Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 148 discussion

Actual exam question from Isaca's CISM
Question #: 148
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to determine if a recent investment in access control software was successful?

  • A. Senior management acceptance of the access control software
  • B. A comparison of security incidents before and after software installation
  • C. A business impact analysis (BIA) of the systems protected by the software
  • D. A review of the number of key risk indicators (KRIs) implemented for the software
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Matini
Highly Voted 2 years, 1 month ago
Implementing an access control software will not necessarily change the criticality of the asset to the organization's strategic objectives. I would choose B
upvoted 11 times
vavofa5697
1 year, 9 months ago
agreed
upvoted 1 times
...
Ziggybooboo
2 years, 1 month ago
Agreed
upvoted 1 times
...
...
meelaan
Highly Voted 1 year, 7 months ago
Selected Answer: C
As sw has been installed recently... we dont have enough indcidents to judge...
upvoted 8 times
...
5fd6335
Most Recent 2 weeks, 5 days ago
Wow, all Wrong. it should be D.
upvoted 1 times
...
DarkMag
4 weeks, 1 day ago
Selected Answer: B
B is the correct answer
upvoted 1 times
...
helg420
6 months, 1 week ago
Selected Answer: B
B. A comparison of security incidents before and after software installation This method directly measures the effectiveness of the software in reducing security breaches or unauthorized access attempts. An improvement in security posture, demonstrated by decreased incidents is a clear indicator of the investment's success. While senior management acceptance (Option A) is important for organizational support, it doesn't directly measure the software's effectiveness in enhancing security. A business impact analysis (Option C) assesses the potential effects of disruptions to business operations but is not specifically suited to evaluating the success of security measures. Reviewing the number of key risk indicators (Option D) implemented for the software could provide some insights into monitoring capabilities, but it doesn't directly measure the success in mitigating security incidents or improving control effectiveness as clearly as a comparison of incident rates does.
upvoted 1 times
...
Chaser
6 months, 2 weeks ago
Security incidents can be more than Access control violations. It is C
upvoted 1 times
...
sphenixfire
1 year, 2 months ago
Selected Answer: B
I would say b
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
B. A comparison of security incidents before and after software installation The BEST way to determine if a recent investment in access control software was successful is to perform a comparison of security incidents before and after the software installation. This approach allows for a direct assessment of the software's impact on security.
upvoted 1 times
...
richck102
1 year, 5 months ago
B. A comparison of security incidents before and after software installation
upvoted 1 times
...
sedardna
1 year, 5 months ago
Selected Answer: C
ES C Los incidentes son variables y no siempre constantes. Hay que comparar con la realidad de la empresa
upvoted 1 times
...
Abhey
1 year, 6 months ago
Selected Answer: B
. By comparing the number and severity of security incidents before and after the software was installed, an organization can determine if the software has been effective in reducing the risk of unauthorized access to critical systems and data. This approach provides a quantitative assessment of the software's effectiveness and can help inform decisions about future investments in access control or other security technologies.
upvoted 1 times
...
Broesweelies
1 year, 10 months ago
Selected Answer: B
B. A comparison of security incidents before and after software installation The best way to determine if a recent investment in access control software was successful is to compare the number of security incidents that occurred before the software was installed with the number that occurred after it was installed. This will provide a clear indication of whether the software is effectively controlling access to systems and reducing the risk of security incidents. Other options, like senior management acceptance, business impact analysis and review of the number of key risk indicators implemented for the software are important but don't provide clear indication that software is effectively controlling access and reducing the risk of security incidents.
upvoted 3 times
...
Prospect57
1 year, 10 months ago
Selected Answer: B
B is my answer. Appears to be consensus here on that.
upvoted 2 times
...
baranikumar_v
1 year, 10 months ago
B. Comparing the number of security incidents before and after the software installation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...