CISM Certified Information Security Manager – Question1316

What is the MOST effective way to ensure information security incidents will be managed effectively and in a timely manner?

A.
Establish and measure key performance indicators (KPIs)
B. Communicate incident response procedures to staff
C. Test incident response procedures regularly
D. Obtain senior management commitment

Correct Answer: A

CISM Certified Information Security Manager – Question1315

Which of the following is the BEST way to improve the timely reporting of information security incidents?

A.
Perform periodic simulations with the incident response team
B. Integrate an intrusion detection system (IDS) in the DMZ
C. Incorporate security procedures in help desk processes
D. Regularly reassess and update the incident response plan

Correct Answer: B

CISM Certified Information Security Manager – Question1313

An organization has detected sensitive data leakage caused by an employee of a third-party contractor. What is the BEST course of action to address this issue?

A.
Activate the organization’s incident response plan
B. Include security requirements in outsourcing contracts
C. Terminate the agreement with the third-party contractor
D. Limit access to the third-party contractor

Correct Answer: A

CISM Certified Information Security Manager – Question1312

Which of the following external entities would provide the BEST guidance to an organization facing advanced attacks?

A.
Recognized threat intelligence communities
B. Open-source reconnaissance
C. Disaster recovery consultants widely endorsed in industry forums
D. Incident response experts from highly regarded peer organizations

Correct Answer: D

CISM Certified Information Security Manager – Question1311

Which of the following is the PRIMARY purpose of red team testing?

A.
To determine the organization’s preparedness for an attack
B. To assess the vulnerability of employees to social engineering
C. To establish a baseline incident response program
D. To confirm the risk profile of the organization

Correct Answer: A