00:00

QUESTION 21

Which of the following is the BEST approach to incident response for an organization migrating to a cloud-based solution?

Correct Answer: D

QUESTION 22

Which of the following should be the PRIMARY objective of an information security governance framework?

Correct Answer: A
According to the Certified Information Security Manager (CISM) Study Manual, "The primary objective of information security governance is to provide a framework for managing and controlling information security practices and technologies at an enterprise level. Its goal is to manage and reduce risk through a process of identification, assessment, and management of those risks."
While demonstrating senior management commitment, compliance with industry best practices, and ensuring user compliance with policies are all important aspects of information security governance, they are not the primary objective. The primary objective is to manage and reduce risk by establishing a framework for managing and controlling information security practices and technologies at an enterprise level.

QUESTION 23

Which of the following BEST indicates that an organization has effectively tested its business continuity and disaster recovery plans within the stated recovery time objectives (RTOs)?

Correct Answer: D

QUESTION 24

Which of the following is the BEST indication of effective information security governance?

Correct Answer: C

QUESTION 25

Which of the following will ensure confidentiality of content when accessing an email system over the Internet?

Correct Answer: B