CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 945


Which of the following would MOST effectively ensure that a new server is appropriately secured?

Show Answer
Correct Answer: D

Conducting penetration testing most effectively ensures that a new server is appropriately secured because it involves simulating real-world attacks to identify vulnerabilities and weaknesses. This comprehensive evaluation allows for potential security issues to be identified and addressed before they can be exploited, ensuring that the server is secure from various types of threats.

Discussion

12 comments
Sign in to comment
koala_layOption: D
Apr 19, 2024

All of the options mentioned can contribute to ensuring that a new server is appropriately secured. However, if I had to choose the most effective option, I would go with option D, conducting penetration testing. Penetration testing involves simulating real-world attacks on the server to identify vulnerabilities and weaknesses in the system. This allows for a comprehensive evaluation of the server's security posture and helps identify potential entry points for unauthorized access. By performing penetration testing, any security vulnerabilities can be identified and addressed before they can be exploited by malicious actors.

Cyberbug2021Option: A
May 22, 2024

You can not do a penn test everytime a new server is brought up

60d8b7dOption: D
Aug 28, 2024

Option A only focuses on technical controls but a pen test will test other forms of controls, like physical controls.

SilverFoxOption: A
May 26, 2024

ensure vs assure so going with A

POWNEDOption: D
Jul 31, 2024

Have to argue that pen test is the answer here. Ensure means to make certain. Only option to ensure you are secure is to have a third party try to break into the server. Keep in mind physical security along with technical.

wickhaarry
Mar 25, 2024

D. Conducting penetration testing

richck102Option: A
Apr 20, 2024

A. Enforcing technical security standards

Uncle_LuciferOption: A
Jun 13, 2024

B to D are doing investigative or identifying threats only A is implementing control

HN2025Option: A
Jan 27, 2025

Enforcing technical security standards ensures that the server is configured and maintained according to best practices and security guidelines. These standards typically cover various aspects of server security, such as hardening, patch management, access controls, and monitoring. By adhering to these standards, organizations can systematically address security risks and vulnerabilities, leading to a more secure server environment.

1899f17
Nov 28, 2024

B. Performing secure code reviews

realmjmjOption: D
Dec 27, 2024

Option A is just to wear the armor, to "ensure" it is secured, you will need to use a spear (Option D) to "test" it. my 2 cents.

Josef4CISMOption: A
Jan 18, 2025

Enforcing technical security standards as in the form of baseline configurations. Similar question exists in this question pool - they are just worded differently.