exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 824 discussion

Actual exam question from Isaca's CISM
Question #: 824
Topic #: 1
[All CISM Questions]

The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization. Which of the following should be done FIRST?

  • A. Re-evaluate the risk.
  • B. Ask the business owner for the new remediation plan.
  • C. Inform senior management.
  • D. Implement compensating controls.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Marcelus1714
10 months, 4 weeks ago
Selected Answer: A
It says "the FIRST", the first is to re-evaluate the risk and then let's see what you do
upvoted 2 times
...
afc1019
1 year, 5 months ago
Selected Answer: A
When a new vulnerability is identified that affects key data processing systems, the first step the information security manager should take is to re-evaluate the risk. This involves assessing the potential impact of the vulnerability on the organization's data processing systems, the likelihood of exploitation, and the potential consequences if the vulnerability is left unaddressed. By re-evaluating the risk, the information security manager can determine the urgency and severity of the vulnerability and prioritize the response accordingly. This will help in making informed decisions about the appropriate remediation actions to be taken to mitigate the risk effectively.
upvoted 1 times
...
AXL1
1 year, 5 months ago
new vulnerability = no patch available Key system = critical the best solution would be to implement compensating controls, so D
upvoted 1 times
Salilgen
9 months, 3 weeks ago
If the risk is low (i.e. the likelyood is low) you could decide to do nothing. Then the FIRST thing is A
upvoted 1 times
...
...
koala_lay
1 year, 5 months ago
Selected Answer: A
A. Re-evaluate the risk.
upvoted 2 times
...
richck102
1 year, 5 months ago
A. Re-evaluate the risk.
upvoted 2 times
...
karanvp
1 year, 6 months ago
Selected Answer: B
Answer may be B. If any new vulnerabilities, just assign to business owner for remediation. Why do we re-evaluate risk for new vulnerabilities(Option A).
upvoted 1 times
wickhaarry
1 year, 5 months ago
because its a new vulnerability and risk level is not known
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...