Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 48 discussion

Actual exam question from Isaca's CISM
Question #: 48
Topic #: 1
[All CISM Questions]

An information security team plans to increase password complexity requirements for a customer-facing site, but there are concerns it will negatively impact the user experience. Which of the following is the information security manager's BEST course of action?

  • A. Evaluate business compensating controls.
  • B. Quantify the security risk to the business.
  • C. Assess business impact against security risk.
  • D. Conduct industry benchmarking.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alifjouj
2 months, 3 weeks ago
Selected Answer: A
4-eyes principle for instance...
upvoted 1 times
...
kokh94
3 months, 2 weeks ago
Selected Answer: A
a Compensating Control: is a mechanism that is put in place to satisfy the requirement for a security measure that is deemed too difficult or impractical to implement at the present time. changing password requirements and resulting in negatively impacting user experience means it is impractical, so the needed is to evaluate compensating controls.
upvoted 1 times
...
simon205
7 months ago
A. The IS team have decided to increase the PSW complexity to mitigate the risk , it means the risk has been identified and the impact to business has been highlighted already . So if the technical mitigation action is not good enough , we have to find its alternative solution such as SSO ....
upvoted 3 times
...
Bisibaby
8 months, 1 week ago
I think the business impact has already been done which is negatively affecting customers experience. The next step is to identify a compensating control
upvoted 2 times
...
e891cd1
9 months, 3 weeks ago
Selected Answer: C
C but it could also be a ISACA is weird sometimes. on the business end they might look at compensating controls that could make it less impactful on the customer..
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: C
The information security manager's BEST course of action is C. Assess business impact against security risk. This approach balances the security risk associated with weak passwords against the potential negative impact on the user experience caused by increased password complexity requirements. By carefully evaluating these factors, the information security manager can make an informed decision that prioritizes both security and usability.
upvoted 2 times
...
Viperhunter
12 months ago
Selected Answer: C
Assessing the business impact against security risk involves weighing the potential security benefits of increased password complexity against the potential negative impact on the user experience. This approach considers both security and usability factors, helping the information security team make informed decisions that strike a balance between security requirements and user satisfaction. While options like evaluating business compensating controls (option A), quantifying the security risk to the business (option B), and conducting industry benchmarking (option D) are valuable activities, assessing business impact against security risk specifically addresses the trade-off between security and user experience, allowing for a more balanced decision-making process.
upvoted 2 times
...
Nickprata
1 year ago
Selected Answer: C
The thing ISM conduct the assessment then suggest the appropriate solution. ISM SHOULD NOT FOLLOW WHAT USERS LIKES BLINDLY.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. Assess business impact against security risk. While the other options (A, B, and D) are also important considerations, assessing the business impact against security risk allows the organization to make a well-rounded decision that considers both security and usability concerns, which is crucial for achieving effective and balanced security measures.
upvoted 1 times
...
Patt70
1 year, 2 months ago
Answer is C. The reason I think, it is mention " there are concerns it will negatively impact the user experience". Hence we need to think from business or operational or customer experience perspective.
upvoted 1 times
...
Azurefox79
1 year, 3 months ago
Selected Answer: C
C is the CISM answer, you are a manager for the exam. A is absolutely a great idea but its not the business answer. get out of the technical analyst mindset for this exam to pass.
upvoted 1 times
...
DavoA
1 year, 4 months ago
Selected Answer: C
"plans to increase.." would require impact analysis
upvoted 1 times
...
karanvp
1 year, 5 months ago
"A" - Compensating control i.e. MFA, SSO, etc
upvoted 1 times
[Removed]
1 year, 5 months ago
first you have to do the impact. maybe you dont need compensating controls
upvoted 2 times
...
...
richck102
1 year, 6 months ago
C. Assess business impact against security risk.
upvoted 1 times
...
CarlLimps
1 year, 9 months ago
Selected Answer: C
C is the answer. It's the same as saying take a "risk based approach".
upvoted 1 times
...
Antonivs
1 year, 10 months ago
Selected Answer: C
C, clearly :)
upvoted 2 times
...
Prospect57
1 year, 10 months ago
Selected Answer: C
C. You should always look at the impact to the business when determining what to do next.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...