CISM (CISM) ISACA 3 — Questions and Answers
Question 1: A security incident causes a 6-hour outage for a system with an RTO of 4 hours. This PRIMARILY indicates a failure in:
- Incident response planning
- Vulnerability management
- Business continuity / disaster recovery planning (Correct answer)
- Change management procedures
Correct answer: Business continuity / disaster recovery planning
Failing to recover within the established RTO indicates that business continuity and disaster recovery plans were insufficient or ineffectively executed.
Question 2: When conducting a third-party vendor risk assessment, which document provides the MOST assurance regarding a vendor's security controls?
- The vendor's self-completed security questionnaire
- A SOC 2 Type II report from an independent auditor (Correct answer)
- The vendor's published security policy
- A sample penetration test report provided by the vendor
Correct answer: A SOC 2 Type II report from an independent auditor
A SOC 2 Type II report provides independent, audited evidence that controls were operating effectively over a period of time, not just at a point in time.
Question 3: The PRIMARY reason an information security manager should align the security strategy with the business strategy is to:
- Reduce the overall IT budget
- Ensure security receives adequate funding
- Enable the organization to achieve its business objectives securely (Correct answer)
- Comply with regulatory requirements
Correct answer: Enable the organization to achieve its business objectives securely
Security strategy must support business goals so that security enables rather than impedes the achievement of organizational objectives.
Question 4: Which of the following is the MOST effective control to protect against insider threats?
- Implementing perimeter firewalls and IDS systems
- Enforcing separation of duties and least privilege access (Correct answer)
- Requiring all employees to sign acceptable use policies
- Conducting annual background checks on all staff
Correct answer: Enforcing separation of duties and least privilege access
Separation of duties and least privilege limit what any single insider can access or do, directly reducing the impact of malicious or negligent insider actions.
Question 5: An organization wants to transfer risk associated with a specific cyber threat. The MOST appropriate risk treatment option is:
- Implementing additional technical controls
- Accepting the risk as within tolerance
- Purchasing cyber liability insurance (Correct answer)
- Discontinuing the business process that generates the risk
Correct answer: Purchasing cyber liability insurance
Cyber liability insurance transfers the financial impact of a cyber incident to a third party, which is the definition of risk transfer.
Question 6: During a post-incident review, the team determines that attackers gained access through a compromised service account with excessive privileges. The BEST long-term remediation is:
- Changing all service account passwords immediately
- Implementing privileged access management with just-in-time access (Correct answer)
- Disabling all service accounts until reviewed
- Adding multi-factor authentication to the affected service account
Correct answer: Implementing privileged access management with just-in-time access
Privileged access management with just-in-time provisioning systematically enforces least privilege for service accounts, addressing the root cause of excessive standing privileges.
Question 7: Which of the following BEST describes the purpose of a data classification policy?
- To assign monetary values to data assets
- To define handling requirements based on data sensitivity (Correct answer)
- To establish retention schedules for all organizational data
- To identify which employees can create new data repositories
Correct answer: To define handling requirements based on data sensitivity
Data classification defines categories of sensitivity and establishes appropriate handling, storage, and transmission requirements for each category.
A security incident causes a 6-hour outage for a system with an RTO of 4 hours.
This PRIMARILY indicates a failure in: