exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 106 discussion

Actual exam question from Isaca's CISM
Question #: 106
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS)?

  • A. Establish and present appropriate metrics that track performance.
  • B. Perform industry research annually and document the overall ranking of the IPS.
  • C. Perform a penetration test to demonstrate the ability to protect.
  • D. Provide yearly competitive pricing to illustrate the value of the IPS.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
GAAMMC
4 weeks ago
Selected Answer: C
Given he needs to justify the cost, C speaks to a cost to benefit
upvoted 1 times
...
alifjouj
6 months ago
Selected Answer: C
periodic testing of effectiveness
upvoted 1 times
...
angellorv
9 months, 3 weeks ago
(C) ISACA CISM 15ed Review Manuan Section 1.6.5 (Value Delivery Metrics): Control cost-effectiveness that is determined by periodic testing The effectiveness of controls as determined by testing.
upvoted 1 times
...
simon205
10 months, 1 week ago
C. We have to prove its capability and pay for its maintenance cost . Just like we buy insurance , we are not expecting its daily metrics , but we just need it during major incident .
upvoted 1 times
...
Manix
1 year, 1 month ago
Selected Answer: C
pentest results are the best evidence of effectiveness.
upvoted 1 times
...
CISSPST
1 year, 5 months ago
PenTest is just a snapshot in time of the system's effectiveness but tracking the system's performance (e.g. no. of incidents prevented successfully and impact to business if the incidents were not prevented) gives more visibility to the RoI on the TCO. Correct answer is A.
upvoted 3 times
...
oluchecpoint
1 year, 5 months ago
A. Establish and present appropriate metrics that track performance. The best way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS) is to establish and present appropriate metrics that track the system's performance. This approach demonstrates the tangible value of the IPS and its effectiveness in protecting the organization's network and data. By using metrics related to the system's performance, such as the number of detected and blocked intrusion attempts, reduction in security incidents, or the cost savings resulting from prevented breaches, the manager can provide concrete evidence of the IPS's impact on security.
upvoted 1 times
oluchecpoint
1 year, 5 months ago
Establishing and presenting metrics that track performance not only justifies the maintenance fees but also helps in monitoring and improving the IPS's effectiveness over time, which is essential for maintaining a strong security posture.
upvoted 1 times
...
...
pc2502
1 year, 6 months ago
C. is the right answer
upvoted 1 times
...
richck102
1 year, 9 months ago
A. Establish and present appropriate metrics that track performance.
upvoted 2 times
...
Mauro4
1 year, 11 months ago
Selected Answer: A
Overarching answer (A). B, C, and D all fall under the metric category.
upvoted 1 times
...
Antonivs
2 years, 1 month ago
Selected Answer: A
A for sure
upvoted 1 times
...
STUDYER2
2 years, 1 month ago
Does anyone know how the correct answers are provided? thanks..
upvoted 1 times
fac161f
6 months ago
I would like to know that too.
upvoted 1 times
...
...
KANLA
2 years, 1 month ago
A is my option. Provision of data is the best way for justification
upvoted 1 times
...
Prospect57
2 years, 1 month ago
Selected Answer: A
A is my answer. Agreeing w/ the majority here.
upvoted 1 times
...
SSP_Secure
2 years, 1 month ago
Justification is result oriented and that need can be justified only through data points or Performance.
upvoted 1 times
...
D2D2
2 years, 2 months ago
Selected Answer: A
A for sure
upvoted 2 times
...
MSKid
2 years, 3 months ago
Selected Answer: A
Voting A also. CISM AIO 2nd - Metrics
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago