Certified Information Security Manager (CISM) — Questions and Answers
Question 1: An organization experiences a security incident involving a third-party vendor's system. The CISM should FIRST:
- File a complaint with the vendor's regulatory body
- Deploy monitoring tools on all vendor-connected systems
- Invoke the vendor's contractual incident notification and response obligations (Correct answer)
- Immediately terminate the vendor contract
Correct answer: Invoke the vendor's contractual incident notification and response obligations
Contractual incident notification and response obligations should be invoked immediately to ensure the vendor takes required action and shares necessary information.
Question 2: Which metric defines the maximum amount of data loss an organization can tolerate, measured in time?
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
- Recovery Point Objective (RPO) (Correct answer)
- Mean Time to Recover (MTTR)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, indicating how far back in time a recovery point must be.
Question 3: An organization is considering purchasing cyber liability insurance. From a risk management perspective, this is an example of:
- Risk acceptance
- Risk transfer (Correct answer)
- Risk mitigation
- Risk avoidance
Correct answer: Risk transfer
Purchasing cyber liability insurance transfers the financial consequences of a security event to a third-party insurer.
Question 4: Which of the following BEST describes the relationship between information security risk management and enterprise risk management (ERM)?
- Information security risk is one category of risk managed within the broader ERM framework (Correct answer)
- Information security risk management replaces ERM in technology-heavy organizations
- ERM is a subset of information security risk management
- Information security risk management operates independently of ERM
Correct answer: Information security risk is one category of risk managed within the broader ERM framework
Information security risk is one of many risk categories (financial, operational, strategic) managed within the overarching enterprise risk framework.
Question 5: A CISM is reviewing an incident response plan (IRP). Which element is MOST critical to include?
- A list of all security software licenses
- Detailed technical specifications for all security tools
- Defined escalation procedures and communication chains (Correct answer)
- Annual training completion records for all staff
Correct answer: Defined escalation procedures and communication chains
Clearly defined escalation procedures and communication chains ensure that the right people are notified and empowered to act during an incident.
Question 6: A newly appointed CISM discovers the organization has no formal security governance structure. The FIRST step should be to:
- Perform a full network vulnerability scan
- Conduct a security awareness training campaign
- Obtain executive sponsorship and establish governance authority (Correct answer)
- Deploy endpoint detection and response tools
Correct answer: Obtain executive sponsorship and establish governance authority
Without executive sponsorship and formal governance authority, a CISM cannot effectively implement or enforce any security program.
Question 7: A manufacturing company's CISO, Linda, is developing a new cyber-risk governance procedure. What should Linda do initially to ensure the success of this process?
- Charter a security steering committee consisting of IT, security, and business leaders (Correct answer)
- Develop a risk management process similar to what is found in ISO/IEC 27001
- Charter a security steering committee consisting of IT and cybersecurity leaders
- Develop a RACI matrix that defines executive roles and responsibilities
Correct answer: Charter a security steering committee consisting of IT, security, and business leaders
The best course of action is to establish a chartered information security steering group with representatives from business, IT, and security leaders. Business executives need to get involved and participate in discussions and decisions if security governance is to be successful. <br> <br> It is false to say that you should "develop a RACI matrix that outlines executive roles and responsibilities" since, while vital, a RACI matrix is only a small component of a formalized information security steering committee. It is erroneous to say, "Charter a security steering group made up of leaders in IT and cybersecurity." A security steering committee must also have business leaders on it. Because security governance, which is more than risk management, is the topic of this question, it is erroneous to say that you should "develop a risk management process comparable to what is found in ISO/IEC 27001."
Question 8: During a security incident, who is PRIMARILY responsible for declaring an incident a 'major incident'?
- The external auditor assigned to the organization
- A designated incident manager or crisis management team (Correct answer)
- The system administrator who detected the anomaly
- The help desk technician who received the initial report
Correct answer: A designated incident manager or crisis management team
A designated incident manager or crisis management team, with appropriate authority, is responsible for formally declaring and escalating major incidents.
Question 9: A CISM discovers that an incident was caused by an unpatched vulnerability that had been known for 90 days. The ROOT CAUSE was most likely:
- An insider threat by a disgruntled employee
- An inadequate firewall configuration
- An advanced nation-state threat actor
- A failure in the vulnerability management program (Correct answer)
Correct answer: A failure in the vulnerability management program
A known vulnerability remaining unpatched for 90 days indicates a failure in the vulnerability management program's identification, prioritization, or remediation processes.
Question 10: Which of the following is a KEY benefit of integrating compliance and security program activities?
- Duplication of effort is reduced and security controls serve multiple purposes simultaneously (Correct answer)
- Compliance activities can replace security risk assessments entirely
- Compliance integration eliminates the need for external audits
- The organization can focus exclusively on regulatory requirements rather than threats
Correct answer: Duplication of effort is reduced and security controls serve multiple purposes simultaneously
Integrating compliance and security reduces duplication by using shared controls, frameworks, and assessments to meet both security and regulatory objectives efficiently.
Question 11: Which of the following BEST describes the purpose of a security operations center (SOC)?
- To develop and maintain information security policies
- To continuously monitor, detect, and respond to security incidents (Correct answer)
- To conduct annual penetration tests on critical systems
- To manage compliance with regulatory requirements
Correct answer: To continuously monitor, detect, and respond to security incidents
A SOC provides continuous monitoring and incident detection and response capabilities to protect the organization.
Question 12: What is the MAIN benefit of having a documented chain of custody during incident investigation?
- It speeds up the technical recovery of affected systems
- It replaces the need for forensic tool certifications
- It satisfies cyber insurance policy documentation requirements
- It ensures evidence integrity and admissibility in legal or regulatory proceedings (Correct answer)
Correct answer: It ensures evidence integrity and admissibility in legal or regulatory proceedings
A chain of custody documents who handled evidence, when, and how, ensuring its integrity is maintained for use in legal or regulatory proceedings.
Question 13: Who is responsible for making sure that data is categorized and that particular security precautions are taken?
- The custodian
- The end user
- Senior management (Correct answer)
- The security officer
Correct answer: Senior management
Senior management is accountable for ensuring that information is categorized and that specific protective measures are taken. As the highest level of management within an organization, senior management holds the ultimate responsibility for information security and the protection of organizational assets. This includes establishing policies and procedures for information classification and ensuring that appropriate protective measures are implemented.
Question 14: Which of the following BEST describes the role of a CISM during a major security incident?
- Personally performing technical forensics on affected systems
- Providing strategic oversight, coordination, and communication (Correct answer)
- Deciding whether to pay a ransom demand
- Writing all incident reports and post-mortem documentation
Correct answer: Providing strategic oversight, coordination, and communication
During a major incident, the CISM's role is strategic — providing oversight, coordinating the response team, and managing communication with leadership.
Question 15: Which of the following BEST describes the relationship between incident response and disaster recovery?
- Incident response is managed by IT while disaster recovery is managed by facilities
- Disaster recovery is triggered only after incident response is fully complete
- Incident response focuses on containment and investigation; disaster recovery focuses on restoring business operations (Correct answer)
- They are identical processes with the same objectives
Correct answer: Incident response focuses on containment and investigation; disaster recovery focuses on restoring business operations
Incident response focuses on containing, investigating, and eradicating threats, while disaster recovery focuses on restoring critical business operations and systems.
Question 16: Which of the following BEST illustrates an effective security governance reporting structure?
- Security reports are shared only within the IT department
- CISO reports to both the CEO and board with regular updates (Correct answer)
- Security metrics are reported only after incidents occur
- CISO reports to the CTO only
Correct answer: CISO reports to both the CEO and board with regular updates
Effective governance requires the CISO to report to senior leadership and the board regularly, ensuring visibility and accountability at the highest levels.
Question 17: Which of the following BEST describes the purpose of an incident response retainer with a third-party firm?
- To ensure pre-negotiated access to expert resources during a crisis (Correct answer)
- To outsource all internal security operations permanently
- To replace the need for an internal incident response plan
- To satisfy cyber insurance policy requirements only
Correct answer: To ensure pre-negotiated access to expert resources during a crisis
A retainer pre-negotiates access to specialized incident response expertise and resources, reducing response time and ensuring availability during a major incident.
Question 18: A CISM is conducting a risk assessment and discovers a high likelihood threat with low potential impact. This risk should be:
- Automatically mitigated regardless of cost
- Immediately escalated to the board
- Transferred to a third-party insurer
- Evaluated in the context of the organization's risk appetite (Correct answer)
Correct answer: Evaluated in the context of the organization's risk appetite
All risks, regardless of their individual dimensions, must be evaluated against the organization's defined risk appetite before determining the appropriate response.
Question 19: Which of the following represents a governance control rather than a technical control?
- Acceptable use policy (Correct answer)
- Intrusion detection system
- Multi-factor authentication
- Encryption of data at rest
Correct answer: Acceptable use policy
An acceptable use policy is a governance (administrative) control that defines rules and expectations for users, rather than a technical enforcement mechanism.
Question 20: During an active ransomware incident, the FIRST priority of the CISM should be to:
- Activate the incident response plan and isolate affected systems (Correct answer)
- Replace all encrypted systems with new hardware
- Pay the ransom to restore operations as quickly as possible
- Issue a public statement to customers and stakeholders
Correct answer: Activate the incident response plan and isolate affected systems
Activating the incident response plan and isolating affected systems are the immediate priorities to contain the ransomware and prevent further spread.
Question 21: A security information and event management (SIEM) system generates 10,000 alerts daily, but analysts can only investigate 200. The BEST approach to address this is to:
- Disable low-severity alert categories to reduce volume
- Hire more security analysts to handle the full alert volume
- Purchase additional SIEM licenses to increase capacity
- Tune detection rules and implement risk-based alert prioritization (Correct answer)
Correct answer: Tune detection rules and implement risk-based alert prioritization
Tuning detection rules and prioritizing alerts based on risk ensures analysts focus on the most impactful events without permanently silencing potentially important signals.
Question 22: A CISM is selecting security controls for a new information security program. Controls should PRIMARILY be selected based on:
- The lowest acquisition and implementation cost
- What peer organizations have implemented
- Vendor recommendations and marketing materials
- Risk assessment results and business requirements (Correct answer)
Correct answer: Risk assessment results and business requirements
Control selection should be driven by risk assessment results and business requirements to ensure controls address actual risks and support business operations.
Question 23: It is possible to monitor unusual server traffic between internal and external parties to:
- Evaluate the process resiliency of server operations
- Record the trace of advanced persistent threats (Correct answer)
- Support a nonrepudiation framework in e-commerce
- Verify the effectiveness of an intrusion detection system
Correct answer: Record the trace of advanced persistent threats
Monitoring abnormal server communication from inside the organization to external parties can serve the purpose of recording the trace of advanced persistent threats (APTs).
Question 24: An organization accepts a residual risk. What does this mean?
- The remaining risk after controls are applied is deemed tolerable (Correct answer)
- The risk assessment was incomplete
- The risk has been transferred to an insurer
- The risk has been fully eliminated through controls
Correct answer: The remaining risk after controls are applied is deemed tolerable
Residual risk is what remains after controls are applied; accepting it means management finds the remaining exposure within tolerance.
Question 25: Which of the following BEST describes a threat in the context of information security risk?
- A potential cause of an unwanted event that could harm an asset (Correct answer)
- The financial impact of a security breach
- A control that has failed to prevent an incident
- A weakness in a system or process
Correct answer: A potential cause of an unwanted event that could harm an asset
A threat is any potential cause of an unwanted incident that could result in harm to an organization's assets or operations.
Question 26: What is 'residual risk' in information security risk management?
- The risk associated with legacy systems only
- The risk transferred to cyber insurance policies
- The risk that remains after controls have been applied (Correct answer)
- The original risk before any assessment is performed
Correct answer: The risk that remains after controls have been applied
Residual risk is the amount of risk that remains after security controls have been implemented to reduce or manage the inherent risk.
Question 27: What is the purpose of a risk register in information security management?
- To list all employees with access to sensitive systems
- To record identified risks, their assessments, and treatment decisions (Correct answer)
- To document all installed security software
- To track security incident response timelines
Correct answer: To record identified risks, their assessments, and treatment decisions
A risk register is a formal document that records identified risks, their assessed likelihood and impact, treatment options chosen, and residual risk levels.
Question 28: Separation of duties in security governance is PRIMARILY intended to:
- Speed up security approvals
- Automate compliance reporting
- Decrease the number of security staff needed
- Reduce the risk of fraud and error by distributing responsibilities (Correct answer)
Correct answer: Reduce the risk of fraud and error by distributing responsibilities
Separation of duties distributes critical responsibilities so that no single person can complete a high-risk task alone, reducing the risk of fraud or error.
Question 29: A CISM is evaluating third-party vendors. Which risk is MOST relevant to this activity?
- Liquidity risk
- Market risk
- Supply chain and third-party risk (Correct answer)
- Reputational risk
Correct answer: Supply chain and third-party risk
Third-party vendors introduce supply chain and vendor risk, where weaknesses in vendor security posture can compromise the organization's own security.
Question 30: A succession plan within business continuity primarily addresses:
- Designating backup personnel who can assume critical roles if key individuals are unavailable (Correct answer)
- Planning for the acquisition of a competitor following a market disruption
- The order in which IT systems are restored after a disaster
- Scheduling the rotation of staff across different recovery teams
Correct answer: Designating backup personnel who can assume critical roles if key individuals are unavailable
A succession plan ensures that backup personnel are identified and trained to assume critical roles if primary individuals are unavailable during a crisis.
Certified Information Security Manager (CISM)
The CISM certification, administered by ISACA, validates expertise in managing and overseeing enterprise information security programs, covering governance, risk management, program development, and incident management. It targets experienced security managers and professionals seeking to demonstrate management-level security competence.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds