CISM Exam Question 71

To overcome the perception that security is a hindrance to business activities, it is important for an information security manager to:
  • CISM Exam Question 72

    Which of the following is the BEST way to compete for funding for an information security program in an organization with limited resources?
  • CISM Exam Question 73

    An organization's information security manager is performing a post-incident review of a security incident in which the following events occurred:
    * A bad actor broke into a business-critical FTP server by brute forcing an administrative password
    * The third-party service provider hosting the server sent an automated alert message to the help desk, but was ignored
    * The bad actor could not access the administrator console, but was exposed to encrypted data transferred to the server
    * After three hours, the bad actor deleted the FTP directory, causing incoming FTP attempts by legitimate customers to fail Which of the following could have been prevented by conducting regular incident response testing?
  • CISM Exam Question 74

    An information security manager is alerted to multiple security incidents across different business units, with unauthorized access to sensitive data and potential data exfiltration from critical systems. Which of the following is the BEST course of action to appropriately classify and prioritize these incidents?
  • CISM Exam Question 75

    During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to: