Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 222 discussion

Actual exam question from Isaca's CISM
Question #: 222
Topic #: 1
[All CISM Questions]

An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?

  • A. Initiate incident response.
  • B. Initiate a device reset.
  • C. Conduct a risk assessment.
  • D. Disable remote access.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
david124
1 week, 4 days ago
Selected Answer: C
what classification would you give it? how would you base the severity of the incident if you don't know what the risk is? C is the most common sense
upvoted 1 times
...
helg420
6 months, 1 week ago
Selected Answer: A
A. Initiate incident response. The first action that an information security manager should take upon being notified of the loss of a personal mobile device containing corporate information is to initiate the incident response process. This process is designed to handle such events with a structured approach, which typically includes steps such as assessing the situation, containing the impact, eradicating the threat if any, and recovering from the incident.
upvoted 2 times
...
shervin2s
8 months ago
Selected Answer: A
That's an incident, Risk hasn't changed.
upvoted 2 times
...
xcjxcj
8 months, 2 weeks ago
Selected Answer: A
Device is lost, so not able to do proper risk assessment.
upvoted 1 times
...
oluchecpoint
9 months, 3 weeks ago
Selected Answer: C
Answer C
upvoted 1 times
...
AlexJacobson
9 months, 4 weeks ago
Selected Answer: C
I'd go with C. We first need to establish what corporate information was on it. It's a totally different game if you have confidential data on there vs. some marketing materials. So before we panic and spend more time and resources than necessary, we need to assess the actual risk of this. BTW, I think the word "personal" was put in there to imply there wasn't MDM at play, so remote wipe is likely not possible.
upvoted 2 times
xcjxcj
8 months, 2 weeks ago
Most case employee don't have a full picture how many corporate info is stored. And now the device is not with him.
upvoted 2 times
...
...
POWNED
11 months ago
Selected Answer: A
Based on my post answer is A.
upvoted 1 times
...
POWNED
11 months ago
If it just said a device was lost without including corporate information I would agree the answer is C. Since the report included corporate information was on the phone this should immediately move into incident response. Answer is A.
upvoted 1 times
...
Learner76
11 months, 2 weeks ago
Selected Answer: C
Without knowing what was lost and the impact, declaring an incident is premature.
upvoted 2 times
...
AaronS1990
1 year, 2 months ago
Selected Answer: C
It’s definitely C. Resetting wouldn’t achieve anything and disabling remote access would actually be counterproductive. You may do A, and if the question asked the BEST response I’d go with that however it asks first. So it’s C
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. Conduct a risk assessment. In this scenario, the first step the information security manager should take is to conduct a risk assessment. This is a critical initial action because it allows the organization to understand the potential impact of the loss of the personal mobile device containing corporate information and assess the level of risk associated with the incident.
upvoted 2 times
...
Hugo1717
1 year, 2 months ago
Selected Answer: C
The correct answer is C. Conduct a risk assessment. Explanation: When an employee reports the loss of a personal mobile device containing corporate information, the first step the information security manager should take is to conduct a risk assessment. This assessment will help determine the potential impact of the loss on the organization's information security. Here's why the other options are not the first step: A. Initiate incident response: Before initiating an incident response, it's important to assess the potential risks associated with the loss of the device. The risk assessment will guide the appropriate incident response actions.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: B
From the ISACA's CISM Review Manual 15th Edition: "In the event of a loss of a device containing corporate information, the immediate priority is to ensure that the data on the device cannot be accessed. The first step would generally be to initiate a remote wipe or reset of the device, if possible."
upvoted 1 times
Hugo1717
1 year, 2 months ago
Here its a personal data, no MDM installed so no wipe option. Risk assessment must be performed first, if needed an incident response will be initiated.
upvoted 1 times
...
SilverFox
1 year ago
I have a copy of the ISACA Manual 15th Ed + 16th in Electronic format and I have not ONCE been able to find a quote of yours in the manual. Nevertheless - I do review your views with respect. It is better than reading through all the dubious ChatGPT responses.
upvoted 2 times
...
...
richck102
1 year, 5 months ago
A. Initiate incident response.
upvoted 1 times
...
Saisharan
1 year, 5 months ago
How come it is A. It should be Option D. By disabling remote access, the organization can prevent unauthorized access to corporate data and minimize the potential impact of the incident. Let me know your thoughts.
upvoted 2 times
AaronS1990
1 year, 2 months ago
You wouldn’t be able to use or locate the device without remote access. How could disabling it possibly help?
upvoted 2 times
...
...
Abhey
1 year, 6 months ago
Selected Answer: A
The FIRST step the information security manager should take is to initiate incident response. Incident response includes taking immediate steps to prevent further damage or unauthorized access to the corporate information. The incident response team can then assess the situation, conduct a risk assessment, and determine appropriate next steps such as disabling remote access or resetting the device.
upvoted 1 times
AaronS1990
1 year, 2 months ago
Another shit ChatGPT answer that gives no value whatsoever to the discussion
upvoted 3 times
...
...
meelaan
1 year, 7 months ago
Selected Answer: A
Its A Only
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...