Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 106 discussion

Actual exam question from Isaca's CISM
Question #: 106
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS)?

  • A. Establish and present appropriate metrics that track performance.
  • B. Perform industry research annually and document the overall ranking of the IPS.
  • C. Perform a penetration test to demonstrate the ability to protect.
  • D. Provide yearly competitive pricing to illustrate the value of the IPS.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alifjouj
2 months, 3 weeks ago
Selected Answer: C
periodic testing of effectiveness
upvoted 1 times
...
angellorv
6 months, 1 week ago
(C) ISACA CISM 15ed Review Manuan Section 1.6.5 (Value Delivery Metrics): Control cost-effectiveness that is determined by periodic testing The effectiveness of controls as determined by testing.
upvoted 1 times
...
simon205
7 months ago
C. We have to prove its capability and pay for its maintenance cost . Just like we buy insurance , we are not expecting its daily metrics , but we just need it during major incident .
upvoted 1 times
...
Manix
10 months ago
Selected Answer: C
pentest results are the best evidence of effectiveness.
upvoted 1 times
...
CISSPST
1 year, 1 month ago
PenTest is just a snapshot in time of the system's effectiveness but tracking the system's performance (e.g. no. of incidents prevented successfully and impact to business if the incidents were not prevented) gives more visibility to the RoI on the TCO. Correct answer is A.
upvoted 3 times
...
oluchecpoint
1 year, 2 months ago
A. Establish and present appropriate metrics that track performance. The best way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS) is to establish and present appropriate metrics that track the system's performance. This approach demonstrates the tangible value of the IPS and its effectiveness in protecting the organization's network and data. By using metrics related to the system's performance, such as the number of detected and blocked intrusion attempts, reduction in security incidents, or the cost savings resulting from prevented breaches, the manager can provide concrete evidence of the IPS's impact on security.
upvoted 1 times
oluchecpoint
1 year, 2 months ago
Establishing and presenting metrics that track performance not only justifies the maintenance fees but also helps in monitoring and improving the IPS's effectiveness over time, which is essential for maintaining a strong security posture.
upvoted 1 times
...
...
pc2502
1 year, 3 months ago
C. is the right answer
upvoted 1 times
...
richck102
1 year, 5 months ago
A. Establish and present appropriate metrics that track performance.
upvoted 2 times
...
Mauro4
1 year, 7 months ago
Selected Answer: A
Overarching answer (A). B, C, and D all fall under the metric category.
upvoted 1 times
...
Antonivs
1 year, 9 months ago
Selected Answer: A
A for sure
upvoted 1 times
...
STUDYER2
1 year, 9 months ago
Does anyone know how the correct answers are provided? thanks..
upvoted 1 times
fac161f
2 months, 3 weeks ago
I would like to know that too.
upvoted 1 times
...
...
KANLA
1 year, 10 months ago
A is my option. Provision of data is the best way for justification
upvoted 1 times
...
Prospect57
1 year, 10 months ago
Selected Answer: A
A is my answer. Agreeing w/ the majority here.
upvoted 1 times
...
SSP_Secure
1 year, 10 months ago
Justification is result oriented and that need can be justified only through data points or Performance.
upvoted 1 times
...
D2D2
1 year, 11 months ago
Selected Answer: A
A for sure
upvoted 2 times
...
MSKid
1 year, 12 months ago
Selected Answer: A
Voting A also. CISM AIO 2nd - Metrics
upvoted 2 times
...
mad68
2 years ago
Selected Answer: A
Establishing and presenting appropriate metrics that track performance is the only way to justify the cost, a penetration test only shows it works and can be used in the metrics.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...