exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 852 discussion

Actual exam question from Isaca's CISM
Question #: 852
Topic #: 1
[All CISM Questions]

Which of the following is an information security manager's MOST important action to mitigate the risk associated with malicious software?

  • A. Disabling end-user computer peripheral access ports
  • B. Implementing a multi-layered security program
  • C. Ensuring antivirus has the latest definition files
  • D. Strengthening security patch implementation processes
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pabl0T0rrez
Highly Voted 1 year, 1 month ago
B? multi-layered security program is generally considered the most effective approach...
upvoted 7 times
AlexJacobson
5 months, 2 weeks ago
No only that, but the infosec manager's job is not to touch, but to advise, shape and influence.
upvoted 1 times
...
DERCHEF2009
1 year, 1 month ago
agree with you
upvoted 3 times
...
...
1899f17
Most Recent 1 month, 2 weeks ago
C Ensuring antivirus has the latest definition files
upvoted 1 times
...
oluchecpoint
10 months, 1 week ago
Selected Answer: B
Option B
upvoted 2 times
...
AaronS1990
10 months, 3 weeks ago
Selected Answer: B
B- Defence in depth to put it another way
upvoted 4 times
...
sundersam23
12 months ago
Selected Answer: B
Among the options provided, the MOST important action for an information security manager to mitigate the risk associated with malicious software is B. Implementing a multi-layered security program. A multi-layered security program combines various security measures and controls to create a comprehensive defense against malicious software. It involves implementing multiple layers of protection at different points in the IT infrastructure and user environment, significantly reducing the risk of successful malware attacks.
upvoted 2 times
...
CISSPST
12 months ago
The most likely answer is B. According to ncsc.gov.uk "Since there's no way to completely protect your organization against malware infection, you should adopt a 'defense-in-depth' approach. This means using layers of defense with several mitigations at each layer." This could include disabling of peripheral access ports and keeping OS and antivirus software up-to-date among other methods.
upvoted 2 times
...
richck102
1 year ago
B. Implementing a multi-layered security program
upvoted 1 times
...
karanvp
1 year ago
D may not be correct answer as the risk is related to Malware.
upvoted 1 times
...
chanke
1 year, 1 month ago
Selected Answer: B
Defense in-depth/multi-layered security program is the most effective approach.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago