CISM (CISM) 2 — Questions and Answers
Question 1: A newly appointed CISM is reviewing the organization's information security governance structure. Which of the following BEST demonstrates effective governance?
- Security decisions are made exclusively by the IT department
- The board of directors receives regular security risk reports (Correct answer)
- Security policies are updated only after a breach occurs
- The CISO manages all security activities without oversight
Correct answer: The board of directors receives regular security risk reports
Effective governance requires board-level oversight and accountability, including regular reporting on security risks.
Question 2: During a risk assessment, an organization identifies a threat with a high likelihood but low impact. What is the MOST appropriate risk treatment?
- Transfer the risk through cyber insurance
- Accept the risk due to low impact
- Implement controls proportional to the risk level (Correct answer)
- Avoid the risk by discontinuing the related activity
Correct answer: Implement controls proportional to the risk level
Controls should be implemented proportional to the overall risk level, balancing likelihood and impact considerations.
Question 3: An organization is developing its information security strategy. Which factor is MOST critical to align the strategy with business objectives?
- Adopting the latest security technologies
- Understanding the organization's risk appetite and business goals (Correct answer)
- Benchmarking against industry peers' security budgets
- Maximizing the number of security controls implemented
Correct answer: Understanding the organization's risk appetite and business goals
Security strategy must be grounded in the organization's risk appetite and specific business objectives to be effective.
Question 4: Which metric BEST demonstrates the effectiveness of a security awareness training program?
- Number of training sessions conducted per year
- Percentage of employees who completed the training
- Reduction in phishing click rates after training (Correct answer)
- Training budget spent per employee
Correct answer: Reduction in phishing click rates after training
Behavioral change metrics like reduced phishing click rates directly measure training effectiveness rather than just participation.
Question 5: A third-party vendor with access to sensitive customer data has suffered a breach. What should the information security manager do FIRST?
- Terminate the vendor contract immediately
- Assess the impact on the organization and notify affected parties per policy (Correct answer)
- Wait for the vendor's incident report before taking action
- Conduct a full audit of all vendor relationships
Correct answer: Assess the impact on the organization and notify affected parties per policy
The immediate priority is assessing organizational impact and fulfilling notification obligations per policy and regulatory requirements.
Question 6: Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in the context of information security?
- To identify all possible security threats to the organization
- To determine the financial cost of implementing security controls
- To identify critical processes and the impact of their disruption (Correct answer)
- To assess the effectiveness of existing security controls
Correct answer: To identify critical processes and the impact of their disruption
A BIA identifies critical business processes, their dependencies, and the consequences of disruption to prioritize recovery efforts.
Question 7: An organization wants to validate its incident response capabilities. Which approach provides the MOST realistic assessment?
- Reviewing incident response documentation for completeness
- Conducting tabletop exercises with the security team
- Performing a full simulation (red team) exercise without prior notice (Correct answer)
- Interviewing key personnel about their incident response roles
Correct answer: Performing a full simulation (red team) exercise without prior notice
Unannounced red team exercises provide the most realistic test of actual incident response capability under realistic conditions.
A newly appointed CISM is reviewing the organization's information security governance structure.
Which of the following BEST demonstrates effective governance?