Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 339 discussion

Actual exam question from ISC's CISSP
Question #: 339
Topic #: 1
[All CISSP Questions]

Which of the following is established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls?

  • A. Security Assessment Report (SAR)
  • B. Organizational risk tolerance
  • C. Risk assessment report
  • D. Information Security Continuous Monitoring (ISCM)
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
stickerbush1970
Highly Voted 2 years, 2 months ago
Selected Answer: D
Agree with D.
upvoted 8 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
8e1c45b
Most Recent 4 months, 1 week ago
Selected Answer: D
Vote for D
upvoted 1 times
...
e58c193
7 months, 3 weeks ago
Selected Answer: C
The report which contains the results of performing a risk assessment or the formal output from the process of assessing risk." https://csrc.nist.gov/glossary/term/risk_assessment_repor
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
D. Information Security Continuous Monitoring (ISCM) Information Security Continuous Monitoring (ISCM) is a comprehensive process that involves the collection of security-related data and information to assess, analyze, and continuously monitor an organization's security posture. It uses pre-established metrics and leverages information available through implemented security controls to provide ongoing visibility into the effectiveness of an organization's security measures.
upvoted 3 times
...
Dee83
1 year, 9 months ago
D. Information Security Continuous Monitoring (ISCM).
upvoted 2 times
...
rdy4u
2 years ago
Selected Answer: D
information security continuous monitoring (ISCM): "A program established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls." https://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program
upvoted 3 times
...
HanzoShimada
2 years, 1 month ago
Selected Answer: D
It says it word for word on nist's official site. https://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program
upvoted 2 times
...
JAckThePip
2 years, 1 month ago
Answer is C "The report which contains the results of performing a risk assessment or the formal output from the process of assessing risk." https://csrc.nist.gov/glossary/term/risk_assessment_report
upvoted 1 times
...
krassko
2 years, 2 months ago
Selected Answer: D
Agree with D
upvoted 4 times
...
ygc
2 years, 2 months ago
C is correct, according to "available in part through implemented security controls"
upvoted 1 times
...
Loveguitar
2 years, 2 months ago
D is the correct answer accorhttps://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program#:~:text=Definition(s)%3A,part%20through%20implemented%20security%20controls.ding to nist
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...