exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 74 discussion

Actual exam question from Isaca's CISM
Question #: 74
Topic #: 1
[All CISM Questions]

An organization finds unauthorized software has been installed on a number of workstations. The software was found to contain a Trojan, which had been uploading data to an unknown external party. Which of the following would have BEST prevented the installation of the unauthorized software?

  • A. Banning executable file downloads at the Internet firewall
  • B. Implementing an intrusion detection system (IDS)
  • C. Implementing application blacklisting
  • D. Removing local administrator rights
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Gowtham2614
3 weeks, 3 days ago
Selected Answer: C
Application white listing
upvoted 1 times
...
oluchecpoint
5 months, 1 week ago
Selected Answer: D
D. Removing local administrator rights is a proactive security measure that can significantly reduce the risk of unauthorized software installations and is considered a best practice in security hygiene.
upvoted 2 times
...
Learner76
7 months, 3 weeks ago
D, remove local admin prevent installation of tools. Not C as you can't blacklist what you don't know. Unless is blocked all and use whitelist policy
upvoted 2 times
...
[Removed]
8 months, 1 week ago
Selected Answer: C
you can sometimes install a software without admin rights: Installing software without admin rights can have some security implications. First, the software may not be able to make system-wide changes that require admin permissions. Additionally, the software may not be able to access certain system files or settings that are only available to admin users.
upvoted 1 times
...
sphenixfire
10 months, 1 week ago
Selected Answer: D
sure d
upvoted 1 times
...
oluchecpoint
10 months, 2 weeks ago
D. Removing local administrator rights is a proactive security measure that can significantly reduce the risk of unauthorized software installations and is considered a best practice in security hygiene.
upvoted 1 times
...
drewl25
11 months, 4 weeks ago
Selected Answer: C
To best prevent the installation of unauthorized software that contains a Trojan and uploads data to an unknown external party, the organization should implement application blacklisting. Application blacklisting is a security control that involves identifying and blocking specific applications or software from being installed or executed on workstations or devices within the organization's network. It maintains a list of unauthorized or high-risk applications that are prohibited from being installed or run. By implementing application blacklisting, the organization can prevent the installation of unauthorized software by blocking the specific software or applications known to be high-risk or unauthorized. This control helps protect against malicious software, such as Trojans, that can compromise the security of the organization's systems and data.
upvoted 2 times
odus1
11 months ago
Is better to say whitelisting than bkacklisting because you can’t know all malicious applications. In other words, block all with exceptions.
upvoted 5 times
...
...
richck102
1 year, 1 month ago
D. Removing local administrator rights
upvoted 1 times
...
Antonivs
1 year, 5 months ago
Selected Answer: D
D first, then C
upvoted 2 times
...
Broesweelies
1 year, 5 months ago
Selected Answer: D
D. Removing local administrator rights would have BEST prevented the installation of the unauthorized software. This would have limited the ability of the Trojan to install itself on the workstations by limiting the user's ability to install software without proper approval.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago