Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 66 discussion

Actual exam question from Isaca's CISM
Question #: 66
Topic #: 1
[All CISM Questions]

An information security manager MUST have an understanding of an information security program?

  • A. Understanding current and emerging technologies
  • B. Establishing key performance indicators (KPIs)
  • C. Conducting periodic risk assessments
  • D. Obtaining stakeholder input
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ZeeM12
Highly Voted 1 year, 10 months ago
horribly written question.
upvoted 17 times
...
mad68
Highly Voted 2 years ago
This question does to lend itself to any of the answers.
upvoted 8 times
...
OlaYiMiKa
Most Recent 3 months, 3 weeks ago
The question asked in an ambiguous way
upvoted 3 times
...
f6acde0
11 months, 3 weeks ago
What are they even asking here. Delete it.
upvoted 3 times
...
Viperhunter
12 months ago
Selected Answer: D
An information security manager must have an understanding of an information security program, and obtaining stakeholder input is a crucial aspect of this understanding. Stakeholder input helps in identifying the needs, expectations, and priorities of different stakeholders within the organization, which, in turn, contributes to the development and implementation of an effective information security program.
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: B
I answered KPIs, and then I checked with Bard after seeing everyone's vote - this is what Bard said: The answer is B. Establishing key performance indicators (KPIs). An information security manager must have a strong understanding of all the aspects of an information security program, but establishing key performance indicators (KPIs) is the most crucial aspect. Key performance indicators (KPIs) are measurable metrics that track the progress and effectiveness of an organization's information security program. Establishing KPIs allows the information security manager to:
upvoted 1 times
...
Viperhunter
1 year ago
Selected Answer: C
Understanding an information security program is crucial for an information security manager to effectively conduct periodic risk assessments. By having an understanding of the program, the manager can identify and assess potential risks to the organization's information assets, systems, and processes. This understanding is foundational for implementing appropriate controls, mitigating risks, and ensuring the ongoing effectiveness of the information security program. While understanding current and emerging technologies (option A), establishing key performance indicators (KPIs) (option B), and obtaining stakeholder input (option D) are also important aspects of information security management, they may be influenced by or contribute to the overall understanding of the information security program. However, conducting periodic risk assessments is a specific activity that directly relies on this understanding.
upvoted 2 times
...
POWNED
1 year ago
Not going to answer the question because it does not make sense! haha
upvoted 3 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: D
Option D
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Wording is wrong. So, the answer is that an information security manager should have a comprehensive understanding of all these areas to effectively manage an information security program.
upvoted 1 times
...
jennarink13
1 year, 4 months ago
Poorly written. I guess the answer is TRUE? Lmao
upvoted 1 times
...
ddharia94
1 year, 5 months ago
Selected Answer: C
Risk assessment
upvoted 1 times
...
Jae_kes
1 year, 5 months ago
Selected Answer: D
D. Obtaining stakeholder input
upvoted 3 times
...
richck102
1 year, 6 months ago
D. Obtaining stakeholder input
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: C
The question is asking which of the following is a necessary understanding that an information security manager must have regarding an information security program. Conducting periodic risk assessments: Conducting periodic risk assessments is an important component of an information security program, and an information security manager must have an understanding of how to conduct them.
upvoted 2 times
...
mad68
1 year, 6 months ago
Please remove or rewrite the question. It is not really a question.
upvoted 1 times
...
dedfef
1 year, 6 months ago
what is this basura
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...