exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 465 discussion

Actual exam question from Isaca's CISM
Question #: 465
Topic #: 1
[All CISM Questions]

Using which of the following metrics will BEST help to determine the resiliency of IT infrastructure security controls?

  • A. Percentage of outstanding high-risk audit issues
  • B. Number of incidents resulting in disruptions
  • C. Number of successful disaster recovery tests
  • D. Frequency of updates to system software
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dravidian
Highly Voted 1 year, 4 months ago
Selected Answer: B
The question is clear in asking how can we best measure the resiliency of the security program. This is not all about DR. The best way to measure resiliency would be see how many incidents that actually end up causing a disruption. B is the right answer.
upvoted 11 times
...
Josef4CISM
Most Recent 1 month, 3 weeks ago
Selected Answer: C
Successful disaster recovery tests confirm the response capabilities black on white. In contrast a low number of incidents that have resulted in disasters does not confirm the response capabilities. You may assume that your DRP works - but you cannot confirm for sure. Therefore answer C is right.
upvoted 1 times
...
AlexJacobson
7 months, 1 week ago
Selected Answer: C
Again, a tough question. I'm gonna go with C here since DR tests are there to test whether the system is resilient enough in the face of a disaster. Just because a business didn't have many incidents that resulted in a disruption doesn't mean it's IT infrastructure is resilient. It can easily be luck of not facing an incident sever enough.
upvoted 3 times
03allen
2 months, 4 weeks ago
I agree on this
upvoted 1 times
...
...
POWNED
8 months, 3 weeks ago
Selected Answer: B
Do not think data recovery test is a metric... going with B.
upvoted 2 times
POWNED
8 months, 3 weeks ago
*disaster recovery test
upvoted 1 times
...
...
Alizadeh
8 months, 3 weeks ago
Selected Answer: C
C. Number of successful disaster recovery tests
upvoted 1 times
...
Uncle_Lucifer
9 months ago
Selected Answer: B
due to word "resilience" it cant be data recovery test. Its B
upvoted 1 times
...
koala_lay
9 months, 3 weeks ago
Selected Answer: C
The metric that would best help determine the resiliency of IT infrastructure security controls is option C: Number of successful disaster recovery tests. Disaster recovery tests are designed to simulate various potential incidents or disruptions to the IT infrastructure and evaluate the effectiveness of the security controls in place. By measuring the number of successful tests, organizations can assess how well their infrastructure can recover from such events and how resilient their security controls are. This metric provides a direct measurement of the ability to withstand and recover from potential security breaches or incidents.
upvoted 2 times
...
oluchecpoint
12 months ago
Selected Answer: C
C. Number of successful disaster recovery tests This metric directly assesses the ability of IT infrastructure security controls to recover and maintain operations after a disaster or incident. Successful disaster recovery tests indicate that the controls are effective in ensuring resiliency and business continuity. Monitoring the number of successful tests over time can help identify trends and provide insights into the overall resiliency of the IT infrastructure security controls.
upvoted 1 times
...
AaronS1990
1 year ago
Selected Answer: B
The key here is the term "resiliency". If the system is resilient enough we may not even have a disruption in the first place so i'll go with B
upvoted 3 times
...
richck102
1 year, 2 months ago
B. Number of incidents resulting in disruptions
upvoted 2 times
...
wello
1 year, 2 months ago
Selected Answer: B
B. Number of incidents resulting in disruptions
upvoted 2 times
...
Saisharan
1 year, 3 months ago
The number of successful disaster recovery tests provides a direct measure of the effectiveness and resiliency of IT infrastructure security controls. It demonstrates the ability of the organization to recover and restore critical systems and data in the event of a disruptive incident. By conducting regular tests and achieving successful outcomes, it indicates that the security controls in place are capable of withstanding and recovering from various disruptions or incidents. Option C
upvoted 3 times
...
Tsubasa1234
1 year, 5 months ago
Selected Answer: C
C. The number of successful disaster recovery tests is best suited to assess the resiliency of IT infrastructure security controls. Disaster recovery plans are critical to address system disruptions due to security events or natural disasters. Periodic testing can verify that the plan actually works. On the other hand, the percentage of unresolved high-risk audit issues is a less reliable metric because it is also affected if the issue is fixed before the audit is completed. Also, the frequency of system software updates, while it may help strengthen security controls, is not directly relevant to assessing resiliency. B. Number of incidents resulting in disruptions is not the best measure of the robustness of the security controls in an IT infrastructure. This is because the frequency of security incidents is not an indicator of the robustness of security controls, which are affected by other factors as well.
upvoted 3 times
koala_lay
9 months, 3 weeks ago
Agree to the answer C Thanks for your detailed explanation.
upvoted 1 times
...
...
CarlLimps
1 year, 6 months ago
Selected Answer: C
I'm thinking this should be C. Number of successful disaster recovery tests. Perhaps I'm not understanding the question.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago