exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 325 discussion

Actual exam question from Isaca's CISM
Question #: 325
Topic #: 1
[All CISM Questions]

Which of the following is MOST important for an information security manager to verify before conducting full-functional continuity testing?

  • A. Incident response and recovery plans are documented in simple language
  • B. Copies of recovery and incident response plans are kept offsite
  • C. Teams and individuals responsible for recovery have been identified
  • D. Risk acceptance by the business has been documented.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 11 months ago
Selected Answer: C
While having documented risk acceptance by the business is important, it is more critical for the information security manager to verify that the teams and individuals responsible for recovery have been identified. This is because in the event of a disaster or interruption, the focus should be on restoring normal operations as quickly as possible, and having identified and trained teams and individuals in place will aid in this process. If the responsible individuals are not known, this can result in delays and confusion during the recovery process.
upvoted 13 times
...
aokisan
Highly Voted 2 years, 1 month ago
Selected Answer: D
before test, risk should be accepted.
upvoted 9 times
...
Marcelus1714
Most Recent 10 months ago
Selected Answer: C
C seems the right one in this context
upvoted 1 times
...
oluchecpoint
11 months, 3 weeks ago
Selected Answer: D
D. Risk acceptance by the business has been documented.
upvoted 1 times
...
jcisco123
1 year, 1 month ago
Selected Answer: C
Even if risk acceptance has been documented, without the right teams and individuals identified and prepared to execute recovery plans, the testing process may not be effective or successful. We need to select the option which is 'Most' important.
upvoted 2 times
...
oluchecpoint
1 year, 4 months ago
C. Teams and individuals responsible for recovery have been identified. Before conducting continuity testing, it's critical to ensure that the teams and individuals responsible for the recovery process have been identified and are ready to execute their roles effectively. Without clearly defined and designated responsible parties, continuity testing may not yield meaningful results, and the organization's ability to respond to incidents and recover from disasters could be compromised. While the other options (A, B, and D) are also important considerations in information security and business continuity planning, ensuring that the right people and teams are in place for recovery is foundational to the success of continuity testing and overall security preparedness.
upvoted 1 times
...
Hugo1717
1 year, 5 months ago
Selected Answer: C
The correct answer is C. Teams and individuals responsible for recovery have been identified. Explanation: Among the options provided, verifying that teams and individuals responsible for recovery have been identified is the most important factor for an information security manager to ensure before conducting full-functional continuity testing. Here's why this option is the most important: C. Teams and individuals responsible for recovery have been identified: In continuity testing, it's crucial to know who will be responsible for executing recovery plans and actions when a disaster or disruption occurs. Identifying and confirming the availability and readiness of these teams and individuals ensures that the testing process can be effectively coordinated and executed.
upvoted 1 times
...
Diekky
1 year, 6 months ago
If every other conditions are met and business do not accept risk then nothing can be done, therefore risk acceptance by the business is more suitable
upvoted 1 times
...
richck102
1 year, 7 months ago
C. Teams and individuals responsible for recovery have been identified
upvoted 2 times
...
Abhey
1 year, 8 months ago
Selected Answer: C
Before conducting full-functional continuity testing, the most important thing for an information security manager to verify is that teams and individuals responsible for recovery have been identified. This is because these teams and individuals are the ones who will be responsible for executing the recovery plans during the continuity testing. Without identifying the appropriate teams and individuals, it will be difficult to assess the organization's ability to recover from a disaster or disruption.
upvoted 1 times
...
dark_3k03r
1 year, 9 months ago
Selected Answer: C
The driving factor for continuity testing should be to keep the business running. With this in mind, the only correct answer is (C) as it is the only one that addresses uptime. Rationale: (A) IR in simple language is great but does nothing to address keeping the business running. Cause without the proper people it's not going anywhere. (B) Keeping the copies offsite doesn't help when you need them right now. (D) Risk acceptance is important, but you need someone to carry out those orders. Thus why (C) is the correct answer.
upvoted 3 times
...
Ziggybooboo
2 years, 2 months ago
I would go with C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...