CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 92


What is the PRIMARY benefit of effective configuration management?

Show Answer
Correct Answer: CD

The primary benefit of effective configuration management is decreased risk to the organization's systems. By properly managing and documenting all changes to system configurations, organizations minimize the likelihood of unauthorized or incorrect alterations that can lead to security vulnerabilities, system outages, or compliance issues. While standardization, reduced incidents, and improved vulnerability management are essential outcomes, they collectively contribute to the overarching goal of reducing risk.

Discussion

17 comments
Sign in to comment
BroesweeliesOption: C
Jan 15, 2023

C. Decreased risk to the organization's systems is the PRIMARY benefit of effective configuration management. Configuration management is the process of identifying, documenting, and controlling changes to systems and devices within an organization's infrastructure. By effectively managing configurations, the organization can minimize the risk of unauthorized changes, ensure that systems are in compliance with security policies, and easily identify and rollback any changes that may have introduced security vulnerabilities. A, B, and D are also benefits of effective configuration management, but they are secondary to the primary benefit which is decreased risk to the organization's systems. Standardization of system support ensures that all systems are configured and maintained in a consistent manner; Reduced frequency of incidents help to minimize the number of security incidents that occur; Improved vulnerability management help to identify and address vulnerabilities in a timely manner.

aokisanOption: C
Dec 26, 2022

configuration management is not only contributed for vulnerabilities.

MSKidOption: D
Oct 18, 2022

CISM AIO 2nd - Under "Configuration Management"

MSKidOption: D
Oct 18, 2022

Answer D also noted CISM AIO 2nd - Under "IT Service Management"

Prospect57Option: C
Jan 15, 2023

C covers "D" since "Risks" are in the form of vulnerabilities & threats.

Salilgen
Feb 12, 2024

Configuration management reduces vulnerabilities. However, improving vulnerability management does not reduce risk in the absence of threat

adamshupOption: C
Apr 11, 2023

PRIMARY benefit

AntonivsOption: C
Jan 26, 2023

C for sure

CISM_newbieOption: D
Apr 5, 2023

Trick question... improving vulnerability mgt decreases risk to the org's systems. Matter of what comes first, the chicken or the egg? Either way I'm good with either answer but by the book I believe the formal answer is (D).

richck102Option: C
May 25, 2023

C. Decreased risk to the organization's systems

oluchecpointOption: C
Sep 2, 2023

C. Decreased risk to the organization's systems The PRIMARY benefit of effective configuration management is the decreased risk to the organization's systems. Effective configuration management helps ensure that systems are configured correctly and consistently, reducing the likelihood of configuration errors, security vulnerabilities, and operational issues. This, in turn, lowers the overall risk to the organization's systems and data. While the other options (A, B, and D) are also important benefits of configuration management, they are typically secondary to the main goal of reducing risk.

ViperhunterOption: A
Nov 20, 2023

Effective configuration management involves maintaining and controlling the configuration items within an organization's IT infrastructure. Standardization of system support is a key outcome of configuration management, leading to a more stable and predictable IT environment. Standardized configurations help reduce variability, enhance system reliability, and streamline support processes, contributing to overall operational efficiency. While options B, C, and D are potential benefits of configuration management, they are often secondary to the primary goal of achieving standardization in system support.

oluchecpointOption: C
Feb 3, 2024

C. Decreased risk to the organization's systems The PRIMARY benefit of effective configuration management is the decreased risk to the organization's systems. Effective configuration management helps ensure that systems are configured correctly and consistently, reducing the likelihood of configuration errors, security vulnerabilities, and operational issues. This, in turn, lowers the overall risk to the organization's systems and data. While the other options (A, B, and D) are also important benefits of configuration management, they are typically secondary to the main goal of reducing risk.

seric01Option: A
Feb 22, 2024

I went for A, which seems to be the wrong option. Checked with AI though which also chose A. My reasoning is about the same as AI's. he PRIMARY benefit of effective configuration management is A. Standardization of system support. Configuration management ensures that all systems are consistent and adhere to the desired specifications. This standardization simplifies system support, as it reduces variability and makes troubleshooting more straightforward. Please note that while the other options can be benefits of configuration management, they are not the primary benefit.

helg420Option: C
May 7, 2024

C. Decreased risk to the organization's systems The primary benefit of effective configuration management is the decreased risk to the organization's systems. By meticulously tracking and managing changes to the system configurations, organizations can ensure that all changes are intentional, authorized, and properly documented. This meticulous oversight helps in minimizing the unintended consequences of changes that could introduce vulnerabilities or destabilize systems, thereby significantly reducing the risk to the organization's IT infrastructure. Configuration management provides visibility into how systems and controls rely on each other, informing network stakeholders of the potential impact of change to network components. This visibility and control are essential for maintaining the integrity, stability, and security of the systems, aligning with the overarching goal of decreasing risk.

angellorvOption: D
May 11, 2024

(D) - ISACA CISM 15ed Review Manual: The information security manager must provide ongoing - management of the operational information security components. This includes system patching procedures and configuration management. Thus decreasing an existing weakness or flaw in an OS, network, or application - reducing vulnerability. Also, for ISACA keep in mind that "RISK" = THREATS * VULNERABILITIES * CONSEQUENCES = $$ impact to the organization.

2dbaccaOption: A
Jun 3, 2024

The primary benefit of configuration management is consistency of systems and software.

BamBamBigalo
Jun 12, 2024

Are the "correct" answer actually verified?