exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 819 discussion

Actual exam question from Isaca's CISM
Question #: 819
Topic #: 1
[All CISM Questions]

Which of the following methods is the BEST way to demonstrate that an information security program provides appropriate coverage?

  • A. Gap assessment
  • B. Vulnerability scan report
  • C. Maturity assessment
  • D. Security risk analysis
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Josef4CISM
1 month, 2 weeks ago
Selected Answer: D
Put it this way: A maturity assessment tells you HOW WELL you are doing. A risk assessment tells you WHETHER you have done the needed steps. You can implement steps in an inefficient way - but a mitigated risk is a mitigated risk. Hope this makes sense.
upvoted 1 times
...
Booict
7 months, 1 week ago
Selected Answer: D
D - provides a broader evaluation of the entire information security program. It measures the program’s current state against predefined criteria or best practices, offering a comprehensive view of its effectiveness and coverage. This holistic approach is more suitable for demonstrating that the program provides appropriate coverage.
upvoted 2 times
...
oluchecpoint
1 year, 5 months ago
Selected Answer: D
D. Security Risk Analysis. Security risk analysis assesses the organization's overall security posture by identifying and analyzing risks. It evaluates the effectiveness of security controls and their alignment with business objectives. A well-conducted security risk analysis provides a comprehensive view of the security program's coverage and its ability to address the organization's specific risks and threats. It is considered the most comprehensive and strategic method for demonstrating appropriate coverage.
upvoted 2 times
...
richck102
1 year, 7 months ago
C. Maturity assessment
upvoted 2 times
...
Dopy
1 year, 8 months ago
Selected Answer: C
a maturity assessment is the BEST way to demonstrate that an information security program provides appropriate coverage as the risk analysis feeds into the maturity assessment
upvoted 3 times
...
Jae_kes
1 year, 8 months ago
Selected Answer: C
C. Maturity assessment
upvoted 3 times
...
wello
1 year, 8 months ago
Selected Answer: D
a security risk analysis is the BEST method to demonstrate that an information security program provides appropriate coverage as it comprehensively assesses risks, vulnerabilities, and associated controls to ensure adequate protection of information assets.
upvoted 4 times
...
Pabl0T0rrez
1 year, 9 months ago
??? C. maturity assessment - the best way to demonstrate that an information security program provides appropriate coverage. A security risk analysis is an assessment of the risks to an organization's information assets.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago