Courseiva

Certified Information Security Manager CISM (CISM) — Questions 1–75

924 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
Multi-Selectmedium

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Select 3 answers
A.Employee's years of service
B.Employee role and job function
C.Past phishing click rate trends
D.Number of security incidents in the past year
E.Current threat landscape and prevalent attack types
AnswersB, C, E

Role and job function determine exposure to targeted attacks, such as finance staff facing invoice fraud or executives facing spear phishing. Tailoring simulation difficulty by function ensures relevance and avoids over-testing low-risk roles, satisfying the stem's design factor requirement.

Why this answer

Option B (Employee role and job function) is correct because employees in finance, HR, or executive roles face different phishing lures and risk levels, so simulations should be tailored to the specific threats and responsibilities of each role. Option C (Past phishing click rate trends) is correct because historical click-rate data reveals which users or departments are most susceptible, allowing frequency and difficulty to be adjusted upward or downward based on demonstrated performance. Option E (Current threat landscape and prevalent attack types) is correct because simulations must reflect real-world tactics such as credential harvesting, QR-code phishing, or business email compromise that are actively trending, ensuring training stays relevant.

Option A (Employee's years of service) is not a reliable indicator of phishing susceptibility, since tenure does not correlate consistently with security awareness or behavior. Option D (Number of security incidents in the past year) is too broad and lagging an indicator; it does not directly inform the design of phishing simulation frequency or difficulty the way role, click trends, and threat landscape do.

2
MCQmedium

After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?

A.Re-assess the risk using a different methodology
B.Lower the risk tolerance to match the residual risk
C.Seek management approval for acceptance or implement additional controls
D.Ignore the residual risk since controls are already in place
AnswerC

Residual risk above tolerance cannot simply be left; the risk owner must decide. Either obtain formal management approval to accept the elevated exposure or apply further controls to bring it within tolerance, preserving accountability and documented risk ownership.

Why this answer

When residual risk exceeds the established risk tolerance, the organization must either implement additional controls to reduce the risk further or formally accept the residual risk through management approval. This aligns with the risk treatment decision-making process in ISO 31000 and the CISM framework, where risk acceptance is a management responsibility. Option C correctly identifies these two valid paths.

Exam trap

The CISM exam often tests the misconception that risk assessment methodology changes can resolve residual risk issues, but the trap here is that candidates may choose Option A, thinking a different methodology will yield a more favorable result, when in fact the correct action is to treat the risk through additional controls or formal acceptance.

How to eliminate wrong answers

Option A is wrong because re-assessing with a different methodology does not change the actual risk level; it only changes the measurement, which is a form of risk avoidance through redefinition rather than proper treatment. Option B is wrong because lowering the risk tolerance to match the residual risk is a reactive and inappropriate response that undermines the risk appetite set by the organization; risk tolerance should drive control decisions, not be adjusted to fit uncontrolled risk. Option D is wrong because ignoring residual risk violates the fundamental principle of risk management that requires continuous monitoring and response when risk exceeds tolerance; controls do not absolve the organization from addressing unacceptable residual risk.

3
MCQmedium

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

A.To avoid the need for a chain of custody
B.To ensure the firm understands the organization's IT environment
C.To guarantee lower costs
D.To reduce the time needed to engage the firm when an incident occurs
AnswerD

A retainer pre-negotiates rates, scope and contact details with the forensic firm, so engagement begins immediately when an incident strikes rather than after procurement and contracting delays. This directly reduces the time to engage, preserving volatile evidence.

Why this answer

Having a pre-negotiated contract reduces the time to engage forensic experts, which is critical during an incident.

4
MCQmedium

During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?

A.Conduct a security awareness training for the target company's employees.
B.Perform a comprehensive risk assessment of the target company's security posture.
C.Align the target company's security policies with the acquirer's policies.
D.Implement the acquirer's security governance framework immediately.
AnswerB

Without a formal governance framework, the CISO cannot know what controls, gaps or exposures exist. A comprehensive risk assessment of the target's security posture establishes that baseline, informing subsequent governance design, policy alignment and remediation priorities.

Why this answer

Without a formal security governance structure, the CISO must first understand the target company's current security posture through a comprehensive risk assessment. This step identifies vulnerabilities, threats, and gaps in controls, providing the baseline data needed to prioritize integration efforts and align with the acquirer's governance framework. Skipping this assessment risks implementing policies that are irrelevant or ineffective against the target's actual risks.

Exam trap

ISACA often tests the principle that governance integration must begin with understanding the current state (risk assessment) rather than jumping to policy alignment or implementation, which is a common mistake candidates make by assuming immediate enforcement is the first step.

How to eliminate wrong answers

Option A is wrong because conducting security awareness training before understanding the target's risk profile and existing security gaps is premature; training should be tailored to identified risks and policies, not implemented in a vacuum. Option C is wrong because aligning security policies without first assessing the target's current state can result in policies that conflict with existing technical controls or fail to address critical vulnerabilities. Option D is wrong because immediately implementing the acquirer's governance framework without a risk assessment may disrupt operations, miss unknown threats, and create resistance due to lack of contextual understanding.

5
MCQhard

An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?

A.A KRI is always a lagging indicator of past incidents.
B.A KRI is reported only to the board, while a KPI is reported to management.
C.A KRI measures how well security processes are performing against targets.
D.A KRI provides early warning of increasing risk exposure.
AnswerD

A key risk indicator is a forward-looking metric that signals rising risk before it materializes into incidents. It helps the organization anticipate and mitigate threats. Unlike a KPI, which measures performance against objectives, a KRI tracks conditions that could lead to loss, such as increasing vulnerability counts or growing third-party exposure.

Why this answer

A key risk indicator is forward-looking, providing early warning of increasing risk exposure so leadership can act before incidents occur. A key performance indicator measures how well processes meet targets. The CISO should use KRIs to anticipate risk and KPIs to assess operational effectiveness, ensuring the metrics program supports proactive risk management.

Exam trap

The trap here is equating KRIs with performance measurement, when their defining purpose is predictive risk warning rather than process efficiency.

6
MCQeasy

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

A.Outsource incident response to a managed security service provider (MSSP).
B.Create a dedicated incident response team that reports directly to the CISO.
C.Purchase a new SIEM solution to improve detection accuracy.
D.Develop a detailed incident response coordination plan with defined roles and communication channels, and conduct quarterly joint exercises.
AnswerD

Cross-department coordination gaps, not detection, caused containment delays. A coordination plan assigns explicit roles and communication channels across IT, legal and public affairs, while quarterly joint exercises rehearse them. This directly fixes the procedural void at minimal cost, satisfying leadership's quick, low-budget constraint.

Why this answer

The gap identified in the tabletop exercise is coordination, not detection or tooling, so the fix must address cross-department roles and communication. Developing a formal coordination plan with defined roles and quarterly joint exercises directly closes that gap at low cost, since it leverages existing staff and processes rather than new technology.

Exam trap

CISM often tests the principle that people and process gaps require people and process solutions, so candidates who jump to technology purchases (SIEM, MSSP) miss that the scenario explicitly says detection is already strong.

How to eliminate wrong answers

Option A is wrong because outsourcing to an MSSP does not fix internal coordination between IT, legal, and public affairs, and it adds recurring cost contrary to the minimal-budget constraint. Option B is wrong because a dedicated IR team reporting to the CISO still doesn't establish the cross-department communication channels and roles that the exercise showed were missing. Option C is wrong because the scenario explicitly states detection capabilities are strong, so a new SIEM addresses a problem that doesn't exist and incurs significant cost.

7
Multi-Selectmedium

A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)

Select 2 answers
A.Defined roles, responsibilities, and accountability for information security across business and technology functions.
B.A complete inventory of every software licence held by the engineering department.
C.A consolidated list of the personal mobile devices used by the sales team.
D.A marketing plan describing how security certifications will be promoted to prospective customers.
E.A risk management process that identifies, evaluates, and treats information security risk in line with the organization's risk appetite.
AnswersA, E

Clear ownership and accountability are essential because security obligations span business units, engineering, legal, and operations. Assigning responsibility ensures controls are implemented and maintained rather than assumed, enables escalation, and supports the segregation of duties that auditors and regulators expect from a growing fintech.

Why this answer

Programme scope must cover both governance and risk disciplines. A risk management process translates business context into prioritized protection decisions, while defined roles and accountability ensure those decisions are executed and sustained across functions. Licence lists, marketing plans, and device inventories are useful operational details but are not defining components of programme scope.

Exam trap

The trap here is selecting tangible operational inventories as programme components instead of the governance and risk elements that actually define programme scope.

8
MCQmedium

A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?

A.The specific malware family or attacker tooling identified during initial triage
B.The number of failed login attempts recorded before the successful breach
C.The potential business impact and regulatory notification obligations arising from the exposed records
D.The elapsed time between the first alert and the analyst's acknowledgment of the ticket
AnswerC

Severity classification must reflect the business impact, including regulatory, financial, and reputational consequences. Exposure of payment card data triggers mandatory notification and potential fines under PCI DSS and privacy regulations. CISM emphasizes that incident prioritization is driven by impact to the organization, not by technical metrics alone, making this the primary factor for assigning severity.

Why this answer

Severity levels exist to drive escalation, resource allocation, and executive notification. The determinant must be the consequence to the business, including legal and regulatory exposure. With confirmed unauthorized access to payment card data, notification obligations and financial impact are concrete and significant.

Technical indicators such as failed logins, malware family, or acknowledgment time inform response but do not define the severity of the incident.

Exam trap

The trap here is assuming that technical indicators like malware type or failed login counts determine severity, when severity must be driven by business and regulatory impact.

9
MCQmedium

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

A.Notifying law enforcement and regulatory bodies immediately.
B.Directly managing the technical containment and eradication of the threat.
C.Making strategic decisions, managing communications, and allocating resources.
D.Performing forensic analysis to identify the root cause of the incident.
AnswerC

Strategic decisions, communications and resource allocation sit with the crisis management team, which handles business-level direction rather than technical containment. This satisfies the stem's P1 constraint: the CMT's mandate is enterprise-wide impact and stakeholder messaging, while the incident response team performs tactical containment and eradication.

Why this answer

The CMT handles strategic decisions, communication, and resource allocation, while the IR team focuses on technical response.

10
Multi-Selecthard

A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)

Select 2 answers
A.They remain static over time.
B.They are aligned with business objectives.
C.They are actionable and lead to decisions.
D.They are based on data that is easy to collect.
E.They are expressed in technical jargon.
AnswersB, C

Metrics aligned with business objectives ensure that security efforts support organizational goals and are relevant to executive management. They provide meaningful insights into how security contributes to business success, enabling informed decision-making. This alignment is a key characteristic of effective metrics.

Why this answer

Effective security metrics are aligned with business objectives and are actionable, leading to decisions. These characteristics ensure that metrics are relevant to executive management and support strategic oversight. Other traits, such as ease of collection or technical jargon, do not guarantee effectiveness.

Exam trap

The trap here is equating ease of data collection or technical detail with metric effectiveness, but alignment and actionability are what make metrics valuable.

11
MCQmedium

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

A.Vendor's annual revenue
B.Length of business relationship
C.Contract value
D.Type of data accessed and service criticality
AnswerD

Tiering by data type and service criticality reflects actual risk exposure: sensitive data or business-critical services warrant deeper due diligence, contractual controls and monitoring. This risk-based axis directs limited TPRM effort proportionately, rather than treating all vendors identically.

Why this answer

The tier of a vendor in a TPRM program should be primarily determined by the type of data the vendor accesses and the criticality of the service they provide. These factors directly impact the organization's risk exposure and regulatory compliance obligations. Revenue, relationship length, and contract value do not necessarily correlate with risk.

Exam trap

CISM often tests the misconception that financial metrics (revenue, contract value) determine vendor risk; candidates must focus on data sensitivity and service criticality as the primary drivers.

How to eliminate wrong answers

Option A is wrong because a vendor's annual revenue does not indicate the risk they pose to the organization; a small vendor with access to sensitive data can be high risk. Option B is wrong because a long relationship does not reduce risk; it may even increase complacency. Option C is wrong because contract value is a financial metric, not a risk indicator; a low-value contract for a critical service can still be high risk.

12
MCQmedium

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

A.Include security requirements after contract signing
B.Require third parties to self-attest compliance
C.Embed security clauses in request for proposals (RFPs)
D.Conduct periodic security audits of third parties
AnswerC

Embedding security clauses directly into RFPs forces vendors to demonstrate compliance before selection, making security a scored procurement criterion rather than an afterthought. This satisfies the requirement to integrate security requirements into the procurement process at the earliest, most influential stage, when contractual leverage is greatest.

Why this answer

Embedding security clauses in RFPs ensures that security requirements are formally communicated to potential vendors before any contractual agreement, making them a mandatory part of the procurement process. This proactive approach aligns with the CISM principle of integrating security into business processes from the outset, rather than retrofitting controls after contracts are signed. By specifying requirements such as encryption standards (e.g., AES-256), incident response SLAs, and compliance with frameworks like ISO 27001 in the RFP, the organization can evaluate vendor capabilities upfront and avoid costly renegotiations.

Exam trap

The trap here is that candidates often choose option D (periodic audits) because it seems like a thorough security measure, but they fail to recognize that without security clauses embedded in the RFP, the organization lacks contractual authority to enforce audit findings or require specific technical controls. In CISM, security requirements should be integrated during the procurement process, not after contracts are signed.

How to eliminate wrong answers

Option A is wrong because including security requirements after contract signing is reactive and often leads to weak or unenforceable controls, as vendors may resist changes or lack the technical capability to implement them retroactively. Option B is wrong because self-attestation lacks independent verification and is inherently unreliable; vendors may claim compliance with controls like access logging or data encryption without providing evidence, leaving the organization vulnerable to misrepresentation. Option D is wrong because periodic security audits are a detective control that occurs after the vendor is already engaged, and without contractual security clauses in the RFP, the organization has no legal basis to enforce audit findings or mandate remediation.

13
MCQeasy

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

A.Full-scale exercise
B.Simulation
C.Drill
D.Tabletop exercise
AnswerD

A tabletop exercise gathers stakeholders for a facilitated discussion of a hypothetical scenario, walking through plans and procedures without deploying systems or simulating live traffic. This format directly satisfies the stem's requirement for a discussion-based review, distinguishing it from functional or full-scale exercises that test operational response.

Why this answer

A tabletop exercise is a discussion-based session where participants, guided by a facilitator, walk through a hypothetical incident scenario to evaluate plans, procedures, and decision-making. It does not involve deploying actual resources or simulating live systems; instead, it focuses on reviewing roles, communication, and coordination. This matches the question's description of a facilitated discussion to review plans and procedures.

Other exercise types involve more active or technical execution.

Exam trap

CISM often tests the distinction between discussion-based and operations-based exercises, and candidates may confuse a tabletop exercise with a simulation or drill due to overlapping goals of testing response plans.

How to eliminate wrong answers

Option A is wrong because a full-scale exercise involves actual deployment of resources and personnel in a real-world or simulated operational environment, not just a facilitated discussion. Option B is wrong because a simulation typically uses software or models to replicate system behavior for testing technical responses, which goes beyond a discussion-based review. Option C is wrong because a drill is a coordinated, supervised activity that tests a specific operation or function in a controlled environment, often involving hands-on execution rather than a discussion.

14
MCQmedium

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

A.Provide annual security training to all developers.
B.Assign a security champion to each development team and create a lightweight secure coding checklist.
C.Establish a separate security team that reviews all code after development is complete.
D.Implement a mandatory security gate before each release, requiring a full security review.
AnswerB

Embedding a security champion within each agile team and supplying a lightweight secure coding checklist integrates controls directly into rapid sprints, satisfying the moderate risk appetite and the constraint of avoiding the friction that formal security reviews previously caused.

Why this answer

Assigning a security champion to each development team and providing a lightweight secure coding checklist integrates security into agile workflows without imposing heavy gates. It leverages existing team structures, keeps friction low, and aligns with a moderate risk appetite by embedding security early rather than blocking releases.

Exam trap

CISM often tests the misconception that adding a mandatory security gate or a separate review team is the best way to integrate security, when the exam favors enabling and embedding security within existing agile teams.

How to eliminate wrong answers

Option A is wrong because annual training alone is too infrequent and passive to change day-to-day development behavior or catch issues during rapid releases. Option C is wrong because post-development security review creates a bottleneck and rework, directly conflicting with agile rapid release cycles. Option D is wrong because a mandatory full security gate before every release introduces the exact friction the team has resisted and is disproportionate to a moderate risk appetite.

15
MCQeasy

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

A.Incident response plan
B.Incident response policy
C.Incident response playbook
D.Communication template
AnswerC

A playbook supplies prescriptive, step-by-step procedures for a specific incident type such as ransomware, unlike a policy, which states intent, or a plan, which sets broad structure. It satisfies the need for detailed handling instructions.

Why this answer

Playbooks (or runbooks) provide detailed procedures for specific incident types, while the IR plan is a broader document.

16
MCQhard

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

A.SSL/TLS encryption and VPN access
B.Web application firewall (WAF) and intrusion detection system (IDS)
C.WAF, input validation, and security logging
D.Regular patching and vulnerability scanning
AnswerC

Layered web application defence combines a WAF filtering malicious HTTP traffic, input validation rejecting malformed data at the application, and security logging enabling detection and forensics. Together these satisfy the stem's defence-in-depth objective across preventive and detective control types at the application layer.

Why this answer

Defense-in-depth for the web application layer requires multiple overlapping controls: a WAF filters malicious HTTP traffic, input validation prevents injection attacks at the application layer, and security logging provides detection and forensic capability. Together they address prevention, detection, and response. This combination covers network, application, and monitoring layers.

Exam trap

CISM often tests the confusion between preventive controls (WAF, input validation) and detective/administrative controls (logging, patching), tempting candidates to pick a combination that lacks a key layer.

How to eliminate wrong answers

Option A is wrong because SSL/TLS and VPN address transport encryption and network access, not web application layer threats like SQL injection or XSS. Option B is wrong because WAF and IDS provide prevention and detection but omit input validation, which is a critical application-layer control against injection. Option D is wrong because patching and vulnerability scanning are vulnerability management activities, not layered web application controls; they do not filter or validate live traffic.

17
MCQeasy

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

A.CISO reports to the CFO
B.CISO reports to the CEO or board of directors
C.CISO reports to the CIO
D.CISO reports to the head of internal audit
AnswerB

Reporting directly to the CEO or board removes intermediate IT management from the chain, preventing conflicts where the security function audits the same operations it reports through. This satisfies the independence and authority constraint, giving the CISO unfiltered escalation and budget influence.

Why this answer

Reporting to the board or a senior executive not directly responsible for IT operations ensures independence and reduces conflicts of interest.

18
MCQmedium

A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?

A.Develop a security awareness training program for all employees.
B.Adopt an industry-recognized framework such as ISO/IEC 27001 to structure the program.
C.Implement a security information and event management (SIEM) system to monitor for threats.
D.Conduct a comprehensive risk assessment to identify and prioritize threats to business objectives.
AnswerD

A risk assessment identifies which assets and processes are most critical to achieving business objectives, and prioritizes threats accordingly. This ensures that security investments are directly tied to protecting what matters most to the business. Without this foundational step, subsequent activities like policy development or control selection lack a business-driven rationale, making alignment difficult to demonstrate to the board.

Why this answer

The correct answer is to conduct a risk assessment first. This step identifies which business objectives are at risk and prioritizes threats, enabling the CISO to align security investments with what the business values most. It provides the evidence needed to justify budget allocation and ensures that subsequent security activities are driven by business needs rather than technology or compliance alone.

Exam trap

The trap here is assuming that adopting a framework or implementing a technical control immediately aligns security with business objectives, when alignment actually starts with understanding the business through risk assessment.

19
MCQhard

During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?

A.Inadequate security awareness training
B.Lack of an incident response plan
C.Absence of a procurement security policy
D.Weak access control over cloud resources
AnswerC

Shadow cloud purchasing persists because no policy obliges business units to route acquisitions through IT security. A procurement security policy embeds security review into the buying process, closing the governance gap the stem describes; other deficiencies are symptoms rather than the root cause.

Why this answer

The scenario describes business units procuring cloud services without IT security involvement, which directly indicates the absence of a procurement security policy. Such a policy would mandate security review and approval before any cloud service acquisition, ensuring that security requirements are integrated into the procurement lifecycle. Without it, security is bypassed, leading to ungoverned shadow IT and potential compliance violations.

Exam trap

The trap here is that candidates often confuse a lack of security awareness training (Option A) with the governance failure, but the scenario specifically highlights the absence of a formal procurement process, not a training gap.

How to eliminate wrong answers

Option A is wrong because inadequate security awareness training focuses on user behavior and phishing risks, not on the procedural failure to involve security in procurement decisions. Option B is wrong because a lack of an incident response plan addresses post-breach actions, not the preventive governance gap that allows unauthorized cloud service purchases. Option D is wrong because weak access control over cloud resources is a technical control issue that arises after procurement, whereas the core deficiency here is the missing governance process to enforce security review before acquisition.

20
MCQeasy

During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?

A.A summary of actions taken so far
B.Detailed technical analysis
C.A timeline of all events
D.The root cause of the incident
AnswerA

Stakeholders need a concise summary of actions taken so far to understand the current response state and what is being done, satisfying the communication-priority constraint. This factual update precedes speculation about cause or impact, keeping messaging accurate and reassuring during the incident.

Why this answer

During an incident, the first communication to stakeholders should provide a summary of actions taken so far to establish transparency and demonstrate that the incident response team is actively managing the situation. This aligns with NIST SP 800-61r2 guidance, which prioritizes timely, high-level updates over detailed technical data to avoid overwhelming stakeholders and to maintain trust. Detailed technical analysis, timelines, and root cause determination typically require more investigation and are communicated in subsequent updates.

Exam trap

The CISM exam often tests the misconception that stakeholders need technical depth immediately, but the trap here is that candidates confuse 'first communication' with 'final report' and select root cause or timeline, forgetting that early incident response prioritizes containment status over investigation details.

How to eliminate wrong answers

Option B is wrong because detailed technical analysis is too granular for initial stakeholder communication; it should be reserved for technical teams or post-incident reports. Option C is wrong because a timeline of all events is typically compiled after the incident is contained and is not the first priority for stakeholders who need immediate status. Option D is wrong because the root cause is often unknown early in an incident; communicating an unconfirmed root cause can lead to misinformation and legal liability, per incident response best practices.

21
MCQmedium

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

A.Providing 24/7 security monitoring
B.Eliminating the need for security awareness training
C.Reducing the need for a dedicated security team
D.Embedding security expertise within development teams
AnswerD

Security champions are developers who receive security training and act as the first point of contact within their own teams, embedding expertise where code is written. This satisfies the stem's primary benefit by scaling security knowledge without adding dedicated security headcount to every team.

Why this answer

A security champions program embeds security expertise within development teams by designating individuals who act as liaisons between the security team and developers. This fosters a security culture, enables early identification of security issues, and reduces the bottleneck of a centralized security team. The primary benefit is scaling security knowledge across the organization.

Exam trap

CISM often tests the misconception that security champions can replace security teams or awareness training; the correct answer emphasizes embedding expertise, not reducing headcount.

How to eliminate wrong answers

Option A is wrong because security champions do not provide 24/7 monitoring; that is the role of a SOC. Option B is wrong because the program complements, not eliminates, security awareness training. Option C is wrong because while it may reduce the burden on the security team, it does not eliminate the need for a dedicated security team; it enhances collaboration.

22
MCQmedium

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

A.Level 4 (Managed)
B.Level 2 (Repeatable)
C.Level 5 (Optimizing)
D.Level 3 (Defined)
AnswerC

At Level 5 (Optimizing), processes are continuously improved through quantitative measurement and feedback, satisfying the stem's requirement for proactively measured and optimised security. Lower levels merely define, manage or quantitatively control processes without this continuous optimisation focus.

Why this answer

Level 5 (Optimizing) focuses on continuous improvement through quantitative measurement.

23
MCQmedium

A CISO is reviewing the information security strategy and needs to ensure that security investments are justified in business terms. The CFO has requested that each security initiative be tied to a financial metric that reflects potential loss from cyber events. Which approach is MOST appropriate for the CISO to use?

A.Benchmark the organization's security budget against industry peers.
B.Calculate the annualized loss expectancy (ALE) for each initiative based on risk assessment data.
C.Track the percentage of employees who completed security awareness training.
D.Report the number of security incidents detected per quarter.
AnswerB

ALE expresses risk in financial terms by multiplying the single loss expectancy by the annualized rate of occurrence, directly linking security spending to expected monetary loss. This allows the CISO to compare initiatives on a consistent financial basis and justify investments to the CFO using the same language as other business cases.

Why this answer

Using annualized loss expectancy translates risk into monetary terms, enabling direct comparison of security initiatives against expected financial loss. This aligns security governance with business objectives and provides the CFO with a quantifiable basis for investment decisions, which is a core CISM principle for integrating security into business strategy.

Exam trap

The trap here is confusing operational metrics such as incident counts or training completion with financial metrics that express risk in monetary terms.

24
MCQhard

During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?

A.Enable full packet capture on the network and continue monitoring for attacker activity.
B.Reset the password on the compromised administrator account only and force a change at next logon.
C.Disable the compromised administrator account and rotate all credentials for privileged accounts.
D.Shut down all servers that the administrator account could access until the investigation is complete.
AnswerC

Disabling the compromised account removes the attacker's known access path, and rotating privileged credentials invalidates any other stolen secrets the attacker may hold. This contains the incident without shutting down business operations, which supports the CISM principle of balancing security with business continuity. It also addresses the likelihood that the attacker harvested additional credentials from the compromised administrator's session or memory, closing related entry points.

Why this answer

The most effective containment against credential-based intrusion is to remove the compromised access and invalidate related secrets. Disabling the known compromised administrator account stops the confirmed entry path, while rotating all privileged credentials closes the likely other paths the attacker obtained. This approach contains the threat without unnecessarily halting business operations, which reflects CISM's balance between security response and business continuity.

Blanket shutdowns and passive monitoring fail to remove the adversary's access.

Exam trap

The trap here is treating broad system shutdown as the safest containment, when a proportionate credential-focused action contains the threat with far less business disruption.

25
MCQmedium

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

A.Allow exceptions for senior executives
B.Delay implementation until user acceptance improves
C.Revoke remote access for non-compliant users
D.Provide training on the importance of MFA
AnswerD

User resistance to MFA typically stems from unfamiliarity rather than the control itself. Training explains the rationale and correct enrolment, improving compliance without weakening the policy. Removing or exempting MFA would undermine the remote-access protection the organisation mandated.

Why this answer

Providing training helps users understand the necessity of MFA for security, addressing their concerns and gaining buy-in. Allowing exceptions (A) weakens security, delaying implementation (B) postpones protection, and revoking access (C) is too punitive as a first step.

26
MCQeasy

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

A.The incident response manager
B.The legal counsel
C.The IT director
D.The board of directors or executive management
AnswerD

Board or executive management approval confers enterprise-wide authority and accountability, since only top leadership can mandate compliance across all business units and commit resources. This satisfies the policy's requirement for authority and accountability by placing ownership at the highest governance level.

Why this answer

The IR policy requires senior management approval to demonstrate organizational commitment and allocate necessary resources.

27
MCQeasy

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

A.To ensure chain of custody
B.To reduce time to engage during an incident
C.To reduce legal liability
D.To guarantee confidentiality
AnswerB

A pre-established forensic retainer defines scope, rates and contacts in advance, so the firm can be engaged immediately when an incident occurs. This directly satisfies the stem's constraint of reducing engagement delay, avoiding procurement and legal negotiation during the critical containment window when evidence preservation is time-sensitive.

Why this answer

The primary purpose of a pre-established forensic retainer agreement is to reduce the time to engage during an incident. By having a contract already in place, the organization can bypass procurement and legal review delays, enabling the forensics firm to begin work immediately when an incident occurs, which is critical for preserving volatile evidence and minimizing damage.

Exam trap

The trap is that candidates may think the retainer primarily ensures chain of custody or reduces liability, but the CISM exam focuses on the retainer's purpose of enabling rapid engagement during incidents.

How to eliminate wrong answers

Option A is wrong because chain of custody is a procedural and documentation requirement, not a contractual one; a retainer agreement does not directly ensure chain of custody—that is achieved through proper evidence handling and logging. Option C is wrong because while a retainer may include liability clauses, its primary purpose is not to reduce legal liability; liability reduction is a secondary benefit, and the main goal is rapid engagement. Option D is wrong because confidentiality is typically addressed via a separate non-disclosure agreement (NDA) or terms within the retainer, but the retainer's primary purpose is not to guarantee confidentiality—it is to pre-authorize and expedite forensic services.

28
Multi-Selecthard

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Select 3 answers
A.Chief executive officer (CEO)
B.General counsel (GC)
C.Security analyst
D.Incident response manager
E.Chief financial officer (CFO)
AnswersA, B, E

The CEO sits on the crisis management team to authorise strategic decisions, external communications and resource commitments during a major incident. This satisfies the stem's selection of typical CMT roles, distinguishing executive crisis governance from the tactical incident response team handling containment and recovery.

Why this answer

The Chief Executive Officer (CEO) (A) is a core CMT member because this role owns ultimate business accountability, authorizes major decisions such as taking systems offline or notifying regulators, and communicates with the board and public during a crisis. The General Counsel (GC) (B) belongs on the CMT to assess legal, regulatory, and contractual obligations, including breach-notification laws, litigation risk, and law-enforcement engagement. The Chief Financial Officer (CFO) (E) is included to manage financial impact, authorize emergency spending, handle cyber-insurance claims, and evaluate materiality for financial disclosures.

The Security Analyst (C) is a hands-on technical responder who performs triage, log analysis, and containment tasks rather than strategic crisis-management decisions, so is not typically a CMT member. The Incident Response Manager (D) coordinates the tactical incident-response effort and reports to the CMT, but is not itself a standing CMT role.

Exam trap

The trap here is that candidates confuse the Incident Response Team (IRT) with the Crisis Management Team (CMT), incorrectly selecting operational roles like security analyst or incident response manager instead of the executive leadership roles that constitute the CMT.

29
MCQhard

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

A.Industry analyst recommendations
B.Number of features compared to competitors
C.Total cost of ownership (TCO) analysis
D.Risk reduction value and breach cost avoidance
AnswerD

Expressing the investment as reduced risk exposure and avoided breach cost translates security benefit into financial terms, letting the CISO compare spend against expected loss reduction. Qualitative maturity gains alone cannot quantify value for a business case.

Why this answer

Quantifying security investment value requires translating risk reduction into financial terms — expected breach cost avoidance. This aligns security spending with business risk appetite and demonstrates ROI in language executives understand. It is the most rigorous, business-aligned approach for a CISO's business case.

Exam trap

CISM often tests the confusion between cost analysis (TCO) and value analysis (risk reduction) — candidates pick TCO because it sounds financial, but it only quantifies what you spend, not what you protect.

How to eliminate wrong answers

Option A is wrong because industry analyst recommendations are subjective, may be vendor-influenced, and do not quantify value specific to the organization's risk profile. Option B is wrong because feature comparison is a functional evaluation, not a financial quantification of value — more features do not equal more risk reduction. Option C is wrong because TCO analysis quantifies cost, not value — it tells you what you will spend, not what you will save or protect, so it is only half the business case.

30
Multi-Selectmedium

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Select 2 answers
A.Vulnerability scanning
B.Identity and access management
C.Incident response
D.Security monitoring and detection
E.Application security testing
AnswersC, D

Incident response supplies the SOC's reactive capability: triage, containment, eradication and recovery once detection confirms an event. Without it, monitoring generates alerts with no structured path to resolution, so it is a core operational component alongside detection.

Why this answer

Incident response (C) is a core SOC component because the SOC's mission includes detecting, containing, eradicating, and recovering from security incidents, typically following a defined IR lifecycle and using tools like SIEM alerts, ticketing, and forensic analysis. Security monitoring and detection (D) is also fundamental, as the SOC continuously collects and correlates telemetry (for example, logs and network flows via a SIEM) to identify suspicious activity and generate alerts that drive response. Vulnerability scanning (A) is a vulnerability management activity often performed by a separate team, even if its output may inform SOC prioritization.

Identity and access management (B) is an access-control discipline typically owned by IAM/identity teams, not a defining SOC component. Application security testing (E) belongs to secure development/AppSec functions such as SAST, DAST, and SCA, rather than the SOC's monitoring-and-response core.

Exam trap

CISM often tests the distinction between preventive controls (vulnerability scanning, IAM) and detective/response controls (monitoring, incident response); candidates may incorrectly include preventive functions as core SOC components.

31
Multi-Selecthard

Which of the following are key components of a mature information security program? (Select 2)

Select 2 answers
A.Comprehensive risk management process
B.Adoption of cloud security tools
C.Continuous monitoring and improvement
D.Single point of failure for security decisions
AnswersA, C

Why this answer

A comprehensive risk management process is a foundational component of a mature information security program because it ensures that security controls are aligned with business objectives through systematic identification, assessment, and treatment of risks. This process, often guided by frameworks like ISO 31000 or NIST SP 800-39, enables prioritization of resources based on risk appetite and tolerance, rather than relying on ad-hoc or reactive measures. Without this, the program lacks the structured governance needed to adapt to evolving threats and regulatory requirements.

Exam trap

The trap here is that candidates mistake tactical tools or organizational shortcuts (like a single security decision-maker) for program maturity, when CISM emphasizes that maturity is defined by process integration, governance, and continuous improvement, not by technology adoption or centralized authority.

Why the other options are wrong

B

Tool adoption is not a program component; it's an implementation detail.

D

Mature programs distribute accountability.

32
MCQmedium

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

A.Notify law enforcement
B.Increase the ransom payment
C.Escalate to activate the business continuity/disaster recovery plan
D.Engage the forensics firm to preserve evidence
AnswerC

When recovery cannot meet the maximum tolerable downtime, the incident ceases to be a technical problem and becomes a continuity problem. Escalating to activate the business continuity/disaster recovery plan invokes pre-authorised alternate processing arrangements, restoring critical services through failover rather than waiting for server restoration.

Why this answer

When an incident cannot be resolved within MTD, it escalates to business continuity/disaster recovery activation to restore operations.

33
Multi-Selecthard

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Select 3 answers
A.Security awareness training for board members
B.CISO reporting directly to the CEO
C.Board-level risk committee review of security posture
D.Approval of the information security strategy by the board
E.Regular security incident reports to the board
AnswersC, D, E

A board-level risk committee provides the governance structure through which directors exercise oversight of security posture, satisfying the stem's requirement for board-level accountability. Unlike operational controls, this mechanism escalates cyber risk into enterprise risk reporting, ensuring strategic decisions and risk tolerance are reviewed at the highest level.

Why this answer

Option C is correct because a board-level risk committee provides structured, recurring oversight by reviewing the organization's security posture against its risk appetite, ensuring cyber risk is governed alongside other enterprise risks. Option D is correct because formal board approval of the information security strategy establishes accountability at the highest level and ensures security objectives are aligned with business goals and adequately resourced. Option E is correct because regular security incident reports give the board timely visibility into material incidents, trends, and remediation status, which is a core mechanism of ongoing board-level oversight.

Option A is not essential for board-level oversight, since awareness training educates directors but does not itself create governance or oversight accountability. Option B is also not essential, because while a CISO reporting to the CEO can improve escalation, reporting lines alone do not guarantee board-level oversight of security governance.

Exam trap

CISM often tests the distinction between governance (board-level evaluate/direct/monitor activities) and management (operational or reporting-line decisions), so candidates wrongly select structural items like CISO reporting lines or training as if they were oversight mechanisms.

34
MCQmedium

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

A.At the next quarterly board meeting
B.Immediately after the incident is detected
C.Only after all legal proceedings are concluded
D.Within 2 weeks of incident resolution
AnswerD

Holding the lessons learned meeting within two weeks of resolution captures details while memories remain fresh and evidence is accessible, yet allows initial recovery to settle. This timing balances accuracy against operational demands, yielding actionable improvements to the incident response programme.

Why this answer

Lessons learned meetings should occur within two weeks of incident resolution while details are fresh, to capture accurate feedback and improve the IR plan.

35
Multi-Selectmedium

Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)

Select 2 answers
A.Multiple failed login attempts from an external IP address
B.An increase in network traffic to a known malicious domain
C.A user accessing large volumes of data not related to their job function
D.An employee logging in during non-business hours and downloading files
E.A user updating their password as required by policy
AnswersC, D

This suggests data theft or espionage.

Why this answer

A user accessing large volumes of data unrelated to their job function is a classic behavioral anomaly indicating potential data exfiltration. This pattern often precedes an insider threat incident, as the user may be collecting sensitive information for unauthorized purposes, such as selling it or using it for personal gain. Security information and event management (SIEM) systems typically flag such access based on deviations from baseline user behavior, triggering further investigation.

Exam trap

The trap here is that candidates often confuse external attack indicators (like failed logins or malicious domain traffic) with insider threat indicators, failing to recognize that insider threats are characterized by anomalous internal behavior, not external network events.

36
MCQmedium

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

A.Pareto analysis
B.SWOT analysis
C.5 Whys
D.Fishbone diagram
AnswerC

5 Whys is an iterative interrogative technique that repeatedly asks 'why' to strip away symptomatic layers and expose the underlying causal factor. Applied after containment, it drills from the immediate ransomware trigger down to the root weakness, satisfying the root cause analysis requirement.

Why this answer

The 5 Whys technique involves repeatedly asking 'why' to drill down from a symptom to its root cause. It was developed by Sakichi Toyoda and is widely used in incident response and quality management. By asking 'why' five times, teams can uncover underlying process failures rather than stopping at superficial causes.

Exam trap

CISM often tests the confusion between root cause analysis tools — candidates may pick Fishbone diagram because it also analyzes causes, but only 5 Whys specifically uses the iterative 'why' questioning.

How to eliminate wrong answers

Option A is wrong because Pareto analysis (80/20 rule) prioritizes issues by frequency or impact, not by drilling down to root cause. Option B is wrong because SWOT analysis assesses strengths, weaknesses, opportunities, and threats, which is a strategic planning tool, not a root cause analysis method. Option D is wrong because a Fishbone diagram (Ishikawa) categorizes potential causes but does not inherently involve the iterative 'why' questioning; it is a visual tool often used in conjunction with 5 Whys.

37
MCQeasy

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

A.Regularly meeting with business unit leaders to understand needs and risks.
B.Conducting vulnerability scans twice a year.
C.Developing a security awareness campaign.
D.Purchasing an advanced threat detection system.
AnswerA

Regular engagement with business unit leaders surfaces their objectives and risk tolerance, letting security strategy be shaped around them. This satisfies the alignment goal directly, since security priorities derive from documented business needs rather than from technical or compliance-driven assumptions.

Why this answer

Regularly meeting with business unit leaders to understand needs and risks is the most important activity because it ensures the security program is directly aligned with business objectives, risk appetite, and operational priorities. This engagement allows the CISO to perform a business impact analysis (BIA) and integrate security controls that support strategic goals rather than operating in isolation. Without this alignment, even technically sound security measures may be rejected or underfunded by leadership.

Exam trap

The trap here is that candidates often mistake a tactical security activity (like vulnerability scanning or buying a tool) for strategic alignment, failing to recognize that only direct engagement with business leaders can ensure the security program supports organizational goals.

How to eliminate wrong answers

Option B is wrong because conducting vulnerability scans twice a year is a tactical, reactive activity that identifies technical weaknesses but does not address whether those vulnerabilities align with business priorities or risk tolerance. Option C is wrong because developing a security awareness campaign, while valuable for reducing human risk, is a specific control that does not by itself ensure the security program supports business objectives. Option D is wrong because purchasing an advanced threat detection system is a technology procurement decision that may improve detection capabilities but does not guarantee the security program is aligned with business needs or that the investment is justified by business risk.

38
MCQmedium

A healthcare organization is developing its information security strategy. The CISO is considering how to best align the strategy with the organization's overall business strategy. Which of the following approaches would be MOST effective?

A.Focus the security strategy primarily on compliance with healthcare regulations such as HIPAA.
B.Ensure the security strategy is developed independently by the security team to avoid business influence.
C.Adopt a widely recognized security framework and tailor it to the organization's needs.
D.Integrate security objectives into the business strategy planning process and participate in business strategy discussions.
AnswerD

Integrating security objectives into the business strategy planning process ensures that security is considered from the outset. By participating in business strategy discussions, the CISO can align security initiatives with business goals, identify risks, and ensure that security enables rather than impedes business objectives. This collaborative approach is most effective for alignment.

Why this answer

The most effective approach to align security strategy with business strategy is to integrate security objectives into the business strategy planning process and participate in business strategy discussions. This ensures that security is a core consideration in business decisions, enabling the organization to achieve its goals while managing risk. Other approaches, such as independent development or exclusive focus on compliance, can lead to misalignment and missed opportunities.

Exam trap

The trap here is assuming that adopting a framework or focusing on compliance alone achieves alignment, when true alignment requires active integration with business strategy.

39
MCQeasy

Which of the following incident categories would typically require the involvement of the crisis management team?

A.A P2 high-severity DDoS attack that has been mitigated within a few hours.
B.A P3 medium-severity insider threat involving unauthorized access to a non-critical system.
C.A P4 low-severity phishing email reported by a user.
D.A P1 critical-severity ransomware attack encrypting critical systems.
AnswerD

A P1 ransomware attack encrypting critical systems threatens business continuity and may involve extortion, regulatory notification and executive decisions beyond IT's authority. This severity and cross-functional impact trigger crisis management team involvement, satisfying the stem's requirement for incidents demanding strategic, organisation-wide response rather than routine technical remediation.

Why this answer

A P1 critical-severity ransomware attack encrypting critical systems requires immediate activation of the crisis management team because it poses an existential threat to business operations, often involving legal, PR, executive, and regulatory stakeholders. The crisis management team handles incidents that exceed the capacity of the incident response team, typically those with high business impact, widespread system compromise, or potential for significant financial/reputational damage.

Exam trap

A common pitfall is to assume that any high-severity technical incident automatically triggers crisis management. However, in the CISM framework, crisis management activation depends on the business impact and the need for executive-level decisions. A quickly mitigated DDoS may be handled by the incident response team alone, whereas a critical ransomware attack affecting core business processes requires crisis management due to the potential for significant financial, legal, and reputational consequences.

How to eliminate wrong answers

Option A is wrong because a P2 high-severity DDoS attack that has been mitigated within a few hours is typically handled by the incident response team using network-layer mitigation techniques (e.g., BGP RTBH, rate-limiting, or scrubbing services) and does not require crisis-level escalation. Option B is wrong because a P3 medium-severity insider threat involving unauthorized access to a non-critical system is a standard incident response task, often investigated by the security operations center (SOC) using log analysis and user behavior analytics (UBA), without needing executive crisis management. Option C is wrong because a P4 low-severity phishing email reported by a user is a routine, low-impact event that is handled through standard security awareness processes and automated email filtering (e.g., SPF, DKIM, DMARC checks), not requiring crisis team involvement.

40
MCQhard

During a major incident, the incident response manager must decide whether to declare a crisis and activate the crisis management team (CMT). Which factor is MOST important in making that decision?

A.The availability of the on-call incident responder during the current shift.
B.Whether the incident was detected by an external party rather than internal monitoring.
C.The potential impact on critical business functions and the need for executive-level coordination.
D.The number of alerts generated by the SIEM in the last hour.
AnswerC

CISM defines crisis declaration around significant business impact and the need for strategic coordination across the organization. When an incident threatens critical business functions, reputation, or regulatory obligations, the CMT should be activated to provide executive direction, prioritize resources, and manage stakeholder communications. This factor directly reflects the purpose of the CMT and is the most reliable basis for the decision.

Why this answer

CISM ties crisis declaration to significant business impact and the need for executive-level coordination. The CMT exists to provide strategic direction, resource prioritization, and stakeholder management during severe incidents. Alert volume, detection source, and shift staffing are operational details that do not by themselves determine whether a crisis should be declared.

Exam trap

The trap here is using technical signals such as alert volume instead of business impact to decide on crisis declaration.

41
MCQhard

A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?

A.Conduct a penetration test of the disaster recovery site to validate its security posture.
B.Update the disaster recovery plan to reflect the recovery time objectives (RTOs) and recovery point objectives (RPOs) identified in the BIA.
C.Launch a security awareness programme focused on business continuity responsibilities.
D.Increase the cybersecurity insurance coverage to transfer residual risk identified in the BIA.
AnswerB

The BIA establishes critical business processes and their maximum tolerable downtime and data loss, expressed as RTOs and RPOs. The next logical step is to ensure the disaster recovery plan for information systems is updated to meet these targets. This directly links security and resilience priorities to business impact, ensuring recovery capabilities are aligned with what the business actually needs.

Why this answer

The BIA defines critical processes and their RTOs and RPOs. To make the security programme consistent with these findings, the CISO must ensure disaster recovery and related plans are updated so that systems and data can be restored within the required timeframes. This is a direct, necessary step before validating or transferring risk.

Exam trap

The trap here is treating the BIA as a document to be filed rather than a driver for updating recovery plans; testing or insurance does not substitute for aligning RTOs and RPOs with business needs.

42
MCQmedium

A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?

A.Implement encryption for all data stored in the new region.
B.Review the board's risk appetite statement and tolerance levels for the new region.
C.Perform a gap analysis of current controls against the new region's regulatory requirements.
D.Conduct a business impact analysis (BIA) for all regional operations.
AnswerB

The board's risk appetite and tolerance levels provide the criteria for evaluating and treating risks. Aligning treatment with appetite requires first understanding what the board deems acceptable. This step ensures that subsequent risk assessments and control decisions are consistent with organizational objectives and regulatory constraints. It is the foundational step before any analysis or control implementation in the new region.

Why this answer

Aligning risk treatment with risk appetite begins with understanding the board's appetite and tolerance. The risk appetite statement defines the amount and type of risk the organization is willing to accept, which then guides the selection of controls. Only after this alignment can a gap analysis, BIA, or control implementation be effectively prioritized.

Thus, reviewing the board's risk appetite is the essential first step.

Exam trap

The trap here is assuming that a technical control like encryption or a BIA is the first step, when the board's risk appetite must be established to guide treatment decisions.

43
MCQeasy

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

A.Incident response manager
B.Communications lead
C.Security analysts
D.Forensic investigators
AnswerA

The incident response manager runs the response end to end, tasking technical teams and assigning severity classifications that trigger escalation and notification thresholds. This satisfies the stem's requirement for the coordinating role, distinguishing it from the executive sponsor's governance remit and the communications lead's messaging duties.

Why this answer

The IR manager leads the team, coordinates activities, and classifies incidents based on severity.

44
MCQeasy

An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.

A.Perform daily monitoring of security alerts and coordinate the response to detected incidents.
B.Conduct technical vulnerability assessments of critical systems and track remediation activities.
C.Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.
D.Independently audit the security programme's controls and report findings directly to external regulators.
AnswerC

A security steering committee with cross-functional representation exists to provide governance: setting strategic direction, aligning security investment with business priorities, and resolving conflicts between security and operational needs. This matches its composition, since business, legal, and risk perspectives are needed for strategic trade-off decisions. Operational tasks such as patching or incident response belong to the security team, not this governance body.

Why this answer

A security steering committee is a governance body whose purpose is to align the security programme with business strategy, approve direction, and prioritize initiatives using cross-functional input. Its membership of business, IT, legal, and risk leaders fits strategic decision-making. Operational execution and independent audit are deliberately separated from this body to preserve both efficiency and objectivity.

Exam trap

The trap here is confusing governance oversight with operational execution, assuming a cross-functional committee should perform hands-on security work.

45
MCQmedium

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

A.COBIT 2019
B.NIST SP 800-53
C.ISO 27001 Annex A
D.CIS Controls v8
AnswerD

CIS Controls v8 maps its prioritised safeguards into Implementation Groups IG1, IG2 and IG3, letting organisations sequence controls by maturity and risk. It also targets the most common cyber threats, satisfying both the IG-based and common-threat requirements named in the stem.

Why this answer

CIS Controls v8 provides a prioritized set of actions that collectively form a defense-in-depth set of best practices to mitigate the most common cyber attacks. It is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk and resources, making it the framework that best meets the requirement for prioritized, implementation group-based controls addressing common threats.

Exam trap

The trap is selecting a well-known framework like NIST or ISO without noting the specific requirement for 'implementation group-based' prioritization, which is unique to CIS Controls v8.

How to eliminate wrong answers

Option A is wrong because COBIT 2019 is an IT governance and management framework focused on aligning IT with business objectives, not a prioritized control set for cyber threats. Option B is wrong because NIST SP 800-53 is a comprehensive catalog of security and privacy controls for federal information systems, not organized by implementation groups for prioritization. Option C is wrong because ISO 27001 Annex A provides a list of controls but does not prioritize them into implementation groups based on organizational size or risk.

46
MCQhard

A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?

A.Escalate the incident according to the incident response plan and begin documenting actions.
B.Notify law enforcement and the media before performing any internal investigation.
C.Block the external IP address at the firewall to stop the exfiltration immediately.
D.Immediately take the database server offline to prevent further data loss.
AnswerA

Escalating per the incident response plan ensures the right stakeholders are engaged and that actions are coordinated, documented, and authorized. Documentation supports forensic analysis, legal requirements, and post-incident review. This step aligns with CISM principles of following established procedures, maintaining chain of custody, and avoiding unilateral actions that could compromise the investigation or business operations.

Why this answer

The analyst should escalate according to the incident response plan and begin documenting actions. This ensures proper authorization, coordination, and evidence handling before containment or notification. Premature blocking, shutdown, or external notification can tip off attackers, destroy evidence, or create legal and reputational risk.

Following the plan supports a measured, defensible response aligned with CISM incident management principles.

Exam trap

The trap here is assuming the fastest technical action is best, when unauthorized containment or notification can compromise the investigation and business operations.

47
MCQmedium

A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?

A.The incident requires more than one analyst to investigate and remediate within the standard service-level agreement.
B.The incident was detected by the security operations center (SOC) outside of normal business hours.
C.The incident has the potential to cause significant harm to the organization's brand, finances, or regulatory standing.
D.The incident affects a system that is listed in the configuration management database (CMDB) as business-critical.
AnswerC

Crisis classification is driven by potential enterprise-level impact, spanning brand reputation, financial loss, legal or regulatory exposure, and continuity of critical services. When an incident threatens these dimensions beyond the tolerance defined by executive management, the CMT must be activated because response now requires cross-functional executive authority, external communications, and strategic decision-making rather than technical containment alone.

Why this answer

Crisis-level classification hinges on the potential for enterprise-wide harm to reputation, finances, operations, or regulatory compliance. This impact-based threshold ensures the CMT is convened only when executive authority, cross-functional coordination, and external stakeholder management are genuinely required. Detection source, staffing needs, and asset criticality labels are useful inputs but cannot by themselves indicate that an incident has crossed the crisis threshold.

Exam trap

The trap here is assuming that technical severity or asset criticality automatically equals crisis status, when CISM ties crisis classification to realized or potential business impact.

48
MCQeasy

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

A.Identify assets and their value
B.Calculate the level of risk
C.Establish the risk assessment context
D.Determine the likelihood of threats
AnswerC

Establishing the risk assessment context defines scope, objectives, criteria and assumptions before any identification or analysis occurs. Without this framing, subsequent risk identification and evaluation lack consistent boundaries, making the context step the necessary first action.

Why this answer

Establishing the risk assessment context (C) is the first step because it defines the scope, objectives, and criteria for the assessment, ensuring alignment with organizational goals and risk appetite. Without this foundational step, subsequent activities like asset identification or risk calculation lack direction and may produce irrelevant or misleading results. In the CISM framework, context setting precedes all technical analysis to ensure the assessment is meaningful and actionable.

Exam trap

The trap here is that candidates often confuse 'identify assets' as the first step because it seems intuitive, but CISM emphasizes that context must be set first to ensure the assessment is scoped and relevant, not just a generic inventory exercise.

How to eliminate wrong answers

Option A is wrong because identifying assets and their value is a subsequent step that occurs after the context is established, as the context determines which assets are in scope and how their value should be measured. Option B is wrong because calculating the level of risk is a later analytical step that depends on first understanding the context, identifying assets, and determining threats and likelihoods. Option D is wrong because determining the likelihood of threats requires a defined context to know which threats are relevant and what baseline assumptions apply, making it premature without context.

49
MCQmedium

Which of the following best describes the primary purpose of an Information Security Program?

A.To reduce the number of security incidents to zero.
B.To ensure compliance with all relevant laws and regulations.
C.To align security efforts with business objectives and manage risk.
D.To implement technical security controls across all systems.
AnswerC

An Information Security Program exists to integrate security controls with organisational goals, ensuring risk is managed at a level the business accepts. It satisfies the stem's requirement by framing security as an enabler of objectives rather than a purely technical or compliance exercise.

Why this answer

The primary purpose of an Information Security Program is to align security efforts with business objectives and manage risk to an acceptable level. This ensures that security investments and activities directly support the organization's mission, rather than operating in isolation. A program focused solely on compliance or technical controls may fail to address the dynamic risk landscape and business needs.

Exam trap

The trap here is that candidates often mistake compliance (Option B) as the primary goal, but CISM emphasizes that compliance is a subset of risk management, and the program's core purpose is to enable business objectives by managing risk, not just to satisfy auditors.

Why the other options are wrong

A

Zero incidents is unrealistic; the program aims to manage risk, not eliminate all incidents.

B

Compliance is part of the program but not the primary purpose; the program should support business goals.

D

Technical controls are a component, but the program includes governance, policies, and processes.

50
MCQmedium

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

A.IG2
B.IG1
C.IG3
D.IG0
AnswerB

IG1 defines essential cyber hygiene safeguards implementable with limited expertise and budget, making it the foundational implementation group. Addressing it first satisfies the small business's resource constraint, as IG2 and IG3 demand greater maturity and staffing.

Why this answer

CIS Controls v8 defines Implementation Group 1 (IG1) as the foundational set of safeguards for small businesses with limited resources and low-risk data. IG1 represents basic cyber hygiene and should be implemented first to establish a minimum level of security. Therefore, a small business with limited resources should address IG1 first.

Exam trap

The trap is assuming a higher implementation group is better or that IG0 exists; candidates must know that IG1 is the starting point for resource-constrained organizations.

How to eliminate wrong answers

Option A is wrong because IG2 is for organizations with moderate resources and risk, and builds upon IG1; it is not the first group to address. Option C is wrong because IG3 is for large enterprises with sensitive data and high risk, requiring significant resources. Option D is wrong because IG0 does not exist in CIS Controls v8; implementation groups start at IG1.

51
MCQhard

A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?

A.Mandate that all regions immediately adopt the headquarters policy set unchanged
B.Perform a gap assessment of current regional practices against the chosen framework
C.Procure an integrated GRC platform to consolidate all regional risk registers
D.Commission an external audit of every regional security control simultaneously
AnswerB

Before harmonizing anything, the CISO must know where each region stands relative to the target framework. A structured gap assessment produces the factual baseline that prioritization, sequencing, and board reporting all depend on. Jumping to remediation without that baseline risks funding the wrong regions and leaves no defensible measure of progress for the board's comparison objective.

Why this answer

Comparability across regions requires a common reference framework plus a factual baseline of where each region stands against it. A gap assessment delivers both, giving the CISO evidence to prioritize remediation, allocate budget, and report progress to the board. Mandating uniform policy, buying tooling, or auditing everything at once all presume knowledge the CISO does not yet have and skip the diagnostic step that makes the board's comparison meaningful.

Exam trap

The trap here is choosing a decisive-sounding action such as a global policy mandate or tool purchase when the programme first needs an evidence-based baseline against the chosen framework.

52
MCQmedium

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

A.Issue a legal hold and create forensic images of affected systems
B.Immediately wipe affected systems to prevent further data loss
C.Notify the affected individuals as required by law
D.Delete all logs to avoid exposing sensitive information
AnswerA

A legal hold suspends routine deletion and triggers preservation obligations, while forensic imaging captures a bit-for-bit copy without altering the original media. Together they satisfy the litigation constraint by keeping evidence admissible and unmodified, which mere containment or continued live analysis would jeopardise.

Why this answer

When litigation is anticipated, a legal hold must be issued to prevent destruction of relevant evidence, and forensic copies should be made before remediation.

53
Multi-Selecthard

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Select 3 answers
A.Reactive approach to incidents
B.Continuous improvement
C.Automated security controls
D.Ad hoc processes
E.Quantitative performance metrics
AnswersB, C, E

Mature programs regularly refine processes based on lessons learned.

Why this answer

Continuous improvement (B) is a hallmark of higher maturity because it indicates the security program systematically evaluates and enhances its processes based on lessons learned, shifting from static compliance to adaptive risk management. In CISM terms, this aligns with the 'Optimizing' level (Level 5) in the Capability Maturity Model (CMM), where feedback loops drive iterative refinement of controls and policies.

Exam trap

A common misconception is that 'reactive' or 'ad hoc' processes can be part of a mature program if they are fast, but the CMM framework explicitly defines maturity by predictability, measurement, and optimization, not speed or intuition.

54
Multi-Selecthard

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Select 3 answers
A.Cultural resistance to security controls from business units.
B.Overreliance on automated security tools.
C.Inconsistent enforcement of security policies across subsidiaries.
D.Lack of security awareness training for end users.
E.Legacy systems that cannot be patched or upgraded.
AnswersA, C, E

Often seen when security is perceived as hindering productivity.

Why this answer

Cultural resistance to security controls from business units is a common challenge because security teams must balance risk mitigation with operational efficiency. Business units often perceive controls like mandatory encryption or access restrictions as hindrances to productivity, leading to shadow IT or workarounds that undermine the program's effectiveness.

Exam trap

The trap here is that candidates may confuse 'challenges in implementing' with 'consequences of poor implementation,' leading them to select options like D (lack of training) which is a result, not a root implementation hurdle.

55
MCQhard

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

A.Ignore the fourth party as it is outside the organization's scope
B.Conduct a direct assessment of the fourth party
C.Terminate the contract with the vendor
D.Request the vendor to assess and pass through security requirements to its suppliers
AnswerD

Fourth-party risk cannot be assessed directly by the organisation, so contractual flow-down is the practical control. Requiring the vendor to assess its own suppliers and pass through equivalent security requirements extends governance across the supply chain, satisfying the nth-party visibility constraint the stem describes.

Why this answer

The correct answer is D because the organization cannot directly assess every fourth party in its vendor's supply chain, but it can contractually require the vendor to flow down security requirements and assess its own suppliers. This is the standard nth-party risk management approach recommended by frameworks like NIST SP 800-161 and ISO 28000. It maintains accountability through the vendor while extending controls to the fourth party.

Exam trap

CISM often tests the misconception that an organization must directly assess all parties in its supply chain, when in fact the best practice is to require the vendor to manage and assess its own suppliers through contractual flow-down.

How to eliminate wrong answers

Option A is wrong because ignoring the fourth party leaves a critical blind spot in the risk assessment, especially since the fourth party has access to sensitive customer data. Option B is wrong because conducting a direct assessment of the fourth party is often impractical and may not be permitted by the vendor's contract; the organization typically has no direct relationship with the fourth party. Option C is wrong because terminating the contract is a drastic overreaction that may not be necessary if the risk can be mitigated through contractual flow-down requirements.

56
MCQhard

An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?

A.Accept the risk until the monitoring solution is deployed and document the decision.
B.Implement interim compensating controls such as privileged access review, session logging, and least privilege while planning the monitoring deployment.
C.Transfer the risk by purchasing cyber insurance covering insider fraud.
D.Defer the risk decision to the application owner because they own the budget.
AnswerB

Interim compensating controls reduce exposure immediately while the strategic control is deployed. Privileged access reviews, session logging, and least privilege directly address insider misuse of privileged accounts at low cost. This approach balances risk reduction with the budget and timeline constraints and demonstrates due diligence to regulators.

Why this answer

When a strategic control cannot be deployed quickly, interim compensating controls reduce exposure in the near term. Privileged access reviews, session logging, and least privilege target the insider misuse scenario directly and are feasible within budget. Acceptance, insurance-only transfer, or full delegation do not adequately address a high-likelihood compliance risk during the deployment gap.

Exam trap

The trap here is assuming that a planned future control justifies accepting the risk in the interim without compensating measures.

57
MCQmedium

A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?

A.Update the information security strategy to include merger integration goals.
B.Conduct a security risk assessment of the target company's environment.
C.Implement security controls from the acquiring company on the target's systems.
D.Develop a security integration plan for post-merger activities.
AnswerB

This is correct because a security risk assessment of the target company identifies vulnerabilities, control gaps, and potential threats that could affect the merged entity. It provides the board with the necessary information to make informed decisions about integration and risk mitigation, aligning security with the business objective of a successful merger.

Why this answer

The correct answer is to conduct a security risk assessment of the target company's environment. This step is foundational because it identifies risks that must be managed during the merger. It enables the CISO to provide the board with a clear picture of the security landscape, ensuring that subsequent actions such as strategy updates or control implementations are based on actual risks rather than assumptions.

Exam trap

The trap here is assuming that updating the security strategy or implementing controls should come first, but without a risk assessment, these actions may not address the actual risks of the merger.

58
MCQeasy

An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?

A.The latest cybersecurity threats reported in the industry.
B.Past security incidents that caused significant financial loss.
C.Business requirements derived from risk assessment and compliance obligations.
D.The security budget allocated for the fiscal year.
AnswerC

Controls must map to business requirements, which risk assessment and compliance obligations define. This ties spending to the institution's actual risk exposure and regulatory duties, ensuring security supports business objectives rather than technology preferences or vendor defaults.

Why this answer

Business requirements derived from risk assessment and compliance obligations are the primary driver because they directly align security controls with the institution's specific risk appetite, regulatory mandates (e.g., PCI DSS, SOX, GDPR), and operational needs. This ensures controls are cost-effective and prioritized based on actual exposure rather than reactive or budget-driven decisions.

Exam trap

The trap here is that candidates often pick 'past security incidents' (Option B) because it feels intuitive, but CISM emphasizes a proactive, risk-based governance approach where business requirements and compliance drive control selection, not historical events or budget constraints.

How to eliminate wrong answers

Option A is wrong because focusing solely on the latest cybersecurity threats can lead to chasing trends and implementing controls that do not address the institution's unique risk profile, resulting in wasted resources and potential gaps. Option B is wrong because past incidents, while informative, represent a reactive approach that may not cover emerging or unexperienced risks, and can over-prioritize controls for rare events while ignoring systemic vulnerabilities. Option D is wrong because letting the security budget dictate control selection can result in underfunding critical areas or over-investing in low-priority controls, bypassing the risk-based prioritization that governance frameworks require.

59
MCQhard

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

A.Notify affected customers of the expected delay
B.Continue containment efforts and hope for a faster recovery
C.Escalate to the BC/DR team and the authority who can declare a disaster
D.Shut down the affected system to prevent further impact
AnswerC

When recovery exceeds the maximum tolerable downtime, the incident manager must escalate to the BC/DR team and the authority empowered to declare a disaster, since only that authority can activate continuity arrangements and commit resources beyond the IR team's remit. Continuing technical recovery alone would breach the MTD.

Why this answer

When MTD is exceeded, the incident escalates to business continuity/disaster recovery activation. The BC/DR decision authority should be notified to declare a disaster and activate recovery plans.

60
MCQmedium

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

A.Security budget variance
B.Mean time to detect incidents
C.Phishing simulation click rate
D.Number of security policies updated
AnswerC

Phishing simulation click rate directly measures whether staff apply awareness training by resisting real lures, giving behavioural evidence of programme effectiveness. It satisfies the stem's need for a metric reflecting actual security awareness rather than attendance or completion.

Why this answer

Phishing simulation click rate directly measures how many employees fall for simulated phishing attacks, which is a key indicator of security awareness and the effectiveness of training. A decreasing click rate over time typically indicates improved awareness.

Exam trap

CISM often tests the difference between activity metrics (e.g., number of policies updated, training completion) and effectiveness metrics (e.g., phishing click rate, incident reduction), and candidates may choose a metric that is easy to measure but does not reflect actual awareness.

How to eliminate wrong answers

Option A is wrong because security budget variance measures financial performance, not the effectiveness of awareness training. Option B is wrong because mean time to detect incidents measures the security operations team's detection capabilities, not employee awareness. Option D is wrong because the number of security policies updated is a compliance or documentation metric, not a measure of whether employees understand and apply security practices.

61
MCQmedium

During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?

A.Monitor the connection further without taking action.
B.Block the IP address immediately to prevent data exfiltration.
C.Notify law enforcement about the IP address.
D.Check threat intelligence feeds to confirm maliciousness.
AnswerD

Confirming the IP is genuinely malicious through threat intelligence prevents blocking legitimate business partners or shared infrastructure, which could disrupt operations. Verification establishes attribution and confidence before firewall changes, aligning with the plan's requirement for a defensible blocking decision.

Why this answer

The incident response team must first validate the maliciousness of the IP address using threat intelligence feeds before taking any irreversible action. Blocking an IP without confirmation could disrupt legitimate business operations or tip off an attacker, and the CISM framework emphasizes evidence-based decision-making during incident response.

Exam trap

The trap here is that candidates often choose 'Block the IP immediately' (Option B) because they equate speed with effective containment, but CISM stresses that containment actions must be risk-informed and validated to avoid collateral damage and legal liability.

How to eliminate wrong answers

Option A is wrong because passively monitoring a confirmed malware communication without action risks ongoing data exfiltration and violates the principle of timely containment. Option B is wrong because immediately blocking the IP without verification could cause a denial of service to legitimate services hosted on that IP (e.g., a shared CDN or cloud provider) and may destroy forensic evidence of the C2 channel. Option C is wrong because notifying law enforcement is premature before internal validation and containment; law enforcement notification typically occurs after the organization has confirmed maliciousness and secured its own evidence chain.

62
MCQeasy

A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?

A.Shut down the workstation to stop the malware.
B.Notify the CEO and board of directors about the incident.
C.Run a full antivirus scan on the workstation.
D.Isolate the workstation from the network to prevent further communication.
AnswerD

Isolating the workstation is the immediate containment step that stops the malware from communicating with the command-and-control server and prevents potential lateral movement or data exfiltration. This aligns with the containment phase of incident response. Once isolated, the team can conduct a thorough investigation and remediation without the risk of the attacker continuing to operate.

Why this answer

When a true positive is confirmed, the immediate priority is containment to stop the threat from spreading or causing further harm. Isolating the workstation cuts off command-and-control communication while preserving the system for investigation. This follows the standard incident response sequence of identification, containment, eradication, and recovery, and supports both security and forensic objectives.

Exam trap

The trap here is choosing to shut down or scan the workstation first, which can either destroy evidence or leave the attacker connected, instead of isolating it to contain the threat.

63
MCQeasy

During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?

A.Proceed with disconnection immediately to prevent further damage
B.Keep the server connected but block all inbound/outbound traffic
C.Perform a full disk imaging before disconnection
D.Collect volatile data (memory, processes) before disconnecting
AnswerD

Memory contents and running processes are lost the moment power or network isolation terminates the session, so capturing volatile data first preserves forensic evidence. Containment still proceeds immediately afterwards, satisfying both the investigation and containment objectives.

Why this answer

Volatile data (e.g., memory contents, running processes, network connections) is lost when power is removed or the network interface is disabled. The CIRT leader must follow the order of volatility (RFC 3227) and capture this data first to preserve forensic evidence before containment actions that alter the system state.

Exam trap

The trap here is that candidates may prioritize containment speed (Option A) over forensic preservation, forgetting that volatile data is irrecoverable once the system is powered off or disconnected.

How to eliminate wrong answers

Option A is wrong because immediate disconnection destroys volatile evidence (e.g., memory, active network sessions) that may be critical for attribution and root cause analysis. Option B is wrong because blocking all traffic does not prevent the server from being remotely wiped or overwritten by an attacker, and it still risks loss of volatile data if the system crashes or is shut down. Option C is wrong because full disk imaging captures only non-volatile data; volatile data (e.g., RAM, process list) must be collected separately before any power-off or disconnection.

64
MCQeasy

Which of the following is the PRIMARY responsibility of the CISO in an organization?

A.Managing the IT infrastructure
B.Auditing security controls
C.Performing day-to-day security operations
D.Owning the information security strategy and programme
AnswerD

The CISO owns the information security strategy and programme, aligning security objectives with business goals and reporting to executive leadership. This satisfies the stem's demand for the primary responsibility, distinguishing strategic ownership from operational tasks such as incident response or control implementation delegated to security managers.

Why this answer

The CISO is a senior executive whose primary accountability is owning and directing the information security strategy and programme, aligning it with business objectives and reporting to the board or CEO. This strategic ownership distinguishes the role from operational or assurance functions. Managing infrastructure, auditing controls, and running day-to-day operations are execution responsibilities delegated to IT, audit, and security operations teams respectively.

Exam trap

CISM often tests role boundaries — candidates confuse the CISO's strategic ownership with hands-on operational or audit duties, picking 'auditing security controls' or 'day-to-day operations' because those sound security-related, but governance exams reward the strategic answer.

How to eliminate wrong answers

Option A is wrong because managing IT infrastructure is an IT operations/CIO responsibility, not the CISO's strategic mandate — the CISO sets direction and governance, not server or network administration. Option B is wrong because auditing security controls is an independent assurance function typically performed by internal audit or a third party; if the CISO audited their own programme it would violate separation of duties. Option C is wrong because performing day-to-day security operations (triage, monitoring, patching) is tactical work done by SOC analysts and engineers, not the CISO, whose focus is strategy, risk appetite, and programme governance.

65
MCQeasy

A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?

A.Commission a penetration test of the electronic health record system.
B.Purchase cyber insurance to transfer residual risk to a third party.
C.Deploy an endpoint detection and response tool across all clinical workstations.
D.Define the security strategy and obtain executive approval for the governance framework and charter.
AnswerD

Governance begins with an approved strategy, charter, and clear accountability, which give the security programme authority and direction. Establishing these first ensures subsequent risk assessments, policies, and control investments are sanctioned by leadership and aligned with the provider's obligations, rather than emerging piecemeal from technical teams.

Why this answer

Governance is about direction, accountability, and decision rights. A newly appointed security leader must first secure executive approval of a strategy and governance charter so the programme has authority and alignment. Technical assessments, tools, and insurance are treatments applied once governance establishes priorities, risk appetite, and responsibilities, and performing them first inverts the correct sequence.

Exam trap

The trap here is equating governance with buying security technology or insurance instead of establishing strategy, charter, and accountability first.

66
MCQeasy

What is the primary purpose of a security incident near-miss reporting culture?

A.To increase the security budget
B.To reduce the number of security policies
C.To assign blame for potential incidents
D.To identify and address security gaps proactively
AnswerD

Near-miss reporting captures events that could have caused harm but did not, letting the organisation remediate weaknesses before a real incident exploits them. This directly satisfies the stem's proactive purpose by surfacing control gaps early rather than reacting after damage occurs.

Why this answer

A near-miss reporting culture encourages employees to report events that could have caused harm but did not, so the organisation can analyse root causes and close gaps before a real incident occurs. It is fundamentally proactive: it surfaces latent weaknesses in controls, processes, and human factors. Blame-free reporting is essential because fear of punishment suppresses disclosure and destroys the data needed for improvement.

Exam trap

CISM often tests the proactive versus reactive distinction — candidates may pick 'assign blame' because incident investigations do attribute cause, but near-miss culture is explicitly blame-free and forward-looking, so the exam rewards the proactive learning answer.

How to eliminate wrong answers

Option A is wrong because increasing the security budget is an outcome that may or may not follow; near-miss reporting is about learning and risk reduction, not funding advocacy. Option B is wrong because reducing the number of security policies is unrelated — if anything, near-miss analysis may reveal the need for clearer or additional policies. Option C is wrong because assigning blame is the opposite of the intent; punitive cultures deter reporting, whereas near-miss programmes deliberately separate the human error from the system fix to maximise disclosure.

67
MCQeasy

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

A.Implement technical controls
B.Conduct a risk assessment
C.Purchase security tools
D.Develop security policies
AnswerB

A risk assessment identifies threats, vulnerabilities and business impacts, establishing which controls and priorities the programme needs. It satisfies the stem's first-step requirement by grounding the information security programme in the organisation's actual risk profile before policies, controls or budgets are selected.

Why this answer

Conducting a risk assessment is the foundational first step in developing an information security program because it identifies and prioritizes the specific threats, vulnerabilities, and business impacts that the program must address. Without a risk assessment, any subsequent policies, controls, or tools would be based on assumptions rather than the organization's actual risk profile, leading to misallocated resources and ineffective security. This aligns with the CISM framework, which emphasizes that risk management drives the entire security program lifecycle.

Exam trap

The trap here is that candidates often confuse the logical sequence by thinking 'policies come first' (Option D) because policies seem foundational, but CISM emphasizes that risk assessment must precede policy development to ensure policies are risk-driven and not just compliance checklists.

How to eliminate wrong answers

Option A is wrong because implementing technical controls before understanding the risks can result in deploying irrelevant or misconfigured controls (e.g., a WAF without knowing which web application vulnerabilities exist), wasting budget and potentially creating a false sense of security. Option C is wrong because purchasing security tools without a prior risk assessment leads to tool sprawl and integration issues, such as buying an SIEM without first identifying which log sources are critical to monitor. Option D is wrong because developing security policies without a risk assessment may produce generic, non-contextual policies (e.g., a password policy that doesn't account for the specific threat of credential stuffing against the company's legacy authentication system), making them unenforceable or irrelevant.

68
MCQeasy

A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?

A.Implementing security controls to mitigate identified risks.
B.Purchasing cyber insurance to transfer risk.
C.Conducting a risk assessment to identify and prioritize risks.
D.Developing a disaster recovery plan for the e-commerce platform.
AnswerC

The first step in risk management is to identify and assess risks. This involves understanding the assets, threats, vulnerabilities, and potential impacts. For an e-commerce platform, this includes risks to customer data, payment processing, and availability. A risk assessment provides the foundation for all subsequent risk management activities, ensuring that controls are applied where they are most needed and that resources are allocated effectively.

Why this answer

The correct answer is conducting a risk assessment to identify and prioritize risks. Risk management begins with understanding the risks to the organization's assets and objectives. This assessment informs all subsequent decisions, including which controls to implement, what risks to transfer, and how to plan for recovery.

It ensures that efforts are targeted and effective.

Exam trap

The trap here is jumping to risk treatment options like controls, insurance, or disaster recovery without first conducting a risk assessment to understand what needs to be treated.

69
MCQeasy

An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?

A.Implement technical controls to enforce the policy.
B.Conduct an audit to measure compliance.
C.Communicate the policy to all relevant stakeholders and provide training.
D.Enforce disciplinary actions for non-compliance.
AnswerC

Approved policy alone cannot change behaviour; effectiveness depends on awareness. Communicating to all relevant stakeholders and delivering training ensures every affected party understands their obligations, satisfying the governance committee's intent that the policy actually be followed and enforced across the organisation.

Why this answer

After a policy is approved, the next critical step is to communicate it to all relevant stakeholders and provide training, because a policy that nobody knows about cannot be followed or enforced. Awareness and training are the bridge between approval and actual behavior change, and they are prerequisites for meaningful compliance measurement or enforcement.

Exam trap

CISM often tests the sequence of the policy lifecycle — candidates jump to enforcement or auditing because those sound more 'critical,' but communication and awareness must precede both.

How to eliminate wrong answers

Option A is wrong because implementing technical controls before communicating the policy means users are blocked by controls they do not understand, which creates friction and bypass attempts. Option B is wrong because auditing compliance before the policy has been communicated would measure non-compliance caused by ignorance, not by intent. Option D is wrong because disciplinary action is a last-resort enforcement mechanism and is inappropriate before awareness and training have been delivered.

70
MCQmedium

A financial services firm has activated its crisis management team (CMT) for a significant data breach. The CISO, who is a member of the CMT, is asked to present the technical details of the incident. However, the CMT's primary focus should be on which of the following?

A.Making strategic decisions regarding business continuity and stakeholder communication.
B.Coordinating the technical recovery of affected systems.
C.Conducting a forensic analysis to determine the root cause.
D.Directly managing the incident response team's daily activities.
AnswerA

The CMT is responsible for strategic decision-making during a crisis, including ensuring business continuity, managing communications with stakeholders, and aligning incident response with organizational objectives. Technical details are important but are inputs to these decisions. The CMT focuses on the big picture, such as whether to shut down systems, how to inform customers, and how to maintain trust.

Why this answer

The CMT's primary role during a major incident is to make strategic decisions that affect the entire organization, such as business continuity, resource allocation, and stakeholder communication. While technical input is valuable, the CMT must focus on the broader impact and ensure that the response aligns with business objectives. This separation of strategic and tactical responsibilities is a key CISM principle.

Exam trap

The trap here is assuming the CMT is involved in technical recovery or forensic analysis, when its focus is strategic business decisions.

71
Multi-Selectmedium

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Select 2 answers
A.An insurance claim form for cyber incidents
B.A signed retainer agreement with a forensics firm
C.A list of affected customers from the most recent data breach
D.A root cause analysis report from a previous incident
E.An incident response team with assigned roles and responsibilities
AnswersB, E

A pre-negotiated retainer with a forensics firm guarantees specialist capacity and defined rates are available immediately, avoiding procurement delays during containment. This satisfies the stem's requirement that the component be established before an incident occurs, since forensic demand spikes and vendors cannot be onboarded mid-crisis.

Why this answer

Option B is correct because a signed retainer agreement with a forensics firm is a pre-established arrangement that guarantees rapid access to specialized digital forensics and incident handling expertise when an incident occurs, avoiding delays from procurement or negotiation during a crisis. Option E is correct because an incident response team with clearly assigned roles and responsibilities is a foundational element of any incident response programme, ensuring that containment, eradication, recovery, and communication tasks are executed by accountable personnel per the incident response plan. The remaining options are not essential pre-incident components: A (an insurance claim form) is used after an incident to seek reimbursement, C (a list of affected customers) is an output of breach investigation and notification rather than a preparatory component, and D (a root cause analysis report from a previous incident) is a post-incident artifact that may inform lessons learned but is not required to establish the programme.

72
MCQhard

An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?

A.$400,000
B.$10,000,000
C.$500,000
D.$2,000,000
AnswerA

Annualised loss expectancy multiplies single loss expectancy by annualised rate of occurrence. A $2 million loss every five years gives an exposure factor of 0.2 per year, yielding $400,000. This satisfies the policy's quantitative requirement by expressing expected annual loss in monetary terms, enabling direct comparison against control costs.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, the ARO is 1/5 = 0.2 (one event every five years), and the SLE is $2,000,000. Thus, ALE = 0.2 × $2,000,000 = $400,000.

Exam trap

The trap here is that candidates often confuse the recurrence interval (every 5 years) with the ARO, mistakenly multiplying the loss by 5 instead of dividing, leading to the inflated $10,000,000 option.

How to eliminate wrong answers

Option B is wrong because $10,000,000 results from multiplying the loss ($2M) by 5 (the number of years between occurrences) instead of dividing, which incorrectly inflates the annualized loss. Option C is wrong because $500,000 would be the ALE if the ARO were 0.25 (once every 4 years), not the given 0.2. Option D is wrong because $2,000,000 is the single loss expectancy (SLE), not the annualized figure; it ignores the frequency of occurrence entirely.

73
MCQmedium

A newly appointed CISO is establishing an information security governance framework. The organization has a complex structure with multiple business units, each with its own IT function. The CISO wants to ensure that security decisions are made with input from all relevant stakeholders and that security risks are managed consistently across the enterprise. Which of the following should be the CISO's FIRST step in establishing this framework?

A.Implement a security awareness training program for all employees to build a security culture.
B.Conduct a comprehensive security risk assessment to identify all vulnerabilities and threats.
C.Create a security steering committee composed of senior leaders from each business unit and key corporate functions.
D.Develop a detailed information security policy manual that mandates compliance from all business units.
AnswerC

A security steering committee provides a governance structure for cross-functional decision-making and consistent risk management. It ensures that security is aligned with business objectives and that all stakeholders have a voice. This is a foundational step in establishing governance because it creates the mechanism for oversight and direction, enabling the CISO to drive policy, risk appetite, and resource allocation across the enterprise.

Why this answer

Establishing a security steering committee is the foundational step for governance because it creates the decision-making body that aligns security with business strategy, ensures cross-functional representation, and provides oversight for risk management. Without this structure, subsequent activities like risk assessment, policy development, and awareness training may lack coordination and strategic alignment.

Exam trap

The trap here is assuming that a technical activity like risk assessment or policy writing must come first, when governance actually begins with establishing decision-making structures and accountability.

74
Multi-Selecteasy

Which TWO of the following are components of a typical vulnerability management program?

Select 2 answers
A.Conducting security awareness training
B.Remediating identified vulnerabilities through patching
C.Monitoring network traffic for anomalies
D.Performing penetration tests
E.Conducting regular vulnerability scans
AnswersB, E

Patching directly satisfies the remediation phase of the vulnerability management lifecycle, converting identified weaknesses into resolved risk. A typical programme requires this corrective action alongside discovery and assessment; without remediation, scanning yields no risk reduction. It therefore constitutes a core component, matching the stem's requirement for programme elements.

Why this answer

A vulnerability management program is built around a continuous cycle of discovering, prioritizing, and fixing weaknesses, so option E (conducting regular vulnerability scans) is correct because recurring authenticated and unauthenticated scans are the primary discovery mechanism that populates the vulnerability inventory. Option B (remediating identified vulnerabilities through patching) is correct because remediation—applying vendor patches, configuration changes, or compensating controls—closes the loop and is the ultimate goal of the program; scanning without remediation provides no risk reduction. Option A (security awareness training) belongs to a security education/awareness program, not vulnerability management, since it targets human behavior rather than technical weaknesses.

Option C (monitoring network traffic for anomalies) is a detection/incident-monitoring activity typically handled by IDS/IPS, SIEM, or SOC operations, not vulnerability management. Option D (performing penetration tests) is an offensive security assessment that can validate and supplement a vulnerability management program, but it is a point-in-time testing exercise rather than a core component of the ongoing scan-and-remediate process.

Exam trap

CISM often tests the distinction between vulnerability management (proactive identification and remediation of weaknesses) and other security functions like awareness training, monitoring, or penetration testing, causing candidates to select adjacent activities that are not core components.

75
Multi-Selecthard

An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)

Select 2 answers
A.Determine the root cause of the breach.
B.Confirm that the breach actually occurred.
C.Implement full remediation.
D.Consult with legal counsel regarding notification obligations.
E.Assess the impact on affected individuals.
AnswersB, E

Correct: Essential before any notification.

Why this answer

The incident response team must first confirm that a breach actually occurred before taking any further action, including notification. Premature notification without confirmation can lead to false alarms, legal liability, and reputational damage. Confirmation involves verifying indicators of compromise (IoCs) through log analysis, forensic evidence, and chain-of-custody procedures.

Exam trap

A common pitfall in the CISM exam is that candidates often prioritize immediate notification over the necessary steps of confirming the breach and assessing its impact. They may incorrectly select root cause analysis or legal consultation as the first actions before confirmation.

Page 1 of 13

Page 2