Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 4 Question 42 Discussion

The BEST way to identify the risk associated with a social engineering attack is toAn organization has acquired a company that manufactures Internet of Things (loT) devicesWhat should the information security manager do NEXT?
B) Review the acquired company's data sharing agreements.
A) Update the information security strategy.
C) Review the acquired company's audit reports.
D) Conduct a vulnerability assessment.

Isaca CISM Exam - Topic 4 Question 42 Discussion

Actual exam question for Isaca's CISM exam
Question #: 42
Topic #: 4
[All CISM Questions]

The BEST way to identify the risk associated with a social engineering attack is to

An organization has acquired a company that manufactures Internet of Things (loT) devices

What should the information security manager do NEXT?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Elmer
8 months ago
Audit reports are important too, can't overlook them!
upvoted 0 times
...
Laura
9 months ago
Surprised that updating the security strategy isn't the top priority!
upvoted 0 times
...
Na
9 months ago
But shouldn't we conduct a vulnerability assessment first?
upvoted 0 times
...
Jodi
9 months ago
Definitely agree, those agreements can reveal a lot!
upvoted 0 times
...
William
9 months ago
I think reviewing data sharing agreements is crucial.
upvoted 0 times
...
Brock
9 months ago
This question reminds me of a practice question we did on mergers. I think conducting a vulnerability assessment is crucial, but I’m not completely confident.
upvoted 0 times
...
Lindsey
9 months ago
I’m a bit confused about whether updating the security strategy is necessary right away. Shouldn’t we assess the current situation first?
upvoted 0 times
...
Nieves
9 months ago
I think reviewing audit reports could help identify existing vulnerabilities, but I feel like a vulnerability assessment might be more proactive.
upvoted 0 times
...
Dusti
9 months ago
I remember we discussed the importance of understanding data sharing agreements in class, but I'm not sure if that's the immediate next step here.
upvoted 0 times
...
Mitzie
9 months ago
Okay, let's see here. The question is asking about a common obstacle, so I'm thinking the best approach would be to recommend a solution that addresses a common pain point in the current case assignment process. Migrating to Omni-Channel could be an interesting option to explore.
upvoted 0 times
...
Lina
10 months ago
I think the answer is C. The question is asking about the Employee Restrictions Field, and C says "Own and Subordinates Only", which sounds like it would allow a Support Manager to view cases assigned to their direct reps.
upvoted 0 times
...

Save Cancel