exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 190 discussion

Actual exam question from Isaca's CISM
Question #: 190
Topic #: 1
[All CISM Questions]

The MOST effective way to continuously monitor an organization's cybersecurity posture is to evaluate its:

  • A. compliance with industry regulations.
  • B. key performance indicators (KPIs).
  • C. level of support from senior management.
  • D. timeliness in responding to attacks.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 5 months ago
Selected Answer: B
B. key performance indicators (KPIs). Continuously monitoring an organization's cybersecurity posture effectively is best done by evaluating its key performance indicators (KPIs). KPIs are a set of quantifiable measurements that organizations use to track and evaluate their performance against specific goals or objectives. They can be used to measure various aspects of an organization's cybersecurity posture, such as its ability to detect and respond to threats, the effectiveness of its security controls, and its overall security risk profile. By regularly monitoring and evaluating these KPIs, organizations can identify areas where they need to improve and make adjustments to their cybersecurity strategies accordingly. While compliance with industry regulations, level of support from senior management and timeliness in responding to attacks are important aspects of cybersecurity, Key performance indicators (KPIs) give a more holistic view of the organization cybersecurity posture and help the organization to track progress over time.
upvoted 8 times
[Removed]
1 year ago
this is a chatgpt answer. it will give you a different answer if you ask "what about D"
upvoted 3 times
...
...
afb4b17
Most Recent 1 month, 1 week ago
Selected Answer: D
You cannot predict posture bases on KPIs. Posture is about what you do with the KPIs. Timeliness give an indication of the posture.
upvoted 2 times
...
e891cd1
3 months, 3 weeks ago
B would be more effective to "continuously monitor" an organization posture. D just pertains to responding to incidents and not the organization posture.
upvoted 1 times
...
peelu
7 months ago
Selected Answer: B
Key performance indicators (KPIs).
upvoted 1 times
...
CISM2023
9 months, 1 week ago
Establish, monitor, evaluate and report key information security metrics to provide management with accurate and meaningful information regarding the effectiveness of the information security strategy. , key performance indicators
upvoted 1 times
...
oluchecpoint
10 months, 2 weeks ago
B is right
upvoted 1 times
...
Agamennore
10 months, 2 weeks ago
Selected Answer: B
KPI for continuous monitoring and improvement
upvoted 1 times
...
wello
1 year, 1 month ago
Selected Answer: B
KPIs is the answer.
upvoted 1 times
...
richck102
1 year, 1 month ago
B. key performance indicators (KPIs).
upvoted 1 times
...
mad68
1 year, 2 months ago
Selected Answer: B
B. key performance indicators (KPIs). Key performance indicators (KPIs) are metrics or measurable indicators that provide insights into the organization's cybersecurity posture and performance. By establishing and monitoring relevant KPIs, an organization can assess its security controls, identify trends, measure the effectiveness of security measures, and detect any potential vulnerabilities or weaknesses. KPIs can include metrics such as the number of security incidents, response times to incidents, percentage of systems patched and updated, successful phishing attempts, employee security awareness training completion rates, and other relevant indicators. These metrics provide a quantitative and objective view of the organization's security posture, allowing for ongoing monitoring, analysis, and adjustment of security measures.
upvoted 1 times
...
Abhey
1 year, 2 months ago
Selected Answer: B
KPIs are measurable values that demonstrate how effectively an organization is achieving its cybersecurity goals and objectives. By monitoring KPIs regularly, organizations can quickly identify potential cybersecurity issues and take proactive steps to address them. Examples of cybersecurity KPIs include the number of incidents detected, incident response time, and effectiveness of security controls.
upvoted 1 times
...
MyKasala
1 year, 6 months ago
Selected Answer: A
A is correct
upvoted 1 times
MyKasala
1 year, 6 months ago
Sorry B is correct
upvoted 2 times
...
...
DelTrotter
1 year, 7 months ago
Effectiveness -> metrics, i.e. KPIs.
upvoted 4 times
...
D2D2
1 year, 7 months ago
Correct me if I am wrong, the answer should be B. What are your thoughts?
upvoted 1 times
Ziggybooboo
1 year, 7 months ago
Yes after consideration I agree
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago