CISM (CISM) ISACA 4 — Questions and Answers
Question 1: A penetration test reveals a critical vulnerability in a production system. The system owner refuses to patch it due to potential downtime. The information security manager should:
- Override the system owner and apply the patch
- Accept the risk on behalf of the organization
- Document the risk and escalate to senior management for a formal risk acceptance decision (Correct answer)
- Remove the system from the network until patched
Correct answer: Document the risk and escalate to senior management for a formal risk acceptance decision
Risk acceptance decisions for critical vulnerabilities must be made by appropriate senior stakeholders with authority, not left to system owners or security managers alone.
Question 2: The CISM job practice area that involves identifying and managing information security risks is:
- Information Security Governance
- Information Security Risk Management (Correct answer)
- Information Security Program Development and Management
- Incident Management
Correct answer: Information Security Risk Management
Information Security Risk Management is the CISM domain specifically focused on identifying, assessing, and managing information security risks.
Question 3: When developing key risk indicators (KRIs), the information security manager should ensure they are:
- Based solely on technical vulnerability counts
- Predictive and aligned to risk appetite thresholds (Correct answer)
- Reported only when thresholds are exceeded
- Determined independently by the security team without business input
Correct answer: Predictive and aligned to risk appetite thresholds
Effective KRIs provide early warning signals of emerging risk and are tied to the organization's defined risk appetite so management can act before thresholds are breached.
Question 4: An organization is merging with another company. The MOST important information security consideration during due diligence is:
- Comparing the two companies' IT budgets
- Assessing the target company's security posture and existing vulnerabilities (Correct answer)
- Determining which security team members will be retained
- Selecting a unified security technology platform
Correct answer: Assessing the target company's security posture and existing vulnerabilities
Assessing the target's security posture identifies inherited risks, liabilities, and compliance gaps that could affect the acquiring organization after the merger.
Question 5: Which of the following is the MOST important characteristic of an effective information security policy?
- It uses highly technical language to be precise
- It is approved by senior management and communicated to all staff (Correct answer)
- It describes specific technical implementation steps
- It is updated annually regardless of changes in the environment
Correct answer: It is approved by senior management and communicated to all staff
Senior management approval provides authority and accountability, while communication to all staff ensures awareness — both are essential for policy effectiveness.
Question 6: A security information and event management (SIEM) system generates 10,000 alerts daily, but analysts can only investigate 200. The BEST approach to address this is to:
- Purchase additional SIEM licenses to increase capacity
- Hire more security analysts to handle the full alert volume
- Tune detection rules and implement risk-based alert prioritization (Correct answer)
- Disable low-severity alert categories to reduce volume
Correct answer: Tune detection rules and implement risk-based alert prioritization
Tuning detection rules and prioritizing alerts based on risk ensures analysts focus on the most impactful events without permanently silencing potentially important signals.
Question 7: The PRIMARY objective of information security incident management is to:
- Identify and prosecute those responsible for incidents
- Minimize the impact of incidents and restore normal operations (Correct answer)
- Document incidents for regulatory reporting purposes
- Prevent all future incidents from occurring
Correct answer: Minimize the impact of incidents and restore normal operations
Incident management's primary goal is containment and recovery — minimizing business impact and restoring normal operations as quickly as possible.
A penetration test reveals a critical vulnerability in a production system.
The system owner refuses to patch it due to potential downtime.
The information security manager should: