ISACA Certified Information Security Manager (CISM)
Get full access to the updated question bank and confidently prepare for your exam.
Vendor
ISACA
Certification
Governance Risk and Security
Content
1001 Qs
Status
Verified
Updated
1 day ago
Test the Practice Engine
Experience our interactive testing environment with free demo questions
Premium Bundle
Complete Success Suite
Save $39 Instantly
-
โFull PDF + Interactive Engine Everything you need to pass
-
โAll Advanced Question Types Drag & Drop, Hotspots, Case Studies
-
โPriority 24/7 Expert Support Direct line to certification leads
-
โ90 Days Free Priority Updates Stay current as exams change
Success Metric
98.4% Pass Rate
Standard Simulation
Practice Engine
One-Time Payment
-
Web-Based (Zero Install)
-
Real Testing Environment Virtual & Practice Modes
-
Interactive Engine Drag & Drop, Hotspots
-
60 Days Free Updates
Compatible with All Devices
Basic Tier
PDF Study Guide
Digital Access
- โ Exam Questions (PDF)
- โ Mobile Friendly
- โ 60 Days Updates
Verified 100-Question Preview (CISM)
Verified Community
The CertoMetrics Standard.
Recommend the #1 platform for verified ISACA certification resources.
Success Network
Help a Colleague Succeed.
Invite a peer to get their own updated CISM prep kit.
Exam Overview
The ISACA Certified Information Security Manager (CISM) certification is a globally recognized credential designed for experienced information security managers and those who manage, design, oversee, and assess an enterprise's information security. It validates an individual's expertise in governance, program development, risk management, and incident response, positioning them as strategic leaders capable of aligning security initiatives with business objectives. Earning your CISM demonstrates a deep understanding of the strategic aspects of information security, enhancing your credibility and career prospects in a rapidly evolving threat landscape. This certification is crucial for professionals aspiring to C-suite and senior management roles, offering a distinct advantage in today's competitive market.
Questions
150 multiple-choice questions
Passing Score
450 (on a 200-800 point scale)
Duration
240 Minutes (4 hours)
Difficulty
Expert
Level
Professional/Specialist
Skills Measured
Career Path
Target Roles
Common Questions
Is the material up to date?
Yes. We update our question bank weekly to match the latest ISACA standards. You get free updates for 90 days.
What format do I get?
You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).
Is there a guarantee?
Absolutely. If you fail the CISM exam using our materials, we offer a full money-back guarantee.
When do I get the download?
Instantly. The download link is available in your dashboard immediately after payment is confirmed.
Free Study Guide Samples
Previewing updated CISM bank (100 Questions).
Which of the following should an information security manager do FIRST when planning to develop and implement an information security program?
Correct Option: B
โ
Option B (Correct)
Reasoning: When planning to develop and implement an information security program, the absolute first step for an information security manager is to define and document the information security strategy. This strategy provides the overarching direction, objectives, and scope for the entire program, ensuring it aligns with the organization's business goals and risk appetite. Without a clear strategy, subsequent activities like team identification, obtaining buy-in, or developing training would lack proper foundation and direction.
โ Why the other choices are incorrect:
- Option A is incorrect: Identifying individuals for the information security team is a staffing activity that typically follows the definition of the program's strategy and scope, as the required skills and roles depend on the strategy.
- Option C is incorrect: Obtaining stakeholder consensus and buy-in, while critical, generally occurs after an initial strategy or proposal has been developed. Stakeholders need something concrete to review and agree upon.
- Option D is incorrect: Developing information security awareness training for employees is an operational implementation step of the security program, which occurs much later in the process, after the strategy is defined, policies are established, and controls are being put in place.
Reference: ISACA CISM Review Manual (various editions) - Domain 1: Information Security Governance
Which of the following is the MOST critical consideration when shifting IT operations
To an infrastructure as a service (laas) model hosted in a foreign country?
Correct Option: B
When moving IT operations to an Infrastructure as a Service (IaaS) model hosted in a foreign country, the most critical consideration is the complex legal and regulatory landscape. Laws and regulations of the origin country may have limited or no extraterritorial applicability concerning the data and operations in the foreign jurisdiction. Conversely, the foreign country's laws, including data privacy, residency, and government access laws, will directly apply. This creates significant compliance challenges and necessitates a thorough understanding of the applicable legal frameworks. Failure to do so can lead to severe legal and reputational consequences.
- Option A is incorrect: Liabilities and penalties in the event of a security breach are consequences that arise from a failure to comply with the relevant laws and regulations. While a critical risk, it is an outcome of not adequately addressing the underlying legal complexities (Option B).
- Option C is incorrect: Data labeling is an important practice for data classification and governance. However, it is an internal control mechanism that aids in managing data based on its sensitivity and regulatory requirements, but it does not directly address the fundamental change in the legal jurisdiction itself.
- Option D is incorrect: The concern that data may be stored in unknown locations and may not be easily retrievable is a valid operational and contractual risk. However, the primary reason why these locations matter in a foreign country often ties back to legal requirements (e.g., data residency, government access laws) which are part of the broader legal and regulatory considerations highlighted in Option B. Furthermore, the "unknown" aspect can be mitigated through contractual agreements; the critical issue remains the legal implications of the known locations.
Reference: https://www.isaca.org/resources/isaca-journal/issues
Which of the following BEST indicates an effective security culture?
Correct Option: A
โ Option A (Correct)
Reasoning: An effective security culture integrates information security as a strategic business partner and enabler. This indicates a mature, proactive mindset where security supports business objectives, moving beyond mere compliance to genuine organizational buy-in and ownership. It signifies that security is intrinsically valued and part of the organization's core operations.
โ Why the other choices are incorrect:
- Option B is incorrect: While essential, encouraging incident reporting is an operational task and not the primary indicator of a holistic, effective security culture.
- Option C is incorrect: Following policies demonstrates compliance, but an effective culture transcends rule-following to encompass deep understanding and valuing of security principles.
- Option D is incorrect: Managing risk is an outcome of effective security practices. However, it describes a risk state rather than directly indicating the cultural perception and integration of security within the business.
Reference: https://www.isaca.org/credentialing/cism/cism-resources
The PRIMARY benefit of performing a risk assessment in the development of a business continuity plan (BCP) is that it facilitates an:
Correct Option: B
A risk assessment is a foundational step in developing a Business Continuity Plan (BCP). Its primary benefit is to identify potential threats and vulnerabilities that could disrupt business operations and to evaluate the potential impact and likelihood of such interruptions. This process, often involving a Business Impact Analysis (BIA) as part of the broader risk assessment, helps an organization understand which key processes are critical, what risks they face, and the consequences of their unavailability. This understanding is essential for prioritizing recovery efforts and allocating resources effectively in the BCP.
Reference: https://www.isaca.org/resources/isaca-journal/issues/2021/volume-3/business-continuity-planning-and-risk-assessment-integrating-to-achieve-resilience
Which of the following provides the BEST indication of senior management commitment to the organization's information security strategy?
Correct Option: B
Periodic review of the security capability maturity model directly demonstrates senior management's commitment to the organization's information security strategy. A capability maturity model (CMM) provides a structured approach to assess and improve an organization's security processes and capabilities. Senior management's involvement in periodically reviewing the CMM indicates their active engagement in evaluating the effectiveness of the security program, understanding its strategic alignment, identifying areas for improvement, and making informed decisions to enhance the organization's security posture. This goes beyond mere resource allocation or operational reporting, showing a strategic commitment to continuous improvement.
Why the other choices are incorrect:
- Adequate budget for IT projects: While crucial, an 'adequate budget for IT projects' is a general IT expenditure and does not specifically signify strategic commitment to information security strategy. It could encompass various IT initiatives without a strong security focus.
- The number of information security metrics defined: Defining metrics is a necessary step for measurement, but the sheer 'number' of metrics does not inherently reflect senior management commitment. What matters more is how these metrics are used, reviewed, and acted upon by senior management to drive strategic security decisions.
- Reporting of security training results: Reporting training results is an operational activity that demonstrates compliance and awareness efforts. While important, it is a tactical outcome and does not reflect the same level of strategic oversight and commitment as reviewing the overall maturity and effectiveness of the security program itself.
Reference: ISACA CISM Review Manual (latest edition) - Domain 1: Information Security Governance
Which of the following is the MOST important reason to ensure information security is Aligned with the organizationโs strategy?
Correct Option: B
The correct answer is B. To optimize security risk management.
Why this is the correct answer:
In information security frameworks (such as those from ISACA and (ISC)ยฒ), the ultimate goal of information security is to support the business. By aligning information security with the organizationโs strategy, security professionals understand exactly which assets, processes, and systems are most critical to the business's success.
Understanding the business's strategic goals allows the organization to optimize security risk management by allocating budget, resources, and controls to the areas that matter most, rather than wasting resources protecting low-value assets or implementing controls that hinder business operations.
Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?
Correct Option: D
✅ Option D (Correct)
Reasoning: Incident impact is the MOST appropriate consideration when defining incident classification and categorization levels because it directly determines the severity and priority of an incident. Classification based on impact (e.g., impact on confidentiality, integrity, availability, business operations, financial, reputational, legal/regulatory) allows organizations to allocate appropriate resources, trigger the right response procedures, and prioritize incidents effectively according to their potential or actual harm to the organization.
❌ Why the other choices are incorrect:
- Option A is incorrect: Quantity of impacted assets is a factor that contributes to the overall impact, but it is not the sole or most comprehensive measure. A single highly critical asset's compromise can have a greater impact than many non-critical assets.
- Option B is incorrect: The threat environment refers to the external landscape of potential threats. While important for risk assessment and proactive security measures, it is not the primary criterion for classifying an *already occurring* incident's characteristics or severity.
- Option C is incorrect: Maturity of incident response activities describes an organization's capability to handle incidents. While a mature program might implement more granular classification schemes, the maturity level itself does not define the fundamental criteria for *what* constitutes a specific incident class or category.
Reference: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Which of the following groups MUST be involved in developing information security procedures?
Correct Option: C
โ Option C (Correct)
Reasoning: Information security procedures detail the specific steps employees must follow to implement security policies within their daily operations. For these procedures to be practical, effective, and readily adopted, the business units that will execute them MUST be actively involved in their development. Their involvement ensures that the procedures align with actual workflows, do not create undue operational burdens, and are understood and accepted by those responsible for their execution. This collaborative approach fosters ownership and increases the likelihood of successful implementation and compliance.
โ Why the other choices are incorrect:
- Option A is incorrect: Senior management sets the strategic direction and approves information security policies. While their support is crucial, they typically do not get involved in the detailed development of operational procedures, which is a more tactical activity.
- Option B is incorrect: Internal audit is responsible for independently reviewing and evaluating the effectiveness of controls, including adherence to security procedures. Involving them in the development of procedures would compromise their independence and objectivity in later auditing these procedures.
- Option D is incorrect: The compliance department ensures that procedures meet legal, regulatory, and contractual requirements. While their input is essential for alignment with compliance obligations, they are not typically the primary group involved in drafting the operational steps of security procedures themselves. Their role is more advisory and oversight-focused from a regulatory standpoint.
Reference: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-2/how-to-write-information-security-policies-standards-and-procedures
Which of the following would serve as the BEST starting point when establishing a new security program?
Correct Option: B
When establishing a new security program, the BEST starting point is to adopt an industry framework for information security management. Frameworks like ISO 27001, NIST Cybersecurity Framework, or COBIT provide a structured, comprehensive, and systematic approach to design, implement, operate, monitor, review, maintain, and improve information security. They ensure that all critical aspects of security governance, risk management, and control implementation are considered and integrated, forming a solid foundation for the entire program.
Why the other choices are incorrect:
- A: Threat intelligence reports from reputable industry sources are incorrect: Threat intelligence is vital for understanding current threats and tailoring security controls, but it is not the foundational starting point for *establishing* the program's structure and governance. It informs risk assessments and specific control implementations once the program's framework is in place.
- C: A security control matrix from a similar organization is incorrect: While potentially useful for inspiration or benchmarking, directly adopting another organization's control matrix without understanding its specific context, risk appetite, and regulatory requirements can lead to an ineffective or misaligned security program. It lacks the foundational management structure of a framework.
- D: Published industry best practices for information security management are incorrect: Best practices offer valuable guidance and specific recommendations. However, a comprehensive *framework* (Option B) provides a more holistic, structured, and integrated approach to *managing* information security across the entire organization, encompassing governance, processes, and controls, rather than just a collection of individual best practices. Frameworks often incorporate best practices within their structure.
Reference: https://www.isaca.org/credentialing/cism/cism-resources
Which of the following is MOST influential in driving the effectiveness of an
Information security program?
Correct Option: C
โ Option C (Correct)
Reasoning: Organizational culture is the MOST influential factor in driving the effectiveness of an information security program. Culture encompasses the shared values, beliefs, attitudes, and behaviors of employees regarding security. A strong security culture ensures that policies and standards are adopted and adhered to, that security risks are understood and managed, and that security initiatives are embraced rather than resisted. Even the most robust technical controls, comprehensive policies, or sophisticated metrics will fail if the organizational culture does not foster a proactive and responsible approach to information security.
โ Why the other choices are incorrect:
- Option A is incorrect: Policies and standards are foundational documents that define expectations and requirements. However, their effectiveness is highly dependent on how well they are implemented and, more importantly, adhered to by the workforce, which is largely influenced by organizational culture.
- Option B is incorrect: Organizational risk appetite defines the level of risk an organization is willing to accept. While crucial for guiding security strategy and investments, it sets the boundaries for the program rather than directly driving its day-to-day effectiveness. A program can define its risk appetite but still be ineffective if the culture does not support mitigation efforts within those boundaries.
- Option D is incorrect: Information security metrics are vital for measuring the performance, efficiency, and effectiveness of the security program. They provide data for improvement and demonstrate value. However, metrics are indicators of effectiveness, not the direct drivers of it. A program can have excellent metrics reporting but still struggle with underlying cultural issues that prevent true security posture improvement.
Reference: https://www.isaca.org/credentialing/cism/cism-resources
During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way
to prevent future occurrences?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST relevant to establishing security baselines?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST important to the effectiveness of an information Security steering committee?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the PRIMARY purpose of implementing information security standards?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following BEST helps to identify vulnerabilities introduced by changes to an organization's technical infrastructure?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following elements of a service contract would BEST enable an organization to monitor the information security risk associated with a cloud service provider?
Premium Solution Locked
Unlock all 1001 answers & explanations
An information security manager is notified that a third- party data processor has
Incurred a breach for which it is believed customer data has been lost. The
Information security manager should FIRST?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST important consideration when developing an approach to effectively contain security incidents?
Premium Solution Locked
Unlock all 1001 answers & explanations
Of the following, who is accountable for ensuring the incident response plan is tested?
Premium Solution Locked
Unlock all 1001 answers & explanations
An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following provides the BEST input to determine the level of protection needed for an it system?
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY reason for establishing a data classification scheme is to identify:
Premium Solution Locked
Unlock all 1001 answers & explanations
What is the PRIMARY benefit of effective configuration management?
Premium Solution Locked
Unlock all 1001 answers & explanations
A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following would provide the BEST justification for the implementation of A new security solution?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST essential element of an information security program?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST effective way to improve employee engagement in security awareness training?
Premium Solution Locked
Unlock all 1001 answers & explanations
Web application firewalls (WAFs) are needed in addition to other intrusion prevention and detection technology PRIMARILY because:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following BEST enables the integration of information security governance into corporate governance?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST important consideration during the design phase of a business impact analysis (BIA)?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be an information security manager's PRIMARY focus when preparing for the rollout of a bring your own device (BYOD) program?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST effective way to increase security awareness in an organization?
Premium Solution Locked
Unlock all 1001 answers & explanations
A chief information officer (CIO) recently approved remote access from a system administrator's home as an exception to the security policy. What would be the information security manager's BEST course of action?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be of GREATEST concern to an information security manager assessing the use of generative Al by the marketing team for content creation?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following attributes is MOST important to consider when planning to adopt a recognized standard or framework for information security?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST important benefit of using a cloud access security broker when migrating to a cloud environment?
Premium Solution Locked
Unlock all 1001 answers & explanations
An organization has outsourced many application development activities to a third party that uses contract programmers extensively. Which of the following would provide the BEST assurance that the third party's contract programmers comply with the organization's security policies?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should a newly appointed information security manager do FIRST when evaluating the current incident notification and escalation processes?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following processes determines whether an event gets classified as an incident?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST effective in conveying risk information to senior management?
Premium Solution Locked
Unlock all 1001 answers & explanations
When performing vulnerability scans, the information security team finds multiple systems that do not match security configuration standards, which of the following should be done FIRST?
Premium Solution Locked
Unlock all 1001 answers & explanations
In an organization that has an established social media policy, which of the following is the BEST way to reduce the risk associated with personally identifiable Information (PII) disclosure.
Premium Solution Locked
Unlock all 1001 answers & explanations
A financial institution is planning to introduce a new service that requires the handling of customer data- Which of the following is MOST important for the information security manager to determine?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be done NEXT following senior management's decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?
Premium Solution Locked
Unlock all 1001 answers & explanations
An organization determines that an end user has clicked on a malicious link. Which of the following would MOST effectively prevent similar situations from recurring?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the GREATEST benefit of a successful Information security awareness program?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the PRIMARY reason for creating business cases for investments in information security?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is a PRIMARY reason for senior management to review reports on information security?
Premium Solution Locked
Unlock all 1001 answers & explanations
An information security manager has become aware that system administrators are not changing server administrator accounts from the default usernames. A policy has been created and approved by business managers to require these changes. Which of the following should be the information security manager's FIRST course of action?
Premium Solution Locked
Unlock all 1001 answers & explanations
What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?
Premium Solution Locked
Unlock all 1001 answers & explanations
A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST important reason to integrate nonrepudiation into the design of user authentication?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following provides the MOST assurance that a third-party hosting provider will be able to meet availability requirements?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the PRIMARY objective of the incident management recovery phase?
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY objective of timely declaration of a disaster is to:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is an information security manager's MOST important action during the third-party provider selection process?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the GREATEST challenge when developing key risk indicators (KRIs)?
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY reason to properly classify Information assets is to determine:
Premium Solution Locked
Unlock all 1001 answers & explanations
Management would like to understand the risk associated with engaging an Infrastructure-as-a-Service (IaaS) provider compared to hosting internally. Which of the following would provide the BEST method of comparing risk scenarios?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following BEST indicates ongoing senior management commitment to the organization's information security strategy?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be the PRIMARY focus for an information security manager when reviewing access controls for data stored in an off-premise cloud environment?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following BEST enables an organization to meet information security-related compliance requirements?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST useful input for an information security manager when updating the organization's security policy?
Premium Solution Locked
Unlock all 1001 answers & explanations
Within an incident response plan, which of the following MUST be done before an incident is escalated?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following roles is accountable for the protection of data?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following would BEST enable an organization to secure its business applications to better serve its remote workforce?
Premium Solution Locked
Unlock all 1001 answers & explanations
An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?
Premium Solution Locked
Unlock all 1001 answers & explanations
Management has asked the information security manager to determine criteria for rewriting the controls matrix to reduce the number of controls. Which of
the following is MOST important to consider when making this determination?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST useful input for measuring an information security program's effectiveness over time?
Premium Solution Locked
Unlock all 1001 answers & explanations
Information security controls should be designed PRIMARILY based on:
Premium Solution Locked
Unlock all 1001 answers & explanations
Planning for the implementation of an information security program is MOST effective when it:
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY purpose of the recovery phase in incident response is to:
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY goal when conducting post-incident reviews is to identify:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the MOST important reason for an information security manager to categorize the seventy of incidents?
Premium Solution Locked
Unlock all 1001 answers & explanations
Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST helpful in the development of a cost-effective information security strategy that is aligned with business requirements?
Premium Solution Locked
Unlock all 1001 answers & explanations
The PRIMARY reason for defining information asset ownership is to:
Premium Solution Locked
Unlock all 1001 answers & explanations
An Information security manager has learned that employees have been installing a public Al service application to take notes during meetings. The service is storing meeting discussions in online repositories. Which of the following is the BEST course of action?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the BEST course of action when an information security manager identifies that systems are vulnerable to emerging threats?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following should be the FIRST step in developing an information security strategy?
Premium Solution Locked
Unlock all 1001 answers & explanations
An information security manager determines that a mitigating control was not implemented because the business owner deemed it unnecessary. Which of the following would be the information security manager's BEST course of action?
Premium Solution Locked
Unlock all 1001 answers & explanations
Data classification is PRIMARILY the responsibility of:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the BEST way to evaluate the impact of threat events on an organization's IT operations?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the BEST indication of effective information security governance?
Premium Solution Locked
Unlock all 1001 answers & explanations
Biometrics are BEST used for:
Premium Solution Locked
Unlock all 1001 answers & explanations
A hacking group has posted an organization's employee data on social media. What should the information security manager do FIRST?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the BEST reason to use an offsite mirror site as part of an organization's disaster recovery strategy?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is MOST Important to consider when determining asset valuation?
Premium Solution Locked
Unlock all 1001 answers & explanations
What should an information security manager verify FIRST when reviewing an information asset management program?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which Of the following is the GREATEST benefit of performing a tabletop exercise Of the business continuity plan (BCP)?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is a prerequisite for formulating a business continuity plan (BCP)?
Premium Solution Locked
Unlock all 1001 answers & explanations
An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following is the BEST indicator of the performance of a security program?
Premium Solution Locked
Unlock all 1001 answers & explanations
Which of the following would be the GREATEST obstacle to implementing incident notification and escalation processes in an organization with high turnover?
Premium Solution Locked
Unlock all 1001 answers & explanations
When mitigation is the chosen risk treatment, which of the following roles is responsible for effective implementation of the chosen treatment?
Premium Solution Locked
Unlock all 1001 answers & explanations
In a DevSecOps environment, which of the following is the BEST way to address risk associated with vulnerabilities in application source code?
Premium Solution Locked
Unlock all 1001 answers & explanations
Full Question Bank Locked
You have reached the end of the free study guide preview. Upgrade now to unlock all 1001 questions and the full simulation engine.
Certification Path
Related Certifications
Customer Reviews
Global Community Feedback
David M.
"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."
Sarah J.
"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."
Michael C.
"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"