exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 608 discussion

Actual exam question from Isaca's CISM
Question #: 608
Topic #: 1
[All CISM Questions]

In order to understand an organization's security posture, it is MOST important for an organization's senior leadership to:

  • A. review the number of reported security incidents.
  • B. evaluate results of the most recent incident response test.
  • C. ensure established security metrics are reported.
  • D. assess progress of risk mitigation efforts.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SHERLOCKAWS
4 days, 21 hours ago
Selected Answer: D
Answer is D: Because it reflects how well the organization is addressing known risks, which is a core measure of its security posture.
upvoted 1 times
...
Thavee
5 months, 2 weeks ago
Selected Answer: C
ALL IN ONE CISM EXAM GUIDE, Mc Graw Hill Information Security Program Metrics A metric is a measurement of a periodic or ongoing activity intended to help management understand the activity within the context of overall business operations. In short, metrics are the means through which management can measure key processes and know whether their strategies are working. Metrics are used in many operational processes, but this section emphasizes metrics related to security governance. In other words, there is a distinction between tactical IT security metrics and those that reveal the state of the overall security program. The two are often related, however, as discussed in the sidebar “Return on Security Investment,” later in this chapter.
upvoted 2 times
...
yottabyte
6 months, 2 weeks ago
Selected Answer: C
I will go with C, senior leadership is involved here. assessing the risk progress can be done by the steering committee for option D but for senior leadership, C is more important probably.
upvoted 2 times
...
AlexJacobson
8 months, 1 week ago
Selected Answer: D
I will go with D here. C is the responsibility of infosec manager, not senior leadership. However, senior leadership will assess the progress of risk mitigation efforts via metrics. But yeah, unnecessarily tricky question with somewhat bad wording.
upvoted 1 times
...
POWNED
8 months, 1 week ago
Selected Answer: C
Senior leadership always ties with Metrics. The technical jargon has to be dumbed down for senior leadership with metrics. No they are not building the metrics, but they need to insure they are part of reporting so that they can understand what is going on.
upvoted 1 times
...
POWNED
8 months, 2 weeks ago
Selected Answer: D
In order to ensure the risk is mitigated to the proper risk acceptance level senior leadership needs to assess the progress of risk mitigation efforts. Answer is D
upvoted 1 times
POWNED
8 months ago
Ignore this answer.
upvoted 1 times
...
...
iacini
1 year ago
Selected Answer: D
I would say D, because C is not responsilibity of senior leadership. Establishment of metrics is responsibility of InfoSec Manager and senior leadership needs to make sure that they are assessing the progress of risk mitigation efforts.
upvoted 2 times
...
oluchecpoint
1 year ago
Selected Answer: C
Option C
upvoted 1 times
...
richck102
1 year, 2 months ago
C. ensure established security metrics are reported.
upvoted 2 times
...
devilend
1 year, 3 months ago
Answer: C I th
upvoted 1 times
...
mad68
1 year, 4 months ago
Selected Answer: D
In order to understand an organization's security posture, it is MOST important for an organization's senior leadership to assess the progress of risk mitigation efforts (option D). According to ISACA, security posture is defined as "the security status of an enterprise’s hardware, software and policies. It is the overall security status of an enterprise’s information technology (IT) environment and activities. Security posture is determined by evaluating threats and vulnerabilities and by identifying potential areas of risk. The goal of security posture management is to maintain an optimal level of security for the enterprise’s systems and data."
upvoted 2 times
...
Gr3yGh0sT
1 year, 5 months ago
Selected Answer: D
Gonna have to go with risk mitigation as well.
upvoted 1 times
...
CarlLimps
1 year, 7 months ago
Selected Answer: C
I prefer C - ensure established security metrics are reported.
upvoted 4 times
...
Broesweelies
1 year, 8 months ago
D. assess progress of risk mitigation efforts.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago