๐ŸŽ„

CertoMetrics - 9% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

ISACA Certified Information Security Manager (CISM)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

ISACA

Certification

Governance Risk and Security

Content

1001 Qs

Status

Verified

Updated

1 day ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$108 $69

Save $39 Instantly

  • โœ“
    Full PDF + Interactive Engine Everything you need to pass
  • โœ“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • โœ“
    Priority 24/7 Expert Support Direct line to certification leads
  • โœ“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$59

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$49

Digital Access

  • โœ“ Exam Questions (PDF)
  • โœ“ Mobile Friendly
  • โœ“ 60 Days Updates
Download Free Sample PDF

Verified 100-Question Preview (CISM)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified ISACA certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated CISM prep kit.

Exam Overview

The ISACA Certified Information Security Manager (CISM) certification is a globally recognized credential designed for experienced information security managers and those who manage, design, oversee, and assess an enterprise's information security. It validates an individual's expertise in governance, program development, risk management, and incident response, positioning them as strategic leaders capable of aligning security initiatives with business objectives. Earning your CISM demonstrates a deep understanding of the strategic aspects of information security, enhancing your credibility and career prospects in a rapidly evolving threat landscape. This certification is crucial for professionals aspiring to C-suite and senior management roles, offering a distinct advantage in today's competitive market.

Questions

150 multiple-choice questions

Passing Score

450 (on a 200-800 point scale)

Duration

240 Minutes (4 hours)

Difficulty

Expert

Level

Professional/Specialist

Skills Measured

Information Security Governance
Information Security Risk Management
Information Security Program Development
Information Security Program Operations and Management
Information Security Incident Management and Response

Career Path

Target Roles

Chief Information Security Officer (CISO) Information Security Manager Security Consultant IT Director with Security Responsibilities Security Architect (Senior

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest ISACA standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the CISM exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated CISM bank (100 Questions).

QUESTION 1

Which of the following should an information security manager do FIRST when planning to develop and implement an information security program?

A
Identify individuals for the information security team.
B
Define and document the information security strategy.
C
Obtain stakeholder consensus and buy-in.
D
Develop information security awareness training for employees.

Correct Option: B

โœ… Option B (Correct)
Reasoning: When planning to develop and implement an information security program, the absolute first step for an information security manager is to define and document the information security strategy. This strategy provides the overarching direction, objectives, and scope for the entire program, ensuring it aligns with the organization's business goals and risk appetite. Without a clear strategy, subsequent activities like team identification, obtaining buy-in, or developing training would lack proper foundation and direction.

โŒ Why the other choices are incorrect:

  • Option A is incorrect: Identifying individuals for the information security team is a staffing activity that typically follows the definition of the program's strategy and scope, as the required skills and roles depend on the strategy.
  • Option C is incorrect: Obtaining stakeholder consensus and buy-in, while critical, generally occurs after an initial strategy or proposal has been developed. Stakeholders need something concrete to review and agree upon.
  • Option D is incorrect: Developing information security awareness training for employees is an operational implementation step of the security program, which occurs much later in the process, after the strategy is defined, policies are established, and controls are being put in place.



Reference: ISACA CISM Review Manual (various editions) - Domain 1: Information Security Governance
QUESTION 2

Which of the following is the MOST critical consideration when shifting IT operations

To an infrastructure as a service (laas) model hosted in a foreign country?

A
There may be liabilities and penalties in the event of a security breach.
B
Laws and regulations of the origin country may not be applicable.
C
Labeling of data may help to ensure data is assigned to the connect cloud Type.
D
Data may be stored in unknown locations and may not be easily retrievable.

Correct Option: B

When moving IT operations to an Infrastructure as a Service (IaaS) model hosted in a foreign country, the most critical consideration is the complex legal and regulatory landscape. Laws and regulations of the origin country may have limited or no extraterritorial applicability concerning the data and operations in the foreign jurisdiction. Conversely, the foreign country's laws, including data privacy, residency, and government access laws, will directly apply. This creates significant compliance challenges and necessitates a thorough understanding of the applicable legal frameworks. Failure to do so can lead to severe legal and reputational consequences.


โŒ Why the other choices are incorrect:
  • Option A is incorrect: Liabilities and penalties in the event of a security breach are consequences that arise from a failure to comply with the relevant laws and regulations. While a critical risk, it is an outcome of not adequately addressing the underlying legal complexities (Option B).
  • Option C is incorrect: Data labeling is an important practice for data classification and governance. However, it is an internal control mechanism that aids in managing data based on its sensitivity and regulatory requirements, but it does not directly address the fundamental change in the legal jurisdiction itself.
  • Option D is incorrect: The concern that data may be stored in unknown locations and may not be easily retrievable is a valid operational and contractual risk. However, the primary reason why these locations matter in a foreign country often ties back to legal requirements (e.g., data residency, government access laws) which are part of the broader legal and regulatory considerations highlighted in Option B. Furthermore, the "unknown" aspect can be mitigated through contractual agreements; the critical issue remains the legal implications of the known locations.



Reference: https://www.isaca.org/resources/isaca-journal/issues
QUESTION 3

Which of the following BEST indicates an effective security culture?

A
Information security is seen as a key business partner and enabler.
B
Staff are encouraged by senior management to report security incidents.
C
Security standards and policies are communicated to and followed by staff.
D
Security risk is managed and maintained within acceptable levels.

Correct Option: A

โœ… Option A (Correct)

Reasoning: An effective security culture integrates information security as a strategic business partner and enabler. This indicates a mature, proactive mindset where security supports business objectives, moving beyond mere compliance to genuine organizational buy-in and ownership. It signifies that security is intrinsically valued and part of the organization's core operations.

โŒ Why the other choices are incorrect:

  • Option B is incorrect: While essential, encouraging incident reporting is an operational task and not the primary indicator of a holistic, effective security culture.
  • Option C is incorrect: Following policies demonstrates compliance, but an effective culture transcends rule-following to encompass deep understanding and valuing of security principles.
  • Option D is incorrect: Managing risk is an outcome of effective security practices. However, it describes a risk state rather than directly indicating the cultural perception and integration of security within the business.


Reference: https://www.isaca.org/credentialing/cism/cism-resources
QUESTION 4

The PRIMARY benefit of performing a risk assessment in the development of a business continuity plan (BCP) is that it facilitates an:

A
evaluation of the completeness and robustness of the current backup procedures.
B
understanding of business impact and likelihood of interruption of key processes.
C
effective mitigation strategy against interruptions of business processes.
D
evaluation of the network architecture design to determine redundancy

Correct Option: B

A risk assessment is a foundational step in developing a Business Continuity Plan (BCP). Its primary benefit is to identify potential threats and vulnerabilities that could disrupt business operations and to evaluate the potential impact and likelihood of such interruptions. This process, often involving a Business Impact Analysis (BIA) as part of the broader risk assessment, helps an organization understand which key processes are critical, what risks they face, and the consequences of their unavailability. This understanding is essential for prioritizing recovery efforts and allocating resources effectively in the BCP.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2021/volume-3/business-continuity-planning-and-risk-assessment-integrating-to-achieve-resilience

QUESTION 5

Which of the following provides the BEST indication of senior management commitment to the organization's information security strategy?

A
Adequate budget for IT projects
B
Periodic review of the security capability maturity model
C
The number of information security metrics defined.
D
Reporting of security training results

Correct Option: B

Periodic review of the security capability maturity model directly demonstrates senior management's commitment to the organization's information security strategy. A capability maturity model (CMM) provides a structured approach to assess and improve an organization's security processes and capabilities. Senior management's involvement in periodically reviewing the CMM indicates their active engagement in evaluating the effectiveness of the security program, understanding its strategic alignment, identifying areas for improvement, and making informed decisions to enhance the organization's security posture. This goes beyond mere resource allocation or operational reporting, showing a strategic commitment to continuous improvement.

Why the other choices are incorrect:

  • Adequate budget for IT projects: While crucial, an 'adequate budget for IT projects' is a general IT expenditure and does not specifically signify strategic commitment to information security strategy. It could encompass various IT initiatives without a strong security focus.
  • The number of information security metrics defined: Defining metrics is a necessary step for measurement, but the sheer 'number' of metrics does not inherently reflect senior management commitment. What matters more is how these metrics are used, reviewed, and acted upon by senior management to drive strategic security decisions.
  • Reporting of security training results: Reporting training results is an operational activity that demonstrates compliance and awareness efforts. While important, it is a tactical outcome and does not reflect the same level of strategic oversight and commitment as reviewing the overall maturity and effectiveness of the security program itself.


Reference: ISACA CISM Review Manual (latest edition) - Domain 1: Information Security Governance
QUESTION 6

Which of the following is the MOST important reason to ensure information security is Aligned with the organizationโ€™s strategy?

A
To improve security processes.
B
To optimize security risk management.
C
To identify the organizationโ€™s risk tolerance.
D
when adopting security roles and responsibilities.

Correct Option: B

The correct answer is B. To optimize security risk management.

Why this is the correct answer:

In information security frameworks (such as those from ISACA and (ISC)ยฒ), the ultimate goal of information security is to support the business. By aligning information security with the organizationโ€™s strategy, security professionals understand exactly which assets, processes, and systems are most critical to the business's success.

Understanding the business's strategic goals allows the organization to optimize security risk management by allocating budget, resources, and controls to the areas that matter most, rather than wasting resources protecting low-value assets or implementing controls that hinder business operations.

QUESTION 7

Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?

A
Quantity of impacted assets
B
Threat environment
C
Maturity of incident response activities
D
Incident impact

Correct Option: D

Option D (Correct)

Reasoning: Incident impact is the MOST appropriate consideration when defining incident classification and categorization levels because it directly determines the severity and priority of an incident. Classification based on impact (e.g., impact on confidentiality, integrity, availability, business operations, financial, reputational, legal/regulatory) allows organizations to allocate appropriate resources, trigger the right response procedures, and prioritize incidents effectively according to their potential or actual harm to the organization.

Why the other choices are incorrect:

  • Option A is incorrect: Quantity of impacted assets is a factor that contributes to the overall impact, but it is not the sole or most comprehensive measure. A single highly critical asset's compromise can have a greater impact than many non-critical assets.
  • Option B is incorrect: The threat environment refers to the external landscape of potential threats. While important for risk assessment and proactive security measures, it is not the primary criterion for classifying an *already occurring* incident's characteristics or severity.
  • Option C is incorrect: Maturity of incident response activities describes an organization's capability to handle incidents. While a mature program might implement more granular classification schemes, the maturity level itself does not define the fundamental criteria for *what* constitutes a specific incident class or category.


Reference: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
QUESTION 8

Which of the following groups MUST be involved in developing information security procedures?

A
Senior management
B
Internal audit
C
Business units
D
Compliance department

Correct Option: C

โœ… Option C (Correct)

Reasoning: Information security procedures detail the specific steps employees must follow to implement security policies within their daily operations. For these procedures to be practical, effective, and readily adopted, the business units that will execute them MUST be actively involved in their development. Their involvement ensures that the procedures align with actual workflows, do not create undue operational burdens, and are understood and accepted by those responsible for their execution. This collaborative approach fosters ownership and increases the likelihood of successful implementation and compliance.

โŒ Why the other choices are incorrect:

  • Option A is incorrect: Senior management sets the strategic direction and approves information security policies. While their support is crucial, they typically do not get involved in the detailed development of operational procedures, which is a more tactical activity.
  • Option B is incorrect: Internal audit is responsible for independently reviewing and evaluating the effectiveness of controls, including adherence to security procedures. Involving them in the development of procedures would compromise their independence and objectivity in later auditing these procedures.
  • Option D is incorrect: The compliance department ensures that procedures meet legal, regulatory, and contractual requirements. While their input is essential for alignment with compliance obligations, they are not typically the primary group involved in drafting the operational steps of security procedures themselves. Their role is more advisory and oversight-focused from a regulatory standpoint.


Reference: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-2/how-to-write-information-security-policies-standards-and-procedures
QUESTION 9

Which of the following would serve as the BEST starting point when establishing a new security program?

A
Threat intelligence reports from reputable industry sources
B
An industry framework for information security management
C
A security control matrix from a similar organization
D
Published industry best practices for information security management.

Correct Option: B

When establishing a new security program, the BEST starting point is to adopt an industry framework for information security management. Frameworks like ISO 27001, NIST Cybersecurity Framework, or COBIT provide a structured, comprehensive, and systematic approach to design, implement, operate, monitor, review, maintain, and improve information security. They ensure that all critical aspects of security governance, risk management, and control implementation are considered and integrated, forming a solid foundation for the entire program.

Why the other choices are incorrect:

  • A: Threat intelligence reports from reputable industry sources are incorrect: Threat intelligence is vital for understanding current threats and tailoring security controls, but it is not the foundational starting point for *establishing* the program's structure and governance. It informs risk assessments and specific control implementations once the program's framework is in place.
  • C: A security control matrix from a similar organization is incorrect: While potentially useful for inspiration or benchmarking, directly adopting another organization's control matrix without understanding its specific context, risk appetite, and regulatory requirements can lead to an ineffective or misaligned security program. It lacks the foundational management structure of a framework.
  • D: Published industry best practices for information security management are incorrect: Best practices offer valuable guidance and specific recommendations. However, a comprehensive *framework* (Option B) provides a more holistic, structured, and integrated approach to *managing* information security across the entire organization, encompassing governance, processes, and controls, rather than just a collection of individual best practices. Frameworks often incorporate best practices within their structure.


Reference: https://www.isaca.org/credentialing/cism/cism-resources
QUESTION 10

Which of the following is MOST influential in driving the effectiveness of an

Information security program?

A
Policies and standards.
B
Organizational risk appetite.
C
Organizational culture.
D
Information security metrics.

Correct Option: C

โœ… Option C (Correct)

Reasoning: Organizational culture is the MOST influential factor in driving the effectiveness of an information security program. Culture encompasses the shared values, beliefs, attitudes, and behaviors of employees regarding security. A strong security culture ensures that policies and standards are adopted and adhered to, that security risks are understood and managed, and that security initiatives are embraced rather than resisted. Even the most robust technical controls, comprehensive policies, or sophisticated metrics will fail if the organizational culture does not foster a proactive and responsible approach to information security.

โŒ Why the other choices are incorrect:

  • Option A is incorrect: Policies and standards are foundational documents that define expectations and requirements. However, their effectiveness is highly dependent on how well they are implemented and, more importantly, adhered to by the workforce, which is largely influenced by organizational culture.
  • Option B is incorrect: Organizational risk appetite defines the level of risk an organization is willing to accept. While crucial for guiding security strategy and investments, it sets the boundaries for the program rather than directly driving its day-to-day effectiveness. A program can define its risk appetite but still be ineffective if the culture does not support mitigation efforts within those boundaries.
  • Option D is incorrect: Information security metrics are vital for measuring the performance, efficiency, and effectiveness of the security program. They provide data for improvement and demonstrate value. However, metrics are indicators of effectiveness, not the direct drivers of it. A program can have excellent metrics reporting but still struggle with underlying cultural issues that prevent true security posture improvement.


Reference: https://www.isaca.org/credentialing/cism/cism-resources
QUESTION 11

During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way

to prevent future occurrences?

A
Updating configuration baselines
B
Conducting periodic vulnerability scanning
C
Providing annual information security awareness training
D
Implementing a strict change control process

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 12

Which of the following is MOST relevant to establishing security baselines?

A
Procedures
B
Guidelines
C
Policies
D
Standards

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 13

Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?

A
Root cause analysis
B
Computer forensics
C
Continuous log monitoring
D
Penetration testing

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 14

Which of the following is MOST important to the effectiveness of an information Security steering committee?

A
The committee has strong regulatory knowledge.
B
The committee is comprised of representatives from senior management.
C
The committee uses a risk management framework.
D
The committee has cross-organizational representation.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 15

Which of the following is the PRIMARY purpose of implementing information security standards?

A
To provide management direction with a specific security objective
B
To provide step-by-step instructions for performing security-related tasks
C
To provide a basis for developing information security policies
D
To establish a minimum acceptable security baseline

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 16

Which of the following BEST helps to identify vulnerabilities introduced by changes to an organization's technical infrastructure?

A
Threat analysis
B
Penetration testing
C
Established security baselines
D
An intrusion detection system (IDS)

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 17

Which of the following elements of a service contract would BEST enable an organization to monitor the information security risk associated with a cloud service provider?

A
Compliance status reporting
B
Breach detection and notification
C
Indemnification clause
D
Physical access to service provider premises

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 18

An information security manager is notified that a third- party data processor has

Incurred a breach for which it is believed customer data has been lost. The

Information security manager should FIRST?

A
Notify law enforcement.
B
Request details of the incident.
C
Prevent further transfers to the third party.
D
alert affected customers.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 19

Which of the following is the MOST important consideration when developing an approach to effectively contain security incidents?

A
Assigning senior management accountability for incident containment
B
Isolating systems impacted by incidents from the production environment
C
Minimizing financial losses that may result from outages
D
Mitigating reputational damage that may affect business

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 20

Of the following, who is accountable for ensuring the incident response plan is tested?

A
Business continuity manager
B
Incident response team members
C
Information security manager
D
Business process owner

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 21

An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?

A
Employees use the VPN when accessing the organization's online resources.
B
Employees are trained on the acceptable use policy.
C
Employees use smartphone tethering when accessing from remote locations.
D
Employees physically lock PCs when leaving the immediate area.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 22

Which of the following provides the BEST input to determine the level of protection needed for an it system?

A
Asset classification.
B
Threat analysis.
C
Internal audit findings
D
Vulnerability assessment.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 23

The PRIMARY reason for establishing a data classification scheme is to identify:

A
data-retention strategy.
B
recovery priorities,
C
appropriate controls.
D
data ownership,

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 24

What is the PRIMARY benefit of effective configuration management?

A
Reduced incident frequency
B
Reduced management cost
C
Decreased risk to the organization's systems
D
Improved patch management process

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 25

A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?

A
To gain an understanding of the current business direction
B
To update in accordance with the best business practices
C
To perform a risk assessment of the current IT environment
D
To assess corporate culture

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 26

Which of the following would provide the BEST justification for the implementation of A new security solution?

 

 

A
Internal audit results.
B
Incident management reports.
C
Risk analysis report.
D
Business case.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 27

Which of the following is the MOST essential element of an information security program?

A
Prioritizing program deliverables based on available resources
B
Applying project management practices used by the business
C
Involving functional managers in program development
D
Benchmarking the program with global standards for relevance

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 28

Which of the following is the MOST effective way to improve employee engagement in security awareness training?

A
Requiring annual training with standardized security policies
B
Conducting periodic security webinars
C
Requiring employees to sign an acknowledgment form for training completion
D
Rewarding employees for successful detection of phishing emails

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 29

Web application firewalls (WAFs) are needed in addition to other intrusion prevention and detection technology PRIMARILY because:

A
they prevent modification of application source code.
B
web services require unique forensic evidence.
C
they recognize web application protocols.
D
web service logs are more difficult to analyze.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 30

Which of the following BEST enables the integration of information security governance into corporate governance?

A
An information security steering committee with business representation
B
Clear lines of authority across the organization
C
Well-documented information security policies and standards
D
Senior management approval of the information security strategy

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 31

Which of the following is the MOST important consideration during the design phase of a business impact analysis (BIA)?

A
Selecting quality metrics to monitor business performance
B
Obtaining reserve funding to prepare for possible business failures
C
Estimating the likelihood that end-to-end processes will be disrupted
D
Identifying critical functions for business operations

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 32

Which of the following should be an information security manager's PRIMARY focus when preparing for the rollout of a bring your own device (BYOD) program?

A
Documenting BYOD policy and procedures
B
Benchmarking BYOD incidents within the industry
C
Performing a risk assessment
D
Selecting a mobile device management (MDM) solution

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 33

Which of the following is the MOST effective way to increase security awareness in an organization?

A
Conduct periodic simulated phishing exercises.
B
Implement regularly scheduled information security audits.
C
Include information security requirements in job descriptions.
D
Require signed acknowledgment of information security policies.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 34

A chief information officer (CIO) recently approved remote access from a system administrator's home as an exception to the security policy. What would be the information security manager's BEST course of action?

A
Ensure the system administrator is aware of the risks and monitor remote access.
B
Review the policy on remote access security and recommend changes.
C
Register a formal security incident and escalate to the steering committee.
D
Inform management of the risks involved and disable the administrator's access.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 35

Which of the following should be of GREATEST concern to an information security manager assessing the use of generative Al by the marketing team for content creation?

A
Lack of logging capabilities for generative Al platforms
B
Increased use of generative Al for internal marketing research and non-confidential activities
C
Exposure of sensitive corporate marketing data on generative Al platforms
D
Use of corporate email addresses by the marketing team to register for generative Al services

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 36

Which of the following attributes is MOST important to consider when planning to adopt a recognized standard or framework for information security?

A
Ability to measure and compare
B
Applicability to the organization's needs
C
Cost-benefit of implementation
D
Ease of organization-wide implementation

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 37

Which of the following is the MOST important benefit of using a cloud access security broker when migrating to a cloud environment?

A
Increased third-party assurance.
B
Reduced total cost of ownership (TCO)
C
Enhanced data governance
D
Improved incident management

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 38

An organization has outsourced many application development activities to a third party that uses contract programmers extensively. Which of the following would provide the BEST assurance that the third party's contract programmers comply with the organization's security policies?

A
Perform periodic security assessments of the contractors' activities.
B
Include penalties for noncompliance in the contracting agreement.
C
Conduct periodic vulnerability scans of the application.
D
Require annual signed agreements of adherence to security policies.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 39

Which of the following should a newly appointed information security manager do FIRST when evaluating the current incident notification and escalation processes?

A
Test current incident-related communications plans.
B
Review findings from recent security incidents.
C
Verify industry best practices are incorporated into processes.
D
Interview key incident response stakeholders.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 40

Which of the following processes determines whether an event gets classified as an incident?

A
Business impact analysis (BIA)
B
End-user reporting
C
Triage
D
Threat intelligence reviews

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 41

Which of the following is MOST effective in conveying risk information to senior management?

A
Industry risk report
B
Risk register
C
Balanced scorecard
D
Risk heat map

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 42

When performing vulnerability scans, the information security team finds multiple systems that do not match security configuration standards, which of the following should be done FIRST?

A
Take the systems offline.
B
Discuss the noncompliance with senior management,
C
Determine the level of risk
D
Execute a policy exception for the violation.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 43

In an organization that has an established social media policy, which of the following is the BEST way to reduce the risk associated with personally identifiable Information (PII) disclosure.

A
Delivering regular training to employees about social media usage
B
Monitoring employees' social media usage for confidential content
C
Controlling access to PII within the organization
D
Blocking social media Sites on the corporate network

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 44

A financial institution is planning to introduce a new service that requires the handling of customer data- Which of the following is MOST important for the information security manager to determine?

A
Risk and data privacy reporting requirements for the board
B
Legal and regulatory requirements related to the types of data to be processed
C
Project funding availability to support information security needs
D
Adequacy of infrastructure and technical controls to protect customer information

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 45

Which of the following should be done NEXT following senior management's decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?

A
Create and implement a data minimization plan.
B
Conduct a gap analysis.
C
Encrypt data in transit and at rest.
D
Complete a return on investment (ROI) analysis.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 46

An organization determines that an end user has clicked on a malicious link. Which of the following would MOST effectively prevent similar situations from recurring?

A
End-user training
B
Disabling macros
C
Application allow listing
D
End-user behavior analytics

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 47

Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?

A
Communicate and enforce security policies
B
Conduct security awareness programs
C
El Document and distribute security procedures
D
Adhere to regulatory requirements

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 48

Which of the following is the GREATEST benefit of a successful Information security awareness program?

A
Employees know to inform regulators when internal fraud is identified,
B
Employees understand the consequences of disclosing confidential information.
C
Employees embrace the objectives of security governance.
D
Employees learn to identify significant risks that may be difficult to detect.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 49

Which of the following is the PRIMARY reason for creating business cases for investments in information security?

A
To demonstrate value to the business
B
To meet business compliance requirements
C
To define business asset criticality
D
To reduce the level of business risk

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 50

Which of the following is a PRIMARY reason for senior management to review reports on information security?

A
To ensure security risk is managed cost-effectively
B
To assess the effectiveness of the security program
C
To ensure adequate security resources are available
D
To confirm security audits are regularly performed

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 51

An information security manager has become aware that system administrators are not changing server administrator accounts from the default usernames. A policy has been created and approved by business managers to require these changes. Which of the following should be the information security manager's FIRST course of action?

A
Include the requirement in information security awareness materials.
B
Ensure the policy has been communicated to the system administrators,
C
Require system administrators to sign off on the policy.
D
Perform a policy compliance assessment

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 52

What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?

A
Introduce additional controls to force compliance with policy.
B
Require department users to repeat security awareness training.
C
Report the policy violation to senior management.
D
Perform a vulnerability assessment on the systems within the department.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 53

A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:

A
an increased risk profile.
B
a vulnerability management failure.
C
an increased threat profile.
D
a security control failure.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 54

Which of the following is the MOST important reason to integrate nonrepudiation into the design of user authentication?

A
To ensure actions can be traced to specific users
B
To ensure users cannot escalate their own access privileges
C
To ensure users cannot alter log records within the system
D
To ensure there are no conflicts when changing database records

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 55

Which of the following provides the MOST assurance that a third-party hosting provider will be able to meet availability requirements?

A
Right-to-audit clause
B
The third party's incident response plan
C
Service level agreement (SLA)
D
The third party's business continuity plan (BCP)

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 56

Which of the following is the PRIMARY objective of the incident management recovery phase?

A
To document actions taken to restore IT systems
B
To bring IT services back online
C
To perform a lessons-learned review
D
To recover business operation support

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 57

The PRIMARY objective of timely declaration of a disaster is to:

A
ensure the continuity of the organization's essential services.
B
ensure engagement of business management in the recovery process.
C
assess and correct disaster recovery process deficiencies.
D
protect critical physical assets from further loss.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 58

Which of the following is an information security manager's MOST important action during the third-party provider selection process?

A
Consulting with the third party's clients
B
Determining if the third party is sufficiently staffed
C
Analyzing the third party's existing control environment
D
Performing a network penetration test

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 59

Which of the following is the GREATEST challenge when developing key risk indicators (KRIs)?

A
Aggregating common KRIS
B
Limiting the number of KRIS
C
Comprehensively reporting on KRIS
D
Linking KRIs to specific risks

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 60

The PRIMARY reason to properly classify Information assets is to determine:

A
the appropriate protection based on sensitivity
B
appropriate encryption strength using a risk-based approach.
C
user access levels based on the need to know
D
the business impact if assets are compromised.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 61

Management would like to understand the risk associated with engaging an Infrastructure-as-a-Service (IaaS) provider compared to hosting internally. Which of the following would provide the BEST method of comparing risk scenarios?

A
Reviewing mitigating and compensating controls for each risk scenario.
B
Performing a risk assessment on the IaaS provider.
C
Mapping risk scenarios according to sensitivity of data
D
Mapping the risk scenarios by likelihood and impact on a chart.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 62

Which of the following BEST indicates ongoing senior management commitment to the organization's information security strategy?

A
An efficient incident response program
B
Adequate funding for the information security program
C
Established key performance indicators (KPIs)
D
A comprehensive security awareness training program

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 63

Which of the following should be the PRIMARY focus for an information security manager when reviewing access controls for data stored in an off-premise cloud environment?

A
Reviewing and updating access controls in response to changes in organizational structure
B
Ensuring access is granted to only those individuals whose job functions require it
C
Implementing strong encryption protocols to protect sensitive data
D
Implementing strong password policies and enforcing regular password changes

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 64

Which of the following BEST enables an organization to meet information security-related compliance requirements?

A
Assigning accountability for security compliance to the chief information security officer (CISO)
B
Ensuring the internal audit function includes compliance audits in the annual security audit plan
C
Including compliance requirements as an agenda item in senior management and board meetings
D
Considering compliance requirements when developing the organization's security program

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 65

Which of the following is the MOST useful input for an information security manager when updating the organization's security policy?

A
Security team capabilities
B
Vulnerability scan
C
Risk appetite
D
Industry best practices

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 66

Within an incident response plan, which of the following MUST be done before an incident is escalated?

A
Quantify the financial impact of the incident.
B
Determine the severity of the incident,
C
Quantify the risk associated with the incident.
D
Determine the root cause of the incident.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 67

Which of the following roles is accountable for the protection of data?

A
Data custodian
B
Data administrator
C
CISO
D
Data owner

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 68

Which of the following would BEST enable an organization to secure its business applications to better serve its remote workforce?

A
Enterprise architecture (EA)
B
Industry benchmarks
C
Zero Trust Architecture (ZTA)
D
Secure web gateways

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 69

An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?

A
A business case for transferring the risk.
B
A noncompliance report to initiate remediation activities.
C
Control owner responses based on a root cause analysis.
D
The impact of noncompliance on the organization's risk profile.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 70

Management has asked the information security manager to determine criteria for rewriting the controls matrix to reduce the number of controls. Which of

the following is MOST important to consider when making this determination?

A
Legal compliance
B
Industry best practice
C
Business continuity
D
Organizational structure

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 71

Which of the following is the MOST useful input for measuring an information security program's effectiveness over time?

A
Monthly vulnerability scan reports
B
Key risk indicators (KRIS)
C
Key performance indicators (KPIs)
D
SPeriodic independent audit results

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 72

Information security controls should be designed PRIMARILY based on:

A
a vulnerability assessment
B
business risk scenarios.
C
a business impact analysis (BIA).
D
regulatory requirements.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 73

Planning for the implementation of an information security program is MOST effective when it:

A
prioritizes technology-driven solutions.
B
applies gap analysis to current and future business plans.
C
uses risk-based analysis for security projects.
D
uses decision trees to prioritize security projects.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 74

The PRIMARY purpose of the recovery phase in incident response is to:

A
identify and remove the root cause of an incident.
B
restore services to the point defined in the leading industry control framework.
C
identify and document the lessons learned from an incident.
D
restore services to the point defined in the organization's business continuity plan (BCP).

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 75

The PRIMARY goal when conducting post-incident reviews is to identify:

A
individuals that need additional training.
B
information to be shared with senior management,
C
weaknesses in incident response plans.
D
additional cybersecurity budget needs.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 76

Which of the following is the MOST important reason for an information security manager to categorize the seventy of incidents?

A
To prioritize incidents for legal actions and senior management involvement
B
To identify root causes and vulnerabilities of incidents in the organization's network infrastructure
C
To determine the need for post-incident audits and compliance checks
D
To prioritize the allocation of resources, team composition, and communication strategies

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 77

Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?

A
Internal auditor
B
IT risk manager
C
Risk owner
D
Information security manager

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 78

Which of the following is MOST helpful in the development of a cost-effective information security strategy that is aligned with business requirements?

A
Developing policy standards
B
Enforcing data retention
C
Benchmarking against industry peers
D
Categorizing information assets

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 79

The PRIMARY reason for defining information asset ownership is to:

A
provide guidance on information handling.
B
associate appropriate control costs with critical assets.
C
provide the authority to define and enforce security policies.
D
create accountability for information asset protection,

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 80

An Information security manager has learned that employees have been installing a public Al service application to take notes during meetings. The service is storing meeting discussions in online repositories. Which of the following is the BEST course of action?

A
Convene the incident response team.
B
Report the issue to management
C
Block access to the application.
D
Perform a risk assessment on the application.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 81

Which of the following is the BEST course of action when an information security manager identifies that systems are vulnerable to emerging threats?

A
Frequently update systems and monitor the threat landscape.
B
Notify senior management and key stakeholders of the threats.
C
Monitor the network containing the affected systems for malicious traffic.
D
Increase awareness of the threats among employees who work with the systems.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 82

Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?

A
Risk register
B
Information security policy
C
Control matrix
D
Business impact analysis (BIA)

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 83

Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?

A
Key risk indicators (KRIS)
B
Risk register
C
Security strategy
D
Program metrics

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 84

Which of the following should be the FIRST step in developing an information security strategy?

A
Perform a gap analysis based on the current state.
B
Create a roadmap to identify security baselines and controls.
C
Identify key stakeholders to champion information security
D
Determine acceptable levels of information security risk.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 85

An information security manager determines that a mitigating control was not implemented because the business owner deemed it unnecessary. Which of the following would be the information security manager's BEST course of action?

A
Obtain formal acceptance of the risk.
B
Modify the policy to address exceptions.
C
Create a project plan for the business owner.
D
Document the lack of control application and close the case.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 86

Data classification is PRIMARILY the responsibility of:

A
the data owner.
B
the data custodian.
C
the security manager.
D
senior management,

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 87

Which of the following is the BEST way to evaluate the impact of threat events on an organization's IT operations?

A
Industry benchmarking
B
Controls review
C
Risk assessment
D
Penetration testing

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 88

Which of the following is the BEST indication of effective information security governance?

A
Information security is integrated into organizational processes.
B
Comprehensive security policies reflect organizational objectives.
C
An information security risk register is maintained.
D
The information security program follows industry best practices.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 89

Biometrics are BEST used for:

A
authorization.
B
authentication.
C
accounting.
D
auditing

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 90

A hacking group has posted an organization's employee data on social media. What should the information security manager do FIRST?

A
Escalate to senior management.
B
Inform the impacted employees.
C
Initiate the incident response process.
D
Engage a forensic analysis team,

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 91

Which of the following is the BEST reason to use an offsite mirror site as part of an organization's disaster recovery strategy?

A
To maintain the integrity of data processed in the applications
B
To restore applications and data quickly after a disaster
C
To prevent unauthorized changes made to information in the applications
D
To ensure recovery of applications and data processing after a disaster

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 92

Which of the following is MOST Important to consider when determining asset valuation?

A
Asset recovery cost
B
Potential business loss
C
Cost of insurance premiums
D
Asset classification level

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 93

What should an information security manager verify FIRST when reviewing an information asset management program?

A
Information assets have been classified.
B
Key applications have been secured.
C
Information assets have been inventoried.
D
System owners have been identified.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 94

Which Of the following is the GREATEST benefit of performing a tabletop exercise Of the business continuity plan (BCP)?

A
It identifies appropriate follow-up work to address shortcomings in the plan.
B
It provides a low-cost method of assessing the BCP's completeness.
C
It helps in assessing the availability of compatible backup hardware.
D
It allows for greater participation and planning from the business side,

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 95

Which of the following is a prerequisite for formulating a business continuity plan (BCP)?

A
Comprehensive property inventory
B
System recovery procedures for alternate-site processing
C
Process maps for production applications
D
Recovery time objectives (RTOs) for the business processes

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 96

An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:

A
the regulatory requirement conflicts with business requirements.
B
the risk of noncompliance exceeds the organization's risk appetite.
C
employees are resistant to the controls required by the new regulation.
D
the cost of complying with the regulation exceeds the potential penalties.

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 97

Which of the following is the BEST indicator of the performance of a security program?

A
Changes in the maturity level
B
Changes in return on investments (ROIs)
C
Changes in security training attendance
D
Changes in budget allocation

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 98

Which of the following would be the GREATEST obstacle to implementing incident notification and escalation processes in an organization with high turnover?

A
Lack of alignment with organizational goals
B
Lack of process documentation
C
Lack of communication processes
D
Lack of knowledgeable personnel

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 99

When mitigation is the chosen risk treatment, which of the following roles is responsible for effective implementation of the chosen treatment?

A
Risk owner
B
Application owner
C
Business system owner
D
Control owner

Premium Solution Locked

Unlock all 1001 answers & explanations

QUESTION 100

In a DevSecOps environment, which of the following is the BEST way to address risk associated with vulnerabilities in application source code?

A
Integrating security testing requirements into the pipeline
B
Outsourcing application security testing to a third party
C
Conducting a comprehensive security assessment
D
Enhancing network security controls at the perimeter

Premium Solution Locked

Unlock all 1001 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 1001 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

> Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

> Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat โ— Active Now

๐Ÿ‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting