CITM Exam Questions & Answers
EXIN EPI Certified Information Technology Manager • Exin
100% money-back guarantee
Sample CITM Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Lately, the support desk is receiving several requests for password resets from individuals who appear to be unknown to the organization. Possible criminal activities are suspected, and the organization wishes to address this issue in their information security awareness program. What is the area that requires awareness?
Requests for password resets from unknown individuals suggest social engineering attacks, such as phishing or impersonation, where attackers manipulate users to gain unauthorized access. An information security awareness program should focus on educating staff about social engineering tactics to recognize and prevent such incidents.
E-mail usage (A), instant messaging (B), and internet usage (C) may be vectors for attacks, but the core issue is social engineering, which encompasses tactics used across these channels.
In vendor selection, what is the most important reason for a reference check?
The most important reason for a reference check in vendor selection is to independently verify and validate a vendor's claim (A). Reference checks involve contacting the vendor's previous or current clients to confirm claims about performance, reliability, and service quality, ensuring the vendor can meet contractual obligations. This aligns with vendor management best practices to mitigate risks by validating vendor credibility.
Verify products by other customers (B): Too narrow; reference checks focus on overall performance, not just products.
Obtain financial information (C): Financial data is obtained through financial due diligence, not reference checks.
Identify customers not mentioned (D): Not a primary goal; the focus is on validating provided references.
When selecting a new vendor, continuity needs to be guaranteed as much as possible. At a minimum, which criteria are considered?
To ensure continuity in vendor selection, the key criteria include head count (vendor's staffing capacity to deliver services), support (availability of ongoing technical and operational support), and financial stability (ensuring the vendor remains viable to provide services long-term). These factors directly impact the vendor's ability to maintain service delivery without interruptions, which is critical for business continuity.
Scope, maintenance, and price (A): Scope and price are important but don't directly ensure continuity; maintenance is a subset of support.
Terms and conditions, maintenance, and terms of engagement (B): These are contractual elements, but they don't fully address operational continuity like staffing or financial stability.
Price, training, and support (C): Training is less critical for continuity compared to staffing capacity or financial health.
According to vendor management frameworks, continuity is ensured by evaluating the vendor's operational capacity and long-term reliability, making head count, support, and financial stability the minimum criteria.
The team responsible for network security has proposed a firewall as the preferred control for the network perimeter. How is this type of control categorized?
A firewall is categorized as a technical preventive control (A) in information security management. According to ISO/IEC 27001, preventive controls aim to stop security incidents before they occur, and technical controls involve technology-based solutions. A firewall prevents unauthorized access to the network perimeter by filtering traffic, making it a technical preventive control.
Physical detective control (B): Involves physical measures (e.g., cameras) to detect incidents, not applicable to firewalls.
Administrative deterrent control (C): Involves policies or procedures to discourage violations, not technology-based.
Physical corrective control (D): Addresses physical issues post-incident, not relevant to firewalls.
Before the marketing department will decide on a new advertising campaign, it wants to be able to gain more insights into the customer, being able to predict the products customers will purchase in the near future. What is a 'must-have' criterion in terms of the technology the marketing department is interested in?
To predict future customer purchases, the marketing department requires advanced analytics (B), which involves sophisticated data analysis techniques, such as predictive modeling, machine learning, and data mining. These technologies enable the department to analyze customer behavior, identify patterns, and forecast purchasing trends, supporting targeted advertising campaigns.
Records Management System (RMS) (A): Focuses on managing and storing records, not predictive analysis.
Ad hoc analysis (C): Allows for on-demand, one-off queries but lacks the predictive capabilities of advanced analytics.
Business Intelligence (BI) (D): Provides reporting and historical data analysis but is less focused on predictive modeling compared to advanced analytics.
Advanced analytics aligns with IT strategy goals of leveraging data for competitive advantage, as it supports predictive insights critical for marketing decisions.
Get access to all 50 verified questions with detailed answers.
Unlock All CITM Questions