CISM (CISM) 5 — Questions and Answers
Question 1: An organization experiences a ransomware attack that encrypts critical data. Which recovery option should be prioritized FIRST?
- Negotiate with the attackers to obtain the decryption key
- Restore systems from the most recent clean backup (Correct answer)
- Rebuild all affected systems from scratch
- Report the incident to law enforcement before taking any recovery action
Correct answer: Restore systems from the most recent clean backup
Restoring from clean backups is the fastest and most reliable recovery method that avoids funding criminal activity.
Question 2: Which of the following BEST defines inherent risk in the context of information security risk management?
- Risk that remains after security controls are applied
- Risk that exists before any controls are implemented (Correct answer)
- Risk that has been formally accepted by management
- Risk associated with third-party vendor relationships
Correct answer: Risk that exists before any controls are implemented
Inherent risk is the level of risk existing in the absence of any controls or mitigating factors.
Question 3: A CISM is asked to demonstrate the ROI of the security program. Which approach is MOST appropriate?
- Calculate the total cost of security tools and staff as a percentage of IT budget
- Quantify avoided losses through risk reduction compared to security investment costs (Correct answer)
- Show the number of security incidents blocked during the year
- Present the cost per employee for security awareness training
Correct answer: Quantify avoided losses through risk reduction compared to security investment costs
ROI is best demonstrated by comparing the value of risk reduction (avoided losses) against the cost of security investments.
Question 4: Which of the following is the MOST important factor when prioritizing security vulnerabilities for remediation?
- The age of the vulnerability as reported in CVE databases
- The combined assessment of exploitability and potential business impact (Correct answer)
- The vendor's assigned CVSS score for the vulnerability
- The difficulty of implementing the technical fix
Correct answer: The combined assessment of exploitability and potential business impact
Prioritization should consider both exploitability and the potential impact to the organization's specific business context.
Question 5: An organization is considering outsourcing its security monitoring to a managed security service provider (MSSP). What is the MOST critical concern the CISM should address?
- Ensuring the MSSP uses the latest security technologies
- Defining clear SLAs, escalation procedures, and data handling requirements (Correct answer)
- Verifying the MSSP's staff hold relevant security certifications
- Confirming the MSSP has experience in the same industry sector
Correct answer: Defining clear SLAs, escalation procedures, and data handling requirements
SLAs, escalation procedures, and data handling requirements are foundational to ensuring the MSSP delivers acceptable security outcomes.
Question 6: Which of the following is the BEST indicator that an organization's security culture is mature?
- Employees report suspicious activities voluntarily without being prompted (Correct answer)
- The organization has not experienced a security breach in the past year
- All employees have completed mandatory security awareness training
- Security policies are reviewed and updated annually
Correct answer: Employees report suspicious activities voluntarily without being prompted
Voluntary reporting of suspicious activities demonstrates that employees understand their security responsibilities and proactively support the program.
Question 7: Which of the following BEST describes the relationship between information security risk management and enterprise risk management (ERM)?
- Information security risk management operates independently of ERM
- Information security risk is one category of risk managed within the broader ERM framework (Correct answer)
- ERM is a subset of information security risk management
- Information security risk management replaces ERM in technology-heavy organizations
Correct answer: Information security risk is one category of risk managed within the broader ERM framework
Information security risk is one of many risk categories (financial, operational, strategic) managed within the overarching enterprise risk framework.
An organization experiences a ransomware attack that encrypts critical data.
Which recovery option should be prioritized FIRST?