exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 574 discussion

Actual exam question from Isaca's CISM
Question #: 574
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to ensure when an organization is moving portions of its sensitive database to the cloud?

  • A. The conversion has been approved by the information security team.
  • B. A right to audit clause is included in the contract.
  • C. Input from data owners is included in the requirements definition.
  • D. Data encryption is used in the cloud hosting solution.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sborrainculo
Highly Voted 1 year, 11 months ago
Selected Answer: C
I beg to differ, must be C. Only a data owner could tell which classification is the information and if needs encryption
upvoted 8 times
...
Josef4CISM
Most Recent 2 days, 22 hours ago
Selected Answer: C
Option D is not the right answer. Encryption is an important, but by far not the only control to be considered. Requirements from the data owner must be gathered as they can give information about the sensitivity & criticality of the data (e.g., classification). Based on this, appropriate measures can be identified and implemented, including encryption.
upvoted 1 times
...
ServerBrain
2 months, 3 weeks ago
Selected Answer: D
"its sensitive database"
upvoted 2 times
d7a2ba6
3 weeks, 5 days ago
So IT security team has not approveed it, we can not audit it, and no input from data owners, but in the Windows 7 "server" we enabled bitlocker. This must be OK. :)
upvoted 1 times
...
...
03allen
6 months, 3 weeks ago
Selected Answer: D
the keyword is 'sensitive', so it's D. C does not say anything about the classification, it could be operations and business. people are putting too much on their own opinions.
upvoted 1 times
...
yottabyte
9 months, 2 weeks ago
Selected Answer: C
Only Data owner would be able to tell the classification of data and what sort of encryption is required and if the encryption key is managed by the organization or by the cloud hoster.
upvoted 3 times
...
AlexJacobson
11 months, 3 weeks ago
Selected Answer: B
Right to audit clause - without it, you have no way to assure that security controls in the cloud are what cloud provider is saying they are. The role of the security manager is to ensure that appropriate controls are included in the contract. In the absence of a well-defined contractual agreement, the organization cannot enforce security requirements. The right to audit is one of the controls to be included in the contract.
upvoted 3 times
...
Uncle_Lucifer
1 year, 1 month ago
Selected Answer: D
The key word "sensitive" --> Encryption
upvoted 2 times
...
koala_lay
1 year, 3 months ago
Selected Answer: A
When an organization is moving portions of its sensitive database to the cloud, all the options listed are important in ensuring the security and integrity of the data. However, the MOST important consideration may vary depending on the specific context and requirements of the organization. That being said, if we have to choose the option that is generally considered crucial in such a scenario, it would be: A. The conversion has been approved by the information security team. Obtaining approval from the information security team ensures that the migration process aligns with the organization's security policies and standards. The security team assesses the potential risks and mitigations associated with moving sensitive data to the cloud, and their approval indicates that the necessary security measures have been implemented or planned. This helps in minimizing the chances of data breaches or unauthorized access during and after the migration.
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
Selected Answer: D
D. Data encryption is used in the cloud hosting solution. Data encryption ensures that even if unauthorized access occurs, the data remains protected and unreadable without the appropriate decryption keys. While the other options are also important in the context of cloud migration, such as approval from the information security team, a right to audit clause in the contract, and input from data owners, data encryption is the fundamental security measure that safeguards sensitive information from potential breaches or data leaks in a cloud environment. It forms a critical layer of security for data at rest and in transit in the cloud, and it should be a top priority when moving sensitive data to the cloud.
upvoted 1 times
...
richck102
1 year, 6 months ago
D. Data encryption is used in the cloud hosting solution.
upvoted 1 times
...
Souvik124
1 year, 10 months ago
When an organization is moving portions of its sensitive database to the cloud, the MOST important thing to ensure is that data encryption is used in the cloud hosting solution.
upvoted 1 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: D
The most important thing to ensure when an organization is moving portions of its sensitive database to the cloud is that data encryption is used in the cloud hosting solution.
upvoted 2 times
...
aokisan
2 years ago
Selected Answer: D
encryption is important for sensitive data.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago