exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 865 discussion

Actual exam question from Isaca's CISM
Question #: 865
Topic #: 1
[All CISM Questions]

What should be the FIRST step when investigating an employee suspected of inappropriately downloading proprietary information?

  • A. Check for a signed nondisclosure agreement (NDA).
  • B. Review system access logs.
  • C. Conduct a forensic examination of the device.
  • D. Discuss the concern with the employee.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
richck102
9 months, 2 weeks ago
B. Review system access logs.
upvoted 1 times
...
AaronS1990
11 months ago
Selected Answer: B
A. Check for a signed nondisclosure agreement (NDA). - Pretty sure you already know there has been a breach of terms or you wouldn't be concerned. So for me no need to check this. C. Conduct a forensic examination of the device. - Not necessary at this stage D. Discuss the concern with the employee. - No because you could alarm them to the fact that you're onto them. Answer: B. Review system access logs. - This is the best at this stage as it won't raise the alarm and may gather evidence or otherwise exonerate them.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...