exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 945 discussion

Actual exam question from Isaca's CISM
Question #: 945
Topic #: 1
[All CISM Questions]

Which of the following would MOST effectively ensure that a new server is appropriately secured?

  • A. Enforcing technical security standards
  • B. Performing secure code reviews
  • C. Initiating security scanning
  • D. Conducting penetration testing
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HN2025
1 month ago
Selected Answer: A
Enforcing technical security standards ensures that the server is configured and maintained according to best practices and security guidelines. These standards typically cover various aspects of server security, such as hardening, patch management, access controls, and monitoring. By adhering to these standards, organizations can systematically address security risks and vulnerabilities, leading to a more secure server environment.
upvoted 1 times
...
Josef4CISM
1 month, 1 week ago
Selected Answer: A
Enforcing technical security standards as in the form of baseline configurations. Similar question exists in this question pool - they are just worded differently.
upvoted 1 times
...
realmjmj
2 months ago
Selected Answer: D
Option A is just to wear the armor, to "ensure" it is secured, you will need to use a spear (Option D) to "test" it. my 2 cents.
upvoted 1 times
...
1899f17
3 months ago
B. Performing secure code reviews
upvoted 1 times
...
60d8b7d
6 months ago
Selected Answer: D
Option A only focuses on technical controls but a pen test will test other forms of controls, like physical controls.
upvoted 4 times
...
POWNED
7 months ago
Selected Answer: D
Have to argue that pen test is the answer here. Ensure means to make certain. Only option to ensure you are secure is to have a third party try to break into the server. Keep in mind physical security along with technical.
upvoted 3 times
...
Uncle_Lucifer
8 months, 2 weeks ago
Selected Answer: A
B to D are doing investigative or identifying threats only A is implementing control
upvoted 2 times
...
SilverFox
9 months, 1 week ago
Selected Answer: A
ensure vs assure so going with A
upvoted 3 times
...
Cyberbug2021
9 months, 1 week ago
Selected Answer: A
You can not do a penn test everytime a new server is brought up
upvoted 4 times
...
richck102
10 months, 2 weeks ago
Selected Answer: A
A. Enforcing technical security standards
upvoted 2 times
...
koala_lay
10 months, 2 weeks ago
Selected Answer: D
All of the options mentioned can contribute to ensuring that a new server is appropriately secured. However, if I had to choose the most effective option, I would go with option D, conducting penetration testing. Penetration testing involves simulating real-world attacks on the server to identify vulnerabilities and weaknesses in the system. This allows for a comprehensive evaluation of the server's security posture and helps identify potential entry points for unauthorized access. By performing penetration testing, any security vulnerabilities can be identified and addressed before they can be exploited by malicious actors.
upvoted 4 times
...
wickhaarry
11 months, 1 week ago
D. Conducting penetration testing
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago