Valid CISM Dumps shared by EduDump.com for Helping Passing CISM Exam! EduDump.com now offer the newest CISM exam dumps, the EduDump.com CISM exam questions have been updated and answers have been corrected get the newest EduDump.com CISM dumps with Test Engine here:

Access CISM Dumps Premium Version
(1193 Q&As Dumps, 35%OFF Special Discount Code: freecram)

<< Prev Question Next Question >>

Question 40/425

When a user employs a client-side digital certificate to authenticate to a web server through Secure Socket Layer (SSL), confidentiality is MOST vulnerable to which of the following?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (425q)
Question 1: Which of the following should be determined FIRST when estab...
Question 2: The information classification scheme should:...
Question 3: Which of the following would BEST ensure that security risk ...
Question 4: The BEST time to perform a penetration test is after:...
Question 5: The PRIMARY purpose of installing an intrusion detection sys...
Question 6: The MOST appropriate individual to determine the level of in...
Question 7: A customer credit card database has been breached by hackers...
Question 8: Which of the following guarantees that data in a file have n...
Question 9: A message* that has been encrypted by the sender's private k...
Question 10: Which of the following vulnerabilities presents the GREATEST...
Question 11: If an organization considers taking legal action on a securi...
Question 12: How would an organization know if its new information securi...
Question 13: The purpose of a corrective control is to:...
Question 14: What is the MOST important reason for conducting security aw...
Question 15: To ensure that payroll systems continue on in an event of a ...
Question 16: A new e-mail virus that uses an attachment disguised as a pi...
Question 17: Security audit reviews should PRIMARILY:...
Question 18: A contract bid is digitally signed and electronically mailed...
Question 19: What is an appropriate frequency for updating operating syst...
Question 20: Which of the following would be MOST critical to the success...
Question 21: Who can BEST advocate the development of and ensure the succ...
Question 22: To reduce the possibility of service interruptions, an entit...
Question 23: Which of the following is the MOST effective type of access ...
Question 24: When creating a forensic image of a hard drive, which of the...
Question 25: Which of the following is the MOST important risk associated...
Question 26: Which of the following tools is MOST appropriate for determi...
Question 27: When application-level security controlled by business proce...
Question 28: During the restoration of several servers, a critical proces...
Question 29: There is reason to believe that a recently modified web appl...
Question 30: A web server in a financial institution that has been compro...
Question 31: Which of the following is the GREATEST risk of an inadequate...
Question 32: An organization has adopted a practice of regular staff rota...
Question 33: Which of the following is the BEST method to securely transf...
Question 34: Which of the following is MOST important to consider when de...
Question 35: The PRIMARY reason for using metrics to evaluate information...
Question 36: Successful social engineering attacks can BEST be prevented ...
Question 37: Which of the following is the BEST way to determine if an in...
Question 38: In which of the following system development life cycle (SDL...
Question 39: In a well-controlled environment, which of the following act...
Question 40: When a user employs a client-side digital certificate to aut...
Question 41: Which of the following is the BEST method to provide a new u...
Question 42: When security policies are strictly enforced, the initial im...
Question 43: The FIRST priority when responding to a major security incid...
Question 44: To address the issue that performance pressures on IT may co...
Question 45: The BEST way to ensure that security settings on each platfo...
Question 46: Which of the following activities is MOST likely to increase...
Question 47: Which of the following is the MOST important guideline when ...
Question 48: The BEST approach in managing a security incident involving ...
Question 49: The MAIN advantage of implementing automated password synchr...
Question 50: At the conclusion of a disaster recovery test, which of the ...
Question 51: Requiring all employees and contractors to meet personnel se...
Question 52: The MOST important success factor to design an effective IT ...
Question 53: Ensuring that an organization can conduct security reviews w...
Question 54: Which of the following measures is the MOST effective deterr...
Question 55: Which of the following is generally considered a fundamental...
Question 56: An organization provides information to its supply chain par...
Question 57: Which of the following provides the BKST confirmation that t...
Question 58: Which of the following controls is MOST effective in providi...
Question 59: During the security review of organizational servers, it was...
Question 60: Which of the following presents the GREATEST threat to the s...
Question 61: What is the BEST method to confirm that all firewall rules a...
Question 62: Which of the following is MOST effective in preventing the i...
Question 63: What is the BEST way to ensure data protection upon terminat...
Question 64: There is a time lag between the time when a security vulnera...
Question 65: Which of the following security activities should be impleme...
Question 66: As an organization grows, exceptions to information security...
Question 67: An organization without any formal information security prog...
Question 68: Which of the following is the BEST mechanism to determine th...
Question 69: Which of the following is MOST effective in preventing weakn...
Question 70: Which of the following are the essential ingredients of a bu...
Question 71: Which of the following is the MOST important item to conside...
Question 72: Which of the following BEST ensures timely and reliable acce...
Question 73: The FIRST step in an incident response plan is to:...
Question 74: Which of the following actions should be taken when an onlin...
Question 75: Detailed business continuity plans should be based PRIMARILY...
Question 76: Which of the following is the MOST important requirement for...
Question 77: What is the MOST appropriate change management procedure for...
Question 78: An intrusion detection system (IDS) should:...
Question 79: Which of the following is the BEST method to reduce the numb...
Question 80: An organization has a process in place that involves the use...
Question 81: Senior management has approved employees working off-site by...
Question 82: Which of the following is the MOST relevant metric to includ...
Question 83: The effectiveness of the information security process is red...
Question 84: Which of the following is the MOST immediate consequence of ...
Question 85: A root kit was used to capture detailed accounts receivable ...
Question 86: Which of the following is the MOST appropriate individual to...
Question 87: Which of the following security mechanisms is MOST effective...
Question 88: An organization has learned of a security breach at another ...
Question 89: Which of the following is the PRIMARY advantage of having an...
Question 90: An information security manager has completed a risk assessm...
Question 91: When considering whether to adopt a new information security...
Question 92: The IT function has declared that, when putting a new applic...
Question 93: An organization is already certified to an international sec...
Question 94: Which of the following is the MOST serious exposure of autom...
Question 95: What is the BEST way to alleviate security team understaffin...
Question 96: After assessing and mitigating the risks of a web applicatio...
Question 97: An information security manager has been asked to create a s...
Question 98: Of the following, retention of business records should be PR...
Question 99: A data-hosting organization's data center houses servers, ap...
Question 100: Which of the following presents the GREATEST exposure to int...
Question 101: An organization is considering moving one of its critical bu...
Question 102: The MOST important element in achieving executive commitment...
Question 103: Which of the following is the MOST important area of focus w...
Question 104: Which of the following is the BEST indicator that security a...
Question 105: Which of the following will BEST protect against malicious a...
Question 106: Data owners are normally responsible for which of the follow...
Question 107: An organization has verified that its customer information w...
Question 108: An organization is entering into an agreement with a new bus...
Question 109: When performing a qualitative risk analysis, which of the fo...
Question 110: Which of the following ensures that newly identified securit...
Question 111: When designing the technical solution for a disaster recover...
Question 112: When speaking to an organization's human resources departmen...
Question 113: The business advantage of implementing authentication tokens...
Question 114: Which of the following is the BEST approach to mitigate onli...
Question 115: Which of the following is the FIRST phase in which security ...
Question 116: Of the following, the BEST method for ensuring that temporar...
Question 117: In organizations where availability is a primary concern, th...
Question 118: Security governance is MOST associated with which of the fol...
Question 119: An information security manager has developed a strategy to ...
Question 120: Which of the following practices is BEST to remove system ac...
Question 121: Which of the following reduces the potential impact of socia...
Question 122: The PRIMARY purpose of performing an internal attack and pen...
Question 123: Who should determine the appropriate classification of accou...
Question 124: It is MOST important for an information security manager to ...
Question 125: To justify the establishment of an incident management team,...
Question 126: The PRIMARY driver to obtain external resources to execute t...
Question 127: Nonrepudiation can BEST be ensured by using:...
Question 128: Which of the following mechanisms is the MOST secure way to ...
Question 129: When implementing security controls, an information security...
Question 130: Which of the following would BEST protect an organization's ...
Question 131: A semi-annual disaster recovery test has been completed. Whi...
Question 132: Which of the following authentication methods prevents authe...
Question 133: An information security program should be sponsored by:...
Question 134: The BEST reason for an organization to have two discrete fir...
Question 135: Before engaging outsourced providers, an information securit...
Question 136: An intrusion detection system should be placed:...
Question 137: Security awareness training is MOST likely to lead to which ...
Question 138: In the process of deploying a new e-mail system, an informat...
Question 139: To ensure that all information security procedures are funct...
Question 140: Which of the following is the BEST tool to maintain the curr...
Question 141: Which of the following metrics would be the MOST useful in m...
Question 142: Following a significant change to the underlying code of an ...
Question 143: Which of the following is MOST important for a successful in...
Question 144: Which of the following is an inherent weakness of signature-...
Question 145: An account with full administrative privileges over a produc...
Question 146: Which of the following BEST ensures that information transmi...
Question 147: Which of the following is generally used to ensure that info...
Question 148: What is the BEST way to ensure that contract programmers com...
Question 149: What is the MOST important success factor in launching a cor...
Question 150: What is the BEST method for mitigating against network denia...
Question 151: Which of the following processes is critical for deciding pr...
Question 152: Which of the following is the MOST important process that an...
Question 153: A company has a network of branch offices with local file/pr...
Question 154: Primary direction on the impact of compliance with new regul...
Question 155: Security policies should be aligned MOST closely with:...
Question 156: Which of the following BEST enables an information security ...
Question 157: After obtaining commitment from senior management, which of ...
Question 158: What is the BEST method to verify that all security patches ...
Question 159: An information security manager wishing to establish securit...
Question 160: What is the BEST defense against a Structured Query Language...
Question 161: Which of the following documents would be the BEST reference...
Question 162: The "separation of duties" principle is violated if which of...
Question 163: Which of the following, using public key cryptography, ensur...
Question 164: When training an incident response team, the advantage of us...
Question 165: When contracting with an outsourcer to provide security admi...
Question 166: Managing the life cycle of a digital certificate is a role o...
Question 167: Information security policies should:...
Question 168: The advantage of Virtual Private Network (VPN) tunneling for...
Question 169: Which of the following situations would be the MOST concern ...
Question 170: Internal audit has reported a number of information security...
Question 171: The advantage of sending messages using steganographic techn...
Question 172: A serious vulnerability is reported in the firewall software...
Question 173: A computer incident response team (CIRT) manual should PRIMA...
Question 174: A web-based business application is being migrated from test...
Question 175: Which of the following is the MOST effective solution for pr...
Question 176: Which of the following is MOST critical for the successful i...
Question 177: Good information security standards should:...
Question 178: Which of the following would be MOST effective in ensuring t...
Question 179: Which of the following is the MOST important consideration w...
Question 180: Which of the following recovery strategies has the GREATEST ...
Question 181: Which of the following would BEST assist an information secu...
Question 182: Which of the following controls would BEST prevent accidenta...
Question 183: When an organization is using an automated tool to manage an...
Question 184: Which of the following is the MOST important consideration f...
Question 185: Which of the following is the MOST important to ensure a suc...
Question 186: Who is ultimately responsible for ensuring that information ...
Question 187: A post-incident review should be conducted by an incident ma...
Question 188: A large organization is considering a policy that would allo...
Question 189: Which of the following is the MOST likely to change an organ...
Question 190: Which of the following is the BEST indicator that an effecti...
Question 191: A critical device is delivered with a single user and passwo...
Question 192: The PRIMARY reason for assigning classes of sensitivity and ...
Question 193: Nonrepudiation can BEST be assured by using:...
Question 194: Which of the following practices completely prevents a man-i...
Question 195: Which of the following should be in place before a black box...
Question 196: Which of the following BEST enables the deployment of consis...
Question 197: All risk management activities are PRIMARILY designed to red...
Question 198: The configuration management plan should PRIMARILY be based ...
Question 199: Secure customer use of an e-commerce application can BEST be...
Question 200: Which of the following should be performed FIRST in the afte...
Question 201: Which of the following is the MOST effective, positive metho...
Question 202: An organization has implemented an enhanced password policy ...
Question 203: A major trading partner with access to the internal network ...
Question 204: When a new key business application goes into production, th...
Question 205: Which of the following would represent a violation of the ch...
Question 206: What is the GREATEST risk when there is an excessive number ...
Question 207: Evidence from a compromised server has to be acquired for a ...
Question 208: An organization's operations staff places payment files in a...
Question 209: When configuring a biometric access control system that prot...
Question 210: Which of the following would be the BEST indicator that an o...
Question 211: Which of the following represents a PRIMARY area of interest...
Question 212: Which of the following is the BEST metric for evaluating the...
Question 213: Which of the following are the MOST important criteria when ...
Question 214: An information security organization should PRIMARILY:...
Question 215: What is the MOST important item to be included in an informa...
Question 216: Who can BEST approve plans to implement an information secur...
Question 217: The MOST effective use of a risk register is to:...
Question 218: An extranet server should be placed:...
Question 219: When a large organization discovers that it is the subject o...
Question 220: Security awareness training should be provided to new employ...
Question 221: Which would be the BEST recommendation to protect against ph...
Question 222: Which of the following is the BEST way to ensure that a corp...
Question 223: An organization plans to allow employees to use their own de...
Question 224: When considering the value of assets, which of the following...
Question 225: An operating system (OS) noncritical patch to enhance system...
Question 226: An outsource service provider must handle sensitive customer...
Question 227: Which of the following is the BEST metric for evaluating the...
Question 228: When electronically stored information is requested during a...
Question 229: Which of the following would be the FIRST step in establishi...
Question 230: Documented standards/procedures for the use of cryptography ...
Question 231: Which of the following is MOST important in determining whet...
Question 232: Which of the following would BEST mitigate identified vulner...
Question 233: The MOST effective way to ensure network users are aware of ...
Question 234: Which of the following will BEST ensure that management take...
Question 235: Which of the following would be a MAJOR consideration for an...
Question 236: A desktop computer that was involved in a computer security ...
Question 237: An incident response policy must contain:...
Question 238: Which is the BEST way to measure and prioritize aggregate ri...
Question 239: In the course of examining a computer system for forensic ev...
Question 240: Which of the following would be the MOST effective counterme...
Question 241: In an organization, the responsibilities for IT security are...
Question 242: In order to protect a network against unauthorized external ...
Question 243: Which of the following is the MOST important management sign...
Question 244: Which of the following is the MOST important reason why info...
Question 245: An organization with multiple data centers has designated on...
Question 246: Which of the following is MOST effective for securing wirele...
Question 247: Which of the following is MOST effective in preventing secur...
Question 248: The business continuity policy should contain which of the f...
Question 249: Which of the following is a key area of the ISO 27001 framew...
Question 250: Which of the following is the MOST effective solution for pr...
Question 251: What is the BEST way to ensure that an intruder who successf...
Question 252: The BEST way to mitigate the risk associated with a social e...
Question 253: When a newly installed system for synchronizing passwords ac...
Question 254: Who is responsible for raising awareness of the need for ade...
Question 255: An organization that outsourced its payroll processing perfo...
Question 256: Which of the following is the PRIMARY advantage of desk chec...
Question 257: When a proposed system change violates an existing security ...
Question 258: Which of the following will BEST prevent an employee from us...
Question 259: Which resource is the MOST effective in preventing physical ...
Question 260: Which of the following is the MOST important reason for an i...
Question 261: Which of the following is MOST important when deciding wheth...
Question 262: What task should be performed once a security incident has b...
Question 263: In a social engineering scenario, which of the following wil...
Question 264: Isolation and containment measures for a compromised compute...
Question 265: Which of the following devices should be placed within a DMZ...
Question 266: A database was compromised by guessing the password for a sh...
Question 267: The BEST way to determine if an anomaly-based intrusion dete...
Question 268: When performing a business impact analysis (BIA), which of t...
Question 269: Recovery point objectives (RPOs) can be used to determine wh...
Question 270: At what stage of the applications development process would ...
Question 271: The PRIMARY objective of an Internet usage policy is to prev...
Question 272: Which of the following is the BEST method for ensuring that ...
Question 273: Which of the following application systems should have the s...
Question 274: Why is "slack space" of value to an information security man...
Question 275: To determine how a security breach occurred on the corporate...
Question 276: The BEST way to ensure that an external service provider com...
Question 277: To help ensure that contract personnel do not obtain unautho...
Question 278: During a post-incident review, the sequence and correlation ...
Question 279: An information security program should focus on:...
Question 280: Which of the following is the MAIN reason for performing ris...
Question 281: The effectiveness of virus detection software is MOST depend...
Question 282: A business partner of a factory has remote read-only access ...
Question 283: In business-critical applications, user access should be app...
Question 284: A risk assessment study carried out by an organization noted...
Question 285: An information security manager reviewed the access control ...
Question 286: Which of the following is the MOST important element to ensu...
Question 287: Which of the following devices should be placed within a dem...
Question 288: Of the following, whose input is of GREATEST importance in t...
Question 289: What is the FIRST action an information security manager sho...
Question 290: Which of the following will MOST likely reduce the chances o...
Question 291: Which of the following is the MOST appropriate individual to...
Question 292: In addition to backup data, which of the following is the MO...
Question 293: An information security manager uses security metrics to mea...
Question 294: Which of the following tasks should be performed once a disa...
Question 295: Emergency actions are taken at the early stage of a disaster...
Question 296: An e-commerce order fulfillment web server should generally ...
Question 297: Risk assessment is MOST effective when performed:...
Question 298: An internal review of a web-based application system finds t...
Question 299: The MAIN goal of an information security strategic plan is t...
Question 300: Which of the following features is normally missing when usi...
Question 301: Which of the following will protect the confidentiality of d...
Question 302: Which of the following is the MOST important consideration w...
Question 303: Which of the following is a risk of cross-training?...
Question 304: Which of the following is the BEST method to ensure the over...
Question 305: Which of the following has the highest priority when definin...
Question 306: A border router should be placed on which of the following?...
Question 307: Which of the following is the MOST important action to take ...
Question 308: When collecting evidence for forensic analysis, it is import...
Question 309: A test plan to validate the security controls of a new syste...
Question 310: An organization has been experiencing a number of network-ba...
Question 311: What is the MOST effective access control method to prevent ...
Question 312: When developing security standards, which of the following w...
Question 313: Which of the following are the MOST important individuals to...
Question 314: Which of the following defines the triggers within a busines...
Question 315: When developing a tabletop test plan for incident response t...
Question 316: For virtual private network (VPN) access to the corporate ne...
Question 317: Which of the following is MOST difficult to achieve in a pub...
Question 318: A risk management approach to information protection is:...
Question 319: The MOST important reason to use a centralized mechanism to ...
Question 320: Which of the following is MOST important to the successful p...
Question 321: A possible breach of an organization's IT system is reported...
Question 322: Simple Network Management Protocol v2 (SNMP v2) is used freq...
Question 323: Which of the following devices should be placed within a DMZ...
Question 324: Which of the following is MOST effective in protecting again...
Question 325: Which of the following tools is MOST appropriate to assess w...
Question 326: In business critical applications, where shared access to el...
Question 327: Which of the following would present the GREATEST risk to in...
Question 328: The implementation of a capacity plan would prevent:...
Question 329: Security monitoring mechanisms should PRIMARILY:...
Question 330: The PRIORITY action to be taken when a server is infected wi...
Question 331: Which of the following is the MOST appropriate method for de...
Question 332: Which of the following would be MOST appropriate for collect...
Question 333: Prior to having a third party perform an attack and penetrat...
Question 334: Which of the following is the MOST important consideration w...
Question 335: The return on investment of information security can BEST be...
Question 336: An information security manager has been asked to develop a ...
Question 337: An information security manager learns that a departmental s...
Question 338: An organization keeps backup tapes of its servers at a warm ...
Question 339: The BEST way to ensure that information security policies ar...
Question 340: Access control to a sensitive intranet application by mobile...
Question 341: Which of the following is the BEST way to verify that all cr...
Question 342: Which of the following is the MOST important element to ensu...
Question 343: Which of the following is the MOST appropriate frequency for...
Question 344: Which of the following is an example of a corrective control...
Question 345: Which of the following provides the linkage to ensure that p...
Question 346: Which of the following steps should be performed FIRST in th...
Question 347: Which of the following would be the BEST metric for the IT r...
Question 348: Which of the following BEST ensures that modifications made ...
Question 349: Which of the following BEST provides message integrity, send...
Question 350: Which of the following is the MOST critical activity to ensu...
Question 351: The MAIN reason for deploying a public key infrastructure (P...
Question 352: Which of the following actions should be taken when an infor...
Question 353: In an organization, information systems security is the resp...
Question 354: What is the PRIMARY objective of a post-event review in inci...
Question 355: The BEST method for detecting and monitoring a hacker's acti...
Question 356: The BEST metric for evaluating the effectiveness of a firewa...
Question 357: What is the GREATEST advantage of documented guidelines and ...
Question 358: A benefit of using a full disclosure (white box) approach as...
Question 359: Attacks using multiple methods to spread should be classifie...
Question 360: Which of the following is MOST important for measuring the e...
Question 361: Which of the following events generally has the highest info...
Question 362: Which of the following is the MOST appropriate method to pro...
Question 363: An organization has decided to implement additional security...
Question 364: What is the MAIN drawback of e-mailing password-protected zi...
Question 365: Which of the following areas is MOST susceptible to the intr...
Question 366: Which of the following devices could potentially stop a Stru...
Question 367: To mitigate a situation where one of the programmers of an a...
Question 368: Which of the following would be the BEST defense against sni...
Question 369: Which of the following is the MOST important item to include...
Question 370: When developing a security architecture, which of the follow...
Question 371: An information security manager believes that a network file...
Question 372: Which of the following terms and conditions represent a sign...
Question 373: The main mail server of a financial institution has been com...
Question 374: An intranet server should generally be placed on the:...
Question 375: Which of the following actions should lake place immediately...
Question 376: In designing a backup strategy that will be consistent with ...
Question 377: It is important to develop an information security baseline ...
Question 378: Which of the following techniques MOST clearly indicates whe...
Question 379: When an emergency security patch is received via electronic ...
Question 380: Which of the following environments represents the GREATEST ...
Question 381: When properly tested, which of the following would MOST effe...
Question 382: A security awareness program should:...
Question 383: Which of the following is the initial step in creating a fir...
Question 384: What is the BEST way to ensure users comply with organizatio...
Question 385: Which of the following roles is PRIMARILY responsible for de...
Question 386: The MOST important objective of a post incident review is to...
Question 387: Which of the following disaster recovery testing techniques ...
Question 388: Which of the following is MOST important to the success of a...
Question 389: The MOST important reason that statistical anomaly-based int...
Question 390: Of the following, which is the MOST important aspect of fore...
Question 391: An information security manager is advised by contacts in la...
Question 392: Which of the following is the MOST effective way to treat a ...
Question 393: The PRIMARY focus of the change control process is to ensure...
Question 394: A digital signature using a public key infrastructure (PKI) ...
Question 395: Which of the following activities performed by a database ad...
Question 396: The PRIMARY objective of security awareness is to:...
Question 397: Good information security procedures should:...
Question 398: Which of the following change management activities would be...
Question 399: Which of the following would be the MOST appropriate physica...
Question 400: Priority should be given to which of the following to ensure...
Question 401: A data leakage prevention (DLP) solution has identified that...
Question 402: An unauthorized user gained access to a merchant's database ...
Question 403: The BEST protocol to ensure confidentiality of transmissions...
Question 404: An organization faces severe fines and penalties if not in c...
Question 405: What is the BEST policy for securing data on mobile universa...
Question 406: Which of the following is MOST closely associated with a bus...
Question 407: What is the MOST important element to include when developin...
Question 408: Which of the following technologies is utilized to ensure th...
Question 409: The PRIMARY purpose of involving third-party teams for carry...
Question 410: The MOST effective way to ensure that outsourced service pro...
Question 411: On which of the following should a firewall be placed?...
Question 412: Change management procedures to ensure that disaster recover...
Question 413: As part of an international expansion plan, an organization ...
Question 414: Which of the following is the BEST approach for an organizat...
Question 415: When segregation of duties concerns exists between IT suppor...
Question 416: The MOST important reason for formally documenting security ...
Question 417: The BEST way to facilitate the reporting and escalation of p...
Question 418: To BEST improve the alignment of the information security ob...
Question 419: When a departmental system continues to be out of compliance...
Question 420: In the course of responding 10 an information security incid...
Question 421: Previously accepted risk should be:...
Question 422: An incident response team has determined there is a need to ...
Question 423: Which of the following BEST ensures that security risks will...
Question 424: The PRIMARY consideration when defining recovery time object...
Question 425: Which of the following would be MOST effective in the strate...