exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 591 discussion

Actual exam question from Isaca's CISM
Question #: 591
Topic #: 1
[All CISM Questions]

An information security manager has been notified that two senior executives have the ability to elevate their own privileges in the corporate accounting system, in violation of policy. What is the FIRST step to address this issue?

  • A. Notify the CISO of the security policy violation.
  • B. Perform a system access review.
  • C. Perform a full review of all system transactions over the past 90 days.
  • D. Immediately suspend the executives’ access privileges.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mih
1 week, 4 days ago
Selected Answer: D
First remediate the access and then perform exposure checks
upvoted 1 times
...
AlexJacobson
11 months, 1 week ago
Selected Answer: B
VALIDATE before anything else! So B first, then everything else (if needed later).
upvoted 2 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: B
B. Perform a system access review. Before taking any drastic actions such as notifying the CISO, suspending access privileges, or conducting a full review of all system transactions, it's essential to gather more information and assess the situation. A system access review will help determine the extent of the issue, identify how the privilege elevation is happening, and whether it is a deliberate policy violation or a result of a system misconfiguration. Once you have a better understanding of the problem, you can then take appropriate actions, which may include notifying the CISO, suspending privileges, or conducting further investigations.
upvoted 1 times
...
richck102
1 year, 6 months ago
A. Notify the CISO of the security policy violation. ????
upvoted 2 times
...
Jae_kes
1 year, 6 months ago
Selected Answer: B
B. Perform a system access review.
upvoted 3 times
...
Gr3yGh0sT
1 year, 8 months ago
Selected Answer: D
I think the first order of business will be to address the improper rights. Then you do a full system access review, and notify the CISO of the results.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...