Free Certified Information Security Manager (CISM) MCQ Questions and Answers — Questions and Answers
Question 1: What should a risk management strategy's main goal be?
- Identify credible risks and transfer them to an external party
- Determine the organization's risk appetite
- Eliminate credible risks
- Identify credible risks and reduce them to an acceptable level (Correct answer)
Correct answer: Identify credible risks and reduce them to an acceptable level
The main goal of a risk management strategy is to identify risks, then reduce those risks to levels that upper management can accept. <br> <br> The phrase "determine the organization's risk appetite" is erroneous because, while crucial and necessary for a risk management program to operate correctly, determining risk appetite is not the fundamental goal of a risk management strategy. It is erroneous to say, "Identify credible risks and transfer them to an external entity," when many other potential outcomes for hazards can be discovered. It is erroneous to say "remove credible dangers," as risks can only be decreased to tolerable levels.
Question 2: A manufacturing company's CISO, Linda, is developing a new cyber-risk governance procedure. What should Linda do initially to ensure the success of this process?
- Charter a security steering committee consisting of IT and cybersecurity leaders
- Develop a RACI matrix that defines executive roles and responsibilities
- Charter a security steering committee consisting of IT, security, and business leaders (Correct answer)
- Develop a risk management process similar to what is found in ISO/IEC 27001
Correct answer: Charter a security steering committee consisting of IT, security, and business leaders
The best course of action is to establish a chartered information security steering group with representatives from business, IT, and security leaders. Business executives need to get involved and participate in discussions and decisions if security governance is to be successful. <br> <br> It is false to say that you should "develop a RACI matrix that outlines executive roles and responsibilities" since, while vital, a RACI matrix is only a small component of a formalized information security steering committee. It is erroneous to say, "Charter a security steering group made up of leaders in IT and cybersecurity." A security steering committee must also have business leaders on it. Because security governance, which is more than risk management, is the topic of this question, it is erroneous to say that you should "develop a risk management process comparable to what is found in ISO/IEC 27001."
Question 3: What procedures must be followed before a risk assessment can begin in an organization?
- Determine scope, purpose, and criteria for the audit (Correct answer)
- Determine the qualifications of the firm that will perform the audit
- Determine scope, applicability, and purpose for the audit
- Determine the qualifications of the person(s) who will perform the audit
Correct answer: Determine scope, purpose, and criteria for the audit
Establishing an audit context is essential, according to ISO/IEC 27005 and other risk management standards. This entails choosing the audit's scope or the areas of the company that will be examined. Determining the risk assessment's goal, such as control coverage, control efficacy, or business process effectiveness, is also crucial. The criteria for the audit must then be decided. <br> <br> Since any confirmation of qualifications would be made previous to this point, the phrases "Determine the qualifications of the firm that will execute the audit" and "Determine the qualifications of the person(s) who will perform the audit" are erroneous. It is erroneous to say, "Determine scope, application, and purpose for the audit," as an audit that was not necessary should not be carried out.
Question 4: A risk manager in an organization just finished a risk assessment. One of the conclusions was requested by executive management to be eliminated from the final report by the risk manager. What is demonstrated by this removal?
- Risk acceptance (Correct answer)
- Gerrymandering
- Internal politics
- Risk avoidance
Correct answer: Risk acceptance
Despite being dubious, removing a risk finding from a report implies risk acceptance. However, it may go further than that, and in some professions, this is regarded as carelessness and negligence. Usually, a risk manager would oppose such a move and might think about documenting the situation or possibly making a formal protest. <br> <br> The term "gerrymandering" is erroneous because it refers to the process of drawing election boundaries for governmental purposes. Internal politics is not the ideal response, even though the circumstance may illustrate internal politics. The term "risk avoidance" is erroneous because it refers to ceasing to engage in an activity that poses a risk.
Question 5: A new CISO is managing asset inventory processes at a financial services company. The company uses both on-premises and IaaS-based virtualization services. What method will efficiently identify all active assets?
- Obtain a list of all assets from the patch management platform.
- Perform discovery scans on all networks. (Correct answer)
- Count all of the servers in each data center.
- Obtain a list of all assets from the security event and information management (SIEM) system.
Correct answer: Perform discovery scans on all networks.
Even if none of these methods is perfect, the best initial step is to run discovery scans across all networks. Even so, network engineers must be consulted to ensure that discovery scans in on-premises and IaaS systems scan all known networks. Interviewing system engineers to understand virtual machine management systems and collect inventory data from them are further helpful approaches. <br> <br> It is erroneous to "get a list of all assets from the patch management platform," as patch management systems could not cover some assets in the organization's environment. It is erroneous to say, "Obtain a list of all assets from the patch management platform," as not all assets in the organization's environment may send log data to the SIEM. Because the company uses virtualization technology and IaaS-based platforms, counting servers in an on-premises data center will miss both virtual and IaaS-based assets; therefore, the instruction to "count all of the servers in each data center" is wrong.
Question 6: According to an internal audit of the employee termination procedure, one or more terminated employee user accounts were not locked or deleted in 20% of employee terminations. The internal audit division discovered that regular monthly user access reviews detected 100% of missed account closures, leading to those user accounts being closed by 60 days following user termination. What, if any, corrective measures are necessary?
- Improve the user termination process to reduce the number of missed account closures. (Correct answer)
- Increase user access review process frequency to twice per week.
- Increase user access review process frequency to weekly.
- No action is necessary since monthly user access review process is effective.
Correct answer: Improve the user termination process to reduce the number of missed account closures.
The frequency of improper user terminations is too frequent. The time required to increase the frequency of user access evaluations will be too great. The most excellent solution is to figure out how to make the user termination procedure better. Since there are 20% "misses," every step is assumed to be manual. <br> <br> The user access review process is too time-consuming. Thus the statements "raise user access review process frequency to twice per week" and "increase user access review process frequency to weekly" are wrong. Since there are 20% "misses," every step is assumed to be manual. The statement, "No action is required since monthly user access review process is functional," is untrue because a "miss" rate of 20% would be considered excessive in most firms. A rate of less than 2% is acceptable.
Question 7: What presents the biggest challenge when putting a data classification scheme into practice?
- Implementing and tuning DLP agents on servers and endpoints
- Difficulty with industry regulators
- Understanding the types of data in use
- Training end users on data handling procedures (Correct answer)
Correct answer: Training end users on data handling procedures
The most difficult challenge associated with implementing a data classification program is ensuring that workers understand and are willing to comply with data handling procedures. By comparison, automation is simpler primarily because it is deterministic. <br> <br> "Difficulty with industry regulators" is incorrect because regulators are not typically as concerned with data classification as they are with the protection of relevant information. "Understanding the types of data in use" is incorrect because, although it can be a challenge understanding the data in use in an organization, user compliance is typically the biggest challenge. "Implementing and tuning DLP agents on servers and endpoints" is incorrect because implementing and tuning agents are not usually as challenging as end user behavior training.
What should a risk management strategy's main goal be?