exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 644 discussion

Actual exam question from Isaca's CISM
Question #: 644
Topic #: 1
[All CISM Questions]

Which of the following BEST enables an information security manager to determine the comprehensiveness of an organization’s information security strategy?

  • A. Internal security audit
  • B. Organizational risk appetite
  • C. External security audit
  • D. Business impact analysis (BIA)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d3fa4d2
Highly Voted 9 months, 4 weeks ago
Selected Answer: B
In simple words organization’s information security strategy is something that's tailored based on where the org wants to be (a.k.a risk apetite) audits results are based on complaince.
upvoted 5 times
...
SHERLOCKAWS
Most Recent 4 months, 3 weeks ago
Selected Answer: A
Correct answer is A: Internal security audit. Because it allows the security manager to systematically evaluate whether the strategy is holistic, risk-aligned, and effectively implemented.
upvoted 2 times
...
sm24
1 year ago
So many of you have selected Audits here. Not sure how you can audit a strategy.
upvoted 2 times
...
TamerBeSafe
1 year ago
Selected Answer: C
C. External security audit An external security audit involves an independent examination of an organization's information security policies, processes, and controls by an external entity. This audit assesses the organization's adherence to established standards and best practices, helping to determine the comprehensiveness of the information security strategy. External audits provide an objective perspective and can identify areas for improvement, potential vulnerabilities, and gaps in the security strategy that may not be apparent in internal assessments. While internal security audits (Option A) and other assessments are valuable, an external audit adds an extra layer of validation and objectivity to the evaluation process.
upvoted 1 times
...
POWNED
1 year, 1 month ago
Selected Answer: C
Straight from multiple professional pentesters mouth. A company will almost always pass an internal audit either that be them knowing they are lying or on accident. For the most compressive dive into a businesses security a 3rd party audit needs to be performed.
upvoted 2 times
...
Uncle_Lucifer
1 year, 2 months ago
Selected Answer: C
How is internal audit better than independent (external) audit? Prove this to me. Answer is C
upvoted 2 times
...
oluchecpoint
1 year, 5 months ago
Selected Answer: C
Option C
upvoted 1 times
...
richck102
1 year, 7 months ago
C. External security audit
upvoted 1 times
...
karanvp
1 year, 7 months ago
Selected Answer: B
Answer B: Because a Risk Appetite will decide how comprehensive the Security Strategy should be. Risk Appetite drive security strategy.
upvoted 4 times
...
Jae_kes
1 year, 8 months ago
Selected Answer: A
A. Internal security audit
upvoted 2 times
...
Dravidian
1 year, 9 months ago
Selected Answer: C
Seeing as the question is asking for BEST method to get 'comprehensiveness'. I would go with an 3rd party independent audit of the InfoSec program. Which in this case is Option C. Organization risk appetite can give a good understanding of the program but complete details I don't think so.
upvoted 2 times
...
Broesweelies
2 years ago
Selected Answer: A
Internal audit
upvoted 3 times
...
MyKasala
2 years ago
Selected Answer: B
I guess B
upvoted 2 times
...
aokisan
2 years, 1 month ago
Selected Answer: C
comprehensive understanding is provided by external audit.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...