exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 487 discussion

Actual exam question from Isaca's CISM
Question #: 487
Topic #: 1
[All CISM Questions]

A serious vulnerability was detected in a business application that can be exploited by external attackers to compromise the system. What is the information security manager's BEST course of action?

  • A. Implement temporary remediation.
  • B. Request an immediate shutdown of the application.
  • C. Report the risk to the business application owner.
  • D. Ask the business application owner to apply the fix immediately.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
POWNED
1 year ago
Selected Answer: C
Let me give you an example... your a cop giving out a ticket. Scenario 1: Hand a speeder a ticket (report) you have x amount of days to pay this ticket or a warrant will be put out for your arrest. Scenario 2: Nicley ask the speeder to give you 150 dollars for speeding with no ticket given out. Which scenario do you think the $150 dollars would be collected. Obvious answer in that scenario and its the obvious answer for this question.
upvoted 2 times
...
koala_lay
1 year, 1 month ago
Selected Answer: C
The best course of action would be to report the risk to the business application owner (option C). It is crucial to communicate the vulnerability to the owner of the application, as they are responsible for managing and maintaining the application. They should be made aware of the situation so that appropriate action can be taken. It is their responsibility to apply the necessary fix (option D) to address the vulnerability. Additionally, it may be advisable to collaborate with the business application owner to develop a temporary remediation plan (option A) if the fix cannot be immediately applied.
upvoted 2 times
...
bradseth
1 year, 2 months ago
Selected Answer: C
CCCCCC
upvoted 1 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: C
Option C
upvoted 1 times
...
AaronS1990
1 year, 4 months ago
This is a tricky one: I feel it's between C and D For me: C. Report the risk to the business application owner. This would be the answer if it asked what is the FIRST thing to do. D. Ask the business application owner to apply the fix immediately. This would be the BEST thing to do seeing as it states it is a serious vulnerability.
upvoted 1 times
AlexJacobson
11 months ago
What if it's a 0-day and there's no fix? Then A would be correct. :) So I think it would go something like C->D->A or B
upvoted 1 times
...
...
Nillanash
1 year, 4 months ago
I go with Goseu. C is the correct answer. Thinking like a manager. The Information Security Manager does not fix, the role is to coordinate and report to get it fixed. D is not correct either because we do not need to provide the timeline "immediately" as the business owner knows what to do.
upvoted 2 times
...
Goseu
1 year, 5 months ago
Selected Answer: C
C is correct answer , think like a manager.
upvoted 2 times
...
richck102
1 year, 5 months ago
A. Implement temporary remediation.
upvoted 1 times
...
cangurer
1 year, 9 months ago
Selected Answer: D
reporting to the owner as a first step makes sense but the best action should be to ask to fix it immediately. Even if fix is not possible I would go with A to implement temporary remediation
upvoted 3 times
[Removed]
1 year, 5 months ago
business owner doesnt fix vulnerabilities
upvoted 1 times
Bisibaby
1 year, 4 months ago
The business application could be owned by IT though
upvoted 1 times
AlexJacobson
11 months ago
1) Rarely and hardly 2) Do not assume things not said in the question. You can try to infer, but NEVER assume. Everything you need to answer the question is in the question itself.
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...