exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 266 discussion

Actual exam question from Isaca's CISM
Question #: 266
Topic #: 1
[All CISM Questions]

When defining and communicating roles and responsibilities between an organization and cloud service provider, which of the following situations would present the GREATEST risk to the organization's ability to ensure information risk is managed appropriately?

  • A. The service agreement uses a custom-developed RACI instead of an industry standard RACI to document responsibilities
  • B. The organization believes the provider accepted responsibility for issues affecting security that the provider did not accept
  • C. The organization and provider identified multiple information security responsibilities that neither party was planning to provide
  • D. The service agreement results in unnecessary duplication of effort because shared responsibilities have not been clearly defined
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mad68
Highly Voted 1 year, 4 months ago
Selected Answer: C
C. The organization and provider identified multiple information security responsibilities that neither party was planning to provide. In this situation, if both the organization and the cloud service provider identify multiple information security responsibilities but neither party is actually planning to fulfill those responsibilities, it creates a significant gap in the management of information risk. This lack of clarity and accountability can lead to important security tasks being left unaddressed or overlooked, increasing the organization's exposure to potential risks and vulnerabilities. While the other options (A, B, and D) may also introduce risks and challenges in defining and communicating roles and responsibilities, they do not directly pose as great a risk as option C, where both parties fail to acknowledge and address crucial information security responsibilities.
upvoted 7 times
...
wello
Highly Voted 1 year, 3 months ago
Selected Answer: B
In a cloud service provider relationship, clearly defining and communicating roles and responsibilities is crucial to ensure effective information risk management. Option B poses the greatest risk because it indicates a misalignment or misunderstanding between the organization and the provider regarding the allocation of security responsibilities. If the organization believes that the provider has accepted responsibility for security issues that the provider did not actually agree to, there may be critical security gaps or vulnerabilities that go unaddressed.
upvoted 7 times
...
Adabach
Most Recent 1 day, 21 hours ago
Selected Answer: B
The scenario that presents the GREATEST risk to an organization's ability to manage information risk appropriately is B.
upvoted 1 times
...
yottabyte
6 months, 3 weeks ago
Selected Answer: D
I will go with D as shared responsibilities have not been clearly defined
upvoted 1 times
...
oluchecpoint
8 months ago
Selected Answer: B
B. The organization believes the provider accepted responsibility for issues affecting security that the provider did not accept. This situation presents a significant risk because it involves a misunderstanding or miscommunication regarding the responsibilities for security issues. If the organization assumes the cloud service provider is responsible for certain security aspects when they are not, it can lead to gaps in security coverage and increased information risk. This misunderstanding could result in inadequate security measures, breaches, or data loss
upvoted 1 times
...
oluchecpoint
8 months, 1 week ago
Selected Answer: B
B. The organization believes the provider accepted responsibility for issues affecting security that the provider did not accept. This situation presents a significant risk because it involves a misunderstanding or miscommunication regarding the responsibilities for security issues. If the organization assumes the cloud service provider is responsible for certain security aspects when they are not, it can lead to gaps in security coverage and increased information risk. This misunderstanding could result in inadequate security measures, breaches, or data loss
upvoted 2 times
...
oluchecpoint
1 year, 1 month ago
B. The organization believes the provider accepted responsibility for issues affecting security that the provider did not accept. This situation presents a significant risk because it involves a misunderstanding or miscommunication regarding the responsibilities for security issues. If the organization assumes the cloud service provider is responsible for certain security aspects when they are not, it can lead to gaps in security coverage and increased information risk. This misunderstanding could result in inadequate security measures, breaches, or data loss
upvoted 1 times
...
Agamennore
1 year, 1 month ago
Selected Answer: B
Unknown problem (B) is greater problem than a known one (C)
upvoted 3 times
...
Bl1024
1 year, 1 month ago
Selected Answer: B
Unknown problem (B) is greater problem than a known one (C)
upvoted 1 times
...
Goseu
1 year, 2 months ago
Selected Answer: B
I m with B.
upvoted 1 times
...
richck102
1 year, 4 months ago
i vote C too
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago