exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 243 discussion

Actual exam question from Isaca's CISM
Question #: 243
Topic #: 1
[All CISM Questions]

What is the PRIMARY objective of implementing standard security configurations?

  • A. Maintain a flexible approach to mitigate potential risk to unsupported systems.
  • B. Minimize the operational burden of managing and monitoring unsupported systems.
  • C. Compare configurations between supported and unsupported systems.
  • D. Control vulnerabilities and reduce threats from changed configurations.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Learner76
1 month ago
Selected Answer: D
D - Vulnerability control are easier and there should be no unauthorized configuration which introduced new vulnerability/threats
upvoted 1 times
...
richck102
7 months, 1 week ago
D. Control vulnerabilities and reduce threats from changed configurations.
upvoted 1 times
...
mad68
8 months ago
Selected Answer: D
D. Control vulnerabilities and reduce threats from changed configurations. Implementing standard security configurations involves defining and applying a set of predetermined, secure configuration settings for systems, applications, and network devices. By doing so, the organization aims to establish a baseline security posture that aligns with industry best practices and security standards. The primary goal is to control vulnerabilities and reduce threats that may arise from deviations or unauthorized changes in system configurations. Standard security configurations help ensure consistency and enforce security controls across the organization's IT infrastructure. By maintaining consistent and secure configurations, organizations can minimize the risk of exploitable vulnerabilities and improve their overall security posture.
upvoted 3 times
...
dark_3k03r
9 months ago
Selected Answer: D
The Correct answer is D: Control vulnerabilities and reduce threats from changed configurations. A. Standards are not flexible, you either comply or you don't B. This is an advantage, but not a security advantage. C. This is something you can do but is not the primary objective D. Standards are meant to reduce variance. So this will reduce configuration risk and control the vulnerabilities.
upvoted 1 times
...
vavofa5697
11 months ago
Selected Answer: D
D. it is quite clear and self-explaining
upvoted 1 times
...
MyKasala
1 year ago
Selected Answer: D
D is correct
upvoted 1 times
...
aokisan
1 year, 1 month ago
Selected Answer: C
need for gap analysis.
upvoted 1 times
Ziggybooboo
1 year ago
Disagree, you would standardize to minimize risk
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago