cation level, such as public, internal, confidential, secret, or top secret2. The purpose of labeling is to inform the users of the information about its value and protection re-quirements, and to guide them on how to handle it securely. Labeling can help users to:
*Identify the information they are dealing with and its classification level
*Understand their roles and responsibilities regarding the information
*Follow the security policies and procedures for the information
*Avoid unauthorized access, disclosure, modification, or destruction of the information
*Report any security incidents or breaches involving the information
Labeling can also help organizations to:
*Track and monitor the information and its usage
*Enforce access controls and encryption for the information
*Audit and review the compliance with security standards and regulations for the infor-mation
*Educate and train employees and stakeholders on information security awareness and best practices Therefore, labeling information according to its security classification enhances the likelihood of people handling information securely, as it increases their awareness and accountability, and supports the implementation of security measures. The other op-tions are not the primary benefits of labeling information according to its security clas-sification. Reducing the number and type of countermeasures required is not a benefit, but rather a consequence of applying security controls based on the classification lev-el. Reducing the need to identify baseline controls for each classification is not a bene-fit, but rather a prerequisite for labeling information according to its security classifica-tion. Affecting the consequences if information is handled insecurely is not a benefit, but rather a risk that needs to be managed by implementing appropriate security con-trols and incident response procedures. References: 1: Information Classification - Ad-visera 2:
Information Classification in Information Security - GeeksforGeeks : Infor-mation Security Policy - NIST :
Information Security Classification Framework - Queensland Government
NEW QUESTION # 279
某個組織正在考慮使用第三方來託管敏感的存檔資料。在建立關係之前,下列哪一項是最需要驗證的?
- A. 供應商的資料中心位於同一地理區域。
- B. 加密金鑰不提供給供應商。
- C. 供應商的控制符合組織的安全標準。
- D. 定期對供應商的營運進行獨立審核。
Answer: C
Explanation:
Explanation
The most important thing to verify before entering into a relationship with a third party to host sensitive archived data is the vendor's controls are in line with the organization's security standards. This is because the organization is ultimately responsible for the security and privacy of its data, even if it is stored or processed by a third party. The organization should ensure that the vendor has adequate and effective controls to protect the data from unauthorized access, modification, disclosure, or destruction. The organization should also ensure that the vendor complies with the applicable laws and regulations regarding data protection, such as the General Data Protection Regulation (GDPR) in the European Union. The organization should conduct a thorough risk assessment of the vendor and its services, and establish a clear contract that defines the roles, responsibilities, expectations, and obligations of both parties.
References = CISM Review Manual 15th Edition, Chapter 3, Section 3.2.1, page 1341; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 2, page 2
NEW QUESTION # 280
以下哪项提供了对组织面临的持续威胁的最全面洞察?
- A. 风险登记册
- B. 业务影响分析(BIA)
- C. 漏洞评估
- D. 渗透测试
Answer: A
Explanation:
A risk register provides the MOST comprehensive insight into ongoing threats facing an organization. This is because a risk register is a document that records and tracks the identified risks, their likelihood, impact, mitigation strategies, and status. A risk register helps an organization to monitor and manage the threats that could affect its objectives, assets, and operations. A risk register also helps an organization to prioritize its response efforts and allocate its resources accordingly.
NEW QUESTION # 281
攻击成功后,信息安全经理应该确信恶意软件@在哪个事件响应阶段完成后继续传播?
- A. 标识
- B. 根除
- C. 恢复
- D. 遏制
Answer: D
NEW QUESTION # 282
下列哪一項對於資訊安全計畫的有效性最重要?
- A. 風險管理
- B. 安全指標
- C. 組織文化
- D. IT 治理
Answer: A
Explanation:
Explanation
Risk management is the most important factor for the effectiveness of an information security program, as it provides a systematic and consistent approach to identify, assess, treat, and monitor the information security risks that could affect the organization's objectives. Risk management also helps to align the security program with the business strategy, prioritize the security initiatives and resources, and communicate the value of security to the stakeholders.
References = CISM Review Manual 2022, page 3071; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.1
NEW QUESTION # 283
將惡意軟體事件分類時,應先執行下列哪一步?
- A. 保留取證影像
- B. 移除惡意軟體
- C. 包含受影響的系統
- D. 將備份與生產進行比較
Answer: C
Explanation:
Explanation
The first step when performing triage of a malware incident is to contain the affected system, which means isolating it from the network and preventing any further communication or data transfer with the attacker or other compromised systems. Containing the affected system helps to limit the scope and impact of the incident, preserve the evidence, and prevent the spread of the malware to other systems.
References = NIST SP 800-61 Revision 2, CISM Review Manual 15th Edition
NEW QUESTION # 284
以下哪项是成功的信息安全文化的最佳标志?
- A. 定期进行渗透测试并纠正发现的问题。
- B. 根据工作职能为个人分配角色。
- C. 最终用户知道如何识别和报告事件。
- D. 分配给信息安全的预算是足够的。
Answer: C
NEW QUESTION # 285
為了幫助確保組織的網絡安全計劃滿足業務需求,以下哪項最重要?
- A. 信息安全意識培訓
- B. 信息安全治理
- C. 信息安全指標
- D. 風險評估計劃
Answer: B
Explanation:
Information security governance is MOST important to have in place to help ensure an organization's cybersecurity program meets the needs of the business. This is because information security governance provides the strategic direction, oversight and accountability for the cybersecurity program. It also ensures that the program aligns with the business objectives, risk appetite and compliance requirements of the organization. Information security governance involves defining roles and responsibilities, establishing policies and standards, setting goals and metrics, allocating resources and monitoring performance of the cybersecurity program.
NEW QUESTION # 286
在環境快速變化的組織中,業務管理層已經接受了資訊安全風險。對於資安經理來說,最重要的是確保:
- A. 遵守風險接受框架。
- B. 定期檢視接受的理由。
- C. 接受與業務策略一致。
- D. 變更活動已記錄。
Answer: B
NEW QUESTION # 287
在製定資訊安全計畫的關鍵績效指標 (KPI) 時,下列哪一項是最重要的考量因素?
- A. 與風險偏好一致
- B. 與業務計劃保持一致
- C. 與財務報告保持一致
- D. 與產業框架保持一致
Answer: B
Explanation:
Explanation
Explore
The most important consideration when developing key performance indicators (KPIs) for the information security program is B. Alignment with business initiatives. This is because KPIs are measurable values that demonstrate how effectively the information security program is achieving its objectives and delivering value to the organization. KPIs should be aligned with the business initiatives, such as the strategic goals, the mission, the vision, and the values of the organization, and support the achievement of the desired outcomes and benefits. KPIs should also reflect the needs, expectations, and challenges of the business stakeholders, and provide relevant, meaningful, and actionable information for decision making and improvement. KPIs should not be too technical, complex, or ambiguous, but rather focus on the key aspects of information security performance, such as risk, compliance, maturity, value, and effectiveness.
KPIs are measurable values that demonstrate how effectively the information security program is achieving its objectives and delivering value to the organization. KPIs should be aligned with the business initiatives, such as the strategic goals, the mission, the vision, and the values of the organization, and support the achievement of the desired outcomes and benefits. (From CISM Manual or related resources) References = CISM Review Manual 15th Edition, Chapter 1, Section 1.3.2, page 281; CISM Domain - Information Security Program Development | Infosec2; KPIs in Information Security: The 10 Most Important Security Metrics3
NEW QUESTION # 288
以下哪项对于在安全报告中传达前瞻性趋势最有效?
- A. 关键风险指标(KRIs)
- B. 关键目标指标(KGIs)
- C. 关键绩效指标 (KPI)
- D. 关键控制指标(KCIs)
Answer: C
Explanation:
Key performance indicators (KPIs) are the most effective for communicating forward-looking trends within security reporting. KPIs are metrics used to measure progress towards a specific goal or objective, and can provide insight into the current state of security and any potential issues or risks that may arise in the future. Key control indicators (KCIs), key risk indicators (KRIs), and key goal indicators (KGIs) are all important for measuring security performance and identifying areas for improvement, but KPIs are the most effective for communicating forward-looking trends.
Reference that support this statement include:
"Key Performance Indicators (KPIs) for IT Security" by ISACA. This resource states that KPIs "can be used to measure the performance of security controls and identify trends in security risks."
"Measuring and Managing Information Risk: A FAIR Approach" by The Open Group. This guide states that "KPIs are used to track progress over time and to identify areas where improvements may be needed."
"Key Performance Indicators (KPIs) for Cyber Security" by SANS Institute. This resource states that "KPIs can be used to identify potential risks and measure the effectiveness of security controls.
NEW QUESTION # 289
一個組織收購了國外的公司,以在新市場中獲得優勢。下列哪一項是資安經理應採取的第一步?
- A. 合併兩個現有的資訊安全程序。
- B. 將現有的資訊安全計畫應用於被收購公司。
- C. 確定將使用哪個國家的資訊安全法規。
- D. 評估適用於被收購公司的資訊安全法。
Answer: D
NEW QUESTION # 290
为了在灾难期间保持运营,组织应该调用以下哪些计划?
- A. 事件响应计划
- B. 灾难恢复计划(DRP)
- C. 业务连续性计划(BCP)
- D. 业务应急计划
Answer: C
NEW QUESTION # 291
事件回應團隊由一群經驗豐富的人員組成,在第一次演習中哪種類型的演習對團隊最有利?
- A. 桌面練習
- B. 黑盒滲透測試
- C. 紅隊演習
- D. 災難復原練習
Answer: A
NEW QUESTION # 292
......
Exam Sure Pass ISACA Certification with CISM-CN exam questions: https://www.validdumps.top/CISM-CN-exam-torrent.html
Download Real CISM-CN Exam Dumps for candidates. 100% Free Dump Files: https://drive.google.com/open?id=1c3e2SfKjoLBa0DATDH578BD-u3VifSJw