Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 195 discussion

Actual exam question from Isaca's CISM
Question #: 195
Topic #: 1
[All CISM Questions]

Management has announced the acquisition of a new company. The information security manager of the parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies. To BEST address this concern, the information security manager should:

  • A. escalate concerns for conflicting access rights to management.
  • B. review access rights as the acquisition integration occurs.
  • C. implement consistent access control standards.
  • D. perform a risk assessment of the access rights.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Josef4CISM
1 month, 1 week ago
C is jumping right to the solution already - therefore its wrong. You need to understand the risk first and than act on it.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. This proactive approach involves establishing a standardized set of access control policies and procedures that will be applied consistently across both the parent company and the newly acquired company.
upvoted 1 times
...
Hugo1717
1 year, 2 months ago
Selected Answer: C
The correct answer is C. Implement consistent access control standards. By implementing consistent access control standards, the organization ensures that access rights are aligned and harmonized across both companies. This approach helps prevent conflicts and discrepancies in access permissions that could lead to information exposure. It also establishes a clear framework for managing access and ensures that access rights are granted based on defined roles, responsibilities, and business needs. Why its not D: Performing a risk assessment of access rights is valuable, but it should be coupled with the implementation of standardized access control practices to effectively mitigate the risk of exposure due to conflicting access rights.
upvoted 2 times
cidigi
7 months, 2 weeks ago
1st step is to define, if there is a risk, what is the risk etc. And then having that, you go to the senior management and express your concerns.
upvoted 1 times
...
...
wello
1 year, 5 months ago
Selected Answer: D
verify the risk, them act on it.
upvoted 1 times
...
wello
1 year, 5 months ago
Security manager is not sure whether the different access controls will cause a problem. We need to assess risk first to determine the problems and the fix it.
upvoted 1 times
...
richck102
1 year, 5 months ago
C. implement consistent access control standards.
upvoted 1 times
...
romero318
1 year, 6 months ago
Selected Answer: C
The question is simple. How do we " BEST " address the concern. Risk assessment is what you do first to see where the problems are but to address them you will implement access controls. So C is the answer
upvoted 2 times
cidigi
7 months, 2 weeks ago
To address the COncern, not to Address the Problem, cos we dont know if there is a problem in first place. So to address the concern, you do a risk assessment.
upvoted 1 times
...
AlexJacobson
10 months ago
Infosec manager is "concerned", he's not sure. To be sure he has to assess the situation and risks. Only after that he can go ahead and to other things.
upvoted 1 times
...
...
Abhey
1 year, 6 months ago
Selected Answer: D
Assess the risk first.
upvoted 1 times
...
DelTrotter
1 year, 11 months ago
The question does not state what to do FIRST, but how to BEST address the concern. So, in this case some consistent approach regarding access rights should be taken.
upvoted 4 times
...
aokisan
1 year, 11 months ago
Selected Answer: D
at first, need to asset risk.
upvoted 3 times
...
Ziggybooboo
1 year, 11 months ago
Would you not risk asses first?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...