Certified Information Security Manager (CISM) — Questions and Answers
Question 1: Which of the following BEST describes the purpose of a Business Impact Analysis (BIA)?
- To assess employee compliance with security policies
- To identify all network vulnerabilities in the organization
- To determine critical business processes and the impact of their disruption (Correct answer)
- To calculate the cost of deploying new security technologies
Correct answer: To determine critical business processes and the impact of their disruption
A BIA identifies critical business processes, their dependencies, and the potential impact of disruption, which informs risk prioritization and continuity planning.
Question 2: Which of the following BEST describes the concept of 'privacy by design' in a compliance context?
- Obtaining user consent before collecting any personal data
- Embedding privacy protections into systems and processes from the beginning of development (Correct answer)
- Storing personal data in geographically restricted data centers
- Encrypting all databases containing personal information
Correct answer: Embedding privacy protections into systems and processes from the beginning of development
Privacy by design integrates data privacy protections into systems, processes, and products from inception, rather than adding them as afterthoughts.
Question 3: During an active ransomware incident, the FIRST priority of the CISM should be to:
- Pay the ransom to restore operations as quickly as possible
- Issue a public statement to customers and stakeholders
- Activate the incident response plan and isolate affected systems (Correct answer)
- Replace all encrypted systems with new hardware
Correct answer: Activate the incident response plan and isolate affected systems
Activating the incident response plan and isolating affected systems are the immediate priorities to contain the ransomware and prevent further spread.
Question 4: During a risk assessment, the team identifies a vulnerability with a high likelihood but very low impact. How should this risk MOST likely be treated?
- Implement costly countermeasures to eliminate it
- Accept the risk without further action
- Mitigate it with low-cost controls proportional to impact (Correct answer)
- Transfer the risk through cyber insurance
Correct answer: Mitigate it with low-cost controls proportional to impact
Risk treatment should be proportional; high-likelihood, low-impact risks warrant lightweight mitigating controls rather than expensive remediation or acceptance.
Question 5: A CISM is developing a security roadmap. The roadmap should be aligned to:
- The IT department's annual budget cycle
- The organization's strategic business plan and risk tolerance (Correct answer)
- The latest cybersecurity threat intelligence reports
- Industry peer benchmarks and best practices only
Correct answer: The organization's strategic business plan and risk tolerance
A security roadmap must align to the organization's strategic business plan and risk tolerance to ensure security investments support business goals.
Question 6: Which of the following BEST supports measuring the maturity of an information security program?
- Using a capability maturity model to assess program components (Correct answer)
- Comparing policy counts with peer organizations
- Counting the total number of security incidents in a year
- Tracking the number of security tools deployed
Correct answer: Using a capability maturity model to assess program components
Capability maturity models provide a structured, objective way to assess the maturity and effectiveness of security program components against defined levels.
Question 7: A CISM is tasked with reducing the attack surface of the organization. Which approach BEST achieves this goal?
- Increasing network monitoring capabilities
- Deploying advanced endpoint detection and response tools
- Training employees to recognize social engineering attacks
- Implementing least privilege access and removing unnecessary services (Correct answer)
Correct answer: Implementing least privilege access and removing unnecessary services
Least privilege access and eliminating unnecessary services directly reduces the number of exploitable entry points for attackers.
Question 8: Which of the following BEST describes 'inherent risk' in information security?
- Risk that exists before any controls are implemented (Correct answer)
- Risk associated with third-party vendors only
- Risk transferred to a third party via insurance
- Risk remaining after controls are applied
Correct answer: Risk that exists before any controls are implemented
Inherent risk is the level of risk that exists naturally before any controls or mitigations are put in place.
Question 9: Which metric BEST demonstrates the effectiveness of an information security awareness training program?
- Number of employees who completed training
- Reduction in security incidents caused by human error (Correct answer)
- Number of training modules available
- Cost of delivering the training program
Correct answer: Reduction in security incidents caused by human error
Outcome-based metrics like reduced human-error incidents directly measure whether training changed behavior, not just participation.
Question 10: Which of the following BEST describes the purpose of a security awareness training program?
- To educate employees about threats and their role in protecting information (Correct answer)
- To replace technical security controls
- To satisfy regulatory requirements only
- To test employees with unannounced phishing attacks
Correct answer: To educate employees about threats and their role in protecting information
Security awareness training educates employees about information security threats and their individual responsibilities in protecting organizational assets.
Question 11: Which of the following BEST describes 'forensic preservation' during incident response?
- Immediately restoring affected systems to minimize downtime
- Deleting all logs to protect sensitive information
- Collecting and preserving evidence in a manner that maintains its integrity for investigation (Correct answer)
- Notifying law enforcement before any investigation begins
Correct answer: Collecting and preserving evidence in a manner that maintains its integrity for investigation
Forensic preservation involves collecting evidence using documented, integrity-preserving methods to support investigation and potential legal proceedings.
Question 12: Who is responsible for making sure that data is categorized and that particular security precautions are taken?
- The security Officer
- The end user
- Senior Management (Correct answer)
- The custodian
Correct answer: Senior Management
Routine administration of all aspects of security is delegated, but top management must retain overall accountability.
Question 13: Which of the following is a KEY component of an effective risk communication strategy?
- Translating risk findings into business terms for stakeholders (Correct answer)
- Using technical jargon to demonstrate expertise
- Restricting risk reports to IT and security teams only
- Publishing raw vulnerability data on the intranet
Correct answer: Translating risk findings into business terms for stakeholders
Effective risk communication requires translating technical findings into business-relevant language so that stakeholders can make informed decisions.
Question 14: Which factor MOST influences the priority of information security risk treatment?
- The opinion of the IT department
- The cost of available security technologies
- The age of the affected systems
- The likelihood and potential business impact of the risk (Correct answer)
Correct answer: The likelihood and potential business impact of the risk
Risk prioritization is driven by the combination of likelihood and business impact, ensuring the most critical risks receive attention first.
Question 15: Which of the following is the MOST effective way to ensure third-party vendors comply with the organization's security requirements?
- Limit vendor access to only non-sensitive systems
- Rely on vendors' published security certifications
- Require vendors to sign a security acknowledgment form annually
- Include security requirements in contracts and conduct periodic audits (Correct answer)
Correct answer: Include security requirements in contracts and conduct periodic audits
Contractual security requirements combined with regular audits create enforceable obligations and verification mechanisms.
Question 16: A CISM is presenting the security program's value to executive leadership. Which approach is MOST effective?
- Provide a list of all compliance requirements met
- Present security metrics tied to business risk reduction and outcomes (Correct answer)
- Detail the technical vulnerabilities remediated during the year
- Show the number of security incidents prevented by controls
Correct answer: Present security metrics tied to business risk reduction and outcomes
Executive leadership responds best to security metrics framed in terms of business risk reduction and organizational outcomes.
Question 17: Which of the following BEST describes a 'defense-in-depth' strategy in an information security program?
- Focusing all security investment on the most critical assets only
- Deploying a single, highly capable security platform
- Relying exclusively on perimeter defenses such as firewalls
- Implementing multiple layers of controls so that failure of one does not expose assets (Correct answer)
Correct answer: Implementing multiple layers of controls so that failure of one does not expose assets
Defense-in-depth uses multiple overlapping layers of controls so that no single point of failure can compromise security.
Question 18: What is the PRIMARY difference between a recovery time objective (RTO) and a recovery point objective (RPO)?
- RTO applies to applications; RPO applies to infrastructure
- RTO measures data loss tolerance; RPO measures system downtime tolerance
- RTO is set by IT; RPO is set by business owners
- RTO measures how quickly systems must be restored; RPO measures acceptable data loss (Correct answer)
Correct answer: RTO measures how quickly systems must be restored; RPO measures acceptable data loss
RTO defines the maximum acceptable downtime for system recovery, while RPO defines the maximum acceptable data loss measured in time.
Question 19: An organization accepts a residual risk. What does this mean?
- The risk has been fully eliminated through controls
- The risk assessment was incomplete
- The remaining risk after controls are applied is deemed tolerable (Correct answer)
- The risk has been transferred to an insurer
Correct answer: The remaining risk after controls are applied is deemed tolerable
Residual risk is what remains after controls are applied; accepting it means management finds the remaining exposure within tolerance.
Question 20: Maximum Tolerable Downtime (MTD) is best described as:
- The longest period a business function can be unavailable before causing irreversible harm (Correct answer)
- The time between the last backup and the occurrence of a disaster
- The time required to fully restore all IT systems after a disaster
- The average time between system failures in a production environment
Correct answer: The longest period a business function can be unavailable before causing irreversible harm
MTD (also called Maximum Tolerable Period of Disruption) defines the upper limit of downtime beyond which the organization faces unacceptable consequences.
Question 21: What is Annual Loss Expectancy (ALE) used for in quantitative risk assessment?
- To calculate the number of incidents per year
- To determine the cost of deploying a new firewall
- To measure employee productivity loss from security training
- To estimate the expected financial loss from a risk over a year (Correct answer)
Correct answer: To estimate the expected financial loss from a risk over a year
ALE (ALE = SLE × ARO) estimates the expected annual financial loss from a specific risk, used to justify security investments through cost-benefit analysis.
Question 22: A CISM is selecting security controls for a new information security program. Controls should PRIMARILY be selected based on:
- Vendor recommendations and marketing materials
- Risk assessment results and business requirements (Correct answer)
- What peer organizations have implemented
- The lowest acquisition and implementation cost
Correct answer: Risk assessment results and business requirements
Control selection should be driven by risk assessment results and business requirements to ensure controls address actual risks and support business operations.
Question 23: Which of the following is MOST critical to the long-term success of an information security program?
- Elimination of all third-party relationships
- Use of the latest security technologies
- 100% employee compliance with all policies
- Ongoing executive sponsorship and adequate resourcing (Correct answer)
Correct answer: Ongoing executive sponsorship and adequate resourcing
Sustained executive sponsorship and adequate resources are the most critical success factors for a security program's long-term effectiveness.
Question 24: A CISM is establishing notification procedures for data breach incidents. Under US regulations, breach notification timing is MOST influenced by:
- The organization's public relations strategy
- The type of security tools used to detect the breach
- The organization's internal investigation timeline
- State breach notification laws and applicable federal regulations (Correct answer)
Correct answer: State breach notification laws and applicable federal regulations
US data breach notification requirements are governed by state laws and federal sector-specific regulations, which define mandatory notification timelines.
Question 25: The Payment Card Industry Data Security Standard (PCI DSS) applies to organizations that:
- Issue credit cards directly to consumers
- Store, process, or transmit cardholder data (Correct answer)
- Operate in the financial services sector only
- Process payroll for more than 500 employees
Correct answer: Store, process, or transmit cardholder data
PCI DSS applies to any organization that stores, processes, or transmits payment card data, regardless of industry or size.
Question 26: A Recovery Time Objective (RTO) of four hours means:
- Data must be restored to within four hours of the last backup
- The business can tolerate four hours of data loss before operations are impacted
- The system must be fully functional within four hours of a disaster declaration (Correct answer)
- Recovery teams must assemble within four hours of an incident
Correct answer: The system must be fully functional within four hours of a disaster declaration
RTO specifies the maximum acceptable time to restore a system or process to operational status after a disruption is declared.
Question 27: Which metric BEST demonstrates the effectiveness of an information security governance program to senior leadership?
- Percentage of employees completing security awareness training
- Number of software vulnerabilities patched
- Ratio of security incidents to business risk tolerance (Correct answer)
- Number of firewall rules implemented
Correct answer: Ratio of security incidents to business risk tolerance
Comparing security incidents against defined business risk tolerance gives leadership meaningful insight into how well the governance program is performing relative to strategic objectives.
Question 28: Which framework is MOST commonly used to establish information security governance in US enterprises?
- OWASP Top 10
- CVE
- PCI DSS
- COBIT (Correct answer)
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used for IT and information security governance in enterprises.
Question 29: Which of the following BEST describes a threat in the context of information security risk?
- A potential cause of an unwanted event that could harm an asset (Correct answer)
- The financial impact of a security breach
- A control that has failed to prevent an incident
- A weakness in a system or process
Correct answer: A potential cause of an unwanted event that could harm an asset
A threat is any potential cause of an unwanted incident that could result in harm to an organization's assets or operations.
Question 30: Which of the following is the PRIMARY purpose of a compliance audit?
- To identify all technical vulnerabilities in the organization's systems
- To test employee knowledge of security policies
- To assess whether the organization's controls meet applicable requirements (Correct answer)
- To evaluate the efficiency of the IT department's operations
Correct answer: To assess whether the organization's controls meet applicable requirements
A compliance audit evaluates whether an organization's controls, processes, and practices meet the requirements of applicable laws, regulations, or standards.
Question 31: An organization is merging with another company. The MOST important information security consideration during due diligence is:
- Comparing the two companies' IT budgets
- Selecting a unified security technology platform
- Assessing the target company's security posture and existing vulnerabilities (Correct answer)
- Determining which security team members will be retained
Correct answer: Assessing the target company's security posture and existing vulnerabilities
Assessing the target's security posture identifies inherited risks, liabilities, and compliance gaps that could affect the acquiring organization after the merger.
Question 32: What authentication technique stops authentication replay?
- Wired equivalent privacy encryption usage
- Challenge/response mechanism (Correct answer)
- Hypertext Transfer Protocol basic authentication
- Password hash implementation
Correct answer: Challenge/response mechanism
The challenge/response mechanism is an authentication method that effectively prevents authentication replay attacks.
Question 33: Which of the following is MOST important when communicating about a security incident to external stakeholders?
- Ensuring communications are timely, accurate, and legally reviewed (Correct answer)
- Providing all technical details of the attack immediately
- Delegating all external communication to the IT team
- Waiting until the incident is fully resolved before communicating
Correct answer: Ensuring communications are timely, accurate, and legally reviewed
External incident communications must be timely, factually accurate, and reviewed by legal counsel to manage liability and maintain stakeholder trust.
Question 34: Which of the following BEST describes the purpose of a security operations center (SOC)?
- To continuously monitor, detect, and respond to security incidents (Correct answer)
- To conduct annual penetration tests on critical systems
- To manage compliance with regulatory requirements
- To develop and maintain information security policies
Correct answer: To continuously monitor, detect, and respond to security incidents
A SOC provides continuous monitoring and incident detection and response capabilities to protect the organization.
Question 35: A CISM discovers that business units are making risk decisions without consulting the security team. The BEST corrective action is to:
- Purchase risk management software for all business units
- Implement mandatory security reviews into the project management process (Correct answer)
- Restrict business units from making any IT-related decisions
- Report all business units to senior management immediately
Correct answer: Implement mandatory security reviews into the project management process
Embedding mandatory security reviews into project management processes ensures risk is systematically considered before business decisions are finalized.
Question 36: An organization's board of directors is MOST responsible for which security governance activity?
- Setting risk appetite and oversight (Correct answer)
- Writing security policies
- Managing security operations
- Conducting vulnerability assessments
Correct answer: Setting risk appetite and oversight
The board of directors is responsible for setting the organization's risk appetite and providing oversight of the overall security posture.
Question 37: Which of the following MOST accurately describes a 'compensating control' in a regulatory compliance context?
- A financial payment made to regulators in lieu of implementing required controls
- A duplicate of an existing control added for extra protection
- A technical control that replaces the need for security policies
- An alternative control implemented when the primary required control cannot be met (Correct answer)
Correct answer: An alternative control implemented when the primary required control cannot be met
A compensating control is an alternative measure that provides equivalent protection when the specifically required control cannot be implemented due to technical or business constraints.
Question 38: A CISM discovers that a new business initiative will require processing of EU citizen data. Which regulation MUST be considered?
- GDPR (Correct answer)
- GLBA
- HIPAA
- FISMA
Correct answer: GDPR
The General Data Protection Regulation (GDPR) applies to any organization processing personal data of EU residents, regardless of where the organization is located.
Question 39: What is the role of a cold site in a disaster recovery strategy?
- A cloud environment maintained by a managed service provider
- A fully equipped facility with real-time data replication for immediate failover
- A secondary data center that mirrors the primary site at reduced capacity
- A facility with basic infrastructure such as power and cooling, but no pre-installed IT equipment (Correct answer)
Correct answer: A facility with basic infrastructure such as power and cooling, but no pre-installed IT equipment
A cold site provides basic facilities (space, power, cooling) but has no pre-installed equipment, requiring significant setup time before operations can resume.
Question 40: In the context of CISM, what is the CORRECT formula for calculating risk?
- Risk = Likelihood × Impact (Correct answer)
- Risk = Vulnerability − Control
- Risk = Threat × Asset Value
- Risk = Threat + Vulnerability + Impact
Correct answer: Risk = Likelihood × Impact
Risk is calculated as the product of the likelihood that a threat event will occur and the impact it would have on the organization.
Question 41: What should a risk management strategy's main goal be?
- Identify credible risks and transfer them to an external party
- Identify credible risks and reduce them to an acceptable level (Correct answer)
- Determine the organization's risk appetite
- Eliminate credible risks
Correct answer: Identify credible risks and reduce them to an acceptable level
The main goal of a risk management strategy is to identify risks, then reduce those risks to levels that upper management can accept. <br> <br> The phrase "determine the organization's risk appetite" is erroneous because, while crucial and necessary for a risk management program to operate correctly, determining risk appetite is not the fundamental goal of a risk management strategy. It is erroneous to say, "Identify credible risks and transfer them to an external entity," when many other potential outcomes for hazards can be discovered. It is erroneous to say "remove credible dangers," as risks can only be decreased to tolerable levels.
Question 42: A security incident causes a 6-hour outage for a system with an RTO of 4 hours. This PRIMARILY indicates a failure in:
- Change management procedures
- Incident response planning
- Business continuity / disaster recovery planning (Correct answer)
- Vulnerability management
Correct answer: Business continuity / disaster recovery planning
Failing to recover within the established RTO indicates that business continuity and disaster recovery plans were insufficient or ineffectively executed.
Question 43: What is the PRIMARY objective of change management from an information security perspective?
- To obtain approval from the CISO before any system modification
- To ensure changes do not introduce new security vulnerabilities or risks (Correct answer)
- To slow down the implementation of new technologies
- To document all changes made to IT systems for audit purposes
Correct answer: To ensure changes do not introduce new security vulnerabilities or risks
Security-focused change management ensures that system changes are evaluated for security impact before implementation.
Question 44: For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished. The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks. <br> <br> Which of the following would be the information security manager's BEST course of action?
- Acceptance of the information security manager’s decision on the risk to the corporation
- Acceptance of the business manager’s decision on the risk to the corporation
- Review of the risk assessment with executive management for final input (Correct answer)
- Create a new risk assessment and BIA to resolve the disagreement
Correct answer: Review of the risk assessment with executive management for final input
The best approach for the information security manager in this situation would be to review the risk assessment with executive management for final input.
Question 45: A CISM has identified a critical vulnerability but the cost of remediation exceeds the potential loss. The MOST appropriate risk response is:
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk transfer
- Risk mitigation
Correct answer: Risk acceptance
When remediation costs exceed the potential impact, accepting the risk is the most cost-effective response, provided it falls within the organization's risk appetite.
Question 46: When developing security policies, a CISM should ensure they are:
- Written in highly technical language for precision
- Updated monthly to reflect the latest threat intelligence
- Approved by senior management and communicated to all staff (Correct answer)
- Comprehensive enough to cover every possible security scenario
Correct answer: Approved by senior management and communicated to all staff
Security policies must be formally approved by senior management and communicated to all relevant staff to be enforceable and effective.
Question 47: What is the FIRST step in developing a Business Continuity Plan?
- Establishing communication procedures for incidents
- Conducting a Business Impact Analysis (BIA) (Correct answer)
- Defining roles and responsibilities for the recovery team
- Identifying recovery strategies and backup sites
Correct answer: Conducting a Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) is conducted first to identify critical business functions and quantify the impact of disruptions before recovery strategies are defined.
Question 48: An organization is considering purchasing cyber liability insurance. From a risk management perspective, this is an example of:
- Risk mitigation
- Risk transfer (Correct answer)
- Risk avoidance
- Risk acceptance
Correct answer: Risk transfer
Purchasing cyber liability insurance transfers the financial consequences of a security event to a third-party insurer.
Question 49: A third-party vendor has access to the organization's sensitive systems. Which control BEST reduces the associated risk?
- Requiring the vendor to sign a non-disclosure agreement
- Conducting periodic vendor security assessments and right-to-audit clauses (Correct answer)
- Limiting communication with the vendor to email only
- Requiring the vendor to purchase liability insurance
Correct answer: Conducting periodic vendor security assessments and right-to-audit clauses
Periodic assessments and right-to-audit clauses provide ongoing assurance that vendors maintain required security standards throughout the relationship.
Question 50: A risk assessment reveals that a control is more expensive than the risk it mitigates. A CISM should RECOMMEND:
- Implementing the control anyway for compliance purposes
- Escalating to law enforcement immediately
- Outsourcing the entire IT function
- Accepting the risk if it falls within the risk appetite (Correct answer)
Correct answer: Accepting the risk if it falls within the risk appetite
When a control's cost exceeds the risk value it addresses, accepting the risk is appropriate if it aligns with the organization's defined risk appetite.
Question 51: Which of the following BEST describes the relationship between incident response and disaster recovery?
- Incident response is managed by IT while disaster recovery is managed by facilities
- Incident response focuses on containment and investigation; disaster recovery focuses on restoring business operations (Correct answer)
- Disaster recovery is triggered only after incident response is fully complete
- They are identical processes with the same objectives
Correct answer: Incident response focuses on containment and investigation; disaster recovery focuses on restoring business operations
Incident response focuses on containing, investigating, and eradicating threats, while disaster recovery focuses on restoring critical business operations and systems.
Question 52: Which of the following BEST describes a 'control deficiency' in a compliance context?
- A security tool that has been deprecated by the vendor
- A failure of a control to operate as intended or meet a required standard (Correct answer)
- A regulatory requirement that the organization believes is excessive
- An employee who has violated an acceptable use policy
Correct answer: A failure of a control to operate as intended or meet a required standard
A control deficiency is a gap where a control either doesn't exist, fails to operate as designed, or fails to meet the required standard.
Question 53: What distinguishes a Recovery Point Objective (RPO) from a Recovery Time Objective (RTO)?
- Both measure the same thing but apply to different departments
- RPO measures acceptable data loss in time; RTO measures recovery speed (Correct answer)
- RPO measures recovery speed; RTO measures data loss tolerance
- RPO applies to hardware; RTO applies to software
Correct answer: RPO measures acceptable data loss in time; RTO measures recovery speed
RPO defines the maximum tolerable data loss window (e.g., last 4 hours of transactions), while RTO defines how quickly systems must be back online.
Question 54: An information security manager wants to verify that security controls are operating as intended. Which activity is MOST appropriate?
- Conducting a control effectiveness audit or assessment (Correct answer)
- Updating the information security policy
- Hiring additional security analysts
- Purchasing additional security software licenses
Correct answer: Conducting a control effectiveness audit or assessment
Control effectiveness audits verify that implemented controls are functioning correctly and actually reducing risk as designed.
Question 55: A third-party vendor with access to sensitive customer data has suffered a breach. What should the information security manager do FIRST?
- Assess the impact on the organization and notify affected parties per policy (Correct answer)
- Wait for the vendor's incident report before taking action
- Conduct a full audit of all vendor relationships
- Terminate the vendor contract immediately
Correct answer: Assess the impact on the organization and notify affected parties per policy
The immediate priority is assessing organizational impact and fulfilling notification obligations per policy and regulatory requirements.
Question 56: When developing key risk indicators (KRIs), the information security manager should ensure they are:
- Determined independently by the security team without business input
- Based solely on technical vulnerability counts
- Reported only when thresholds are exceeded
- Predictive and aligned to risk appetite thresholds (Correct answer)
Correct answer: Predictive and aligned to risk appetite thresholds
Effective KRIs provide early warning signals of emerging risk and are tied to the organization's defined risk appetite so management can act before thresholds are breached.
Question 57: A CISM is presenting a security governance roadmap to the CEO. The presentation should PRIMARILY focus on:
- Security risk in terms of business impact and strategic alignment (Correct answer)
- Technical vulnerability details and patch timelines
- Number of security incidents detected last quarter
- Specific firewall configurations and network diagrams
Correct answer: Security risk in terms of business impact and strategic alignment
Executive presentations should frame security governance in business terms, focusing on risk, impact, and alignment with organizational strategy.
Question 58: A reciprocal agreement for disaster recovery means:
- A vendor agrees to provide replacement hardware within an agreed timeframe
- An insurance provider agrees to cover all recovery costs after a declared disaster
- Two organizations agree to host each other's operations in the event of a disaster (Correct answer)
- An organization contracts a third party to provide guaranteed backup facilities
Correct answer: Two organizations agree to host each other's operations in the event of a disaster
A reciprocal agreement is an arrangement between two organizations to provide backup processing capacity for each other if one experiences a disaster.
Question 59: What is the purpose of a risk register in information security management?
- To record identified risks, their assessments, and treatment decisions (Correct answer)
- To document all installed security software
- To list all employees with access to sensitive systems
- To track security incident response timelines
Correct answer: To record identified risks, their assessments, and treatment decisions
A risk register is a formal document that records identified risks, their assessed likelihood and impact, treatment options chosen, and residual risk levels.
Question 60: What is the FIRST step in the incident response lifecycle according to best practices?
- Containment
- Eradication
- Preparation (Correct answer)
- Recovery
Correct answer: Preparation
Preparation is the first phase of incident response, involving developing plans, training teams, and establishing capabilities before incidents occur.
Question 61: When developing an information security program, a CISM should FIRST:
- Hire additional security analysts
- Conduct employee phishing simulations
- Procure security tools and technologies
- Define the security program's scope and objectives based on business needs (Correct answer)
Correct answer: Define the security program's scope and objectives based on business needs
Defining the scope and objectives aligned to business needs ensures the security program is purposeful, relevant, and capable of gaining organizational support.
Question 62: An organization experiences a ransomware attack that encrypts critical data. Which recovery option should be prioritized FIRST?
- Rebuild all affected systems from scratch
- Restore systems from the most recent clean backup (Correct answer)
- Negotiate with the attackers to obtain the decryption key
- Report the incident to law enforcement before taking any recovery action
Correct answer: Restore systems from the most recent clean backup
Restoring from clean backups is the fastest and most reliable recovery method that avoids funding criminal activity.
Question 63: A CISM discovers that an incident was caused by an unpatched vulnerability that had been known for 90 days. The ROOT CAUSE was most likely:
- A failure in the vulnerability management program (Correct answer)
- An advanced nation-state threat actor
- An insider threat by a disgruntled employee
- An inadequate firewall configuration
Correct answer: A failure in the vulnerability management program
A known vulnerability remaining unpatched for 90 days indicates a failure in the vulnerability management program's identification, prioritization, or remediation processes.
Question 64: Which of the following is the MOST effective control to protect against insider threats?
- Requiring all employees to sign acceptable use policies
- Implementing perimeter firewalls and IDS systems
- Conducting annual background checks on all staff
- Enforcing separation of duties and least privilege access (Correct answer)
Correct answer: Enforcing separation of duties and least privilege access
Separation of duties and least privilege limit what any single insider can access or do, directly reducing the impact of malicious or negligent insider actions.
Question 65: An organization's risk register shows a risk that has been accepted for three years. What action should the CISM recommend?
- Review the risk to determine if it remains within acceptable tolerance given current conditions (Correct answer)
- Continue accepting the risk as long as no incidents have occurred
- Transfer the risk to a third party to limit organizational exposure
- Escalate the risk acceptance to the board immediately
Correct answer: Review the risk to determine if it remains within acceptable tolerance given current conditions
Accepted risks must be periodically reviewed because threat landscapes, business conditions, and risk tolerances change over time.
Question 66: A security manager is asked to measure the return on security investment (ROSI). Which component is ESSENTIAL to calculate ROSI?
- Number of security policies published this year
- Number of security certifications held by staff
- Total hours spent on security awareness training
- Annualized Loss Expectancy (ALE) before and after implementing controls (Correct answer)
Correct answer: Annualized Loss Expectancy (ALE) before and after implementing controls
ROSI is calculated by comparing ALE before and after control implementation against the cost of those controls, quantifying the financial value of the investment.
Question 67: Which statement BEST describes the relationship between RTO and MTD?
- MTD is determined by IT and RTO is determined by business units independently
- RTO defines the data loss threshold while MTD defines the downtime threshold
- RTO and MTD are interchangeable terms used by different frameworks
- RTO must always be shorter than MTD to ensure recovery occurs before irreversible harm (Correct answer)
Correct answer: RTO must always be shorter than MTD to ensure recovery occurs before irreversible harm
RTO must be set shorter than MTD to ensure systems are recovered before the maximum tolerable period of disruption is breached, avoiding irreversible business impact.
Question 68: During a security incident, who is PRIMARILY responsible for declaring an incident a 'major incident'?
- The external auditor assigned to the organization
- The system administrator who detected the anomaly
- The help desk technician who received the initial report
- A designated incident manager or crisis management team (Correct answer)
Correct answer: A designated incident manager or crisis management team
A designated incident manager or crisis management team, with appropriate authority, is responsible for formally declaring and escalating major incidents.
Question 69: What is the MAIN benefit of having a documented chain of custody during incident investigation?
- It speeds up the technical recovery of affected systems
- It replaces the need for forensic tool certifications
- It ensures evidence integrity and admissibility in legal or regulatory proceedings (Correct answer)
- It satisfies cyber insurance policy documentation requirements
Correct answer: It ensures evidence integrity and admissibility in legal or regulatory proceedings
A chain of custody documents who handled evidence, when, and how, ensuring its integrity is maintained for use in legal or regulatory proceedings.
Question 70: Who is responsible for making sure that data is categorized and that particular security precautions are taken?
- The custodian
- The security officer
- Senior management (Correct answer)
- The end user
Correct answer: Senior management
Senior management is accountable for ensuring that information is categorized and that specific protective measures are taken. As the highest level of management within an organization, senior management holds the ultimate responsibility for information security and the protection of organizational assets. This includes establishing policies and procedures for information classification and ensuring that appropriate protective measures are implemented.
Question 71: Which of the following BEST describes the primary objective of information security governance?
- Deploying firewalls and intrusion detection systems
- Training employees on password policies
- Aligning security strategy with business objectives (Correct answer)
- Conducting annual penetration tests
Correct answer: Aligning security strategy with business objectives
Information security governance ensures that security strategies are aligned with and support the overall business objectives of the organization.
Question 72: An organization wants to transfer risk associated with a specific cyber threat. The MOST appropriate risk treatment option is:
- Discontinuing the business process that generates the risk
- Purchasing cyber liability insurance (Correct answer)
- Implementing additional technical controls
- Accepting the risk as within tolerance
Correct answer: Purchasing cyber liability insurance
Cyber liability insurance transfers the financial impact of a cyber incident to a third party, which is the definition of risk transfer.
Question 73: A CISM is implementing a security control framework. Which of the following is MOST important when selecting a framework?
- It must be mandated by a government agency
- It should align with the organization's risk profile and industry requirements (Correct answer)
- It should be the most widely adopted framework globally
- It must be the most recently published framework available
Correct answer: It should align with the organization's risk profile and industry requirements
Framework selection should be based on alignment with the organization's specific risk profile, regulatory environment, and industry context.
Question 74: Which of the following is a KEY responsibility of a CISM when managing the security program lifecycle?
- Approving every change request submitted to the IT team
- Ensuring the program evolves in response to changing business and threat conditions (Correct answer)
- Personally reviewing all access control logs daily
- Conducting all penetration tests personally
Correct answer: Ensuring the program evolves in response to changing business and threat conditions
A CISM must ensure the security program continuously evolves to remain aligned with changing business objectives and an evolving threat environment.
Question 75: A CISM is evaluating third-party vendors. Which risk is MOST relevant to this activity?
- Liquidity risk
- Reputational risk
- Supply chain and third-party risk (Correct answer)
- Market risk
Correct answer: Supply chain and third-party risk
Third-party vendors introduce supply chain and vendor risk, where weaknesses in vendor security posture can compromise the organization's own security.
Question 76: A risk manager in an organization just finished a risk assessment. One of the conclusions was requested by executive management to be eliminated from the final report by the risk manager. What is demonstrated by this removal?
- Risk avoidance
- Risk acceptance (Correct answer)
- Gerrymandering
- Internal politics
Correct answer: Risk acceptance
Despite being dubious, removing a risk finding from a report implies risk acceptance. However, it may go further than that, and in some professions, this is regarded as carelessness and negligence. Usually, a risk manager would oppose such a move and might think about documenting the situation or possibly making a formal protest. <br> <br> The term "gerrymandering" is erroneous because it refers to the process of drawing election boundaries for governmental purposes. Internal politics is not the ideal response, even though the circumstance may illustrate internal politics. The term "risk avoidance" is erroneous because it refers to ceasing to engage in an activity that poses a risk.
Question 77: Which element should be included in a crisis communications plan?
- Pre-approved messaging templates and designated spokespersons for stakeholder communication (Correct answer)
- Database recovery scripts and step-by-step IT restoration procedures
- Technical specifications for backup hardware at the recovery site
- Financial projections for losses during a declared business interruption
Correct answer: Pre-approved messaging templates and designated spokespersons for stakeholder communication
A crisis communications plan defines who communicates, what is communicated, and provides pre-approved templates to ensure timely, consistent, and accurate messaging during a disruption.
Question 78: An organization experiences a security incident involving a third-party vendor's system. The CISM should FIRST:
- Invoke the vendor's contractual incident notification and response obligations (Correct answer)
- Immediately terminate the vendor contract
- Deploy monitoring tools on all vendor-connected systems
- File a complaint with the vendor's regulatory body
Correct answer: Invoke the vendor's contractual incident notification and response obligations
Contractual incident notification and response obligations should be invoked immediately to ensure the vendor takes required action and shares necessary information.
Question 79: Which metric BEST demonstrates the effectiveness of a security awareness training program?
- Number of employees who completed training modules
- Reduction in phishing click rates over time (Correct answer)
- Number of new policies distributed to staff
- Total budget spent on training initiatives
Correct answer: Reduction in phishing click rates over time
A reduction in phishing click rates is a measurable behavioral outcome that directly reflects whether training changed employee actions.
Question 80: A security manager discovers that a business unit is using an unauthorized cloud application containing sensitive data. What is the MOST appropriate initial response?
- Engage the business unit to understand the need and assess the risk (Correct answer)
- Require the application to be removed before further discussion
- Report the business unit manager to senior leadership for disciplinary action
- Immediately block access to the application at the firewall
Correct answer: Engage the business unit to understand the need and assess the risk
Understanding the business need first enables a risk-informed response that balances security with business requirements.
Question 81: Which of the following BEST describes the difference between a regulation and a standard in the context of compliance?
- Regulations are optional; standards are mandatory
- Regulations are legally mandated by governments; standards are typically voluntary industry guidelines (Correct answer)
- There is no practical difference between regulations and standards
- Standards are enforced by government agencies; regulations are created by industry groups
Correct answer: Regulations are legally mandated by governments; standards are typically voluntary industry guidelines
Regulations are legally enforceable requirements imposed by government authorities, while standards are generally voluntary guidelines developed by industry bodies.
Question 82: A CISM is reviewing an incident response plan (IRP). Which element is MOST critical to include?
- Defined escalation procedures and communication chains (Correct answer)
- A list of all security software licenses
- Detailed technical specifications for all security tools
- Annual training completion records for all staff
Correct answer: Defined escalation procedures and communication chains
Clearly defined escalation procedures and communication chains ensure that the right people are notified and empowered to act during an incident.
Question 83: An organization's risk appetite statement should be approved by:
- The board of directors or executive leadership (Correct answer)
- The chief information officer
- The IT steering committee
- The information security manager
Correct answer: The board of directors or executive leadership
Risk appetite is a strategic business decision that must be set and approved at the board or executive level to align with organizational objectives.
Question 84: For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished. The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks. Which of the following would be the information security manager's BEST course of action?
- Create a new risk assessment and BIA to resolve the disagreement
- Acceptance of the information security manager’s decision on the risk to the corporation
- Review of the risk assessment with executive management for final input (Correct answer)
- Acceptance of the business manager’s decision on the risk to the corporation
Correct answer: Review of the risk assessment with executive management for final input
Executive management will be in the best position to consider the big picture and the trade-offs between security and functionality in the entire organization.
Question 85: Which of the following BEST describes the relationship between information security governance and IT governance?
- They are separate and independent frameworks
- They are identical frameworks with different names
- IT governance is a subset of information security governance
- Information security governance is a subset of IT governance (Correct answer)
Correct answer: Information security governance is a subset of IT governance
Information security governance falls within the broader scope of IT governance, which itself operates under the umbrella of corporate governance.
Question 86: Which of the following is the PRIMARY purpose of containment in incident response?
- To document lessons learned from the incident
- To permanently remove the root cause of the incident
- To limit the scope and impact of an ongoing incident (Correct answer)
- To restore affected systems to normal operation
Correct answer: To limit the scope and impact of an ongoing incident
Containment limits the spread and impact of an active incident while preserving evidence and buying time for eradication and recovery.
Question 87: A CISM is conducting a risk assessment and discovers a high likelihood threat with low potential impact. This risk should be:
- Transferred to a third-party insurer
- Immediately escalated to the board
- Automatically mitigated regardless of cost
- Evaluated in the context of the organization's risk appetite (Correct answer)
Correct answer: Evaluated in the context of the organization's risk appetite
All risks, regardless of their individual dimensions, must be evaluated against the organization's defined risk appetite before determining the appropriate response.
Question 88: After an incident is resolved, which activity is MOST important to improve future response?
- Resetting all user passwords organization-wide
- Conducting a post-incident review (lessons learned) (Correct answer)
- Replacing all affected hardware immediately
- Immediately patching all systems in the environment
Correct answer: Conducting a post-incident review (lessons learned)
A post-incident review (lessons learned) identifies what worked, what failed, and improvements to prevent recurrence and enhance future response capability.
Question 89: Which type of test evaluates an organization's incident response capabilities WITHOUT disrupting normal operations?
- Parallel test
- Penetration test
- Tabletop exercise (Correct answer)
- Full interruption test
Correct answer: Tabletop exercise
A tabletop exercise walks participants through a simulated scenario in a discussion format, testing plans and decision-making without operational impact.
Question 90: During a risk assessment, an organization identifies a threat with a high likelihood but low impact. What is the MOST appropriate risk treatment?
- Accept the risk due to low impact
- Implement controls proportional to the risk level (Correct answer)
- Transfer the risk through cyber insurance
- Avoid the risk by discontinuing the related activity
Correct answer: Implement controls proportional to the risk level
Controls should be implemented proportional to the overall risk level, balancing likelihood and impact considerations.
Question 91: Which of the following is a KEY benefit of integrating compliance and security program activities?
- Duplication of effort is reduced and security controls serve multiple purposes simultaneously (Correct answer)
- The organization can focus exclusively on regulatory requirements rather than threats
- Compliance activities can replace security risk assessments entirely
- Compliance integration eliminates the need for external audits
Correct answer: Duplication of effort is reduced and security controls serve multiple purposes simultaneously
Integrating compliance and security reduces duplication by using shared controls, frameworks, and assessments to meet both security and regulatory objectives efficiently.
Question 92: Which of the following is the PRIMARY purpose of a Business Impact Analysis (BIA)?
- To map network topology for disaster recovery
- To identify all IT assets in the organization
- To determine the criticality of business processes and recovery time requirements (Correct answer)
- To assign financial value to security incidents
Correct answer: To determine the criticality of business processes and recovery time requirements
A BIA identifies critical business functions, their dependencies, and the time within which they must be restored to avoid unacceptable consequences.
Question 93: Which of the following represents a governance control rather than a technical control?
- Intrusion detection system
- Acceptable use policy (Correct answer)
- Multi-factor authentication
- Encryption of data at rest
Correct answer: Acceptable use policy
An acceptable use policy is a governance (administrative) control that defines rules and expectations for users, rather than a technical enforcement mechanism.
Question 94: IT risk management initiatives are MOST successful when they:
- Conducted by the IT department
- Treated as distinct process
- Communicated to all employees
- Integrated within business processes (Correct answer)
Correct answer: Integrated within business processes
IT risk management is most successful when integrated within business processes, because the people who own the processes have the context and authority to make risk decisions that stick. Keeping it confined to the IT department or treating it as a separate process isolates it from where risk actually occurs, and merely communicating it to employees doesn't embed it into operations.
Question 95: Which of the following BEST describes the purpose of an incident response retainer with a third-party firm?
- To outsource all internal security operations permanently
- To ensure pre-negotiated access to expert resources during a crisis (Correct answer)
- To satisfy cyber insurance policy requirements only
- To replace the need for an internal incident response plan
Correct answer: To ensure pre-negotiated access to expert resources during a crisis
A retainer pre-negotiates access to specialized incident response expertise and resources, reducing response time and ensuring availability during a major incident.
Question 96: In risk management, which of the following BEST defines a 'vulnerability'?
- A malicious actor targeting the organization
- A weakness that can be exploited by a threat to cause harm (Correct answer)
- The financial loss resulting from a security incident
- The probability that a risk event will occur
Correct answer: A weakness that can be exploited by a threat to cause harm
A vulnerability is a weakness or gap in controls that a threat could exploit to compromise assets or operations.
Question 97: Which US federal law PRIMARILY governs the protection of personal health information in the healthcare industry?
- Gramm-Leach-Bliley Act (GLBA)
- Children's Online Privacy Protection Act (COPPA)
- Sarbanes-Oxley Act (SOX)
- Health Insurance Portability and Accountability Act (HIPAA) (Correct answer)
Correct answer: Health Insurance Portability and Accountability Act (HIPAA)
HIPAA establishes federal standards for protecting the privacy and security of individually identifiable health information in the US healthcare industry.
Question 98: Which of the following BEST supports a 'security by design' approach in program development?
- Purchasing security add-ons for existing systems after deployment
- Integrating security requirements into the project lifecycle from inception (Correct answer)
- Relying on vendors to build security into their products
- Performing security assessments only after systems are deployed
Correct answer: Integrating security requirements into the project lifecycle from inception
Security by design integrates security requirements early in the system development lifecycle, reducing cost and complexity compared to retrofitting controls later.
Question 99: Under the Sarbanes-Oxley Act (SOX), which of the following is a KEY information security requirement?
- Encryption of all employee communications
- Annual penetration testing of all public-facing systems
- Internal controls over financial reporting, including IT general controls (Correct answer)
- Mandatory security awareness training for all employees
Correct answer: Internal controls over financial reporting, including IT general controls
SOX requires organizations to establish and maintain internal controls over financial reporting, which includes IT general controls that protect the integrity of financial systems.
Question 100: The Federal Information Security Modernization Act (FISMA) PRIMARILY applies to:
- Financial institutions regulated by the Federal Reserve
- Healthcare organizations billing Medicare or Medicaid
- US federal agencies and contractors that handle federal information (Correct answer)
- All US companies with more than 100 employees
Correct answer: US federal agencies and contractors that handle federal information
FISMA applies to US federal agencies and contractors that handle federal information, requiring them to develop, document, and implement information security programs.
Question 101: Which of the following BEST describes a gap analysis in the context of information security program development?
- An assessment of vulnerabilities in technical systems
- A comparison of current security capabilities against a target state or framework (Correct answer)
- An inventory of security tools currently deployed
- A review of open audit findings from prior assessments
Correct answer: A comparison of current security capabilities against a target state or framework
A gap analysis measures the difference between the current security state and a desired future state or framework, identifying what needs to be built or improved.
Question 102: During a penetration test, a critical vulnerability is discovered in a production system. What should the information security manager do FIRST?
- Assess the risk and notify appropriate stakeholders per the established process (Correct answer)
- Patch the vulnerability immediately without notifying stakeholders
- Escalate directly to law enforcement
- Terminate the penetration test to prevent further exposure
Correct answer: Assess the risk and notify appropriate stakeholders per the established process
Risk assessment and stakeholder notification per established processes ensure coordinated and appropriate response to discovered vulnerabilities.
Question 103: Which of the following BEST describes the relationship between information security policy and procedures?
- Policies and procedures are interchangeable documents
- Procedures are written by executives; policies by technical staff
- Policies define what must be done; procedures describe how to do it (Correct answer)
- Procedures define what must be done; policies describe how to do it
Correct answer: Policies define what must be done; procedures describe how to do it
Policies establish high-level requirements and intent, while procedures provide step-by-step instructions for implementing those requirements.
Question 104: When reviewing BC/DR plans, the information security manager should PRIMARILY ensure that:
- Recovery sites are located in geographically distant regions from the primary site
- All employees receive training on disaster recovery procedures annually
- Security controls are maintained and not bypassed during recovery operations (Correct answer)
- Insurance coverage adequately compensates for losses during a business interruption
Correct answer: Security controls are maintained and not bypassed during recovery operations
The information security manager must ensure that security controls remain in force during recovery, as the pressure to restore quickly can lead to shortcuts that introduce vulnerabilities.
Question 105: A manufacturing company's CISO, Linda, is developing a new cyber-risk governance procedure. What should Linda do initially to ensure the success of this process?
- Charter a security steering committee consisting of IT, security, and business leaders (Correct answer)
- Charter a security steering committee consisting of IT and cybersecurity leaders
- Develop a risk management process similar to what is found in ISO/IEC 27001
- Develop a RACI matrix that defines executive roles and responsibilities
Correct answer: Charter a security steering committee consisting of IT, security, and business leaders
The best course of action is to establish a chartered information security steering group with representatives from business, IT, and security leaders. Business executives need to get involved and participate in discussions and decisions if security governance is to be successful. <br> <br> It is false to say that you should "develop a RACI matrix that outlines executive roles and responsibilities" since, while vital, a RACI matrix is only a small component of a formalized information security steering committee. It is erroneous to say, "Charter a security steering group made up of leaders in IT and cybersecurity." A security steering committee must also have business leaders on it. Because security governance, which is more than risk management, is the topic of this question, it is erroneous to say that you should "develop a risk management process comparable to what is found in ISO/IEC 27001."
Question 106: When performing information risk assessments, which approach provides the MOST objective results?
- Relying solely on staff interviews
- Copying results from a prior year's assessment
- Combining quantitative data with qualitative expert judgment (Correct answer)
- Using only automated scanning tools
Correct answer: Combining quantitative data with qualitative expert judgment
A hybrid approach leverages measurable data for objectivity while using expert judgment to address gaps that tools and metrics cannot fully capture.
Question 107: What is the PRIMARY purpose of a Business Continuity Plan (BCP)?
- To ensure critical business functions can continue during and after a disruption (Correct answer)
- To document the IT infrastructure and recovery procedures
- To assign accountability for security incidents to key personnel
- To eliminate all risks that could disrupt business operations
Correct answer: To ensure critical business functions can continue during and after a disruption
A BCP is designed to ensure that critical business functions can continue during and after a disruption, minimizing operational impact.
Question 108: Which of the following is the MOST important characteristic of an effective information security policy?
- It is approved by senior management and aligned to business objectives (Correct answer)
- It is updated at least quarterly to reflect new threats
- It references specific technical security tools and vendors
- It contains detailed step-by-step security procedures
Correct answer: It is approved by senior management and aligned to business objectives
Policies derive their authority and effectiveness from senior management approval and alignment with business goals.
Question 109: An organization wants to ensure its security governance program remains effective over time. The BEST mechanism is:
- Outsourcing all security functions to a managed provider
- Implementing a zero-trust network architecture
- One-time security policy review at program launch
- Continuous monitoring and periodic program reviews (Correct answer)
Correct answer: Continuous monitoring and periodic program reviews
Continuous monitoring and periodic reviews ensure the governance program adapts to changing threats, business needs, and regulatory requirements.
Question 110: When aligning information security strategy with business objectives, the security manager should PRIMARILY focus on:
- Enabling business goals while managing risk to acceptable levels (Correct answer)
- Implementing the latest security technologies
- Ensuring compliance with all regulations
- Eliminating all identified vulnerabilities
Correct answer: Enabling business goals while managing risk to acceptable levels
Security strategy must support business objectives by balancing risk management with operational enablement rather than simply enforcing controls.
Question 111: The PRIMARY objective of information security incident management is to:
- Identify and prosecute those responsible for incidents
- Minimize the impact of incidents and restore normal operations (Correct answer)
- Document incidents for regulatory reporting purposes
- Prevent all future incidents from occurring
Correct answer: Minimize the impact of incidents and restore normal operations
Incident management's primary goal is containment and recovery — minimizing business impact and restoring normal operations as quickly as possible.
Question 112: Which metric BEST demonstrates the effectiveness of a security awareness training program?
- Percentage of employees who completed the training
- Reduction in phishing click rates after training (Correct answer)
- Training budget spent per employee
- Number of training sessions conducted per year
Correct answer: Reduction in phishing click rates after training
Behavioral change metrics like reduced phishing click rates directly measure training effectiveness rather than just participation.
Question 113: Which of the following is MOST important when prioritizing risks for treatment?
- The age of the vulnerability
- The vendor's severity rating
- The number of systems affected
- The potential business impact and likelihood (Correct answer)
Correct answer: The potential business impact and likelihood
Risks should be prioritized based on their potential business impact and likelihood of occurrence, not just technical severity or vendor ratings.
Question 114: When an employee is terminated, the MOST critical immediate security action is:
- Conducting an exit interview about security responsibilities
- Recovering company-issued equipment
- Revoking all logical access to systems and data (Correct answer)
- Notifying the employee's manager and HR
Correct answer: Revoking all logical access to systems and data
Revoking logical access immediately prevents a departing employee from accessing, exfiltrating, or damaging organizational systems or data.
Question 115: A CISM is informed that regulatory requirements in the organization's industry have changed. The MOST appropriate response is to:
- Outsource all compliance activities to a third-party firm
- Wait until the next scheduled audit to assess the impact
- Notify the board only after all required changes are implemented
- Immediately conduct a gap analysis to identify required changes to controls and processes (Correct answer)
Correct answer: Immediately conduct a gap analysis to identify required changes to controls and processes
A prompt gap analysis identifies what the new requirements demand and where current controls fall short, enabling timely and prioritized remediation.
Question 116: Which of the following is the BEST indicator that an organization's security culture is mature?
- Employees report suspicious activities voluntarily without being prompted (Correct answer)
- The organization has not experienced a security breach in the past year
- Security policies are reviewed and updated annually
- All employees have completed mandatory security awareness training
Correct answer: Employees report suspicious activities voluntarily without being prompted
Voluntary reporting of suspicious activities demonstrates that employees understand their security responsibilities and proactively support the program.
Question 117: Which of the following BEST describes the purpose of a data classification policy?
- To assign monetary values to data assets
- To identify which employees can create new data repositories
- To define handling requirements based on data sensitivity (Correct answer)
- To establish retention schedules for all organizational data
Correct answer: To define handling requirements based on data sensitivity
Data classification defines categories of sensitivity and establishes appropriate handling, storage, and transmission requirements for each category.
Question 118: Which risk assessment approach assigns numerical values to probability and impact to calculate risk scores?
- Scenario-based assessment
- Quantitative risk assessment (Correct answer)
- Qualitative risk assessment
- Delphi technique
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values (often monetary) to calculate risk scores, enabling objective comparison and cost-benefit analysis.
Question 119: A CISM wants to improve detection of security incidents. The MOST effective improvement is to:
- Implement continuous monitoring with defined detection use cases aligned to risks (Correct answer)
- Increase the number of security policies documented
- Purchase the newest endpoint antivirus solution available
- Hire additional help desk staff to handle user reports
Correct answer: Implement continuous monitoring with defined detection use cases aligned to risks
Continuous monitoring with detection use cases aligned to the organization's specific risk profile maximizes the relevance and effectiveness of detection capabilities.
Question 120: Which of the following BEST illustrates the principle of 'security by design'?
- Integrating security requirements into the software development lifecycle from the start (Correct answer)
- Installing endpoint detection software on all developer workstations
- Conducting a penetration test before a system goes live
- Applying security patches promptly after they are released
Correct answer: Integrating security requirements into the software development lifecycle from the start
Security by design means embedding security considerations into the design and development process from inception rather than retrofitting controls at the end.
Question 121: When conducting a third-party vendor risk assessment, which document provides the MOST assurance regarding a vendor's security controls?
- The vendor's self-completed security questionnaire
- A sample penetration test report provided by the vendor
- The vendor's published security policy
- A SOC 2 Type II report from an independent auditor (Correct answer)
Correct answer: A SOC 2 Type II report from an independent auditor
A SOC 2 Type II report provides independent, audited evidence that controls were operating effectively over a period of time, not just at a point in time.
Question 122: Which of the following BEST describes the role of a CISM in supporting a regulatory examination?
- Limiting examiner access to only the IT department
- Coordinating the organization's response and ensuring requested evidence is complete and accurate (Correct answer)
- Delaying the examination until all identified gaps are remediated
- Personally answering all examiner questions without consulting legal counsel
Correct answer: Coordinating the organization's response and ensuring requested evidence is complete and accurate
The CISM coordinates the examination response, ensuring examiners receive complete, accurate evidence while collaborating with legal, compliance, and business teams.
Question 123: When assigning ownership of information assets, the MOST appropriate owner is typically:
- The business unit manager responsible for the asset (Correct answer)
- The system administrator
- The IT security team
- The external auditor
Correct answer: The business unit manager responsible for the asset
Business unit managers, as the primary users and beneficiaries of information assets, are the most appropriate owners with accountability for their protection.
Question 124: Which of the following is MOST important when establishing risk assessment criteria?
- Aligning criteria with the organization's business objectives and risk appetite (Correct answer)
- Adopting criteria from the most recent regulatory guidance
- Using the same criteria as peer organizations in the industry
- Selecting criteria that minimize the number of identified risks
Correct answer: Aligning criteria with the organization's business objectives and risk appetite
Risk assessment criteria must reflect the organization's specific business objectives and risk appetite to produce meaningful and actionable results.
Question 125: Which of the following BEST defines 'security culture' within a governance context?
- The frequency of penetration testing conducted annually
- The shared values, behaviors, and attitudes toward security among employees (Correct answer)
- The number of security policies documented by the organization
- The technical security tools deployed across the organization
Correct answer: The shared values, behaviors, and attitudes toward security among employees
Security culture refers to the collective attitudes, values, and behaviors of employees toward security, which governance programs aim to develop and reinforce.
Question 126: An organization's security audit reveals that access rights are not reviewed regularly. The MOST effective control to address this finding is:
- Requiring all users to acknowledge the acceptable use policy annually
- Establishing a periodic user access recertification process (Correct answer)
- Implementing stricter password complexity requirements
- Deploying a data loss prevention solution
Correct answer: Establishing a periodic user access recertification process
Periodic access recertification requires managers to review and validate user access rights on a scheduled basis, directly addressing the lack of regular access reviews.
Question 127: A succession plan within business continuity primarily addresses:
- Scheduling the rotation of staff across different recovery teams
- Planning for the acquisition of a competitor following a market disruption
- The order in which IT systems are restored after a disaster
- Designating backup personnel who can assume critical roles if key individuals are unavailable (Correct answer)
Correct answer: Designating backup personnel who can assume critical roles if key individuals are unavailable
A succession plan ensures that backup personnel are identified and trained to assume critical roles if primary individuals are unavailable during a crisis.
Question 128: Which of the following BEST illustrates an effective security governance reporting structure?
- Security metrics are reported only after incidents occur
- CISO reports to both the CEO and board with regular updates (Correct answer)
- CISO reports to the CTO only
- Security reports are shared only within the IT department
Correct answer: CISO reports to both the CEO and board with regular updates
Effective governance requires the CISO to report to senior leadership and the board regularly, ensuring visibility and accountability at the highest levels.
Question 129: A CISM discovers that a business unit is non-compliant with a key regulatory requirement. The MOST appropriate action is to:
- Immediately report the business unit to the regulator
- Ignore the issue if the probability of examination is low
- Document the non-compliance, assess risk, and initiate a remediation plan with appropriate escalation (Correct answer)
- Shut down the business unit's operations until compliance is achieved
Correct answer: Document the non-compliance, assess risk, and initiate a remediation plan with appropriate escalation
Non-compliance should be documented, risk-assessed, and addressed through a formal remediation plan with appropriate escalation to management.
Question 130: During a post-incident review, the team determines that attackers gained access through a compromised service account with excessive privileges. The BEST long-term remediation is:
- Disabling all service accounts until reviewed
- Implementing privileged access management with just-in-time access (Correct answer)
- Changing all service account passwords immediately
- Adding multi-factor authentication to the affected service account
Correct answer: Implementing privileged access management with just-in-time access
Privileged access management with just-in-time provisioning systematically enforces least privilege for service accounts, addressing the root cause of excessive standing privileges.
Question 131: A security manager examines the logs of numerous devices to ascertain how a security breach on the business network happened. <br> <br> Which of the following BEST makes it easier to compare and analyze these logs?
- Time server (Correct answer)
- Proxy server
- Database server
- Domain name server
Correct answer: Time server
A time server best enables log comparison because synchronized, consistent timestamps across all devices are required before events from different sources can be sequenced and correlated. DNS, database, and proxy servers serve other functions and do nothing to ensure the time alignment needed to reconstruct the order of a breach.
Question 132: Which of the following BEST describes the relationship between information security risk management and enterprise risk management (ERM)?
- Information security risk is one category of risk managed within the broader ERM framework (Correct answer)
- Information security risk management operates independently of ERM
- ERM is a subset of information security risk management
- Information security risk management replaces ERM in technology-heavy organizations
Correct answer: Information security risk is one category of risk managed within the broader ERM framework
Information security risk is one of many risk categories (financial, operational, strategic) managed within the overarching enterprise risk framework.
Question 133: What is the PRIMARY purpose of tabletop exercises in incident management?
- To validate the incident response plan and team readiness through discussion-based scenarios (Correct answer)
- To test technical security controls in a live environment
- To train help desk staff on ticket escalation procedures
- To satisfy annual penetration testing requirements
Correct answer: To validate the incident response plan and team readiness through discussion-based scenarios
Tabletop exercises use discussion-based scenarios to test the incident response plan's effectiveness and identify gaps in team readiness without disrupting operations.
Question 134: A CISM candidate is reviewing the organization's information security governance structure. Which element is MOST critical to effective governance?
- Executive management accountability and oversight (Correct answer)
- Third-party penetration testing schedule
- Dedicated security operations center
- Automated vulnerability scanning tools
Correct answer: Executive management accountability and oversight
Governance requires senior leadership accountability; without it, security strategy lacks authority and resources.
Question 135: When developing a security governance program, a CISM should FIRST:
- Understand the organization's business strategy and objectives (Correct answer)
- Purchase security tools and technologies
- Hire additional security staff
- Conduct a gap analysis of current controls
Correct answer: Understand the organization's business strategy and objectives
Understanding the business strategy ensures that the security governance program is aligned with and supports organizational goals from the outset.
Question 136: Which of the following BEST defines inherent risk in the context of information security risk management?
- Risk that has been formally accepted by management
- Risk that remains after security controls are applied
- Risk associated with third-party vendor relationships
- Risk that exists before any controls are implemented (Correct answer)
Correct answer: Risk that exists before any controls are implemented
Inherent risk is the level of risk existing in the absence of any controls or mitigating factors.
Question 137: Who holds ULTIMATE responsibility for ensuring that business continuity planning is adequate and funded?
- The IT disaster recovery team lead
- Senior management or the board of directors (Correct answer)
- The Chief Information Security Officer (CISO)
- The Business Continuity Manager
Correct answer: Senior management or the board of directors
Senior management and the board of directors are ultimately accountable for business continuity, as they are responsible for the organization's overall resilience and risk posture.
Question 138: What is 'residual risk' in information security risk management?
- The risk associated with legacy systems only
- The risk that remains after controls have been applied (Correct answer)
- The original risk before any assessment is performed
- The risk transferred to cyber insurance policies
Correct answer: The risk that remains after controls have been applied
Residual risk is the amount of risk that remains after security controls have been implemented to reduce or manage the inherent risk.
Question 139: Which of the following BEST describes the relationship between IT governance and information security governance?
- Information security governance is a subset of IT governance (Correct answer)
- They operate independently with no overlap
- They are identical and interchangeable
- IT governance reports to information security governance
Correct answer: Information security governance is a subset of IT governance
Information security governance is a subset of IT governance, which itself is a component of overall corporate governance.
Question 140: The PRIMARY goal of the 'lessons learned' phase of incident response is to:
- Finalize forensic evidence for law enforcement
- Identify improvements to prevent or better handle future incidents (Correct answer)
- Assign blame to responsible employees
- Update insurance claims after the incident
Correct answer: Identify improvements to prevent or better handle future incidents
Lessons learned translate incident experience into actionable improvements in controls, processes, and plans to reduce future risk.
Question 141: An organization wants to validate its incident response capabilities. Which approach provides the MOST realistic assessment?
- Reviewing incident response documentation for completeness
- Interviewing key personnel about their incident response roles
- Conducting tabletop exercises with the security team
- Performing a full simulation (red team) exercise without prior notice (Correct answer)
Correct answer: Performing a full simulation (red team) exercise without prior notice
Unannounced red team exercises provide the most realistic test of actual incident response capability under realistic conditions.
Question 142: During a business continuity exercise, the recovery team is unable to restore a critical system within the defined RTO. The BEST immediate action for the information security manager is to:
- Extend the RTO to match actual recovery capability
- Discipline the team members responsible for the delay
- Declare the exercise a failure and reschedule it
- Document the failure and update the BCP based on lessons learned (Correct answer)
Correct answer: Document the failure and update the BCP based on lessons learned
Exercises are learning opportunities — documenting gaps and updating the BCP to address them is the constructive response that improves actual recovery capability.
Question 143: Which metric is MOST useful for measuring the effectiveness of a security awareness program?
- Number of policies employees acknowledged
- Number of employees who completed training modules
- Reduction in security incidents attributable to human error over time (Correct answer)
- Total cost of the training program delivery
Correct answer: Reduction in security incidents attributable to human error over time
Measuring the reduction in human-error-related incidents over time provides evidence of behavior change, the true goal of awareness training.
Question 144: A CISM is developing a security governance framework. Which document should serve as the TOP-LEVEL foundation?
- Security procedures
- Risk register
- Information security policy (Correct answer)
- Security standards
Correct answer: Information security policy
The information security policy is the top-level document that establishes management's intent and provides the foundation for all other security standards and procedures.
Question 145: Unusual server communication between internal and external parties may be observed to:
- Verify the effectiveness of an intrusion detection system
- Evaluate the process resiliency of server operations
- Record the trace of advanced persistent threats (Correct answer)
- Support a nonrepudiation framework in e-commerce
Correct answer: Record the trace of advanced persistent threats
The most important feature of target attacks as seen in advanced persistent threats is that malware secretly sends information back to a command and control server. Therefore, monitoring of outbound server communications that do not follow predefined routes will be the best control to detect such security events.
Question 146: Which of the following is the MOST important factor in determining incident severity?
- The number of systems technically involved
- The type of attack technique used by the threat actor
- The time of day the incident was detected
- The potential business impact of the incident (Correct answer)
Correct answer: The potential business impact of the incident
Incident severity should be determined by potential business impact — the degree of harm to operations, data, reputation, and stakeholders.
Question 147: A CISM is establishing data classification as part of the security program. The PRIMARY benefit is to:
- Comply with all applicable data protection regulations automatically
- Reduce the cost of data storage across the organization
- Enable the IT team to delete unnecessary data
- Ensure appropriate controls are applied based on data sensitivity (Correct answer)
Correct answer: Ensure appropriate controls are applied based on data sensitivity
Data classification ensures that protective controls are proportionate to data sensitivity, so critical data receives stronger protection than non-sensitive data.
Question 148: A CISM is developing a compliance program. The FIRST step should be to:
- Identify all applicable laws, regulations, and contractual obligations (Correct answer)
- Assign compliance responsibilities to the legal team only
- Conduct an internal audit of all existing controls
- Purchase GRC (governance, risk, compliance) software
Correct answer: Identify all applicable laws, regulations, and contractual obligations
Identifying all applicable regulatory, legal, and contractual requirements is the foundational step before any compliance program activities can be structured.
Question 149: Which of the following is the BEST technique to catch an intruder who breaks into a network without doing any damage?
- Perform periodic penetration testing
- Install a honeypot on the network (Correct answer)
- Implement vendor default settings
- Establish minimum security baselines
Correct answer: Install a honeypot on the network
A honeypot is the best tool to catch a non-destructive intruder because it's a decoy system designed to lure and observe attackers while keeping real assets safe. Baselines, penetration testing, and default settings are preventive or assessment measures—they don't actively detect or study an intruder already moving inside the network.
Question 150: Which of the following BEST describes the role of a CISM during a major security incident?
- Deciding whether to pay a ransom demand
- Personally performing technical forensics on affected systems
- Providing strategic oversight, coordination, and communication (Correct answer)
- Writing all incident reports and post-mortem documentation
Correct answer: Providing strategic oversight, coordination, and communication
During a major incident, the CISM's role is strategic — providing oversight, coordinating the response team, and managing communication with leadership.
Question 151: Which of the following is MOST important when establishing a security program budget?
- Allocating the maximum available IT budget to security
- Matching the budget of industry peers
- Prioritizing tool purchases over personnel costs
- Justifying spend based on risk reduction and business value (Correct answer)
Correct answer: Justifying spend based on risk reduction and business value
Security budgets should be justified through demonstrated risk reduction and business value, enabling rational resource allocation decisions.
Certified Information Security Manager (CISM)
The CISM certification, administered by ISACA, validates expertise in managing and overseeing enterprise information security programs, covering governance, risk management, program development, and incident management. It targets experienced security managers and professionals seeking to demonstrate management-level security competence.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds