CISM (CISM) ISACA 5 — Questions and Answers
Question 1: An information security manager is asked to justify a proposed security investment to the CFO. The MOST persuasive approach is to:
- Present the technical specifications of the security solution
- Quantify the risk reduction in terms of business impact and financial exposure (Correct answer)
- Cite industry benchmarks for security spending as a percentage of IT budget
- Reference recent high-profile breaches at competitor organizations
Correct answer: Quantify the risk reduction in terms of business impact and financial exposure
Quantifying risk reduction in financial terms connects security investment to business value in language that resonates with financial decision-makers.
Question 2: Which of the following BEST describes a gap analysis in the context of information security program development?
- An assessment of vulnerabilities in technical systems
- A comparison of current security capabilities against a target state or framework (Correct answer)
- A review of open audit findings from prior assessments
- An inventory of security tools currently deployed
Correct answer: A comparison of current security capabilities against a target state or framework
A gap analysis measures the difference between the current security state and a desired future state or framework, identifying what needs to be built or improved.
Question 3: When an employee is terminated, the MOST critical immediate security action is:
- Recovering company-issued equipment
- Revoking all logical access to systems and data (Correct answer)
- Notifying the employee's manager and HR
- Conducting an exit interview about security responsibilities
Correct answer: Revoking all logical access to systems and data
Revoking logical access immediately prevents a departing employee from accessing, exfiltrating, or damaging organizational systems or data.
Question 4: The concept of 'defense in depth' is BEST described as:
- Installing the most advanced firewall available
- Layering multiple independent security controls so that failure of one does not compromise overall security (Correct answer)
- Prioritizing network security over endpoint security
- Conducting deep penetration testing across all systems
Correct answer: Layering multiple independent security controls so that failure of one does not compromise overall security
Defense in depth uses multiple layers of controls so that an attacker who bypasses one layer still faces additional barriers before reaching a target.
Question 5: During a business continuity exercise, the recovery team is unable to restore a critical system within the defined RTO. The BEST immediate action for the information security manager is to:
- Extend the RTO to match actual recovery capability
- Document the failure and update the BCP based on lessons learned (Correct answer)
- Discipline the team members responsible for the delay
- Declare the exercise a failure and reschedule it
Correct answer: Document the failure and update the BCP based on lessons learned
Exercises are learning opportunities — documenting gaps and updating the BCP to address them is the constructive response that improves actual recovery capability.
Question 6: Which of the following BEST illustrates the principle of 'security by design'?
- Conducting a penetration test before a system goes live
- Integrating security requirements into the software development lifecycle from the start (Correct answer)
- Applying security patches promptly after they are released
- Installing endpoint detection software on all developer workstations
Correct answer: Integrating security requirements into the software development lifecycle from the start
Security by design means embedding security considerations into the design and development process from inception rather than retrofitting controls at the end.
Question 7: An organization's security audit reveals that access rights are not reviewed regularly. The MOST effective control to address this finding is:
- Implementing stricter password complexity requirements
- Establishing a periodic user access recertification process (Correct answer)
- Deploying a data loss prevention solution
- Requiring all users to acknowledge the acceptable use policy annually
Correct answer: Establishing a periodic user access recertification process
Periodic access recertification requires managers to review and validate user access rights on a scheduled basis, directly addressing the lack of regular access reviews.
An information security manager is asked to justify a proposed security investment to the CFO.
The MOST persuasive approach is to: