exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 839 discussion

Actual exam question from Isaca's CISM
Question #: 839
Topic #: 1
[All CISM Questions]

Which of the following parties should be responsible for determining access levels to an application that processes client information?

  • A. The identity and access management team
  • B. The business client
  • C. The information security team
  • D. Business unit management
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Y0GA
5 months, 1 week ago
Consensus here and with GPT is D because DETERMINATION would come from the business management side. Otherwise ENFORCEMENT, etc., would come from AIM, etc.
upvoted 1 times
...
Marcelus1714
8 months, 1 week ago
I went for D, but maybe D is accountable and A responsible?...
upvoted 1 times
Salilgen
7 months ago
hummm... I think so
upvoted 1 times
...
...
Soleandheel
10 months, 4 weeks ago
D. Business unit management
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: A
In practice, a collaborative approach that involves these parties working together is often the most effective way to determine access levels for an application processing client information. This approach helps strike a balance between business needs, security requirements, and regulatory compliance. The order of implementation should be as follow A>C>D>B
upvoted 1 times
...
afc1019
1 year, 2 months ago
Selected Answer: A
The other options are incorrect because: B. The business client does not have the expertise or knowledge to assess the risks involved in determining access levels. C. The information security team can provide input into the decision-making process, but they should not have the final say. D. Business unit management is responsible for the overall business, but they should not be involved in the technical aspects of determining access levels.
upvoted 1 times
...
AXL1
1 year, 2 months ago
It's nice to have your opinion but what is the right answer ? I mean ISACA response is the only one that matters. I start thinking that this site is creating more confusion
upvoted 1 times
AlexJacobson
8 months, 3 weeks ago
It's only creating confusion if you are trying to cheat your way to CISM. These discussions are absolutely invaluable because they are the closest thing to "learning in a group". People sharing their views and educated guesses. Only those who are trying to braindump the exam are complaining. Cheaters shouldn't pass the exam anyway.
upvoted 1 times
...
...
richck102
1 year, 3 months ago
D. Business unit management
upvoted 1 times
AlexJacobson
8 months, 3 weeks ago
It's only creating confusion if you are trying to cheat your way to CISM. These discussions are absolutely invaluable because they are the closest thing to "learning in a group". People sharing their views and educated guesses. Only those who are trying to braindump the exam are complaining. Cheaters shouldn't pass the exam anyway.
upvoted 1 times
...
AlexJacobson
8 months, 3 weeks ago
Sorry, I meant this as an answer to AXL1 above your comment.
upvoted 1 times
...
...
karanvp
1 year, 3 months ago
The keyword is "responsible". Client decide access levels; but responsible is with IAM team / BU.
upvoted 1 times
...
Dopy
1 year, 3 months ago
Selected Answer: D
the identity and access management team carryout the task of providing access based on the business unit manager.
upvoted 3 times
...
Tia33
1 year, 4 months ago
Selected Answer: D
D - No one knows information systems better than business unit management (data owners)
upvoted 3 times
...
wello
1 year, 4 months ago
Selected Answer: D
business unit management (option D) should be responsible for determining access levels to an application that processes client information. Their understanding of the business context, ownership of outcomes, and contextual knowledge of the data make them best suited to make informed decisions about access rights within their respective business units.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago