Certified Information Security Manager CISM · Free Practice Question Medium
Question 28
-
A
The organization’s questionnaire is clearly not detailed enough.
-
B
The person who answered the questions is not adequately familiar with the service provider’s security program.
-
C
The CISO should suspect that the service provider is being dishonest.
-
D
The service provider has an exemplary security program.
Reveal correct answer
Correct answer: B
Explanation
Correct Answer:
"The person who answered the questions is not adequately familiar with the service provider’s security program." is correct. When a service provider answers “yes” to every question, it is likely that the person answering the questions is either unfamiliar with their security program or answering it in haste, in the hopes it will not be scrutinized.
Incorrect Answers:
"The service provider has an exemplary security program." is incorrect because even the most exemplary security program is likely to answer “no” to at least a few questions in a questionnaire.
"The organization’s questionnaire is clearly not detailed enough." is incorrect, because although this is a plausible answer, it is not the best answer.
"The CISO should suspect that the service provider is being dishonest." is incorrect because this is a rash judgment (although it may in fact be true).
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
