exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 705 discussion

Actual exam question from Isaca's CISM
Question #: 705
Topic #: 1
[All CISM Questions]

When remote access to confidential information is granted to a vendor for analytic purposes, which of the following is the MOST important security consideration?

  • A. The vendor must be able to amend data
  • B. The vendor must agree to the organization's information security policy
  • C. Data is encrypted in transit and at rest at the vendor site
  • D. Data is subject to regular access log review
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
richck102
Highly Voted 1 year, 5 months ago
C. Data is encrypted in transit and at rest at the vendor site
upvoted 5 times
...
xcjxcj
Highly Voted 9 months, 1 week ago
Selected Answer: B
B includes C and D.
upvoted 5 times
...
shootnot
Most Recent 8 months, 2 weeks ago
C - Look at the choices from the view of which one of this if absent would be a concern for ISM
upvoted 1 times
...
AlexJacobson
10 months, 4 weeks ago
Selected Answer: B
I'd say B because it's the most comprehensive answer. When signing a contract with a vendor it's good to include security requirements (like agreeing to ISP and whatever is stated there).
upvoted 2 times
...
Cyberbug2021
1 year ago
Selected Answer: D
The Data is not being transferred but ACCESS is given. Encryption is always good but knowing exactly what is being accessed is more critical. Sure you can have contracts and ask vendor to follow your security policy but you won't know if all of it is being followed unless there is an audit or issue which causes review. But access logs are crucial.
upvoted 1 times
AlexJacobson
10 months, 4 weeks ago
But vendor is likely not going to run analytics on company's infrastructure, but will copy over the data to their systems.
upvoted 1 times
...
...
Cyberbug2021
1 year ago
Selected Answer: D
Need to be able to review access logs of the data to make sure there is no misuse
upvoted 1 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: B
B. The vendor must agree to the organization's information security policy
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
I think it's actually kind of a trick question, to where yes B should theoretically include C. But we don't know their current security policy therefore the most direct and apparent MOST important would be C. Once again, they should really remove ambiguous questions like this that leave room for arguments at to what exactly they mean.
upvoted 2 times
CISSPST
1 year, 2 months ago
Totally agree, with your answer and regd the responses that leave room for arguments. While it is true that the vendor has to agree with the security policy this is broadly applicable to all contracts. The question is specifically referring to remote access to sensitive data, and therefore encryption of data in transit and at rest is best choice.
upvoted 1 times
...
...
rbg8
1 year, 6 months ago
Selected Answer: B
B because encrypting data in transit and in rest, must be a part of the security policy. Then security policy is higher level so this is the managers answer.
upvoted 4 times
...
DERCHEF2009
1 year, 7 months ago
Selected Answer: B
It is B
upvoted 3 times
...
Souvik124
1 year, 10 months ago
The MOST important security consideration when remote access to confidential information is granted to a vendor for analytic purposes is that the vendor must agree to the organization's information security policy.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...