CISM (CISM) ISACA 2 — Questions and Answers
Question 1: A newly appointed information security manager discovers that business units independently procure cloud services without IT involvement. What is the BEST first step?
- Immediately block all unauthorized cloud services
- Conduct a risk assessment of existing shadow IT
- Establish a cloud governance policy with business stakeholder input (Correct answer)
- Report the violations to senior management for disciplinary action
Correct answer: Establish a cloud governance policy with business stakeholder input
Establishing a cloud governance policy with stakeholder input addresses the root cause by creating an approved framework rather than reacting punitively.
Question 2: Which metric BEST demonstrates the effectiveness of a security awareness training program?
- Number of employees who completed training modules
- Reduction in phishing click rates over time (Correct answer)
- Total budget spent on training initiatives
- Number of new policies distributed to staff
Correct answer: Reduction in phishing click rates over time
A reduction in phishing click rates is a measurable behavioral outcome that directly reflects whether training changed employee actions.
Question 3: An organization's risk appetite statement should be approved by:
- The information security manager
- The IT steering committee
- The board of directors or executive leadership (Correct answer)
- The chief information officer
Correct answer: The board of directors or executive leadership
Risk appetite is a strategic business decision that must be set and approved at the board or executive level to align with organizational objectives.
Question 4: When a critical vulnerability is discovered in a vendor-supplied application, the information security manager should FIRST:
- Patch the application immediately without testing
- Notify the vendor and await their official patch
- Assess the risk and determine interim mitigating controls (Correct answer)
- Shut down the application until a patch is available
Correct answer: Assess the risk and determine interim mitigating controls
Assessing risk and implementing interim controls allows the organization to make an informed decision about continued operation while a permanent fix is developed.
Question 5: The PRIMARY purpose of a business impact analysis (BIA) in the context of information security is to:
- Identify all existing threats to the organization
- Determine the criticality of systems and acceptable recovery times (Correct answer)
- Assign dollar values to information assets
- Justify the security budget to executive management
Correct answer: Determine the criticality of systems and acceptable recovery times
A BIA identifies which systems are critical to business operations and establishes RTO and RPO targets to guide recovery planning.
Question 6: An information security manager receives a legal hold notice related to ongoing litigation. The MOST important immediate action is to:
- Notify the security operations center to monitor related systems
- Suspend data retention policies for all relevant data
- Coordinate with legal counsel and preserve all potentially relevant information (Correct answer)
- Encrypt all data associated with the litigation matter
Correct answer: Coordinate with legal counsel and preserve all potentially relevant information
Coordinating with legal counsel and preserving relevant information ensures compliance with legal obligations and prevents spoliation of evidence.
Question 7: Which of the following BEST describes the relationship between information security governance and IT governance?
- They are separate and independent frameworks
- Information security governance is a subset of IT governance (Correct answer)
- IT governance is a subset of information security governance
- They are identical frameworks with different names
Correct answer: Information security governance is a subset of IT governance
Information security governance falls within the broader scope of IT governance, which itself operates under the umbrella of corporate governance.
A newly appointed information security manager discovers that business units independently procure cloud services without IT involvement.
What is the BEST first step?