exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 671 discussion

Actual exam question from Isaca's CISM
Question #: 671
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to include in a post-incident review following a data breach?

  • A. An evaluation of the effectiveness of the information security strategy
  • B. Documentation of regulatory reporting requirements
  • C. A review of the forensics chain of custody
  • D. Evaluations of the adequacy of existing controls
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 11 months ago
Selected Answer: D
The MOST important aspect to include in a post-incident review following a data breach is D. Evaluations of the adequacy of existing controls. It is important to assess and evaluate the effectiveness of the existing controls in place to prevent such incidents from happening in the future. This will help identify any gaps or weaknesses in the current security measures and guide the organization in implementing improvements and making necessary changes to prevent similar incidents from happening again.
upvoted 9 times
...
Thavee
Most Recent 8 months, 2 weeks ago
Selected Answer: A
Answer is A. A. encompasses d. Please do not focus data breach just only technical way. Data breach could be caused from poor Policies, infrequent updated security strategy as per latest rolled out technologies, or untrained users who plugged in the USB stick into his working PC.
upvoted 1 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: D
D. Evaluations of the adequacy of existing controls Assessing the adequacy of existing controls is crucial because it helps identify the weaknesses and vulnerabilities that led to the data breach in the first place. This evaluation can lead to the development of effective remediation plans and improvements in security measures to prevent future breaches.
upvoted 1 times
...
richck102
1 year, 6 months ago
D. Evaluations of the adequacy of existing controls
upvoted 1 times
...
Souvik124
1 year, 10 months ago
All of the options listed are important to include in a post-incident review following a data breach, but if we have to choose the MOST important, it would be D.
upvoted 4 times
...
Boomers
1 year, 11 months ago
Selected Answer: A
The most important aspect to include in a post-incident review following a data breach is an evaluation of the effectiveness of the information security strategy.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...