Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 198 discussion

Actual exam question from Isaca's CISM
Question #: 198
Topic #: 1
[All CISM Questions]

Which of the following is MOST likely to affect an organization's ability to respond to security incidents in a timely manner?

  • A. Lack of senior management buy-in
  • B. Inadequate detective control performance
  • C. Misconfiguration of security information and event management (SIEM) tool
  • D. Complexity of network segmentation
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mad68
Highly Voted 1 year, 6 months ago
Selected Answer: A
The "CISM Review Manual, 16th Edition eBook*" , section 4.2.20 states: "Lack of management buy-in and organizational consensus- Most challenges result from a lack of management buy-in..... When an incident occurs, the management response may not be provided as expected, thus hindering incident management efforts.
upvoted 8 times
...
Josef4CISM
Most Recent 1 month, 1 week ago
Just a hint to rule out some of the answer options: Often the naswer options mean the same thing, bit are described differently. In this case, B and C are the same as a misconfigured SIEM (answer C) is a inadequate detective control (answer B). Such answer options are most likely wrong! In this case answer A is right.
upvoted 3 times
...
oluchecpoint
6 months ago
Selected Answer: B
B. Inadequate detective control performance Inadequate detective control performance is the most likely factor to affect an organization's ability to respond to security incidents in a timely manner. Detective controls are a crucial component of a comprehensive cybersecurity strategy, as they help identify security incidents and threats as they occur or shortly after they happen.
upvoted 2 times
Raven89
3 weeks ago
without senior management there are not detective controls approved
upvoted 1 times
...
...
e891cd1
7 months, 3 weeks ago
B..The first stage in incident management is Identification and Detection.
upvoted 1 times
...
UnoMigz
11 months, 2 weeks ago
Selected Answer: D
Take note of the "Timely manner". and they're about to "Respond". It assumes that all controls are implemented but it was not properly setup. Correct answer is D
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
B. Inadequate detective control performance Inadequate detective control performance is the most likely factor to affect an organization's ability to respond to security incidents in a timely manner. Detective controls are a crucial component of a comprehensive cybersecurity strategy, as they help identify security incidents and threats as they occur or shortly after they happen.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: B
IMHO is B due to the sentence “in a timely manner”, and the support of management doesn’t affect timing
upvoted 3 times
...
Hugo1717
1 year, 2 months ago
Selected Answer: B
The correct answer is B. Inadequate detective control performance. Explanation: Detective controls are security measures designed to identify and alert an organization about security incidents or breaches after they have occurred. If these controls are inadequate or not performing effectively, it can significantly impact an organization's ability to detect security incidents in a timely manner. Option A, "Lack of senior management buy-in," can impact the overall support and resources allocated to incident response efforts, but it is not as directly related to the technical ability to respond to incidents.
upvoted 3 times
...
sham222
1 year, 4 months ago
Selected Answer: A
Keyword here is "organization". Had the question been about "an engineer's" ability to respond, then maybe B or C would be a better answer. But since this is referring to the entire org, then I believe management would be the factor causing the lack of resources, budget, best hiring practices, tooling, etc.
upvoted 3 times
...
ddharia94
1 year, 4 months ago
Selected Answer: B
It is B.
upvoted 1 times
...
richck102
1 year, 5 months ago
A. Lack of senior management buy-in
upvoted 2 times
...
Abhey
1 year, 6 months ago
Selected Answer: B
All of the given options may affect an organization's ability to respond to security incidents in a timely manner, but the MOST likely one is B. Inadequate detective control performance. Detective controls are used to identify potential security incidents and initiate a response. If these controls are not performing effectively, incidents may go undetected or not be identified in a timely manner, which could significantly impact the organization's ability to respond to incidents in a timely manner.
upvoted 2 times
...
CarlPTY07
1 year, 8 months ago
Selected Answer: A
Clearly A
upvoted 4 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
The correct answer is A. Lack of senior management buy-in. A lack of buy-in from senior management can result in limited resources, insufficient budget allocation, and a lack of prioritization for incident response. This can negatively impact an organization's ability to respond to security incidents in a timely manner.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...