Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 2 Question 33 Discussion

Which of the following is MOST likely to be included in an enterprise information security policy?
B) Consequences of noncompliance
A) Password composition requirements
C) Audit trail review requirements
D) Security monitoring strategy

Isaca CISM Exam - Topic 2 Question 33 Discussion

Actual exam question for Isaca's CISM exam
Question #: 33
Topic #: 2
[All CISM Questions]

Which of the following is MOST likely to be included in an enterprise information security policy?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Gaynell
8 months ago
Not sure if A is the most likely, seems too basic for a policy.
upvoted 0 times
...
Alita
9 months ago
Surprised that D isn't mentioned more, monitoring is key!
upvoted 0 times
...
Blair
9 months ago
C is crucial too, can't skip audit trails!
upvoted 0 times
...
Nilsa
9 months ago
I think B is more important, noncompliance needs clear consequences.
upvoted 0 times
...
Anisha
9 months ago
Definitely A, password rules are a must!
upvoted 0 times
...
Eladia
9 months ago
Security monitoring strategy sounds crucial, but I wonder if it's too detailed for an enterprise policy. I guess it depends on the organization.
upvoted 0 times
...
Eloisa
9 months ago
Audit trail review requirements seem like they could be part of a security policy, but I feel like they might be more operational than policy-related.
upvoted 0 times
...
Merlyn
9 months ago
I remember a practice question that emphasized consequences of noncompliance as a key part of security policies. That might be the answer.
upvoted 0 times
...
Jodi
9 months ago
I think password composition requirements are important, but I'm not sure if they belong in the main policy.
upvoted 0 times
...
Donte
9 months ago
Hmm, I'm a bit confused about the persistent storage part. Do we need to create a separate directory for the journal files, or can we just mount the /var/log/journal directory directly?
upvoted 0 times
...
Wei
9 months ago
Okay, I've got this. The question is asking which events the company must notify the NYSE about. Based on the options, it looks like the answer is D - all of the listed events, including changes to the business, officers/directors, and independent accountants. I'm confident that's the right answer.
upvoted 0 times
...
Monroe
9 months ago
I'm leaning towards "Design" because I feel like we're beginning to shape the website's structure. But I still have doubts about whether it could also be "Develop."
upvoted 0 times
...
Maryann
9 months ago
This one seems straightforward - the question is asking about a drug that inhibits xanthine oxidase and affects the metabolism of 6-mercaptopurine. Based on that, I think the answer is B. Allopurinol.
upvoted 0 times
...
Martha
10 months ago
Building risk-free systems? That doesn't sound quite right. I think the focus should be on managing and mitigating risks, not eliminating them entirely. Let me think this through again.
upvoted 0 times
...
Marci
10 months ago
I'm a bit confused on whether the expense should be measured at the grant date fair value or the reporting date fair value. I'll need to review the IFRS 2 guidance carefully.
upvoted 0 times
...

Save Cancel