Courseiva

CISM Information Security Program Practice Question

A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?

⚠ Common exam trap

ISACA CISM often tests the distinction between operational/technical metrics and business/risk metrics, trapping candidates who confuse activity-based measures (e.g., training hours) with outcome-based financial justification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Estimated financial exposure from unmitigated risks.

Senior management is primarily concerned with financial impact and risk exposure. Estimated financial exposure from unmitigated risks directly translates technical vulnerabilities into monetary terms, enabling informed budget decisions. This aligns with the CISM focus on aligning security programs with business objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security incidents detected per month.

    Why it's wrong here

    Incident counts are lagging and operational, showing activity rather than avoided loss, so they do not translate into financial or risk-reduction terms executives fund. It tempts because detection volume is easy to measure, and it would suit a security operations report rather than a business case.

  • ✓

    Estimated financial exposure from unmitigated risks.

    Why this is correct

    Estimated financial exposure translates residual risk into monetary terms, the language executives use for capital allocation decisions. Senior management weighs security investment against potential loss, so quantifying unmitigated risk in financial figures directly satisfies the business-case constraint, unlike technical metrics such as vulnerability counts or control coverage percentages.

  • ✗

    Percentage of systems patched within 30 days.

    Why it's wrong here

    Patch percentage is a technical compliance measure, not a financial or risk-quantified outcome, so it does not translate into the cost-avoidance language executives use. It is tempting because it is objective and auditable, but it belongs in operational metrics reporting rather than a business case.

  • ✗

    Hours spent on security training.

    Why it's wrong here

    Training hours measure activity, not risk reduction or financial impact, so they fail to justify spend to senior management. It is tempting because training is a common control and hours are easy to log, but the metric would suit compliance reporting rather than a business case.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.