Sample questions
Certified Information Security Manager CISM practice questions
In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrenc…
A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group…
A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendation…
An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the…
A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communi…
A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best s…
After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices?…
An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)
A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?
Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable i…
A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?
Order the steps for establishing a security incident response team (IRT).
Arrange the steps for implementing a new firewall rule in an enterprise environment.
During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals.…
Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?
Order the steps for implementing a security awareness training program.
An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)
During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?
An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?
What is the PRIMARY purpose of a security champions program?
What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?
During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?