CISM (CISM) 4 — Questions and Answers
Question 1: Which of the following BEST describes the purpose of a security operations center (SOC)?
- To develop and maintain information security policies
- To continuously monitor, detect, and respond to security incidents (Correct answer)
- To conduct annual penetration tests on critical systems
- To manage compliance with regulatory requirements
Correct answer: To continuously monitor, detect, and respond to security incidents
A SOC provides continuous monitoring and incident detection and response capabilities to protect the organization.
Question 2: When conducting a post-incident review, which outcome is MOST valuable for improving the security program?
- Identifying which employees failed to follow security procedures
- Documenting the financial losses caused by the incident
- Identifying root causes and implementing corrective actions (Correct answer)
- Reporting the incident details to regulatory authorities
Correct answer: Identifying root causes and implementing corrective actions
Root cause analysis and corrective actions prevent recurrence and strengthen the overall security posture.
Question 3: An organization's risk register shows a risk that has been accepted for three years. What action should the CISM recommend?
- Continue accepting the risk as long as no incidents have occurred
- Review the risk to determine if it remains within acceptable tolerance given current conditions (Correct answer)
- Transfer the risk to a third party to limit organizational exposure
- Escalate the risk acceptance to the board immediately
Correct answer: Review the risk to determine if it remains within acceptable tolerance given current conditions
Accepted risks must be periodically reviewed because threat landscapes, business conditions, and risk tolerances change over time.
Question 4: Which security framework is PRIMARILY focused on managing and improving cybersecurity risk in critical infrastructure sectors?
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- PCI DSS
- SOC 2
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF was developed specifically to help critical infrastructure organizations manage and reduce cybersecurity risk.
Question 5: A CISM is tasked with reducing the attack surface of the organization. Which approach BEST achieves this goal?
- Increasing network monitoring capabilities
- Implementing least privilege access and removing unnecessary services (Correct answer)
- Training employees to recognize social engineering attacks
- Deploying advanced endpoint detection and response tools
Correct answer: Implementing least privilege access and removing unnecessary services
Least privilege access and eliminating unnecessary services directly reduces the number of exploitable entry points for attackers.
Question 6: Which of the following is the MOST effective way to ensure third-party vendors comply with the organization's security requirements?
- Rely on vendors' published security certifications
- Include security requirements in contracts and conduct periodic audits (Correct answer)
- Require vendors to sign a security acknowledgment form annually
- Limit vendor access to only non-sensitive systems
Correct answer: Include security requirements in contracts and conduct periodic audits
Contractual security requirements combined with regular audits create enforceable obligations and verification mechanisms.
Question 7: What is the PRIMARY objective of change management from an information security perspective?
- To slow down the implementation of new technologies
- To ensure changes do not introduce new security vulnerabilities or risks (Correct answer)
- To document all changes made to IT systems for audit purposes
- To obtain approval from the CISO before any system modification
Correct answer: To ensure changes do not introduce new security vulnerabilities or risks
Security-focused change management ensures that system changes are evaluated for security impact before implementation.
Which of the following BEST describes the purpose of a security operations center (SOC)?