exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 259 discussion

Actual exam question from Isaca's CISM
Question #: 259
Topic #: 1
[All CISM Questions]

An organization has implemented a new security control in response to a recently discovered vulnerability. Several employees have voiced concerns that the control disrupts their ability to work. Which of the following is the information security manager's BEST course of action?

  • A. Evaluate compensating control options.
  • B. Educate users about the vulnerability.
  • C. Accept the vulnerability.
  • D. Report the control risk to senior management.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oluchecpoint
Highly Voted 1 year, 1 month ago
A. Evaluate compensating control options. Explanation: Compensating controls are security measures or countermeasures that are put in place to mitigate the risk of a vulnerability when the primary control measure may disrupt normal operations. In this case, if employees are experiencing disruptions due to the new security control, it's essential to assess whether there are alternative or compensating controls that can provide the necessary security without causing significant disruptions. The goal of this action is to balance security needs with operational requirements. It demonstrates a proactive approach to addressing security concerns while minimizing the impact on employees' ability to work.
upvoted 8 times
shervin2s
6 months, 2 weeks ago
ChatGPT is wrong
upvoted 1 times
...
oluchecpoint
8 months, 1 week ago
Correct answer is D
upvoted 1 times
...
...
Adabach
Most Recent 1 day, 21 hours ago
Selected Answer: A
The best course of action for the information security manager is to A. Evaluate compensating control options.
upvoted 1 times
...
SHERLOCKAWS
1 week, 1 day ago
Selected Answer: A
If the current control is too disruptive, you look for alternative controls
upvoted 1 times
...
Shackman66
1 week, 3 days ago
Selected Answer: A
No point reporting to SM if you dont have a solution first (compensating control) Hence A.
upvoted 1 times
...
Pichon
4 weeks, 1 day ago
Selected Answer: D
D is the one most likely to be the best option
upvoted 1 times
...
yottabyte
6 months, 1 week ago
Selected Answer: A
You evaluate compensating controls before taking it up to senior management, if they ask if there is any other solution, you can't show the back of your hands.
upvoted 3 times
e891cd1
6 months ago
A .Agree you have to analyze or evaluate before you report.
upvoted 1 times
...
...
afoo1314
6 months, 1 week ago
Selected Answer: A
When you report the control risk to senior management, they will ask what is your option or suggestion. As an IS manager, it is your task to evaluate the option, then present to senior management.
upvoted 1 times
...
Marcelus1714
6 months, 2 weeks ago
Selected Answer: A
the BEST way is A... if you do D what? you report it and that's it? nothing more?
upvoted 1 times
...
oluchecpoint
8 months ago
Selected Answer: D
Correct answer is D
upvoted 1 times
...
oluchecpoint
8 months, 1 week ago
Selected Answer: D
Option D Same question is in CISM QAE
upvoted 1 times
...
acf4e9a
11 months, 3 weeks ago
Selected Answer: D
Concerns are raised by employees and not business unit management thus it would be appropriate to bring the conflict to senior management who are in a better position to assess the concerns vs risk and then decide the best course of action whether to enforce the control or evaluate for compensating control or something else.
upvoted 2 times
...
Orange_Grape_Mango
1 year, 2 months ago
Selected Answer: D
Refer to the question 217 of the V10 CISM Manual under Domain 3 Answer is D
upvoted 2 times
...
wello
1 year, 3 months ago
Selected Answer: D
Senior management can then evaluate the significance of the concerns raised by employees in the context of the organization's overall security objectives, operational requirements, and risk appetite. They can consider the potential disruptions caused by the control and determine whether any adjustments or compensating measures are necessary.
upvoted 3 times
...
richck102
1 year, 4 months ago
A. Evaluate compensating control options.
upvoted 1 times
...
dark_3k03r
1 year, 6 months ago
Selected Answer: A
The correct answer is (A): (A) This is the correct way to handle this as it helps the user and keeps the vulnerabiltiy at bay (B) Educating the user doesn't change the fact that it disrupts their work (C) If a control was implemented before, then you can tell it was unacceptable to accept the vulnerability (D) Management should already be aware of the risk, so this can't be it.
upvoted 3 times
...
ccKane
1 year, 7 months ago
Why not A?
upvoted 1 times
...
MyKasala
1 year, 8 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago