Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 137 discussion

Actual exam question from Isaca's CISM
Question #: 137
Topic #: 1
[All CISM Questions]

An information security manager was informed that a planned penetration test could potentially disrupt some services. Which of the following should be the FIRST course of action?

  • A. Estimate the impact and inform the business owner.
  • B. Accept the risk and document it in the risk register.
  • C. Ensure the service owner is available during the penetration test.
  • D. Reschedule the activity during an approved maintenance window.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
D2D2
Highly Voted 2 years ago
Selected Answer: A
You should let the owner know about the impact and have them decide to accept or reschedule. Open to discussion to see what others think.
upvoted 10 times
oluchecpoint
1 year, 2 months ago
Owner is aware of the risk before approval, the owner should be available during the test will make logical approach
upvoted 1 times
...
...
alifjouj
Most Recent 2 months, 3 weeks ago
Selected Answer: D
clearly D. or test on a similar environnement
upvoted 2 times
...
oluchecpoint
8 months, 2 weeks ago
Selected Answer: A
Assess and inform business ownwer
upvoted 1 times
...
Marcelus1714
8 months, 2 weeks ago
Selected Answer: A
Would you reschedule without estimating the impact first? I believe is A...
upvoted 1 times
...
e891cd1
8 months, 4 weeks ago
D would be the most logical since it says "approve" meaning there were some escalation process and authorization process involved with the stake-holders before the windows was chosen to minimize disruption.
upvoted 1 times
...
Learner76
12 months ago
D - keywords "Disrupt services" and "Approved maintenance window"
upvoted 1 times
...
DonnyX
1 year, 1 month ago
I assume a planned pen-test is fully approved.. that's why we called "planned" .. if the question says "planning", maybe I will think D is the best option.. since it has been planed , I assume we we can do is estimate the impact and make a risk-based decision according to the estimated imapct with biz owner.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. Ensure the service owner is available during the penetration test. Before proceeding with a planned penetration test that could potentially disrupt some services, it is crucial to have the service owner or relevant stakeholders involved and available during the test. This ensures that they are aware of the potential disruptions, can provide real-time support or troubleshooting if issues arise, and can make informed decisions about any necessary actions during the test.
upvoted 1 times
...
DavoA
1 year, 4 months ago
Selected Answer: A
inform the business owner
upvoted 1 times
...
karanvp
1 year, 5 months ago
Maintenance Window period may be very short and I dont think Pen Test can be completed within such a short time period
upvoted 1 times
...
45
1 year, 5 months ago
Selected Answer: A
If it’s a “planned penetration test” I’m assuming it’s already approved therefore you should estimate the impact as the security manager and inform the business owner.
upvoted 1 times
...
richck102
1 year, 5 months ago
A. Estimate the impact and inform the business owner.
upvoted 1 times
...
Naijaboy
1 year, 6 months ago
Selected Answer: D
Doing it during maintenance window means that there's less impact to users and if anything goes wrong, change can always be rolled back with very minimum impact
upvoted 1 times
[Removed]
1 year, 4 months ago
but there's still an impact,
upvoted 1 times
...
...
bambs
1 year, 7 months ago
The first course of action should be to reschedule the penetration test during an approved maintenance window to minimize the risk of disrupting services. This option provides a balance between security testing and service continuity. Option A may be necessary after the decision to reschedule has been made, as it will allow the impact of the rescheduling to be estimated and communicated to the business owner. Option B is not appropriate in this situation because it does not address the issue of potentially disrupting services. Option C is also not the best course of action, as having the service owner available does not necessarily prevent disruption of services during the penetration test. D is the right answer
upvoted 3 times
drewl25
1 year, 3 months ago
Read the question over, the answer is: A. The pent test is already PLANNED meaning they approved the pent test, so why would they reschedule it!!! The have to measure what it looks like while users are active so they can know when something suspicious is going down on their network(measuring the business impact). Second, the business owner is in the best position to assess the potential impact on critical services and make informed decisions based on the organization's priorities and risk appetite.
upvoted 1 times
Learner76
12 months ago
Yes, planned but the new information came later therefore new decision is needed. If disruption is expected, business operation should take priority and therefore reschedule to maintenance window should be right. Just my assessment.
upvoted 1 times
...
...
...
meelaan
1 year, 8 months ago
Selected Answer: A
Seems A is right
upvoted 2 times
...
Prospect57
1 year, 10 months ago
Selected Answer: A
A is my answer. Looks to be the consensus here.
upvoted 2 times
...
mohit05
1 year, 11 months ago
Selected Answer: A
(A) is the appropriate option
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...