CISM Exam Question 41

An organization's main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated task?
  • CISM Exam Question 42

    A newly appointed information security manager of a retailer with multiple stores discovers an HVAC (heating, ventilation, and air conditioning) vendor has remote access to the stores to enable real-time monitoring and equipment diagnostics. Which of the following should be the information security manager's FIRST course of action?
  • CISM Exam Question 43

    An information security manager determines there are a significant number of exceptions to a newly released industry-required security standard. Which of the following should be done NEXT?
  • CISM Exam Question 44

    Which of the following would be MOST helpful to identify worst-case disruption scenarios?
  • CISM Exam Question 45

    Which of the following is the BEST way to ensure the capability to restore clean data after a ransomware attack?