Exam CISM All QuestionsBrowse all questions from this exam
Question 852

Which of the following is an information security manager's MOST important action to mitigate the risk associated with malicious software?

    Correct Answer: B

    To mitigate the risk associated with malicious software, an information security manager's most important action is to implement a multi-layered security program. This comprehensive approach combines various security measures and controls to create multiple layers of defense, significantly reducing the risk of successful malware attacks. By addressing multiple potential points of failure and attack vectors, the effectiveness of the overall security posture is enhanced, providing a more robust protection against malicious software.

Discussion
Pabl0T0rrezOption: B

B? multi-layered security program is generally considered the most effective approach...

DERCHEF2009

agree with you

AlexJacobson

No only that, but the infosec manager's job is not to touch, but to advise, shape and influence.

AaronS1990Option: B

B- Defence in depth to put it another way

oluchecpointOption: B

Option B

sundersam23Option: B

Among the options provided, the MOST important action for an information security manager to mitigate the risk associated with malicious software is B. Implementing a multi-layered security program. A multi-layered security program combines various security measures and controls to create a comprehensive defense against malicious software. It involves implementing multiple layers of protection at different points in the IT infrastructure and user environment, significantly reducing the risk of successful malware attacks.

CISSPSTOption: B

The most likely answer is B. According to ncsc.gov.uk "Since there's no way to completely protect your organization against malware infection, you should adopt a 'defense-in-depth' approach. This means using layers of defense with several mitigations at each layer." This could include disabling of peripheral access ports and keeping OS and antivirus software up-to-date among other methods.

1899f17Option: C

C Ensuring antivirus has the latest definition files

richck102Option: B

B. Implementing a multi-layered security program

karanvpOption: B

D may not be correct answer as the risk is related to Malware.

chankeOption: B

Defense in-depth/multi-layered security program is the most effective approach.