
CISM-CN Updated Exam Dumps [2024] Practice Valid Exam Dumps Question
CISM-CN Sample with Accurate & Updated Questions
NEW QUESTION # 184
下列哪一項最能讓新的資安經理獲得高階管理層對資訊安全治理計畫的支持?
- A. 展示該計劃對組織的價值
- B. 提供組織內資訊安全事件的範例
- C. 討論類似組織中的治理計劃
- D. 提供外部審核結果
Answer: A
Explanation:
Explanation
The best way to obtain senior management support for an information security governance program is to demonstrate the program's value to the organization, such as how it can help achieve business objectives, reduce operational risks, enhance resilience, and comply with regulations. Demonstrating the value of information security governance can help senior management understand the benefits and costs of the program, and motivate them to participate in the decision-making process. The other options, such as discussing governance programs in similar organizations, providing external audit results, or providing examples of incidents, may not be sufficient or persuasive enough to obtain senior management support, as they may not reflect the specific needs and goals of the organization. References:
* https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/how-to-involve-senior-managemen
* https://www.sans.org/white-papers/992/
* https://www.govtech.com/blogs/lohrmann-on-cybersecurity/how-to-get-management-support-for-your-sec
NEW QUESTION # 185
平衡記分卡最有效地實現信息安全:
- A. 項目管理
- B. 性能。
- C. 風險管理。
- D. 治理。
Answer: D
Explanation:
A balanced scorecard most effectively enables information security govern-ance. Information security governance is the process of establishing and maintaining a framework to provide assurance that information security strategies are aligned with and support business objectives, are consistent with applicable laws and regulations, and are managed effectively and efficiently1. A balanced scorecard is a tool for meas-uring and communicating the performance and progress of an organization toward its strategic goals. It typically includes four perspectives: financial, customer, internal pro-cess, and learning and growth2. A balanced scorecard can help information security managers to:
* Align information security objectives with business objectives and communicate them to senior management and other stakeholders
* Monitor and report on the effectiveness and efficiency of information security processes and controls
* Identify and prioritize improvement opportunities and corrective actions
* Demonstrate the value and benefits of information security investments
* Foster a culture of security awareness and continuous learning
Several sources have proposed models or frameworks for applying the balanced scorecard approach to information security governance34 . The other options are not the most effective applications of a balanced scorecard for information security. Pro-ject management is the process of planning, executing, monitoring, and closing pro-jects to achieve specific objectives within constraints such as time, budget, scope, and quality. A balanced scorecard can be used to measure the performance of individual projects or project portfolios, but it is not specific to information security projects. Per-formance is the degree to which an organization or a process achieves its objectives or meets its standards. A balanced scorecard can be used to measure the performance of information security processes or functions, but it is not limited to performance measurement. Risk management is the process of identifying, analyzing, evaluating, treating, monitoring, and communicating risks that affect an organization's objec-tives. A balanced scorecard can be used to measure the risk exposure and risk appetite of an organization, but it is not a tool for risk assessment or treatment. Reference: 1: Information Security Governance - ISACA 2: Balanced scorecard - Wikipedia 3: Key Per-formance Indicators for Security Governance Part 1 - ISACA 4: A Strategy Map for Se-curity Leaders: Applying the Balanced Scorecard Framework to Information Security - Security Intelligence : How to Measure Security From a Governance Perspective - ISA-CA : Project management - Wikipedia : Performance measurement - Wikipedia : Risk management - Wikipedia
NEW QUESTION # 186
下列哪一項最能實現有效的資訊資產分類流程?
- A. 在分類過程中包含安全要求
- B. 分析稽核結果
- C. 檢視資產的恢復時間目標 (RTO) 要求
- D. 分配所有權
Answer: D
Explanation:
Explanation
Assigning ownership is the best way to enable an effective information asset classification process, as it establishes the authority and responsibility for the information asset and its protection. The owner of the information asset should be involved in the classification process, as they have the best knowledge of the value, sensitivity, and criticality of the asset, as well as the impact of its loss or compromise. The owner should also ensure that the asset is properly labeled, handled, and secured according to its classification level.
(From CISM Review Manual 15th Edition)
References: CISM Review Manual 15th Edition, page 64, section 2.2.1.2; Information Asset and Security Classification Procedure1, section 3.1.
NEW QUESTION # 187
事後審查發現,用戶錯誤導致了重大違規行為。在審核過程中確定以下哪一項最重要?
- A. 針對用戶錯誤的適當紀律程序
- B. 用戶之前造成的事件的證據
- C. 違規發生的時間和地點
- D. 用戶錯誤的根本原因
Answer: D
NEW QUESTION # 188
以下哪種方法是證明信息安全計劃提供適當覆蓋範圍的最佳方法?
- A. 安全風險分析
- B. 差距評估
- C. 漏洞掃描報告
- D. 成熟度評估
Answer: D
NEW QUESTION # 189
從硬碟執行取證資料擷取時建立並外部儲存磁碟雜湊值的主要原因是:
- A. 在分析過程中驗證完整性。
- B. 意外更改時恢復原始資料。
- C. 在分析過程中驗證機密性。
- D. 在媒體發生故障時提供備份。
Answer: A
Explanation:
Explanation
The main purpose of creating and storing an external disk hash value when performing forensic data acquisition from a hard disk is to validate the integrity of the data during the analysis. This is done by comparing the original hash value of the disk to the hash value created during the acquisition process, which can be used to ensure that the data has not been tampered with or corrupted in any way. Additionally, by creating a hash value of the disk, it can be used to quickly verify the integrity of any data that is accessed from the disk in the future.
NEW QUESTION # 190
在取證分析期間嘗試恢復特定文件的資料時,最大的挑戰是:
- A. 已執行進階磁碟格式化。
- B. 磁貼已被覆蓋。
- C. 目錄中的所有檔案已刪除。
- D. 磁碟上的分割區表已被刪除。
Answer: B
Explanation:
Explanation
Data recovery is the process of restoring data that has been lost, corrupted, or deleted. When a file is deleted, it is usually not physically erased from the disk, but only marked as free space by the operating system.
Therefore, it may be possible to recover the file by using specialized tools that scan the disk for the file's data.
However, if the file has been overwritten by another file or data, then the original file's data is lost and cannot be recovered. The other options are not as challenging as overwriting, because they only affect the logical structure of the disk, not the physical data. For example, the partition table, the directory, and the formatting information can be reconstructed or bypassed by using forensic tools. References = CISM Review Manual,
16th Edition, Chapter 5, Section 5.4.1.2
NEW QUESTION # 191
下列哪一項是安全資訊和事件管理 (SIEM) 系統提供的最大價值?
- A. 有利於風險發生的監控
- B. 衡量漏洞對業務流程的影響
- C. 維護安全策略的儲存庫基礎
- D. 將事件日誌重新導向至備用位置以實現業務連續性計劃
Answer: A
Explanation:
Explanation
The greatest value provided by a Security Information and Event Management (SIEM) system is facilitating the monitoring of risk occurrences. SIEM systems collect, analyze and alert on security-related data from various sources such as firewall logs, intrusion detection/prevention systems, and system logs. This allows organizations to identify security threats in real-time and respond quickly, helping to mitigate potential harm to their systems and data.
NEW QUESTION # 192
一家在全球開展業務的組織正計劃利用第三方服務提供者來處理薪資資訊。下列哪一個問題為組織帶來了最大的風險?
- A. 第三方合約不包含違約情況下的賠償條款。
- B. 第三方的服務等級協定 (SLA) 不包括正常運作時間的保證。
- C. 第三方未提供遵守資料產生地當地法規的證據。
- D. 第三方沒有可供審查的獨立控制評估。
Answer: C
Explanation:
Explanation
The third party's lack of compliance with local regulations poses the greatest risk to the organization, as it may expose the organization to legal, regulatory, or reputational consequences, such as fines, sanctions, lawsuits, or loss of customer trust. Payroll information is considered sensitive personal data that may be subject to different privacy and security laws depending on the jurisdiction where it is generated, processed, or stored. Therefore, the organization should ensure that the third party adheres to the applicable regulations and standards, and obtains the necessary certifications or attestations to demonstrate compliance.
References = CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task
1.22; Ensuring Vendor Compliance and Third-Party Risk Mitigation; How to Manage Access Risk Regarding Third-Party Service Providers
NEW QUESTION # 193
在創建組織的災難恢復計劃 (DRP) 時,信息安全經理應首先執行以下哪項操作?
- A. 進行業務影響分析 (BIA)
- B. 制定響應和恢復策略。
- C. 識別響應和恢復學習。
- D. 審查溝通計劃。
Answer: A
Explanation:
Conducting a business impact analysis (BIA) is the first step when creating an organization's disaster recovery plan (DRP) because it helps to identify and prioritize the critical business functions or processes that need to be restored after a disruption, and determine their recovery time objectives (RTOs) and recovery point objectives (RPOs)2. Identifying the response and recovery teams is not the first step, but rather a subsequent step that involves assigning roles and responsibilities for executing the DRP. Reviewing the communications plan is not the first step, but rather a subsequent step that involves defining the communication channels and protocols for notifying and updating the stakeholders during and after a disruption. Developing response and recovery strategies is not the first step, but rather a subsequent step that involves selecting and implementing the appropriate solutions and procedures for restoring the critical business functions or processes. Reference: 2 https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/business-impact-analysis-bia-and-disaster-recovery-planning-drp
NEW QUESTION # 194
以下哪一項最能有效地確保新服務器得到適當的保護?
- A. 執行技術安全標準
- B. 進行滲透測試
- C. 啟動安全掃描
- D. 執行安全代碼審查
Answer: A
Explanation:
Enforcing technical security standards is the most effective way to ensure that a new server is appropriately secured because it ensures that the server complies with the organization's security policies and best practices, such as encryption, authentication, patching, and hardening. Performing secure code reviews is not relevant for securing a new server, unless it is running custom applications that need to be verified for security flaws. Conducting penetration testing is not sufficient for securing a new server, because it only identifies vulnerabilities that can be exploited by attackers, but does not fix them. Initiating security scanning is not sufficient for securing a new server, because it only detects known vulnerabilities or misconfigurations, but does not enforce security standards or remediate issues. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-3/secure-code-review https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 195
下列哪一項事件最有可能要求組織重新檢視其資訊安全框架?
- A. 最近的網路安全攻擊
- B. IT 提供的新服務
- C. 實施了一項新技術
- D. 風險模式的變化
Answer: D
Explanation:
Explanation
Changes to the risk landscape are the most likely events to require an organization to revisit its information security framework, because they may affect the organization's risk appetite, risk tolerance, risk profile, and risk treatment strategies. The information security framework should be aligned with the organization's business objectives and risk management approach, and should be reviewed and updated regularly to reflect the changing internal and external environment.
References =
CISM Review Manual, 16th Edition, ISACA, 2020, p. 35: "The information security framework should be reviewed and updated regularly to ensure that it remains aligned with the enterprise's business objectives and risk management approach and reflects the changing internal and external environment." CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: "Changes in the risk landscape may require the enterprise to revisit its risk appetite, risk tolerance, risk profile, and risk treatment strategies."
NEW QUESTION # 196
下列誰的意見對於資訊安全戰略的發展最為重要?
- A. 進程擁有者
- B. 公司審計師
- C. 最終用戶
- D. 安全架構師。
Answer: A
Explanation:
Explanation
Process owners are the people who are responsible for the design, execution, and improvement of the business processes that support the organization's objectives and operations. Process owners have the greatest importance in the development of an information security strategy, as they provide the input and feedback on the business requirements, expectations, and priorities that the information security strategy should address and support. Process owners also help to identify and assess the risks and impacts that the business processes face, and to define and implement the security controls and measures that can mitigate or reduce them. Process owners also facilitate the alignment and integration of the information security strategy with the business strategy, as well as the communication and collaboration among the various stakeholders and functions involved in the information security program. End users, security architects, and corporate auditors are all important stakeholders in the information security program, but they do not have the greatest importance in the development of an information security strategy. End users are the people who use the information systems and services that the information security program protects and enables. End users provide the input and feedback on the usability, functionality, and performance of the information systems and services, as well as the security awareness and behavior that they exhibit. Security architects are the people who design and implement the security architecture that supports the information security strategy. Security architects provide the input and feedback on the technical requirements, capabilities, and solutions that the information security strategy should leverage and optimize. Corporate auditors are the people who evaluate and verify the compliance and effectiveness of the information security program. Corporate auditors provide the input and feedback on the standards, regulations, and best practices that the information security strategy should follow and adhere to. Therefore, process owners have the greatest importance in the development of an information security strategy, as they provide the input and feedback on the business requirements, expectations, and priorities that the information security strategy should address and support. References = CISM Review Manual 2023, page 31 1; CISM Practice Quiz 2
NEW QUESTION # 197
下列哪一項對改善組織安全狀況的努力影響最大?
- A. 記錄完整的安全性策略和程序
- B. 定期向高階管理層報告
- C. 安全控制自動化
- D. 高層對安全問題的支持態度
Answer: D
Explanation:
Explanation
The supportive tone at the top regarding security is the greatest impact on efforts to improve an organization's security posture. This means that senior management should demonstrate their commitment and leadership to information security by setting clear goals, allocating adequate resources, communicating effectively, and rewarding good practices. A supportive tone at the top can also influence the culture and behavior of the organization, as well as foster trust and collaboration among stakeholders12. References = CISM Review Manual 15th Edition, page 1261; CISM Item Development Guide, page 82
NEW QUESTION # 198
將事件分類標準納入事件回應計畫的最大好處是什麼?
- A. 恢復資源的最佳化分配
- B. 有效保護資訊資產
- C. 更清楚了解中斷的影響
- D. 監控與控制事件管理成本的能力
Answer: A
Explanation:
Explanation
The explanation given in the manual is:
Incident classification criteria enable an organization to prioritize incidents based on their impact and urgency. This allows for an optimized allocation of recovery resources to minimize business disruption and ensure timely restoration of normal operations. The other choices are benefits of incident management but not directly related to incident classification criteria.
NEW QUESTION # 199
下列哪一項對於讓安全操作與 IT 治理架構保持一致最有幫助?
- A. 安全操作程序
- B. 安全風險評估
- C. 業務影響分析 (BIA)
- D. 資訊安全政策
Answer: A
NEW QUESTION # 200
在使事件回應計畫與公司策略一致時,應先更新下列哪一項?
- A. 安全程序
- B. 風險因應場景
- C. 災難復原計畫 (DRP)
- D. 事件通知計劃
Answer: B
Explanation:
Explanation
The answer to the question is C. Risk response scenarios. This is because risk response scenarios are the predefined plans and actions that the organization will take to respond to specific types of incidents, such as cyberattacks, natural disasters, or data breaches. Risk response scenarios should be aligned with the corporate strategy, which defines the vision, mission, goals, and objectives of the organization, and guides the decision-making and resource allocation processes. By aligning the risk response scenarios with the corporate strategy, the organization can ensure that the incident response plan supports the achievement of the desired outcomes and benefits, and minimizes the impact and disruption to the business operations and performance.
Risk response scenarios are the predefined plans and actions that the organization will take to respond to specific types of incidents. Risk response scenarios should be aligned with the corporate strategy, which defines the vision, mission, goals, and objectives of the organization. (From CISM Manual or related resources) References = CISM Review Manual 15th Edition, Chapter 4, Section 4.2.2, page 2111; CISM domain 4:
Information security incident management [2022 update] | Infosec2; A Guide to Effective Incident Management Communications3
NEW QUESTION # 201
基於異常的入侵檢測系統 (IDS) 通過收集以下數據來運行:
- A. 正常網絡行為並將其用作測量異常活動的基線
- B. 來自歷史數據的攻擊模式簽名
- C. 異常網絡行為並向防火牆發出指令以丟棄惡意連接
- D. 異常網絡行為並將其用作測量正常活動的基線
Answer: A
Explanation:
An anomaly-based intrusion detection system (IDS) operates by gathering data on normal network behavior and using it as a baseline for measuring abnormal activity. This is important because it allows the IDS to detect any activity that is outside of the normal range of usage for the network, which can help to identify potential malicious activity or security threats. Additionally, the IDS will monitor for any changes in the baseline behavior and alert the administrator if any irregularities are detected. By contrast, signature-based IDSs operate by gathering attack pattern signatures from historical data and comparing them against incoming traffic in order to identify malicious activity.
NEW QUESTION # 202
以下哪项是确定防火墙是否已配置为提供全面边界防御的最佳方法9
- A. 针对防火墙的模拟拒绝服务 (DoS) 攻击
- B. 来自外部源的 ping 测试
- C. 当前防火墙规则集的验证
- D. 来自内部源的防火墙端口扫描
Answer: C
Explanation:
A validation of the current firewall rule set is the best method for determining whether a firewall has been configured to provide a comprehensive perimeter defense because it verifies that the firewall rules are consistent, accurate, and effective in allowing or blocking traffic according to the security policies and standards of the organization. A port scan of the firewall from an internal source is not a good method because it does not test the firewall's behavior from an external perspective, which is more relevant for perimeter defense. A ping test from an external source is not a good method because it only tests the firewall's availability and responsiveness, not its security or functionality. A simulated denial of service (DoS) attack against the firewall is not a good method because it only tests the firewall's resilience and performance under high traffic load, not its security or functionality. Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing
NEW QUESTION # 203
下列哪一項是軟體開發專案中資訊安全經理的主要角色?
- A. 在早期設計階段識別不合規情況
- B. 增強安全軟體設計意識
- C. 辨識軟體安全弱點
- D. 評估並批准安全應用架構
Answer: B
NEW QUESTION # 204
......
Pass ISACA CISM-CN Premium Files Test Engine pdf - Free Dumps Collection: https://www.actualpdf.com/CISM-CN_exam-dumps.html
CISM-CN Exam Info and Free Practice Test | ActualPDF: https://drive.google.com/open?id=1VRT9WIfTG9gz7ytdhDPulF6cTzTDz2r3
