Courseiva

Certified Information Security Manager CISM (CISM) — Questions 175

871 questions total · 12pages · All types, answers revealed

Page 1 of 12

Page 2
1
Multi-Selectmedium

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Select 3 answers
A.Employee's years of service
B.Employee role and job function
C.Past phishing click rate trends
D.Number of security incidents in the past year
E.Current threat landscape and prevalent attack types
AnswersB, C, E

Different roles face different phishing risks.

Why this answer

Employee role, past click rates, and current threat landscape help tailor simulations for effectiveness and relevance.

2
MCQmedium

After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?

A.Re-assess the risk using a different methodology
B.Lower the risk tolerance to match the residual risk
C.Seek management approval for acceptance or implement additional controls
D.Ignore the residual risk since controls are already in place
AnswerC

This aligns with risk management process.

Why this answer

When residual risk exceeds the established risk tolerance, the organization must either implement additional controls to reduce the risk further or formally accept the residual risk through management approval. This aligns with the risk treatment decision-making process in ISO 31000 and the CISM framework, where risk acceptance is a management responsibility. Option C correctly identifies these two valid paths.

Exam trap

The CISM exam often tests the misconception that risk assessment methodology changes can resolve residual risk issues, but the trap here is that candidates may choose Option A, thinking a different methodology will yield a more favorable result, when in fact the correct action is to treat the risk through additional controls or formal acceptance.

How to eliminate wrong answers

Option A is wrong because re-assessing with a different methodology does not change the actual risk level; it only changes the measurement, which is a form of risk avoidance through redefinition rather than proper treatment. Option B is wrong because lowering the risk tolerance to match the residual risk is a reactive and inappropriate response that undermines the risk appetite set by the organization; risk tolerance should drive control decisions, not be adjusted to fit uncontrolled risk. Option D is wrong because ignoring residual risk violates the fundamental principle of risk management that requires continuous monitoring and response when risk exceeds tolerance; controls do not absolve the organization from addressing unacceptable residual risk.

3
MCQmedium

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

A.To avoid the need for a chain of custody
B.To ensure the firm understands the organization's IT environment
C.To guarantee lower costs
D.To reduce the time needed to engage the firm when an incident occurs
AnswerD

A pre-signed retainer allows immediate deployment without contract delays.

Why this answer

Having a pre-negotiated contract reduces the time to engage forensic experts, which is critical during an incident.

4
MCQmedium

During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?

A.Conduct a security awareness training for the target company's employees.
B.Perform a comprehensive risk assessment of the target company's security posture.
C.Align the target company's security policies with the acquirer's policies.
D.Implement the acquirer's security governance framework immediately.
AnswerB

Initial assessment informs integration strategy.

Why this answer

Without a formal security governance structure, the CISO must first understand the target company's current security posture through a comprehensive risk assessment. This step identifies vulnerabilities, threats, and gaps in controls, providing the baseline data needed to prioritize integration efforts and align with the acquirer's governance framework. Skipping this assessment risks implementing policies that are irrelevant or ineffective against the target's actual risks.

Exam trap

ISACA often tests the principle that governance integration must begin with understanding the current state (risk assessment) rather than jumping to policy alignment or implementation, which is a common mistake candidates make by assuming immediate enforcement is the first step.

How to eliminate wrong answers

Option A is wrong because conducting security awareness training before understanding the target's risk profile and existing security gaps is premature; training should be tailored to identified risks and policies, not implemented in a vacuum. Option C is wrong because aligning security policies without first assessing the target's current state can result in policies that conflict with existing technical controls or fail to address critical vulnerabilities. Option D is wrong because immediately implementing the acquirer's governance framework without a risk assessment may disrupt operations, miss unknown threats, and create resistance due to lack of contextual understanding.

5
MCQhard

An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?

A.Continue current mitigation efforts and reassess after another hour.
B.Increase the capacity of the DDoS mitigation service.
C.Escalate to the crisis management team to consider activating the disaster recovery plan.
D.Notify customers of a prolonged outage.
AnswerC

This allows for a timely decision to invoke BC/DR before MTD expires.

Why this answer

If an incident cannot be resolved within the MTD, it should transition to BC/DR activation. The decision authority (e.g., CISO or CMT) should declare a disaster.

6
MCQeasy

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

A.Outsource incident response to a managed security service provider (MSSP).
B.Create a dedicated incident response team that reports directly to the CISO.
C.Purchase a new SIEM solution to improve detection accuracy.
D.Develop a detailed incident response coordination plan with defined roles and communication channels, and conduct quarterly joint exercises.
AnswerD

Cost-effective and directly improves coordination.

Why this answer

Correct answer is D because developing a detailed incident response coordination plan with defined roles and communication channels, and conducting quarterly joint exercises, directly addresses the coordination gap at low cost. Option A (outsourcing) is expensive and may not align with government requirements. Option B (dedicated team) could be costly and does not leverage existing staff.

Option C (new SIEM) does not fix coordination.

7
MCQeasy

Which of the following is a leading indicator of security program effectiveness?

A.Phishing click rate
B.Mean time to detect (MTTD)
C.Breach count
D.Number of security incidents
AnswerA

Phishing click rate is a leading indicator of user susceptibility and can be tracked proactively.

Why this answer

Leading indicators predict future security performance, and phishing click rate is a proactive measure that can be improved before a breach occurs.

8
MCQmedium

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

A.Notifying law enforcement and regulatory bodies immediately.
B.Directly managing the technical containment and eradication of the threat.
C.Making strategic decisions, managing communications, and allocating resources.
D.Performing forensic analysis to identify the root cause of the incident.
AnswerC

The CMT provides executive-level oversight and decision-making.

Why this answer

The CMT handles strategic decisions, communication, and resource allocation, while the IR team focuses on technical response.

9
MCQmedium

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

A.Vendor's annual revenue
B.Length of business relationship
C.Contract value
D.Type of data accessed and service criticality
AnswerD

Risk is driven by data sensitivity and business impact.

Why this answer

Vendor tiering should be based on the risk they pose. Data access and service criticality directly affect organizational risk.

10
MCQmedium

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

A.Include security requirements after contract signing
B.Require third parties to self-attest compliance
C.Embed security clauses in request for proposals (RFPs)
D.Conduct periodic security audits of third parties
AnswerC

This ensures security is a contractual requirement from the start.

Why this answer

Embedding security clauses in RFPs ensures that security requirements are formally communicated to potential vendors before any contractual agreement, making them a mandatory part of the procurement process. This proactive approach aligns with the CISM principle of integrating security into business processes from the outset, rather than retrofitting controls after contracts are signed. By specifying requirements such as encryption standards (e.g., AES-256), incident response SLAs, and compliance with frameworks like ISO 27001 in the RFP, the organization can evaluate vendor capabilities upfront and avoid costly renegotiations.

Exam trap

The trap here is that candidates often choose option D (periodic audits) because it seems like a thorough security measure, but they fail to recognize that without security clauses embedded in the RFP, the organization lacks contractual authority to enforce audit findings or require specific technical controls. In CISM, security requirements should be integrated during the procurement process, not after contracts are signed.

How to eliminate wrong answers

Option A is wrong because including security requirements after contract signing is reactive and often leads to weak or unenforceable controls, as vendors may resist changes or lack the technical capability to implement them retroactively. Option B is wrong because self-attestation lacks independent verification and is inherently unreliable; vendors may claim compliance with controls like access logging or data encryption without providing evidence, leaving the organization vulnerable to misrepresentation. Option D is wrong because periodic security audits are a detective control that occurs after the vendor is already engaged, and without contractual security clauses in the RFP, the organization has no legal basis to enforce audit findings or mandate remediation.

11
MCQeasy

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

A.Full-scale exercise
B.Simulation
C.Drill
D.Tabletop exercise
AnswerD

Tabletop exercises are discussion-based and used to validate plans and procedures.

Why this answer

A tabletop exercise is a discussion-based exercise where team members walk through a scenario to identify strengths and gaps.

12
MCQmedium

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

A.Provide annual security training to all developers.
B.Assign a security champion to each development team and create a lightweight secure coding checklist.
C.Establish a separate security team that reviews all code after development is complete.
D.Implement a mandatory security gate before each release, requiring a full security review.
AnswerB

Incorporates security into the process without heavy process overhead.

Why this answer

Assigning a security champion to each team and creating a lightweight secure coding checklist integrates security into the agile development process without causing significant friction. Security champions provide ongoing guidance and can help enforce secure coding practices in real-time, which aligns with the rapid release cycles. Option A (annual training) is insufficient to change behavior and does not provide continuous oversight.

Option C (separate security team review after development) introduces delays and friction, as developers have already completed their work. Option D (mandatory security gate before release) can cause bottlenecks and resentment, likely being bypassed or causing slowdowns that the company wants to avoid.

13
MCQeasy

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

A.Incident response plan
B.Incident response policy
C.Incident response playbook
D.Communication template
AnswerC

Playbooks provide step-by-step guidance for specific incident types.

Why this answer

Playbooks (or runbooks) provide detailed procedures for specific incident types, while the IR plan is a broader document.

14
MCQhard

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

A.SSL/TLS encryption and VPN access
B.Web application firewall (WAF) and intrusion detection system (IDS)
C.WAF, input validation, and security logging
D.Regular patching and vulnerability scanning
AnswerC

Combines prevention, detection, and monitoring.

Why this answer

Defense-in-depth at the web application layer requires overlapping controls: prevention (input validation), detection (WAF), and monitoring/response (security logging). Option A (SSL/TLS and VPN) provides encryption but does not prevent application-layer attacks. Option B (WAF and IDS) misses a preventive control like input validation.

Option D (patching and scanning) addresses vulnerabilities but lacks real-time detection and response.

15
MCQeasy

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

A.CISO reports to the CFO
B.CISO reports to the CEO or board of directors
C.CISO reports to the CIO
D.CISO reports to the head of internal audit
AnswerB

This structure provides independence and direct access to top management, enhancing authority.

Why this answer

Reporting to the board or a senior executive not directly responsible for IT operations ensures independence and reduces conflicts of interest.

16
MCQhard

During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?

A.Inadequate security awareness training
B.Lack of an incident response plan
C.Absence of a procurement security policy
D.Weak access control over cloud resources
AnswerC

A procurement policy should require security review before purchasing cloud services.

Why this answer

The scenario describes business units procuring cloud services without IT security involvement, which directly indicates the absence of a procurement security policy. Such a policy would mandate security review and approval before any cloud service acquisition, ensuring that security requirements are integrated into the procurement lifecycle. Without it, security is bypassed, leading to ungoverned shadow IT and potential compliance violations.

Exam trap

The trap here is that candidates often confuse a lack of security awareness training (Option A) with the governance failure, but the scenario specifically highlights the absence of a formal procurement process, not a training gap.

How to eliminate wrong answers

Option A is wrong because inadequate security awareness training focuses on user behavior and phishing risks, not on the procedural failure to involve security in procurement decisions. Option B is wrong because a lack of an incident response plan addresses post-breach actions, not the preventive governance gap that allows unauthorized cloud service purchases. Option D is wrong because weak access control over cloud resources is a technical control issue that arises after procurement, whereas the core deficiency here is the missing governance process to enforce security review before acquisition.

17
MCQeasy

During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?

A.A summary of actions taken so far
B.Detailed technical analysis
C.A timeline of all events
D.The root cause of the incident
AnswerA

A high-level summary keeps stakeholders informed while the team works on deeper analysis.

Why this answer

During an incident, the first communication to stakeholders should provide a summary of actions taken so far to establish transparency and demonstrate that the incident response team is actively managing the situation. This aligns with NIST SP 800-61r2 guidance, which prioritizes timely, high-level updates over detailed technical data to avoid overwhelming stakeholders and to maintain trust. Detailed technical analysis, timelines, and root cause determination typically require more investigation and are communicated in subsequent updates.

Exam trap

The CISM exam often tests the misconception that stakeholders need technical depth immediately, but the trap here is that candidates confuse 'first communication' with 'final report' and select root cause or timeline, forgetting that early incident response prioritizes containment status over investigation details.

How to eliminate wrong answers

Option B is wrong because detailed technical analysis is too granular for initial stakeholder communication; it should be reserved for technical teams or post-incident reports. Option C is wrong because a timeline of all events is typically compiled after the incident is contained and is not the first priority for stakeholders who need immediate status. Option D is wrong because the root cause is often unknown early in an incident; communicating an unconfirmed root cause can lead to misinformation and legal liability, per incident response best practices.

18
MCQmedium

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

A.Providing 24/7 security monitoring
B.Eliminating the need for security awareness training
C.Reducing the need for a dedicated security team
D.Embedding security expertise within development teams
AnswerD

Correct. Champions act as liaisons and advocates for security.

Why this answer

Security champions are advocates embedded in development teams to help integrate security into the development lifecycle, promoting secure development practices.

19
MCQmedium

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

A.Level 4 (Managed)
B.Level 2 (Repeatable)
C.Level 5 (Optimizing)
D.Level 3 (Defined)
AnswerC

Level 5 focuses on continuous improvement and optimization based on metrics.

Why this answer

Level 5 (Optimizing) focuses on continuous improvement through quantitative measurement.

20
MCQhard

An organization is under a DDoS attack that is saturating their internet link. The incident response team needs to mitigate the attack. Which action should be taken first?

A.Activate cloud-based DDoS mitigation services.
B.Shut down all public-facing services.
C.Implement rate limiting on the perimeter firewall.
D.Contact the ISP to null-route the attack IPs.
AnswerA

Correct: Scalable and effective.

Why this answer

Activating cloud-based DDoS mitigation services is the correct first step because these services are designed to absorb and scrub volumetric attacks at the network edge, before traffic reaches the saturated internet link. This preserves legitimate traffic while filtering malicious packets, which is critical when the link itself is overwhelmed and on-premises devices cannot process the volume.

Exam trap

The trap here is that when the link is saturated, only an upstream cloud-based service can absorb the volume before it reaches the organization's infrastructure. Rate limiting or null-routing are not effective first steps because the attack traffic is already overwhelming the link.

How to eliminate wrong answers

Option B is wrong because shutting down all public-facing services is a drastic, last-resort measure that causes complete denial of service to legitimate users, whereas the goal is to maintain availability during mitigation. Option C is wrong because implementing rate limiting on the perimeter firewall is ineffective when the internet link is already saturated; the firewall itself may become overwhelmed or drop legitimate traffic due to indiscriminate rate limits. Option D is wrong because contacting the ISP to null-route attack IPs is a reactive step that typically requires manual coordination and may take too long, and null-routing can also block legitimate traffic if the source IPs are spoofed or shared with valid users.

21
MCQmedium

An employee emails a spreadsheet containing employee salaries to all staff by mistake. According to the exhibit, what is the minimum handling requirement that was violated?

A.HighlyConfidential handling requirements
B.Confidential handling requirements
C.Internal handling requirements
D.Public handling requirements
AnswerB

Salaries are confidential; email lacks encryption and need-to-know.

Why this answer

The email containing employee salaries was sent to all staff, which is a violation of the 'Confidential' handling requirement. Confidential data, such as salary information, must be restricted to authorized recipients only, and mass distribution to all staff exceeds that authorization. The exhibit likely classifies salary data as 'Confidential', not 'HighlyConfidential', making option B the correct minimum violated requirement.

Exam trap

A common pitfall in ISACA CISM exams is the distinction between 'Confidential' and 'HighlyConfidential' classifications. Candidates often overclassify sensitive data like salary information as 'HighlyConfidential', but the minimum violated requirement is typically 'Confidential' when the data is not top-secret.

How to eliminate wrong answers

Option A is wrong because 'HighlyConfidential' handling requirements typically apply to data like trade secrets or PII with severe impact, and salary data is usually classified as 'Confidential' in standard data classification schemes. Option C is wrong because 'Internal' handling requirements apply to data that can be shared broadly within the organization but not externally, whereas salary data is more restricted than general internal data. Option D is wrong because 'Public' handling requirements apply to data intended for public disclosure, and salary data is never classified as public.

22
MCQmedium

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

A.Allow exceptions for senior executives
B.Delay implementation until user acceptance improves
C.Revoke remote access for non-compliant users
D.Provide training on the importance of MFA
AnswerD

Training addresses the root cause of complaints—lack of understanding—and promotes compliance.

Why this answer

Providing training helps users understand the necessity of MFA for security, addressing their concerns and gaining buy-in. Allowing exceptions (A) weakens security, delaying implementation (B) postpones protection, and revoking access (C) is too punitive as a first step.

23
MCQeasy

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

A.The incident response manager
B.The legal counsel
C.The IT director
D.The board of directors or executive management
AnswerD

Senior management approval ensures policy authority and resource commitment.

Why this answer

The IR policy requires senior management approval to demonstrate organizational commitment and allocate necessary resources.

24
MCQeasy

Refer to the exhibit. The exhibit shows network traffic from a server to a database. What does this pattern MOST likely indicate?

A.Query optimization issue
B.SQL injection attempt
C.Normal application load
D.Database server crash
AnswerB

SQL injection tools often create many connections to execute queries, matching the pattern.

Why this answer

The exhibit shows a pattern of repeated SQL query-like strings in the network traffic, such as 'SELECT * FROM users WHERE id = 1 OR 1=1', which is a classic SQL injection payload. This indicates an attacker is attempting to manipulate the SQL query to bypass authentication or extract data, not a normal application load or performance issue. The sudden spike in similar requests with malicious syntax confirms an active SQL injection attempt.

Exam trap

CISM often tests the distinction between a performance issue (like query optimization) and a security incident (like SQL injection) by presenting traffic patterns that look similar to slow queries but contain telltale injection syntax, tricking candidates into choosing the benign option.

How to eliminate wrong answers

Option A is wrong because query optimization issues typically show gradual performance degradation or repeated slow queries, not a burst of malformed SQL strings with injection patterns. Option C is wrong because normal application load would show consistent, well-formed queries without suspicious characters like 'OR 1=1' or comment sequences. Option D is wrong because a database server crash would manifest as connection timeouts, error codes, or abrupt traffic cessation, not a sustained stream of injection attempts.

25
MCQeasy

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

A.To ensure chain of custody
B.To reduce time to engage during an incident
C.To reduce legal liability
D.To guarantee confidentiality
AnswerB

Having a contract in place speeds up the hiring process.

Why this answer

The primary purpose of a pre-established forensic retainer agreement is to reduce the time to engage during an incident. By having a contract already in place, the organization can bypass procurement and legal review delays, enabling the forensics firm to begin work immediately when an incident occurs, which is critical for preserving volatile evidence and minimizing damage.

Exam trap

The trap is that candidates may think the retainer primarily ensures chain of custody or reduces liability, but the CISM exam focuses on the retainer's purpose of enabling rapid engagement during incidents.

How to eliminate wrong answers

Option A is wrong because chain of custody is a procedural and documentation requirement, not a contractual one; a retainer agreement does not directly ensure chain of custody—that is achieved through proper evidence handling and logging. Option C is wrong because while a retainer may include liability clauses, its primary purpose is not to reduce legal liability; liability reduction is a secondary benefit, and the main goal is rapid engagement. Option D is wrong because confidentiality is typically addressed via a separate non-disclosure agreement (NDA) or terms within the retainer, but the retainer's primary purpose is not to guarantee confidentiality—it is to pre-authorize and expedite forensic services.

26
Multi-Selecthard

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Select 3 answers
A.Chief executive officer (CEO)
B.General counsel (GC)
C.Security analyst
D.Incident response manager
E.Chief financial officer (CFO)
AnswersA, B, E

CEO provides executive leadership.

Why this answer

The CEO is correct because as the highest-ranking executive, they provide strategic direction, authorize critical decisions (e.g., public disclosure, resource allocation), and serve as the primary liaison to the board of directors during a major incident. The GC is correct because they manage legal risks, ensure compliance with breach notification laws (e.g., GDPR, CCPA), and oversee communications with regulators and law enforcement. The CFO is correct because they assess financial impacts, approve emergency budgets, and coordinate with insurance carriers for cyber liability claims.

Exam trap

The trap here is that candidates confuse the Incident Response Team (IRT) with the Crisis Management Team (CMT), incorrectly selecting operational roles like security analyst or incident response manager instead of the executive leadership roles that constitute the CMT.

27
MCQmedium

Refer to the exhibit. A system administrator reviews the log and notices repeated failed SSH attempts from the same IP address. What is the most appropriate risk response?

A.Change the password policy to require 12-character passwords.
B.Increase logging verbosity to capture more details.
C.Disable SSH access and use console only.
D.Implement account lockout after 3 failed attempts.
AnswerD

This control directly mitigates brute-force attacks by locking accounts.

Why this answer

Implementing an account lockout policy after 3 failed attempts directly mitigates brute-force SSH attacks by preventing further authentication attempts from the same IP address. This is a standard risk response (risk reduction) that limits the attacker's ability to guess credentials without requiring changes to the SSH protocol or disabling remote access entirely.

Exam trap

The trap here is that candidates confuse preventive controls (password policy) with detective controls (logging) or overcorrect with risk avoidance (disabling SSH), instead of recognizing that a targeted brute-force attack is best addressed with a specific technical control like account lockout that directly blocks the attack pattern.

How to eliminate wrong answers

Option A is wrong because changing the password policy to require 12-character passwords is a preventive control that reduces the likelihood of successful password guessing, but it does not stop repeated failed SSH attempts from the same IP address in real time; the attacker can still attempt unlimited guesses. Option B is wrong because increasing logging verbosity only improves detection and forensic analysis, not prevention or response; it does not stop the ongoing attack or reduce risk. Option C is wrong because disabling SSH access and using console only is an extreme risk avoidance that eliminates remote administration entirely, which is often operationally impractical and not the most appropriate response for a targeted brute-force attempt.

28
MCQhard

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

A.Industry analyst recommendations
B.Number of features compared to competitors
C.Total cost of ownership (TCO) analysis
D.Risk reduction value and breach cost avoidance
AnswerD

This directly links investment to avoided losses.

Why this answer

Comparing the cost of the tool against the average cost of a data breach (e.g., $4.35M) provides a clear financial justification.

29
Multi-Selectmedium

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Select 2 answers
A.Vulnerability scanning
B.Identity and access management
C.Incident response
D.Security monitoring and detection
E.Application security testing
AnswersC, D

Core SOC function.

Why this answer

A SOC focuses on monitoring, detection, and response. Vulnerability management and identity management are separate functions.

30
Multi-Selectmedium

A security manager is designing a security awareness program. Which TWO metrics are leading indicators of program effectiveness?

Select 2 answers
A.Knowledge assessment scores from training.
B.Phishing simulation click rate.
C.Number of security incidents reported by employees.
D.Number of phishing emails reported by users.
E.Mean time to detect (MTTD) a phishing attack.
AnswersA, B

Indicates retention of training content.

Why this answer

Leading indicators predict future performance. Phishing click rate and knowledge assessment scores measure current behavior and knowledge, which can predict future incidents.

31
Multi-Selecthard

Which of the following are key components of a mature information security program? (Select 2)

Select 2 answers
A.Comprehensive risk management process
B.Adoption of cloud security tools
C.Continuous monitoring and improvement
D.Single point of failure for security decisions
AnswersA, C

Why this answer

A comprehensive risk management process is a foundational component of a mature information security program because it ensures that security controls are aligned with business objectives through systematic identification, assessment, and treatment of risks. This process, often guided by frameworks like ISO 31000 or NIST SP 800-39, enables prioritization of resources based on risk appetite and tolerance, rather than relying on ad-hoc or reactive measures. Without this, the program lacks the structured governance needed to adapt to evolving threats and regulatory requirements.

Exam trap

The trap here is that candidates mistake tactical tools or organizational shortcuts (like a single security decision-maker) for program maturity, when CISM emphasizes that maturity is defined by process integration, governance, and continuous improvement, not by technology adoption or centralized authority.

Why the other options are wrong

B

Tool adoption is not a program component; it's an implementation detail.

D

Mature programs distribute accountability.

32
MCQmedium

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

A.Notify law enforcement
B.Increase the ransom payment
C.Escalate to activate the business continuity/disaster recovery plan
D.Engage the forensics firm to preserve evidence
AnswerC

BC/DR activation is triggered when MTD is at risk, ensuring continuity of critical functions.

Why this answer

When an incident cannot be resolved within MTD, it escalates to business continuity/disaster recovery activation to restore operations.

33
Multi-Selecthard

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Select 3 answers
A.Security awareness training for board members
B.CISO reporting directly to the CEO
C.Board-level risk committee review of security posture
D.Approval of the information security strategy by the board
E.Regular security incident reports to the board
AnswersC, D, E

Committee provides dedicated oversight.

Why this answer

These three elements ensure the board can fulfill its oversight role effectively.

34
MCQmedium

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

A.At the next quarterly board meeting
B.Immediately after the incident is detected
C.Only after all legal proceedings are concluded
D.Within 2 weeks of incident resolution
AnswerD

This timeframe ensures information is still fresh and improvements can be implemented quickly.

Why this answer

Lessons learned meetings should occur within two weeks of incident resolution while details are fresh, to capture accurate feedback and improve the IR plan.

35
Multi-Selectmedium

Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)

Select 2 answers
A.Multiple failed login attempts from an external IP address
B.An increase in network traffic to a known malicious domain
C.A user accessing large volumes of data not related to their job function
D.An employee logging in during non-business hours and downloading files
E.A user updating their password as required by policy
AnswersC, D

This suggests data theft or espionage.

Why this answer

A user accessing large volumes of data unrelated to their job function is a classic behavioral anomaly indicating potential data exfiltration. This pattern often precedes an insider threat incident, as the user may be collecting sensitive information for unauthorized purposes, such as selling it or using it for personal gain. Security information and event management (SIEM) systems typically flag such access based on deviations from baseline user behavior, triggering further investigation.

Exam trap

The trap here is that candidates often confuse external attack indicators (like failed logins or malicious domain traffic) with insider threat indicators, failing to recognize that insider threats are characterized by anomalous internal behavior, not external network events.

36
MCQmedium

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

A.Pareto analysis
B.SWOT analysis
C.5 Whys
D.Fishbone diagram
AnswerC

5 Whys repeatedly asks 'why' to reach root cause.

Why this answer

The 5 Whys technique is a simple root cause analysis method that iteratively asks 'why' to move from symptoms to root causes.

37
MCQeasy

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

A.Regularly meeting with business unit leaders to understand needs and risks.
B.Conducting vulnerability scans twice a year.
C.Developing a security awareness campaign.
D.Purchasing an advanced threat detection system.
AnswerA

Direct engagement ensures security supports business objectives.

Why this answer

Regularly meeting with business unit leaders to understand needs and risks is the most important activity because it ensures the security program is directly aligned with business objectives, risk appetite, and operational priorities. This engagement allows the CISO to perform a business impact analysis (BIA) and integrate security controls that support strategic goals rather than operating in isolation. Without this alignment, even technically sound security measures may be rejected or underfunded by leadership.

Exam trap

The trap here is that candidates often mistake a tactical security activity (like vulnerability scanning or buying a tool) for strategic alignment, failing to recognize that only direct engagement with business leaders can ensure the security program supports organizational goals.

How to eliminate wrong answers

Option B is wrong because conducting vulnerability scans twice a year is a tactical, reactive activity that identifies technical weaknesses but does not address whether those vulnerabilities align with business priorities or risk tolerance. Option C is wrong because developing a security awareness campaign, while valuable for reducing human risk, is a specific control that does not by itself ensure the security program supports business objectives. Option D is wrong because purchasing an advanced threat detection system is a technology procurement decision that may improve detection capabilities but does not guarantee the security program is aligned with business needs or that the investment is justified by business risk.

38
MCQeasy

Which of the following incident categories would typically require the involvement of the crisis management team?

A.A P2 high-severity DDoS attack that has been mitigated within a few hours.
B.A P3 medium-severity insider threat involving unauthorized access to a non-critical system.
C.A P4 low-severity phishing email reported by a user.
D.A P1 critical-severity ransomware attack encrypting critical systems.
AnswerD

P1 incidents require executive involvement and CMT activation.

Why this answer

A P1 critical-severity ransomware attack encrypting critical systems requires immediate activation of the crisis management team because it poses an existential threat to business operations, often involving legal, PR, executive, and regulatory stakeholders. The crisis management team handles incidents that exceed the capacity of the incident response team, typically those with high business impact, widespread system compromise, or potential for significant financial/reputational damage.

Exam trap

A common pitfall is to assume that any high-severity technical incident automatically triggers crisis management. However, in the CISM framework, crisis management activation depends on the business impact and the need for executive-level decisions. A quickly mitigated DDoS may be handled by the incident response team alone, whereas a critical ransomware attack affecting core business processes requires crisis management due to the potential for significant financial, legal, and reputational consequences.

How to eliminate wrong answers

Option A is wrong because a P2 high-severity DDoS attack that has been mitigated within a few hours is typically handled by the incident response team using network-layer mitigation techniques (e.g., BGP RTBH, rate-limiting, or scrubbing services) and does not require crisis-level escalation. Option B is wrong because a P3 medium-severity insider threat involving unauthorized access to a non-critical system is a standard incident response task, often investigated by the security operations center (SOC) using log analysis and user behavior analytics (UBA), without needing executive crisis management. Option C is wrong because a P4 low-severity phishing email reported by a user is a routine, low-impact event that is handled through standard security awareness processes and automated email filtering (e.g., SPF, DKIM, DMARC checks), not requiring crisis team involvement.

39
MCQeasy

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

A.Incident response manager
B.Communications lead
C.Security analysts
D.Forensic investigators
AnswerA

The IR manager oversees the entire response and classifies the incident.

Why this answer

The IR manager leads the team, coordinates activities, and classifies incidents based on severity.

40
MCQmedium

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

A.COBIT 2019
B.NIST SP 800-53
C.ISO 27001 Annex A
D.CIS Controls v8
AnswerD

CIS Controls v8 uses IG1, IG2, IG3 for prioritization and is threat-informed.

Why this answer

CIS Controls v8 are organized into Implementation Groups (IG1, IG2, IG3) and provide a prioritized, threat-informed set of controls.

41
MCQmedium

During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?

A.Gap analysis
B.Legal review
C.Training
D.Stakeholder consultation
AnswerB

Legal review follows drafting to ensure legal validity.

Why this answer

After drafting, legal review ensures compliance with laws and regulations.

42
MCQeasy

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

A.Identify assets and their value
B.Calculate the level of risk
C.Establish the risk assessment context
D.Determine the likelihood of threats
AnswerC

Setting the scope, objectives, and criteria is the initial step in risk assessment.

Why this answer

Establishing the risk assessment context (C) is the first step because it defines the scope, objectives, and criteria for the assessment, ensuring alignment with organizational goals and risk appetite. Without this foundational step, subsequent activities like asset identification or risk calculation lack direction and may produce irrelevant or misleading results. In the CISM framework, context setting precedes all technical analysis to ensure the assessment is meaningful and actionable.

Exam trap

The trap here is that candidates often confuse 'identify assets' as the first step because it seems intuitive, but CISM emphasizes that context must be set first to ensure the assessment is scoped and relevant, not just a generic inventory exercise.

How to eliminate wrong answers

Option A is wrong because identifying assets and their value is a subsequent step that occurs after the context is established, as the context determines which assets are in scope and how their value should be measured. Option B is wrong because calculating the level of risk is a later analytical step that depends on first understanding the context, identifying assets, and determining threats and likelihoods. Option D is wrong because determining the likelihood of threats requires a defined context to know which threats are relevant and what baseline assumptions apply, making it premature without context.

43
MCQmedium

Which of the following best describes the primary purpose of an Information Security Program?

A.To reduce the number of security incidents to zero.
B.To ensure compliance with all relevant laws and regulations.
C.To align security efforts with business objectives and manage risk.
D.To implement technical security controls across all systems.
AnswerC

Why this answer

The primary purpose of an Information Security Program is to align security efforts with business objectives and manage risk to an acceptable level. This ensures that security investments and activities directly support the organization's mission, rather than operating in isolation. A program focused solely on compliance or technical controls may fail to address the dynamic risk landscape and business needs.

Exam trap

The trap here is that candidates often mistake compliance (Option B) as the primary goal, but CISM emphasizes that compliance is a subset of risk management, and the program's core purpose is to enable business objectives by managing risk, not just to satisfy auditors.

Why the other options are wrong

A

Zero incidents is unrealistic; the program aims to manage risk, not eliminate all incidents.

B

Compliance is part of the program but not the primary purpose; the program should support business goals.

D

Technical controls are a component, but the program includes governance, policies, and processes.

44
MCQmedium

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

A.IG2
B.IG1
C.IG3
D.IG0
AnswerB

Correct. IG1 is the foundational set of controls for small businesses.

Why this answer

CIS Controls v8 defines Implementation Group 1 (IG1) as the basic set of controls for small businesses with limited resources. IG1 is designed to be the minimum standard and should be implemented first.

45
MCQmedium

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

A.Issue a legal hold and create forensic images of affected systems
B.Immediately wipe affected systems to prevent further data loss
C.Notify the affected individuals as required by law
D.Delete all logs to avoid exposing sensitive information
AnswerA

Legal hold preserves data, and forensic images capture the state for evidence.

Why this answer

When litigation is anticipated, a legal hold must be issued to prevent destruction of relevant evidence, and forensic copies should be made before remediation.

46
Multi-Selecthard

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Select 3 answers
A.Reactive approach to incidents
B.Continuous improvement
C.Automated security controls
D.Ad hoc processes
E.Quantitative performance metrics
AnswersB, C, E

Mature programs regularly refine processes based on lessons learned.

Why this answer

Continuous improvement (B) is a hallmark of higher maturity because it indicates the security program systematically evaluates and enhances its processes based on lessons learned, shifting from static compliance to adaptive risk management. In CISM terms, this aligns with the 'Optimizing' level (Level 5) in the Capability Maturity Model (CMM), where feedback loops drive iterative refinement of controls and policies.

Exam trap

A common misconception is that 'reactive' or 'ad hoc' processes can be part of a mature program if they are fast, but the CMM framework explicitly defines maturity by predictability, measurement, and optimization, not speed or intuition.

47
Multi-Selecthard

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Select 3 answers
A.Cultural resistance to security controls from business units.
B.Overreliance on automated security tools.
C.Inconsistent enforcement of security policies across subsidiaries.
D.Lack of security awareness training for end users.
E.Legacy systems that cannot be patched or upgraded.
AnswersA, C, E

Often seen when security is perceived as hindering productivity.

Why this answer

Cultural resistance to security controls from business units is a common challenge because security teams must balance risk mitigation with operational efficiency. Business units often perceive controls like mandatory encryption or access restrictions as hindrances to productivity, leading to shadow IT or workarounds that undermine the program's effectiveness.

Exam trap

The trap here is that candidates may confuse 'challenges in implementing' with 'consequences of poor implementation,' leading them to select options like D (lack of training) which is a result, not a root implementation hurdle.

48
MCQhard

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

A.Ignore the fourth party as it is outside the organization's scope
B.Conduct a direct assessment of the fourth party
C.Terminate the contract with the vendor
D.Request the vendor to assess and pass through security requirements to its suppliers
AnswerD

Contractual flow-down ensures requirements are met down the chain.

Why this answer

Requiring the vendor to manage its sub-suppliers through contractual flow-down ensures the organization's risk requirements extend throughout the supply chain.

49
MCQeasy

A small marketing firm with 50 employees experiences a ransomware attack. The IT administrator quickly isolates the infected workstations by disconnecting them from the network. The company has a backup strategy that performs nightly backups to an on-premises NAS device. The administrator restores the affected systems from the most recent backup, but some files remain encrypted. The users report that the backups from the last two days show corruption as well. The firm does not have a formal incident response plan. The owner is anxious to get back to work and asks the administrator what to do next. What should the administrator do?

A.Restore from an older backup taken before the infection
B.Contact law enforcement immediately
C.Pay the ransom to get the decryption key
D.Run a full antivirus scan on the restored systems
AnswerA

Older backups are likely unencrypted and can be restored after verifying integrity.

Why this answer

Restoring from an older backup (before the ransomware infection occurred) is the most likely way to get clean data. Paying the ransom is not recommended as it encourages attackers and there is no guarantee. Contacting law enforcement is a good step but not the immediate technical solution.

Running an antivirus scan is insufficient for decryption.

50
MCQmedium

Given the exhibit, what is the MOST appropriate action for the information security manager?

A.Request board approval to accept the risk level
B.Declare a security crisis and mobilize incident response
C.Escalate to the board for immediate decision
D.Implement the action plan to reduce KRI value
AnswerD

Yellow status needs management action as planned.

Why this answer

The exhibit shows a Key Risk Indicator (KRI) trending above the defined threshold but within the risk appetite, meaning the risk is not yet critical. The information security manager should implement the existing action plan to reduce the KRI value back to an acceptable level, as this is a proactive risk treatment measure aligned with the organization's risk management framework. This avoids unnecessary escalation or crisis declaration while addressing the risk in a controlled manner.

Exam trap

The trap here is that candidates often confuse a KRI threshold breach with a security incident, leading them to choose crisis response (Option B) or immediate escalation (Option C), when in fact the correct action is to follow the pre-planned mitigation steps as part of normal risk management.

How to eliminate wrong answers

Option A is wrong because requesting board approval to accept the risk level is premature; the risk has not exceeded the risk appetite, and acceptance should only be considered after the action plan fails or the risk is deemed unavoidable. Option B is wrong because declaring a security crisis and mobilizing incident response is an overreaction; the KRI is above threshold but not at a crisis level, and incident response is for active security breaches, not for managing risk indicators. Option C is wrong because escalating to the board for an immediate decision bypasses the established risk management process; the manager should first execute the planned mitigation actions before seeking board intervention.

51
MCQeasy

An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?

A.The latest cybersecurity threats reported in the industry.
B.Past security incidents that caused significant financial loss.
C.Business requirements derived from risk assessment and compliance obligations.
D.The security budget allocated for the fiscal year.
AnswerC

Controls must align with business needs and risk appetite.

Why this answer

Business requirements derived from risk assessment and compliance obligations are the primary driver because they directly align security controls with the institution's specific risk appetite, regulatory mandates (e.g., PCI DSS, SOX, GDPR), and operational needs. This ensures controls are cost-effective and prioritized based on actual exposure rather than reactive or budget-driven decisions.

Exam trap

The trap here is that candidates often pick 'past security incidents' (Option B) because it feels intuitive, but CISM emphasizes a proactive, risk-based governance approach where business requirements and compliance drive control selection, not historical events or budget constraints.

How to eliminate wrong answers

Option A is wrong because focusing solely on the latest cybersecurity threats can lead to chasing trends and implementing controls that do not address the institution's unique risk profile, resulting in wasted resources and potential gaps. Option B is wrong because past incidents, while informative, represent a reactive approach that may not cover emerging or unexperienced risks, and can over-prioritize controls for rare events while ignoring systemic vulnerabilities. Option D is wrong because letting the security budget dictate control selection can result in underfunding critical areas or over-investing in low-priority controls, bypassing the risk-based prioritization that governance frameworks require.

52
MCQhard

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

A.Notify affected customers of the expected delay
B.Continue containment efforts and hope for a faster recovery
C.Escalate to the BC/DR team and the authority who can declare a disaster
D.Shut down the affected system to prevent further impact
AnswerC

When MTD is exceeded, BC/DR must be activated to restore operations.

Why this answer

When MTD is exceeded, the incident escalates to business continuity/disaster recovery activation. The BC/DR decision authority should be notified to declare a disaster and activate recovery plans.

53
MCQhard

Refer to the exhibit. This error log indicates a failure in which component of information security governance?

A.Policy enforcement
B.Access control
C.Segregation of duties
D.Audit trail
AnswerB

The user lacks necessary permissions, indicating an access control issue.

Why this answer

The error shows that a user lacks privileges to update a policy, indicating a breakdown in access control. Option A (policy enforcement) is broader and refers to compliance with policies, not updating them. Option C (segregation of duties) is about dividing tasks to prevent fraud, not about insufficient privileges.

Option D (audit trail) is about logging, which is functioning as the error was logged.

54
MCQhard

You are the information security manager for a mid-sized e-commerce company with 500 employees. The company recently experienced a data breach where an attacker exploited a vulnerability in a third-party payment processing API, resulting in the exposure of 10,000 customer credit card numbers. The breach was detected by an external forensics team 90 days after the initial compromise. The board is concerned about the company's ability to detect and respond to incidents. Currently, the company has a part-time security team of three people who focus on firewall management and antivirus updates. There is no formal incident response plan, and security monitoring is limited to basic log review once a week. The CISO has asked you to recommend a course of action to improve the security posture, with a focus on governance and oversight. Which of the following is the BEST course of action?

A.Immediately implement a PCI DSS compliance program to ensure all payment data handling meets industry standards.
B.Develop and implement an incident response plan, establish a security operations center (SOC) with 24/7 monitoring, and define clear roles and responsibilities.
C.Purchase and deploy a next-generation firewall and endpoint detection and response (EDR) tools across the network.
D.Outsource all security operations to a managed security service provider (MSSP) with a focus on threat intelligence.
AnswerB

This addresses governance, detection, and response holistically.

Why this answer

The core governance issue is the lack of a formal incident response plan and adequate monitoring. Establishing a SOC with 24/7 monitoring directly addresses the 90-day detection gap, while defining roles and responsibilities ensures accountability and oversight, which are key governance principles. This approach aligns with the CISM focus on establishing processes and oversight rather than just deploying technology.

Exam trap

The trap here is that candidates often choose a technology-focused answer (like C or D) because it seems more concrete, but the CISM exam emphasizes that governance and oversight—such as having a formal plan and defined roles—must come before technology investments to ensure effective security management.

How to eliminate wrong answers

Option A is wrong because PCI DSS compliance is a standard for handling payment card data, but it does not directly address the lack of incident detection and response capabilities; it focuses on preventive controls and data security, not on governance of incident response. Option C is wrong because purchasing next-generation firewalls and EDR tools is a tactical, technology-centric solution that does not establish the governance framework, incident response plan, or monitoring processes needed to detect and respond to breaches in a timely manner. Option D is wrong because outsourcing to an MSSP without first having an internal incident response plan and defined roles can lead to a lack of ownership and oversight; it shifts responsibility but does not fix the governance gap, and the board's concern is about the company's own ability to detect and respond.

55
MCQmedium

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

A.Security budget variance
B.Mean time to detect incidents
C.Phishing simulation click rate
D.Number of security policies updated
AnswerC

Correct: Direct measure of user behavior.

Why this answer

Phishing simulation click rate directly measures user behavior change, a key indicator of awareness effectiveness.

56
MCQhard

A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?

A.Decentralized with business unit CISO
B.Outsourced security management
C.Centralized with CISO reporting to CEO
D.Hybrid with executive accountability
AnswerD

Correct: CISO to CIO, board updates, CFO accountable.

Why this answer

This structure shows the CISO reporting to CIO (dotted line to board), with executive accountability assigned to CFO, typical of a tiered governance model.

57
MCQmedium

During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?

A.Monitor the connection further without taking action.
B.Block the IP address immediately to prevent data exfiltration.
C.Notify law enforcement about the IP address.
D.Check threat intelligence feeds to confirm maliciousness.
AnswerD

Verification through threat intelligence ensures the action is justified.

Why this answer

The incident response team must first validate the maliciousness of the IP address using threat intelligence feeds before taking any irreversible action. Blocking an IP without confirmation could disrupt legitimate business operations or tip off an attacker, and the CISM framework emphasizes evidence-based decision-making during incident response.

Exam trap

The trap here is that candidates often choose 'Block the IP immediately' (Option B) because they equate speed with effective containment, but CISM stresses that containment actions must be risk-informed and validated to avoid collateral damage and legal liability.

How to eliminate wrong answers

Option A is wrong because passively monitoring a confirmed malware communication without action risks ongoing data exfiltration and violates the principle of timely containment. Option B is wrong because immediately blocking the IP without verification could cause a denial of service to legitimate services hosted on that IP (e.g., a shared CDN or cloud provider) and may destroy forensic evidence of the C2 channel. Option C is wrong because notifying law enforcement is premature before internal validation and containment; law enforcement notification typically occurs after the organization has confirmed maliciousness and secured its own evidence chain.

58
MCQmedium

An organization is developing an information security program for a new subsidiary. Which approach BEST ensures that the subsidiary's program complements the parent's?

A.Replicate the parent's policies exactly
B.Adopt a recognized international standard such as ISO 27001
C.Perform a separate risk assessment for the subsidiary
D.Outsource security management to a third party
AnswerB

A common standard facilitates interoperability and consistency across entities.

Why this answer

Adopting a recognized international standard such as ISO 27001 ensures that the subsidiary's information security program is built on a globally accepted framework, which inherently aligns with the parent's program through common controls, terminology, and audit criteria. This approach provides a structured, risk-based methodology that complements the parent's program without requiring exact replication, which may not fit the subsidiary's unique operational context. ISO 27001's Annex A controls and Plan-Do-Check-Act (PDCA) cycle facilitate interoperability and consistent governance across entities.

Exam trap

The trap here is that candidates often choose 'Perform a separate risk assessment' (Option C) because it seems like a logical first step, but the question asks for the approach that BEST ensures complementarity, and a risk assessment alone does not provide a unifying framework—ISO 27001 does.

How to eliminate wrong answers

Option A is wrong because replicating the parent's policies exactly ignores the subsidiary's unique legal, regulatory, and operational environment, potentially causing non-compliance with local laws (e.g., GDPR in Europe) or misalignment with the subsidiary's specific risk profile. Option C is wrong because performing a separate risk assessment for the subsidiary, while necessary, is only a component of program development and does not by itself ensure complementarity with the parent's program; without a common framework, the risk assessment outputs may not map to the parent's controls. Option D is wrong because outsourcing security management to a third party transfers operational responsibility but does not guarantee that the subsidiary's program will complement the parent's; the third party's methodology may diverge from the parent's governance structure, leading to gaps in oversight and reporting.

59
MCQeasy

During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?

A.Proceed with disconnection immediately to prevent further damage
B.Keep the server connected but block all inbound/outbound traffic
C.Perform a full disk imaging before disconnection
D.Collect volatile data (memory, processes) before disconnecting
AnswerD

This preserves forensic evidence while allowing containment.

Why this answer

Volatile data (e.g., memory contents, running processes, network connections) is lost when power is removed or the network interface is disabled. The CIRT leader must follow the order of volatility (RFC 3227) and capture this data first to preserve forensic evidence before containment actions that alter the system state.

Exam trap

The trap here is that candidates may prioritize containment speed (Option A) over forensic preservation, forgetting that volatile data is irrecoverable once the system is powered off or disconnected.

How to eliminate wrong answers

Option A is wrong because immediate disconnection destroys volatile evidence (e.g., memory, active network sessions) that may be critical for attribution and root cause analysis. Option B is wrong because blocking all traffic does not prevent the server from being remotely wiped or overwritten by an attacker, and it still risks loss of volatile data if the system crashes or is shut down. Option C is wrong because full disk imaging captures only non-volatile data; volatile data (e.g., RAM, process list) must be collected separately before any power-off or disconnection.

60
MCQeasy

Which of the following is the PRIMARY responsibility of the CISO in an organization?

A.Managing the IT infrastructure
B.Auditing security controls
C.Performing day-to-day security operations
D.Owning the information security strategy and programme
AnswerD

The CISO leads the security strategy and programme.

Why this answer

The CISO is accountable for developing and maintaining the information security strategy and programme.

61
MCQeasy

What is the primary purpose of a security incident near-miss reporting culture?

A.To increase the security budget
B.To reduce the number of security policies
C.To assign blame for potential incidents
D.To identify and address security gaps proactively
AnswerD

Correct: Proactive improvement.

Why this answer

Encouraging reporting of near misses helps identify weaknesses and prevent future incidents.

62
MCQeasy

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

A.Implement technical controls
B.Conduct a risk assessment
C.Purchase security tools
D.Develop security policies
AnswerB

A risk assessment identifies threats, vulnerabilities, and impacts, guiding the security program's priorities.

Why this answer

Conducting a risk assessment is the foundational first step in developing an information security program because it identifies and prioritizes the specific threats, vulnerabilities, and business impacts that the program must address. Without a risk assessment, any subsequent policies, controls, or tools would be based on assumptions rather than the organization's actual risk profile, leading to misallocated resources and ineffective security. This aligns with the CISM framework, which emphasizes that risk management drives the entire security program lifecycle.

Exam trap

The trap here is that candidates often confuse the logical sequence by thinking 'policies come first' (Option D) because policies seem foundational, but CISM emphasizes that risk assessment must precede policy development to ensure policies are risk-driven and not just compliance checklists.

How to eliminate wrong answers

Option A is wrong because implementing technical controls before understanding the risks can result in deploying irrelevant or misconfigured controls (e.g., a WAF without knowing which web application vulnerabilities exist), wasting budget and potentially creating a false sense of security. Option C is wrong because purchasing security tools without a prior risk assessment leads to tool sprawl and integration issues, such as buying an SIEM without first identifying which log sources are critical to monitor. Option D is wrong because developing security policies without a risk assessment may produce generic, non-contextual policies (e.g., a password policy that doesn't account for the specific threat of credential stuffing against the company's legacy authentication system), making them unenforceable or irrelevant.

63
MCQhard

Refer to the exhibit. Based on the exhibit, what is the security implication of this cloud storage bucket policy?

A.Denies all access except from 10.0.0.0/8
B.Allows only users from 10.0.0.0/8 to read and write
C.Allows any authenticated user to read and write objects
D.Allows any user from internal network to read objects, but any user can write objects from anywhere
AnswerB

Correct. The policy uses a Condition to deny read and write for IPs outside 10.0.0.0/8, effectively allowing only users from that range to read and write.

Why this answer

The bucket policy includes a Condition block with NotIpAddress for both read and write actions, denying access from IP addresses outside the 10.0.0.0/8 range. This restricts both read and write operations to users from the internal network, making Option B correct.

Exam trap

This question tests the distinction between explicit Deny with IP conditions and unrestricted Allow actions, where candidates mistakenly think a Deny on one action applies globally or that a missing Condition implies no access, rather than understanding that each action is evaluated independently.

How to eliminate wrong answers

Option A is wrong because the policy does not deny all access except from 10.0.0.0/8; it only denies write access from outside that range, while read access is unrestricted. Option B is wrong because the policy does not allow only users from 10.0.0.0/8 to read and write; it allows any user to read objects, and only write access is restricted to the 10.0.0.0/8 range. Option C is wrong because the policy does not require authentication for read access; the `s3:GetObject` action has no condition, so it allows anonymous (unauthenticated) users to read objects, not just authenticated users.

64
Multi-Selectmedium

Which TWO are essential elements of an information security program?

Select 2 answers
A.Vulnerability scanning tools
B.Risk management process
C.Network firewall
D.Security awareness training
E.Incident response plan
AnswersD, E

Education is a key element of a security program.

Why this answer

Security awareness training is an essential element of an information security program because it directly addresses the human factor, which is often the weakest link in security. A formal, ongoing training program ensures that employees understand policies, recognize threats like phishing, and follow secure behaviors, thereby reducing risk. Without it, technical controls alone cannot prevent social engineering or user errors, making it a foundational component of any security program.

Exam trap

ISACA often tests the distinction between program-level elements (like processes and plans) and operational tools or controls (like firewalls or scanners), leading candidates to mistakenly select technical solutions as essential program components.

65
MCQeasy

An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?

A.Implement technical controls to enforce the policy.
B.Conduct an audit to measure compliance.
C.Communicate the policy to all relevant stakeholders and provide training.
D.Enforce disciplinary actions for non-compliance.
AnswerC

Awareness and understanding are prerequisites for compliance.

Why this answer

After a security policy is approved, the next critical step is to communicate the policy to all relevant stakeholders and provide training. This ensures that employees understand the policy, their responsibilities, and how to comply. Without effective communication and training, the policy is unlikely to be adopted correctly, rendering it ineffective.

Option A is incorrect because implementing technical controls before stakeholders are aware of the policy can lead to confusion and non-compliance. Option B is incorrect because auditing for compliance should occur after the policy has been communicated and implemented, not immediately after approval. Option D is incorrect because disciplinary actions should only be enforced after stakeholders have been given the opportunity to understand the policy through communication and training.

66
Multi-Selectmedium

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Select 2 answers
A.An insurance claim form for cyber incidents
B.A signed retainer agreement with a forensics firm
C.A list of affected customers from the most recent data breach
D.A root cause analysis report from a previous incident
E.An incident response team with assigned roles and responsibilities
AnswersB, E

Having a retainer in place reduces time to engage external forensics.

Why this answer

An IR team with defined roles and a signed retainer with a forensics firm are critical preparatory elements. The IR plan is also prepared, but the question asks for components established before an incident.

67
MCQhard

An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?

A.$400,000
B.$10,000,000
C.$500,000
D.$2,000,000
AnswerA

ALE = $2,000,000 * 0.2 = $400,000.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, the ARO is 1/5 = 0.2 (one event every five years), and the SLE is $2,000,000. Thus, ALE = 0.2 × $2,000,000 = $400,000.

Exam trap

The trap here is that candidates often confuse the recurrence interval (every 5 years) with the ARO, mistakenly multiplying the loss by 5 instead of dividing, leading to the inflated $10,000,000 option.

How to eliminate wrong answers

Option B is wrong because $10,000,000 results from multiplying the loss ($2M) by 5 (the number of years between occurrences) instead of dividing, which incorrectly inflates the annualized loss. Option C is wrong because $500,000 would be the ALE if the ARO were 0.25 (once every 4 years), not the given 0.2. Option D is wrong because $2,000,000 is the single loss expectancy (SLE), not the annualized figure; it ignores the frequency of occurrence entirely.

68
Multi-Selecteasy

Which TWO of the following are components of a typical vulnerability management program?

Select 2 answers
A.Conducting security awareness training
B.Remediating identified vulnerabilities through patching
C.Monitoring network traffic for anomalies
D.Performing penetration tests
E.Conducting regular vulnerability scans
AnswersB, E

Remediation is a core component.

Why this answer

Vulnerability management includes scanning for vulnerabilities and remediation (patching).

69
Multi-Selecthard

An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)

Select 2 answers
A.Determine the root cause of the breach.
B.Confirm that the breach actually occurred.
C.Implement full remediation.
D.Consult with legal counsel regarding notification obligations.
E.Assess the impact on affected individuals.
AnswersB, E

Correct: Essential before any notification.

Why this answer

The incident response team must first confirm that a breach actually occurred before taking any further action, including notification. Premature notification without confirmation can lead to false alarms, legal liability, and reputational damage. Confirmation involves verifying indicators of compromise (IoCs) through log analysis, forensic evidence, and chain-of-custody procedures.

Exam trap

A common pitfall in the CISM exam is that candidates often prioritize immediate notification over the necessary steps of confirming the breach and assessing its impact. They may incorrectly select root cause analysis or legal consultation as the first actions before confirmation.

70
MCQmedium

A company is restructuring its security governance due to rapid growth. The CISO reports to the CIO. What is the PRIMARY risk of this reporting structure?

A.Compliance with regulations may become difficult
B.The security budget may be insufficient
C.Cooperation between IT and security may decrease
D.Security objectives may be overridden by IT operational goals
AnswerD

Conflict of interest reduces independence.

Why this answer

When the CISO reports to the CIO, security objectives are subordinate to IT operational goals. The CIO's primary mandate is system availability, performance, and cost efficiency, which can lead to security controls being deprioritized or bypassed to meet IT project deadlines. This structural conflict is the primary risk because it directly undermines the independence required for effective security governance.

Exam trap

In ISACA CISM, the question tests the distinction between a symptom (e.g., budget issues, compliance problems) and the root cause (loss of independent security authority) when the CISO reports to the CIO.

How to eliminate wrong answers

Option A is wrong because compliance difficulties are a potential consequence of poor governance, not the primary risk of the reporting structure itself; compliance can still be managed with proper controls. Option B is wrong because budget insufficiency is a symptom of misaligned priorities, not the inherent risk of the reporting line; the budget could be adequate if the CIO prioritizes security. Option C is wrong because cooperation between IT and security typically increases when security reports to IT, as they share the same leadership; the risk is that security's voice is subordinated, not that cooperation decreases.

71
MCQmedium

A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?

A.Data breach
B.Supply chain attack
C.Insider threat
D.Account compromise
AnswerD

The pattern of failed logins followed by a success from a new location indicates compromised credentials.

Why this answer

The scenario describes an account compromise where credentials are likely stolen and used to gain unauthorized access.

72
Multi-Selecthard

Which THREE of the following are essential components of an information security risk management framework?

Select 3 answers
A.Incident response planning
B.Risk identification
C.Compliance auditing
D.Risk assessment
E.Risk treatment
AnswersB, D, E

First step in risk management.

Why this answer

Risk identification is a core component of an information security risk management framework because it systematically catalogs assets, threats, and vulnerabilities that could affect the organization. Without identifying risks, subsequent steps like assessment and treatment cannot be performed. This aligns with the ISACA framework's emphasis on risk identification as the foundational step in the risk management lifecycle.

Exam trap

The trap here is that candidates confuse operational security processes (like incident response) or compliance activities (like auditing) with the core risk management framework components, which are strictly risk identification, risk assessment, and risk treatment as defined by ISACA.

73
Multi-Selecthard

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Select 2 answers
A.Vendor's marketing budget
B.Criticality of the service provided by the vendor
C.Vendor's stock price
D.Type of data accessed by the vendor
E.Vendor's annual revenue
AnswersB, D

Correct. Service criticality affects business impact.

Why this answer

Vendor tiering is typically based on the sensitivity of data the vendor accesses and the criticality of the service they provide. These factors determine the risk level and required controls.

74
MCQmedium

Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?

A.Standards, Enterprise Policy, Procedures, Guidelines
B.Procedures, Standards, Enterprise Policy, Guidelines
C.Guidelines, Procedures, Standards, Enterprise Policy
D.Enterprise Policy, Standards, Procedures, Guidelines
AnswerD

This is the correct hierarchical order.

Why this answer

Enterprise policy sets the tone, followed by standards, then procedures, then guidelines.

75
Multi-Selectmedium

Which THREE of the following should be included in an incident communication template?

Select 3 answers
A.Affected systems or data
B.Description of the incident
C.Actions to be taken by recipients
D.Technical indicators of compromise (IoCs)
E.Attribution of the attacker
AnswersA, B, C

Knowing what is affected is crucial for response.

Why this answer

Communication templates should include the incident description, affected parties, and guidance on actions to take. Technical details and attacker attribution are not typically included in templates.

Page 1 of 12

Page 2