Certified Information Security Manager CISM · Free Practice Question Medium
Question 131
Which action should an information security manager prioritize to ensure effective vulnerability management in aligning with business objectives?
- A Establishing a real-time dashboard for tracking emerging threats
- B Implementing automated patch management for critical assets
- C Conducting regular penetration tests to identify vulnerabilities
- D Developing metrics that align with organizational risk tolerance
Reveal correct answer
Correct answer: D
Explanation
The Correct Answer: Developing metrics that align with organizational risk tolerance: Aligning metrics with the organization's risk tolerance ensures that vulnerability management efforts focus on areas that integrate with overall business objectives and risk management strategies. The Incorrect Answers: Establishing a real-time dashboard for tracking emerging threats: While useful for monitoring threats, this action does not directly ensure that vulnerability management efforts align with business objectives or risk tolerance. Implementing automated patch management for critical assets: Although important for vulnerability management, automated patch management does not inherently align metrics with organizational goals. Conducting regular penetration tests to identify vulnerabilities: This action helps identify vulnerabilities but does not address the alignment of vulnerability management metrics with business strategies or objectives.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
