Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 905 discussion

Actual exam question from Isaca's CISM
Question #: 905
Topic #: 1
[All CISM Questions]

Which or the following is the BEST way to monitor for advanced persistent threats (APT) in an organization?

  • A. Browse the Internet to learn of potential events.
  • B. Search for threat signatures in the environment.
  • C. Search for anomalies in the environment.
  • D. Network with peers in the industry to share information.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
afoo1314
2 months, 3 weeks ago
Selected Answer: C
best way to detect APT is monitor for as abnormalities. SIEM can help on this.
upvoted 2 times
...
Infosecnerd
2 months, 3 weeks ago
C: C. Search for anomalies in the environment is generally the better approach. Here’s why: Anomaly Detection: APTs are designed to evade traditional security measures and blend in with regular network activity. By searching for anomalies—unusual patterns or behaviors in network traffic, system usage, or data access—you can identify potential signs of an APT that might not fit established patterns of normal activity. This proactive monitoring helps in detecting sophisticated threats that are specifically crafted to evade standard detection methods.
upvoted 2 times
...
3czz
9 months ago
Selected Answer: D
it shlould be D
upvoted 3 times
...
richck102
1 year, 1 month ago
Selected Answer: C
C. Search for anomalies in the environment.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...