CISM Information Security Programme Practice Question
A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?
⚠ Common exam trap
CISM often tests the distinction between operational/technical detail and strategic governance-level information, so candidates who equate 'more data' with 'better reporting' pick the log or vulnerability list instead of the risk-and-KPI summary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Top security risks and key performance indicators with trends
Executive dashboards must communicate risk posture and program effectiveness at a glance, so top risks paired with KPIs and trend data give the C-suite actionable insight without operational noise. CISM emphasizes that security reporting to leadership should be business-aligned, forward-looking, and decision-supporting rather than technical. Trends show whether controls are improving or degrading, which is exactly what executives need for governance and budget decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detailed logs of all security incidents from the past week
Why it's wrong here
Raw incident logs overwhelm a one-page dashboard; executives need aggregated risk trends and business impact, not forensic detail. Logs belong in operational SIEM reporting for analyst triage. The dashboard's purpose is decision support at strategic level, so granular event data fails the audience and format constraint.
- ✗
List of all vulnerabilities found during the last scan
Why it's wrong here
A raw vulnerability list lacks business context and prioritisation, so executives cannot act on it within one page. Vulnerability enumeration suits technical remediation tracking by security engineers. Executive reporting requires risk exposure expressed in business terms, which this option does not provide.
- ✓
Top security risks and key performance indicators with trends
Why this is correct
Top risks paired with trended KPIs give executives the forward-looking, decision-grade view a one-page dashboard demands, satisfying the C-suite's need for strategic oversight rather than operational detail. Trend lines expose direction and velocity, enabling informed risk-appetite judgements, while the condensed format respects the brevity constraint the stem imposes.
- ✗
Full results of the latest phishing simulation
Why it's wrong here
Full phishing simulation results are operational metrics for awareness programme tuning, not strategic risk indicators. Executives need click-rate trends and organisational risk posture, not per-user outcomes. The detail exceeds one page and addresses the security team's concerns rather than governance decisions.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.