exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 313 discussion

Actual exam question from Isaca's CISM
Question #: 313
Topic #: 1
[All CISM Questions]

An organization is considering the deployment of encryption software and systems organization-wide. The MOST important consideration should be whether:

  • A. a classification policy has been developed to incorporate the need for encryption
  • B. the business strategy includes exceptions to the encryption standard
  • C. data can be recovered if the encryption keys are misplaced
  • D. the implementation supports the business strategy
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yottabyte
10 months, 2 weeks ago
Selected Answer: D
D is the clear choice here.
upvoted 2 times
...
Agamennore
1 year, 5 months ago
Selected Answer: D
The business strategy is always the driver
upvoted 1 times
...
sphenixfire
1 year, 6 months ago
Selected Answer: C
Its surely c. Knowing because of reasons
upvoted 1 times
AlexJacobson
1 year ago
Well, on a more technical exam like CASP+ that might be the right answer. Here, you have to consider the bigger picture (business) first. So I guess ISACA answer would be D.
upvoted 1 times
...
...
karanvp
1 year, 7 months ago
Encryption should support business strategy; this achieve the security program objective to align with business
upvoted 1 times
...
chanke
1 year, 7 months ago
Selected Answer: D
ISACA CISM test will lean more towards the business even though classification might be the answer for this one I think business strategy alignment is more accurate as per the book.
upvoted 1 times
...
richck102
1 year, 7 months ago
D. the implementation supports the business strategy
upvoted 2 times
...
Abhey
1 year, 9 months ago
Selected Answer: A
The correct answer is A. a classification policy has been developed to incorporate the need for encryption. A classification policy identifies the different types of information that are used within an organization, specifies the appropriate controls to protect each type of information, and defines the handling and storage procedures. Encryption is typically applied to protect sensitive information. Without a classification policy, it can be challenging to identify which information requires encryption and which does not, leading to the improper application of encryption or the underprotection of sensitive information. Therefore, a classification policy is the most important consideration when considering the deployment of encryption software and systems organization-wide.
upvoted 2 times
...
dark_3k03r
1 year, 9 months ago
Selected Answer: D
The most important thing for an information security manager is to keep the business in mind and align the security strategy to the business. With this in mind, the best choice is (D) A. a classification policy doesn't necessarily ensure that it aligns with business strategy B. exempting encryption from the business strategy does little to align it C. This may be a great idea, but again doesn't align to the business strategy.
upvoted 4 times
...
dedfef
1 year, 10 months ago
the answer is A
upvoted 3 times
AlexJacobson
1 year ago
If you say so....
upvoted 1 times
...
...
kortcl
1 year, 11 months ago
The answer should be D
upvoted 2 times
...
MyKasala
2 years ago
Selected Answer: A
A is more relevant
upvoted 2 times
AlexJacobson
1 year ago
Care to elaborate how?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...