Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 572 discussion

Actual exam question from Isaca's CISM
Question #: 572
Topic #: 1
[All CISM Questions]

Which of the following BEST demonstrates that security controls are effective?

  • A. Audit report
  • B. Tabletop simulation
  • C. Risk and control self-assessment
  • D. Business impact analysis (BIA) results
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CarlPTY07
Highly Voted 1 year, 8 months ago
Selected Answer: A
•    Internal and external audit results: Audit reports are generally seen as an in-depth view of the effectiveness of internal controls in the organization. Gregory, Peter H.; Gregory, Peter H.. CISM Certified Information Security Manager Bundle (p. 132). McGraw Hill LLC. Kindle Edition.
upvoted 15 times
...
giovi
Highly Voted 1 year, 8 months ago
Selected Answer: C
Definitely C. Organizations must understand the risks they face and the controls they can implement to manage those risks. They must also conduct regular risk control assessments and self- assessments to determine whether those controls continue to operate effectively.
upvoted 5 times
...
Booict
Most Recent 2 months, 3 weeks ago
Selected Answer: A
A for me
upvoted 1 times
...
koala_lay
1 year, 2 months ago
Selected Answer: A
All of the options mentioned can provide valuable insights into the effectiveness of security controls, but the best demonstration would be an audit report. An audit report is a formal assessment conducted by an independent party that evaluates the adequacy and effectiveness of security controls. It provides an unbiased and objective view of the organization's security posture and can identify any vulnerabilities or weaknesses in the controls. In contrast, the other options mentioned - tabletop simulations, risk and control self-assessments, and business impact analysis (BIA) results - can help identify potential areas of improvement but may not provide the same level of assurance as an audit report.
upvoted 3 times
...
Cert_IT
1 year, 2 months ago
Selected Answer: A
Audit report. While tabletop simulations (option B), risk and control self-assessment (option C), and business impact analysis (BIA) results (option D) are valuable activities and assessments, they may not provide the same level of objective and independent verification of control effectiveness as an audit report. Audit reports are typically conducted by external or internal auditors with expertise in evaluating security controls, making them a strong indicator of control effectiveness.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: A
A. Audit report An audit report is typically the best demonstration that security controls are effective. It provides an independent assessment of an organization's security controls by an external auditor or an internal audit team. Audit reports include findings, recommendations, and conclusions about the effectiveness of security controls based on a comprehensive evaluation of the organization's policies, procedures, and practices. This assessment is generally considered to be an authoritative and objective measure of security control effectiveness.
upvoted 1 times
...
richck102
1 year, 4 months ago
A. Audit report
upvoted 2 times
...
meelaan
1 year, 7 months ago
Selected Answer: A
It A as it is BEST
upvoted 1 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
Audit report demonstrates that security controls are effective.
upvoted 4 times
...
D2D2
1 year, 11 months ago
Selected Answer: C
Risk and control self-assessment (RCSA) shows effectiveness.
upvoted 4 times
Ziggybooboo
1 year, 11 months ago
Agreed
upvoted 1 times
...
AlexJacobson
9 months, 4 weeks ago
Nope, these are for risk monitoring and reporting, the question is about effectiveness of security controls.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...