CISM (CISM) General 5 — Questions and Answers
Question 1: Which of the following BEST describes the purpose of a Recovery Time Objective (RTO)?
- The maximum acceptable data loss measured in time
- The target time within which a business process must be restored after disruption (Correct answer)
- The cost to recover IT systems after a disaster
- The frequency at which data backups are performed
Correct answer: The target time within which a business process must be restored after disruption
RTO defines how quickly a business process must be restored to avoid unacceptable consequences, driving recovery design and investment.
Question 2: What distinguishes a Recovery Point Objective (RPO) from a Recovery Time Objective (RTO)?
- RPO measures recovery speed; RTO measures data loss tolerance
- RPO measures acceptable data loss in time; RTO measures recovery speed (Correct answer)
- Both measure the same thing but apply to different departments
- RPO applies to hardware; RTO applies to software
Correct answer: RPO measures acceptable data loss in time; RTO measures recovery speed
RPO defines the maximum tolerable data loss window (e.g., last 4 hours of transactions), while RTO defines how quickly systems must be back online.
Question 3: An organization wants to ensure its Business Continuity Plan (BCP) remains effective over time. The BEST way to accomplish this is to:
- Lock the BCP document and restrict access to senior management
- Test, review, and update the BCP on a regular schedule (Correct answer)
- Keep the BCP confidential to prevent adversaries from exploiting it
- Outsource business continuity planning entirely to a vendor
Correct answer: Test, review, and update the BCP on a regular schedule
Regular testing, review, and updates ensure the BCP reflects current systems, personnel, and threats, maintaining its effectiveness as conditions change.
Question 4: Which of the following is an example of a detective information security control?
- Data encryption at rest
- Firewall blocking unauthorized traffic
- Intrusion detection system (IDS) alerting on suspicious activity (Correct answer)
- Multi-factor authentication for system access
Correct answer: Intrusion detection system (IDS) alerting on suspicious activity
Detective controls like IDS identify and alert on events that have occurred or are occurring, enabling response without preventing the activity itself.
Question 5: An information security manager wants to verify that security controls are operating as intended. Which activity is MOST appropriate?
- Updating the information security policy
- Conducting a control effectiveness audit or assessment (Correct answer)
- Purchasing additional security software licenses
- Hiring additional security analysts
Correct answer: Conducting a control effectiveness audit or assessment
Control effectiveness audits verify that implemented controls are functioning correctly and actually reducing risk as designed.
Question 6: Which framework is MOST commonly used to align information security management with overall IT governance?
- OWASP Top 10
- NIST SP 800-53
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- PCI DSS
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT provides a comprehensive IT governance and management framework that aligns IT activities, including security, with enterprise objectives.
Question 7: A security manager is asked to measure the return on security investment (ROSI). Which component is ESSENTIAL to calculate ROSI?
- Number of security certifications held by staff
- Annualized Loss Expectancy (ALE) before and after implementing controls (Correct answer)
- Total hours spent on security awareness training
- Number of security policies published this year
Correct answer: Annualized Loss Expectancy (ALE) before and after implementing controls
ROSI is calculated by comparing ALE before and after control implementation against the cost of those controls, quantifying the financial value of the investment.
Which of the following BEST describes the purpose of a Recovery Time Objective (RTO)?