Certified Information Security Manager CISM · Free Practice Question Medium
Question 57
A company is experiencing frequent data breaches due to insufficient configuration management in their IT environment. Which of the following actions should an information security manager prioritize to address this issue?
- A Initiate a vulnerability scanning program targeting all company systems
- B Implement a robust change management process across all departments
- C Perform a detailed risk assessment focusing on configuration-related vulnerabilities
- D Conduct comprehensive security trainings for IT staff to prevent misconfigurations
Reveal correct answer
Correct answer: B
Explanation
The Correct Answer: Implement a robust change management process across all departments: Establishing an effective change management process can directly address issues caused by insufficient configuration management. It ensures that all changes to IT systems are systematically reviewed, approved, documented, and tested, thereby reducing misconfigurations that could lead to security vulnerabilities. By prioritizing change management, the organization can establish a controlled and predictable environment for changes, mitigating the risk of misconfigurations in both current and future systems. The Incorrect Answers: Conduct comprehensive security trainings for IT staff to prevent misconfigurations: While security training is important to increase awareness, it doesn't directly solve the root cause of the misconfigurations, which typically result from ineffective processes rather than lack of knowledge. Training can be an ongoing support activity but does not replace the need for a structured change management procedure. Initiate a vulnerability scanning program targeting all company systems: Vulnerability scanning helps identify existing weaknesses, but it doesn’t inherently prevent misconfigurations. While important, scanning alone cannot ensure that configuration management processes are effective or that misconfigurations do not occur. It addresses symptoms rather than the root cause. Perform a detailed risk assessment focusing on configuration-related vulnerabilities: Although performing a risk assessment can help identify potential vulnerabilities and their impact, it does not actively resolve configuration management deficiencies. Prioritizing a change management process first offers a proactive solution, possibly reducing the need for repeated assessments due to recurring configuration issues.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
