CISM (CISM) 3 — Questions and Answers
Question 1: A CISM is presenting the security program's value to executive leadership. Which approach is MOST effective?
- Detail the technical vulnerabilities remediated during the year
- Present security metrics tied to business risk reduction and outcomes (Correct answer)
- Show the number of security incidents prevented by controls
- Provide a list of all compliance requirements met
Correct answer: Present security metrics tied to business risk reduction and outcomes
Executive leadership responds best to security metrics framed in terms of business risk reduction and organizational outcomes.
Question 2: Which of the following is the MOST important characteristic of an effective information security policy?
- It references specific technical security tools and vendors
- It is approved by senior management and aligned to business objectives (Correct answer)
- It contains detailed step-by-step security procedures
- It is updated at least quarterly to reflect new threats
Correct answer: It is approved by senior management and aligned to business objectives
Policies derive their authority and effectiveness from senior management approval and alignment with business goals.
Question 3: During a penetration test, a critical vulnerability is discovered in a production system. What should the information security manager do FIRST?
- Patch the vulnerability immediately without notifying stakeholders
- Assess the risk and notify appropriate stakeholders per the established process (Correct answer)
- Terminate the penetration test to prevent further exposure
- Escalate directly to law enforcement
Correct answer: Assess the risk and notify appropriate stakeholders per the established process
Risk assessment and stakeholder notification per established processes ensure coordinated and appropriate response to discovered vulnerabilities.
Question 4: What is the PRIMARY difference between a recovery time objective (RTO) and a recovery point objective (RPO)?
- RTO measures data loss tolerance; RPO measures system downtime tolerance
- RTO measures how quickly systems must be restored; RPO measures acceptable data loss (Correct answer)
- RTO applies to applications; RPO applies to infrastructure
- RTO is set by IT; RPO is set by business owners
Correct answer: RTO measures how quickly systems must be restored; RPO measures acceptable data loss
RTO defines the maximum acceptable downtime for system recovery, while RPO defines the maximum acceptable data loss measured in time.
Question 5: An organization is adopting a cloud-first strategy. What is the MOST important security consideration the CISM should address?
- Ensuring the cloud provider has the latest security certifications
- Defining shared responsibility boundaries between the organization and cloud provider (Correct answer)
- Migrating all existing security tools to cloud-native alternatives
- Increasing the security budget to account for cloud risks
Correct answer: Defining shared responsibility boundaries between the organization and cloud provider
Clearly defining the shared responsibility model ensures neither the organization nor the provider has unaddressed security gaps.
Question 6: Which of the following BEST describes the role of information classification in an information security program?
- It determines which employees can access what systems
- It establishes the basis for applying appropriate security controls to data (Correct answer)
- It defines the legal retention requirements for business records
- It categorizes security incidents by severity level
Correct answer: It establishes the basis for applying appropriate security controls to data
Information classification enables organizations to apply controls proportional to the sensitivity and value of the data.
Question 7: A security manager discovers that a business unit is using an unauthorized cloud application containing sensitive data. What is the MOST appropriate initial response?
- Immediately block access to the application at the firewall
- Report the business unit manager to senior leadership for disciplinary action
- Engage the business unit to understand the need and assess the risk (Correct answer)
- Require the application to be removed before further discussion
Correct answer: Engage the business unit to understand the need and assess the risk
Understanding the business need first enables a risk-informed response that balances security with business requirements.
A CISM is presenting the security program's value to executive leadership.
Which approach is MOST effective?