exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 917 discussion

Actual exam question from Isaca's CISM
Question #: 917
Topic #: 1
[All CISM Questions]

Which of the following BEST enables an organization to maintain an appropriate security control environment?

  • A. Periodic employee security training
  • B. Budgetary support for security
  • C. Alignment to an industry security framework
  • D. Monitoring of the threat landscape
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Josef4CISM
1 month, 1 week ago
Selected Answer: D
Answer D is correct: By monitoring the threat landscape, the security manager is able to assess the applicability of threats. If he sees a threat as applicable, may assess whether there is any vulnerability that results in a risk. Referring to a best practice framework can help, but its likely that many controls from the best practice framework are not needed, since there is no applicable use case.
upvoted 1 times
...
shootnot
3 months, 2 weeks ago
C- Framework provides guidelines on appropriate controls. If threat landscape changes, there are several other steps before adjusting controls.
upvoted 1 times
...
yottabyte
5 months, 1 week ago
Selected Answer: D
monitoring threat.
upvoted 1 times
...
POWNED
7 months ago
Best answer here is D. Its always scary seeing training involved in a question. At that point you have to dive into the meat of the question to address every word in the question.
upvoted 1 times
...
AlexJacobson
7 months ago
Selected Answer: D
oh man, don't you just LOVE all those random chatgpt/bard/copilot answers being plastered all over the discussion sections... This sht it killing the site value!... Anyway, I think it's D. You're monitoring what's going on in the wild lands and based on that you figure out the risks and adjust controls where necessary (maintaining an "appropriate security controls environment").
upvoted 4 times
...
SHERLOCKAWS
8 months, 3 weeks ago
Selected Answer: C
An industry security framework such as NIST-CSF would help maintaining an 'appropriate' security controls environment. All other answers are addressed in a security framework.
upvoted 1 times
...
Soleandheel
9 months, 1 week ago
D. Monitoring of the threat landscape.....continuous monitoring is essential.
upvoted 2 times
...
Cyberbug2021
9 months, 1 week ago
Selected Answer: D
Continuous Monitoring - You don't have to align with industry frameworks - you can create your own using different frameworks.
upvoted 2 times
...
Bl1024
9 months, 2 weeks ago
Why not B?
upvoted 1 times
...
koala_lay
10 months, 2 weeks ago
Selected Answer: C
All of the options listed - periodic employee security training, budgetary support for security, alignment to an industry security framework, and monitoring of the threat landscape - can contribute to maintaining an appropriate security control environment. However, if we have to choose the option that best enables an organization to maintain an appropriate security control environment, it would likely be: C. Alignment to an industry security framework. Alignment to an industry security framework provides a structured and comprehensive approach to establishing and maintaining security controls. Industry security frameworks, such as ISO 27001, NIST Cybersecurity Framework, or CIS Controls, offer guidelines, best practices, and standards that organizations can follow to establish effective security controls.
upvoted 3 times
...
richck102
11 months ago
Selected Answer: A
A. Periodic employee security training
upvoted 4 times
...
wickhaarry
11 months, 1 week ago
A. Periodic employee security training
upvoted 2 times
...
oluchecpoint
11 months, 3 weeks ago
Selected Answer: C
C. Alignment to an industry security framework Alignment to an industry security framework provides a structured and comprehensive approach to security controls. It helps organizations establish a strong foundation for security by following best practices and standards specific to their industry. This approach ensures that the organization is addressing known security risks and vulnerabilities effectively.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago