Courseiva

Certified Information Security Manager CISM (CISM) — Questions 151–225

924 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
Multi-Selecthard

A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)

Select 2 answers
A.The use of advanced security technologies such as AI-based threat detection.
B.A requirement that all security decisions be made by the CISO without business input.
C.A clear definition of security roles and responsibilities across the organization.
D.The implementation of a security operations center (SOC) to monitor for threats 24/7.
E.A process for regularly reviewing and updating security policies to reflect changes in the threat landscape.
AnswersC, E

Clearly defining security roles and responsibilities is essential for accountability and effective governance. It ensures that every aspect of the security program has an owner, preventing gaps and overlaps. This clarity also enables better communication and coordination between business units and the security team, aligning security activities with business goals.

Why this answer

An effective security governance framework must include clear roles and responsibilities to ensure accountability, and a process for regularly updating policies to adapt to changes. These components provide the structure and adaptability needed to align security with business objectives and manage risk. Advanced technologies, centralized decision-making, and operational centers are not core governance elements; they are tactical or operational considerations that support the framework.

Exam trap

The trap here is equating governance with operational capabilities or technologies, rather than focusing on the structural and process elements that define oversight and accountability.

152
MCQeasy

A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?

A.Implement an automated policy enforcement system
B.Deploy an asset inventory management tool
C.Conduct security awareness training for all employees
D.Perform a comprehensive penetration test
AnswerC

With a small team and tight budget, awareness training delivers the broadest risk reduction per pound, since most breaches begin with human error such as phishing or weak credential handling, and it scales across the whole workforce without new tooling.

Why this answer

Security awareness training is the most cost-effective initial investment because human error remains the leading cause of security incidents, especially in resource-constrained environments. By educating employees on phishing, social engineering, and safe data handling, the organization reduces the attack surface without requiring expensive tools or specialized staff. This foundational control directly addresses the most common threat vector—user behavior—which automated systems alone cannot fully mitigate.

Exam trap

The trap here is that candidates often overvalue technical controls like penetration tests or automated enforcement, assuming they provide immediate risk reduction, while underestimating the foundational role of human-centric controls in a budget-constrained environment.

How to eliminate wrong answers

Option A is wrong because an automated policy enforcement system typically requires a mature asset inventory and defined policies to function correctly; without those prerequisites, the tool may enforce incorrect rules or miss unmanaged devices, wasting limited budget on a solution that cannot be properly configured. Option B is wrong because deploying an asset inventory management tool, while important, does not directly reduce risk; it provides visibility but requires additional processes and tools to act on that data, and a small team may lack the capacity to remediate findings promptly. Option D is wrong because a comprehensive penetration test is a point-in-time assessment that identifies vulnerabilities but does not build ongoing security capabilities; without a foundation of security awareness and basic controls, the findings may overwhelm the small team and lead to no sustainable improvement.

153
MCQmedium

An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?

A.Develop information security policies and procedures
B.Conduct a risk assessment
C.Select and implement security controls
D.Define security metrics and reporting
AnswerB

A risk assessment identifies threats, vulnerabilities and impacts to patient data, giving the programme its scope and priorities. This satisfies the stem's requirement to establish the programme first, since controls and policies should follow identified risk.

Why this answer

Conducting a risk assessment is the foundational first step because it identifies and prioritizes the specific threats and vulnerabilities facing the healthcare organization's sensitive data (e.g., PHI under HIPAA). Without this baseline understanding, any subsequent policies, controls, or metrics would be misaligned with actual risk exposure, leading to ineffective or wasteful security investments.

Exam trap

ISACA often tests the misconception that policy development is the logical starting point, but CISM emphasizes that risk assessment must precede all other program elements to ensure alignment with business objectives and regulatory requirements.

Why the other options are wrong

A

Policies should be based on risk assessment results, not developed first.

C

Controls are selected after risks are identified.

D

Metrics are defined after program objectives and controls are established.

154
Multi-Selectmedium

A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?

Select 2 answers
A.Focusing exclusively on the most stringent regulatory requirement to satisfy all others
B.Establishing a governance structure with defined roles, responsibilities, and oversight
C.Creating a control framework that maps common controls to multiple regulatory requirements
D.Adopting a single security framework such as ISO 27001 for all regions
E.Implementing separate security programs for each business unit to address unique needs
AnswersB, C

A governance structure provides the foundation for consistent decision-making and accountability across the organization.

Why this answer

A governance structure with defined roles, responsibilities, and oversight (Option B) is critical because it provides the authority, accountability, and decision-making framework needed to align security activities with diverse business units and regulatory requirements. Without clear governance, the program lacks the mechanisms to enforce policies, manage exceptions, and adapt to regional legal variations, such as GDPR in Europe or CCPA in California.

Exam trap

The trap here is that candidates often confuse 'comprehensive' with 'uniform,' leading them to choose Option D (single framework) or Option A (most stringent rule), when in reality, adaptability requires a governance structure that can manage multiple frameworks and exceptions, not a one-size-fits-all approach.

155
MCQeasy

A security analyst receives an alert from the SIEM indicating that a user account has been added to the domain administrators group outside of the change management window. The analyst confirms the change was not authorized. According to CISM incident management principles, what should the analyst do FIRST?

A.Document the alert in the ticketing system and continue monitoring for additional related events before escalating.
B.Remove the account from the domain administrators group to immediately reverse the unauthorized change.
C.Escalate the alert to the incident response team according to the documented incident classification and escalation procedures.
D.Contact the user whose account was added to the domain administrators group to ask if they made the change.
AnswerC

Unauthorized privileged account creation is a potential security incident that must be escalated promptly through the established incident response process. The analyst's first duty is to recognize and report, not to remediate independently. Following the documented classification and escalation path ensures the right resources are engaged and that the incident is tracked, prioritized, and handled consistently. This preserves the integrity of the response process and aligns with CISM's emphasis on defined roles and procedures.

Why this answer

The analyst should escalate the unauthorized privileged account change through the documented incident classification and escalation procedures. This ensures the incident receives appropriate resources and is handled consistently, while preserving evidence and avoiding premature or unilateral actions. Reversing the change, contacting the user, or simply monitoring can compromise the investigation or allow the attacker to expand access.

Exam trap

The trap here is believing that a monitoring analyst should immediately fix or investigate the issue personally, rather than escalate it through the incident response process.

156
MCQmedium

A CISO is presenting the information security program's value to the board. The board is particularly concerned about the organization's ability to detect and respond to advanced threats. Which of the following metrics would BEST demonstrate the program's effectiveness in this area?

A.The mean time to detect (MTTD) and mean time to respond (MTTR) to advanced threats.
B.The percentage of critical assets covered by continuous monitoring.
C.The number of security incidents detected per quarter.
D.The total number of security controls implemented across the enterprise.
AnswerA

MTTD and MTTR directly measure how quickly the organization detects and responds to threats. These metrics demonstrate the efficiency of detection and response processes, which is exactly what the board is concerned about. They provide actionable insights and can be tracked over time to show improvement.

Why this answer

Mean time to detect (MTTD) and mean time to respond (MTTR) are outcome-based metrics that directly reflect the program's ability to detect and respond to threats. They are meaningful to the board because they quantify operational effectiveness and can be benchmarked. Other metrics like incident counts or control counts do not provide the same level of assurance regarding detection and response capabilities.

Exam trap

The trap here is selecting metrics that measure activity or coverage rather than the speed and success of detection and response, which are what the board cares about.

157
MCQeasy

An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?

A.Industry best practices
B.Historical security incidents
C.Business objectives
D.Regulatory compliance requirements
AnswerC

Security objectives exist to enable the organisation's mission; aligning them with business objectives ensures controls support strategic goals and risk appetite, satisfying the stem's requirement for the primary driver rather than technology or compliance alone.

Why this answer

Business objectives are the primary driver for defining security objectives because information security exists to enable the organization to achieve its mission and strategic goals. Security objectives must align with and support business objectives to ensure that resources are allocated effectively and that security controls are prioritized based on risk to the business, not just compliance or generic practices.

Exam trap

The trap here is that candidates often select 'regulatory compliance requirements' as the primary driver because they confuse legal necessity with strategic priority, but CISM emphasizes that security governance must be business-driven, not compliance-driven.

How to eliminate wrong answers

Option A is wrong because industry best practices (e.g., NIST CSF, ISO 27001) provide useful guidance but are not the primary driver; they are tools to help achieve security objectives that must first be derived from business needs. Option B is wrong because historical security incidents inform risk assessment and lessons learned, but they are reactive and do not define proactive strategic objectives aligned with business goals. Option D is wrong because regulatory compliance requirements (e.g., GDPR, PCI DSS) set minimum legal standards but are not the primary driver; compliance alone can lead to a checkbox mentality that fails to address business-specific risks and priorities.

158
MCQmedium

A security manager learns that a production database containing customer records was copied to an unauthorized external drive by a contractor. The incident response team has contained the contractor's access. According to CISM best practices, which action should the security manager take NEXT?

A.Terminate the contractor's employment contract and demand return of the external drive.
B.Notify the legal department and initiate the evidence preservation and chain-of-custody process.
C.Send a company-wide email informing all employees about the contractor's misconduct.
D.Immediately delete the contractor's user account and all associated files to prevent further data loss.
AnswerB

Because the contractor's actions may constitute a criminal offense or trigger regulatory notification duties, the security manager must involve legal counsel immediately and ensure forensic evidence is preserved with documented chain of custody. This protects the organization's ability to pursue legal action, support law enforcement, and meet breach notification obligations. Preserving evidence before any further system changes prevents spoliation and keeps the investigation defensible.

Why this answer

When an incident may involve criminal conduct or regulatory breach notification, the security manager's immediate priority is to engage legal counsel and preserve evidence. This ensures the organization can support law enforcement, defend against liability, and meet notification requirements. Containment has already occurred, so the next step is protecting the integrity of the investigation rather than taking destructive or premature personnel actions.

Exam trap

The trap here is assuming that containment means the incident is over and that administrative actions like termination or account deletion can proceed without first preserving evidence and consulting legal counsel.

159
MCQhard

An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$250,000
B.$1,000,000
C.$125,000
D.$500,000
AnswerA

SLE equals asset value times exposure factor: $2,000,000 × 0.25 = $500,000. ALE equals SLE times ARO: $500,000 × 0.5 = $250,000. This satisfies the stem's quantitative inputs, yielding the expected annual loss from that risk.

Why this answer

The annualized loss expectancy (ALE) is calculated as ALE = AV × EF × ARO, where AV is the asset value ($2,000,000), EF is the exposure factor (0.25), and ARO is the annualized rate of occurrence (0.5). Multiplying these gives $2,000,000 × 0.25 × 0.5 = $250,000, which represents the expected annual financial loss from this risk.

Exam trap

The trap here is that candidates often forget to multiply by the ARO after computing SLE, or they confuse ARO with a percentage and incorrectly apply it as a divisor instead of a multiplier.

How to eliminate wrong answers

Option B ($1,000,000) is wrong because it incorrectly multiplies AV by EF only ($2,000,000 × 0.25 = $500,000) and then doubles it, or misapplies ARO as 1.0 instead of 0.5. Option C ($125,000) is wrong because it multiplies AV by ARO only ($2,000,000 × 0.5 = $1,000,000) and then divides by 8, or incorrectly halves the EF to 0.125. Option D ($500,000) is wrong because it calculates AV × EF ($2,000,000 × 0.25 = $500,000) but omits the ARO multiplier entirely, treating ARO as 1.0.

160
MCQhard

A large enterprise experiences a data breach involving personal identifiable information (PII) of customers. The incident response team has contained the breach and is now in the eradication phase. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is MOST critical?

A.Change all passwords of affected accounts.
B.Notify affected customers about the breach.
C.Deploy additional endpoint protection software.
D.Patch the specific vulnerability identified.
AnswerD

Patching removes the exploited flaw at its source, so the same vulnerability cannot be reused against the organisation. Containment and eradication alone leave the underlying weakness present, meaning a repeat breach remains possible. Applying the vendor fix directly satisfies the CISO's requirement that the vulnerability be permanently closed.

Why this answer

Patching the specific vulnerability is the most critical action during the eradication phase because it permanently removes the root cause of the breach. Without this step, the same attack vector (e.g., an unpatched SQL injection flaw or a known CVE in a web server) remains exploitable, rendering containment efforts temporary. The CISO's goal to prevent recurrence directly requires eliminating the technical weakness, not just mitigating its symptoms.

Exam trap

ISACA often tests the distinction between containment actions (like password resets) and eradication actions (like patching), tricking candidates into choosing a visible, immediate step over the root-cause fix.

How to eliminate wrong answers

Option A is wrong because changing passwords of affected accounts is a containment and recovery action that addresses credential compromise, not the underlying vulnerability (e.g., a code injection flaw) that allowed the breach. Option B is wrong because notifying customers is a legal and public relations obligation that occurs after eradication, but it does not fix the technical root cause. Option C is wrong because deploying additional endpoint protection software is a preventive control that may detect future attacks but does not remove the existing vulnerability; the attacker could still exploit the same unpatched flaw.

161
MCQmedium

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

A.A P1 data breach involving customer personally identifiable information (PII).
B.A P2 denial-of-service attack that is quickly mitigated.
C.A P4 phishing email reported by a user.
D.A P3 insider threat involving an employee accessing unauthorized files.
AnswerA

A P1 breach of customer PII triggers notification duties under GDPR and similar regimes, plus severe reputational fallout. That combination of regulatory exposure and public trust damage exceeds routine IR handling, so the crisis management team must be activated to coordinate legal, communications and executive response.

Why this answer

A P1 data breach involving customer PII triggers mandatory breach notification laws (e.g., GDPR Article 33, HIPAA Breach Notification Rule) and often requires immediate CMT activation to manage regulatory filings, legal liability, and public relations. The CMT is designed for high-severity incidents with significant business, legal, or reputational consequences, which a P1 breach directly entails.

Exam trap

The trap here is that candidates may confuse technical severity (e.g., a DDoS causing downtime) with business/regulatory impact, failing to recognize that only incidents with legal or reputational fallout (like a PII breach) necessitate CMT activation, not merely high technical severity.

How to eliminate wrong answers

Option B is wrong because a P2 denial-of-service attack that is quickly mitigated typically does not involve data loss or regulatory notification requirements, so it would be handled by the technical incident response team without CMT escalation. Option C is wrong because a P4 phishing email reported by a user is a low-severity, routine event that is usually handled via standard security awareness processes and does not warrant CMT involvement. Option D is wrong because a P3 insider threat involving unauthorized file access, while serious, is typically contained and investigated by the incident response team and HR, and only escalates to the CMT if it leads to a confirmed data breach or regulatory exposure.

162
MCQmedium

A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?

A.Immediately terminate the vendor contract and migrate claims processing in-house.
B.Perform a risk assessment of the change in ownership and its impact on data protection obligations.
C.Report the acquisition to the regulator and await instructions before taking any action.
D.Accept the change because the vendor's service-level agreement remains unchanged.
AnswerB

A change in vendor ownership can alter legal jurisdiction, data handling practices, and breach notification obligations, so the risk manager must first assess the resulting risk to the organization. This assessment informs whether to renegotiate, add controls, or exit the relationship. Treating the acquisition as a trigger for reassessment aligns with continuous third-party risk management and gives decision-makers the facts they need.

Why this answer

A change of control at a critical vendor is a risk event that must be reassessed before any treatment decision. Because the contract lacks a change-of-control clause, the organization cannot rely on contractual levers and must understand the new legal, privacy, and operational exposure. Assessing first supports an informed choice among renegotiation, added controls, or managed exit, and preserves evidence of due diligence.

Exam trap

The trap here is assuming that an unchanged service-level agreement means unchanged risk, when ownership changes can alter legal jurisdiction and data protection obligations.

163
MCQeasy

A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?

A.The load balancer distributing traffic to the web servers.
B.The network firewall protecting the e-commerce environment.
C.The customer database containing personal and payment card information.
D.The web server hosting the e-commerce application.
AnswerC

The customer database is the most critical asset because it contains sensitive personal and payment card information. A breach of this data can lead to severe financial penalties, reputational damage, and legal liability. Regulations such as PCI DSS and GDPR impose strict requirements on protecting such data. Therefore, the database should be the primary focus of risk assessment and protection efforts.

Why this answer

The customer database is the most critical asset because it holds sensitive personal and payment card information. Its compromise would result in the most significant impact to the organization, including regulatory fines, financial loss, and reputational harm. While other components like servers, firewalls, and load balancers are important for operations and security, they support the protection of the data.

Risk assessments should prioritize assets based on the potential impact of their loss.

Exam trap

The trap here is focusing on infrastructure components like servers or firewalls instead of the data itself, which is the asset with the highest value and risk.

164
MCQmedium

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

A.Encryption of data at rest
B.Antivirus software
C.Firewalls
D.Security awareness training
AnswerC

Firewalls inspect and filter traffic at network boundaries, enforcing rules that block unauthorised access at the network layer. Host-based or application controls operate at different layers, so firewalls uniquely satisfy the stem's network-layer protection requirement.

Why this answer

Firewalls operate at the network layer (Layer 3) and transport layer (Layer 4) to filter traffic based on IP addresses, ports, and protocols, preventing unauthorized network access. They are a core component of defense-in-depth at the network perimeter and internal segments. This directly matches the requirement for network-layer protection.

Exam trap

CISM often tests the layer at which a control operates, and candidates may pick encryption or antivirus because they sound security-related, missing that the question specifically asks for network-layer protection against unauthorized access.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest protects data confidentiality on storage media, not network access. Option B is wrong because antivirus software operates at the endpoint layer, scanning files and processes, not network traffic. Option D is wrong because security awareness training addresses the human layer, educating users, not enforcing network access controls.

165
MCQhard

A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?

A.Transfer the risk by purchasing cyber insurance that covers clinical system outages.
B.Accept the risk and document it in the risk register with a review date.
C.Perform a residual risk assessment to determine if the compensating controls reduce risk to an acceptable level.
D.Immediately remove the application from the network until the vendor provides a patch.
AnswerC

Compensating controls change the risk picture, so the CISO must reassess residual risk. Network segmentation and enhanced monitoring may reduce likelihood or impact, but only a formal residual risk assessment can show whether the remaining risk is within tolerance. That assessment then informs whether to accept, further treat or escalate the risk, ensuring decisions are based on evidence rather than assumption.

Why this answer

When compensating controls are introduced, the risk profile changes and must be re-evaluated. A residual risk assessment determines whether segmentation and monitoring reduce the risk to a level the hospital can tolerate. Only after that assessment can leadership make an informed decision to accept, further mitigate or transfer the risk.

Acting without this step risks either unnecessary disruption or unrecognized exposure.

Exam trap

The trap here is assuming that implementing compensating controls automatically makes the risk acceptable, skipping the required residual risk assessment.

166
MCQmedium

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

A.Percentage of user access reviews completed on time
B.Mean time to detect (MTTD) security incidents
C.Total cost of security incidents
D.Number of data breaches in the past quarter
AnswerA

Access reviews completed on time measure preventive effort before incidents occur, making them a leading indicator. Unlike breach counts or patch latency, which report past outcomes, this metric signals the health of access governance controls and predicts future exposure from stale entitlements.

Why this answer

Percentage of user access reviews completed on time is a leading indicator because it measures a proactive governance activity that reduces the risk of excessive or inappropriate access before it can be exploited. Completing reviews on time predicts better access control hygiene and lower future incident likelihood. The other options are lagging indicators that report past incidents or their costs.

Exam trap

CISM often tests leading vs. lagging indicators, and candidates may choose MTTD because it sounds proactive, but MTTD is still a lagging measure because it is calculated after incidents occur.

How to eliminate wrong answers

Option B is wrong because mean time to detect (MTTD) is a lagging indicator; it measures how long it took to detect incidents that already occurred. Option C is wrong because total cost of security incidents is a lagging financial outcome of past events. Option D is wrong because number of data breaches in the past quarter is a historical count of incidents that already happened.

167
MCQhard

An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?

A.The cost of implementing the control
B.The residual risk after compensating controls
C.The number of users affected by the exception
D.The duration of the exception
AnswerB

Approving a critical-control bypass hinges on the residual risk remaining once compensating controls are applied, since that figure determines whether the exposure is acceptable. This satisfies the stem's requirement to weigh the true remaining risk rather than the original control's importance.

Why this answer

The most important factor when reviewing an exception request to bypass a critical control is the residual risk after compensating controls. This ensures that the organization's risk appetite is not exceeded and that the compensating controls adequately mitigate the risk to an acceptable level, as required by frameworks like ISO 27001 and NIST SP 800-53.

Exam trap

The trap here is that candidates often focus on operational or business factors (cost, user count, duration) instead of the core risk management principle that the residual risk must be acceptable to the organization.

Why the other options are wrong

A

Cost is a factor but not the most important; risk acceptance is paramount.

C

Number of users is less important than the risk exposure.

D

Duration matters but is secondary to the risk level.

168
Multi-Selecthard

An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)

Select 2 answers
A.All security incidents are resolved within 24 hours
B.Security metrics are included in regular executive reports
C.The program uses the latest encryption standards
D.A formal risk acceptance process is in place and used
E.The security team conducts annual penetration tests
AnswersB, D

Why this answer

Including security metrics in regular executive reports demonstrates that security performance is being measured, tracked, and communicated to leadership as part of ongoing governance. This aligns with a mature security program where security is integrated into business decision-making, not treated as a siloed technical function.

Exam trap

The trap here is that candidates confuse operational effectiveness (e.g., fast incident resolution or use of modern encryption) with process maturity, which is about governance, measurement, and continuous improvement rather than technical speed or tooling.

Why the other options are wrong

A

Resolution time is not necessarily an indicator of maturity; process consistency is more important.

C

Using latest technology is a tactical choice, not a maturity indicator.

E

Annual testing is a good practice but not a strong indicator of overall program maturity.

169
MCQeasy

An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?

A.An incident response plan.
B.A security awareness training program.
C.A comprehensive risk assessment.
D.A formal security charter approved by executive management.
AnswerD

A formal security charter approved by executive management provides the program with authority, scope, and resources. It defines the CISO's mandate, establishes accountability, and ensures alignment with business objectives. Without a charter, the program may lack the necessary support and legitimacy to enforce policies and implement controls effectively.

Why this answer

A formal security charter approved by executive management is the most important first step because it establishes the program's authority, scope, and resources. It ensures that security is aligned with business objectives and provides the CISO with the mandate to implement and enforce the program. Without this foundation, other activities may lack support and effectiveness.

Exam trap

The trap here is focusing on operational activities like training or risk assessments before securing executive mandate and governance.

170
MCQhard

An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?

A.Approve the risk acceptance and document it in the risk register.
B.Validate the cost-benefit analysis and ensure the risk is accepted by the appropriate authority.
C.Transfer the risk by purchasing cyber insurance.
D.Implement compensating controls to reduce the risk to an acceptable level.
AnswerB

Risk acceptance decisions must be based on a valid cost-benefit analysis and approved by the authority whose level matches the risk. The security manager should verify the analysis and escalate for acceptance. This ensures due diligence and proper governance. Only after validation and authorization should the risk be marked as accepted in the register. This step is critical before any acceptance is finalized.

Why this answer

Before a risk can be accepted, the cost-benefit analysis must be validated, and acceptance must be authorized by the appropriate level of management based on the risk score. The security manager's role is to facilitate this process, ensuring that the decision is informed and within governance. Thus, validating the analysis and obtaining proper authorization is the correct next step.

Exam trap

The trap here is assuming that the security manager can simply approve risk acceptance or that any treatment can be applied without proper validation and authority.

171
MCQeasy

Which of the following is the primary reason for conducting a lessons learned meeting after an incident?

A.To document the incident for insurance
B.To update the IR plan and playbooks
C.To satisfy regulatory requirements
D.To assign blame
AnswerB

Capturing what worked and failed during response feeds directly into revising the IR plan and playbooks, satisfying the stem's demand for the primary reason. This closes the improvement loop, embedding corrective actions into future response procedures rather than merely documenting the incident for compliance or post-mortem reporting purposes.

Why this answer

The lessons learned meeting aims to identify improvements to the incident response process.

172
MCQeasy

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

A.Lower cost due to elimination of central security team
B.Rapid decision-making due to fewer layers
C.Increased central control and uniformity
D.Inconsistent security policies and controls across units
AnswerD

Decentralised governance lets each business unit set its own controls, so without a central authority enforcing baselines, policies diverge in strength and coverage. That fragmentation directly satisfies the stem's challenge: inconsistent security policies and controls across units, raising gaps and complicating enterprise-wide risk reporting.

Why this answer

In a decentralized governance model, each business unit manages its own security, which leads to inconsistent policies, controls, and risk postures across the organization. This fragmentation makes it difficult to enforce enterprise-wide standards, aggregate risk, and demonstrate compliance. The key challenge is the lack of uniformity and coordination, not cost or speed.

Exam trap

CISM often tests the ability to distinguish benefits from challenges — candidates see 'rapid decision-making' and pick it as a challenge, but it is actually a benefit of decentralization, not a drawback.

How to eliminate wrong answers

Option A is wrong because decentralization does not necessarily lower costs — it often increases them due to duplicated tools, staff, and effort across business units. Option B is wrong because while decentralization can enable faster local decisions, rapid decision-making is a potential benefit, not a key challenge; the question asks for a challenge. Option C is wrong because increased central control and uniformity is the opposite of what decentralization produces — that is a characteristic of centralized governance.

173
MCQhard

Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?

A.External auditor
B.Internal audit function
C.A role with authority to enforce compliance and impose consequences
D.Chief compliance officer
AnswerC

A role empowered to enforce compliance and impose consequences supplies the missing accountability mechanism: governance requires an owner who can compel adherence and sanction non-compliance. Without enforcement authority, policies remain advisory, so responsibility cannot be assigned or demonstrated. This satisfies the stem's demand for accountability enforcement within the governance policy.

Why this answer

The governance policy lacks a role with explicit authority to enforce compliance and impose consequences, which is essential for accountability. Without such enforcement, policies become aspirational rather than binding, as no mechanism exists to address non-compliance or ensure corrective actions. This aligns with the CISM principle that governance requires clear accountability structures, including disciplinary measures for violations.

Exam trap

The trap here is that candidates confuse oversight roles (auditor, compliance officer) with enforcement authority, failing to recognize that accountability requires a designated role with the power to impose consequences, not just monitor or advise.

How to eliminate wrong answers

Option A is wrong because an external auditor provides independent assessment but lacks the authority to enforce compliance or impose consequences; their role is advisory and verification-based, not punitive. Option B is wrong because the internal audit function evaluates controls and reports findings but does not have the mandate to enforce compliance or impose consequences; it is an oversight body, not an enforcement one. Option D is wrong because a chief compliance officer typically oversees compliance programs but may not have direct authority to impose consequences across the organization; enforcement often requires a higher-level governance role with cross-functional authority.

174
MCQmedium

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

A.Adopt the more stringent security program from the acquirer across the entire entity.
B.Merge the two programs by combining all controls from each.
C.Implement a completely new framework that meets both regulations.
D.Perform a gap analysis against the requirements and prioritize remediation.
AnswerD

A gap analysis against PCI DSS and GDPR requirements identifies where each legacy programme falls short, letting the CISO prioritise remediation by risk and compliance impact. This harmonises differing maturity levels using a common control baseline rather than adopting one company's programme wholesale.

Why this answer

A gap analysis against the combined requirements of PCI DSS and GDPR identifies exactly where each legacy program falls short, allowing the CISO to prioritize remediation based on risk and regulatory obligation. This is the standard, defensible approach for harmonizing programs during M&A because it is evidence-based, accounts for differing maturity levels, and produces a prioritized roadmap rather than a blunt consolidation. It also respects that the two regulations have different scopes (PCI DSS for cardholder data, GDPR for personal data of EU residents).

Exam trap

The trap is choosing the seemingly decisive option ('adopt the stricter program' or 'build a new framework') over the methodical one; CISM emphasizes risk-based, evidence-driven approaches, so gap analysis is almost always the correct answer for harmonization questions.

How to eliminate wrong answers

Option A is wrong because simply adopting the acquirer's program ignores the acquired company's regulatory context and may leave GDPR or PCI DSS gaps if the acquirer's program was not designed for those obligations. Option B is wrong because merging all controls from both programs creates redundancy, conflict, and bloat without identifying which controls actually satisfy the combined requirements — it is a union, not a harmonization. Option C is wrong because building an entirely new framework is costly, slow, and unnecessary when existing frameworks (ISO 27001, NIST) can be mapped to both regulations; it also introduces new risk during integration.

175
MCQeasy

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

A.To reduce the workload on the communications lead.
B.To comply with regulatory requirements for breach notification.
C.To ensure consistent and timely messaging to stakeholders.
D.To avoid legal liability by using approved language.
AnswerC

Pre-approved templates remove drafting delays and standardise wording, so stakeholders receive accurate, timely notifications during high-pressure incidents. This directly satisfies the stem's primary-reason constraint: communication speed and consistency, rather than investigation, containment or forensic accuracy, which other options address.

Why this answer

Communication templates ensure that notifications are consistent, accurate, and timely during the stress of an incident, reducing the risk of errors or omissions.

176
MCQmedium

An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?

A.All security decisions are made by a central security team
B.Each business unit has full autonomy over security without central coordination
C.Security is outsourced to a third-party provider
D.A central security team sets policies and provides oversight, while business units execute security operations
AnswerD

Hybrid governance splits accountability: the central security function defines policy and monitors compliance, while business units own day-to-day execution. This matches the stem's requirement by combining enterprise-wide consistency with delegated operational control, rather than centralising all operations or leaving each unit fully autonomous.

Why this answer

A hybrid governance model combines central oversight with distributed execution: a central security team sets policies, standards, and provides oversight, while business units execute security operations tailored to their needs. This balances consistency with business agility. It is the defining characteristic of a federated or hybrid approach.

Exam trap

CISM often tests the distinction between centralized, decentralized, and hybrid governance — candidates confuse hybrid with decentralized because both involve business units, but hybrid retains central policy-setting and oversight.

How to eliminate wrong answers

Option A is wrong because all decisions made by a central team describes a fully centralized model, not hybrid. Option B is wrong because full autonomy without central coordination describes a decentralized model, which lacks the central policy-setting and oversight that hybrid includes. Option C is wrong because outsourcing security to a third party is a sourcing decision, not a governance model — hybrid governance can exist with or without outsourcing.

177
MCQmedium

A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?

A.Measure the reduction in total security incidents across the organisation year over year.
B.Survey employees annually on their satisfaction with security training content and delivery.
C.Use simulated phishing campaigns with click and report rates, combined with role-based training completion and knowledge assessments.
D.Track the total number of phishing emails reported by staff each month and report the trend.
AnswerC

Combining simulated phishing click and report rates with training completion and knowledge assessment results provides behavioural, participation, and comprehension data. This triangulation shows whether awareness activities change behaviour and where gaps persist, enabling targeted improvement. It gives the board evidence of reduced susceptibility over time, which is the outcome the programme is intended to deliver.

Why this answer

A credible awareness measurement approach combines behavioural evidence from phishing simulations with participation data from training completion and comprehension checks from knowledge assessments. Together these show whether staff can recognise threats and act correctly, and they reveal where reinforcement is needed. This mix produces the trend evidence boards need to judge whether the programme is reducing human risk over time.

Exam trap

The trap here is treating a single metric, such as click rate or incident count, as proof of awareness effectiveness when attribution requires multiple complementary measures.

178
Multi-Selecthard

A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)

Select 3 answers
A.Monetary value of potential losses
B.Detailed technical vulnerabilities
C.Likelihood of occurrence expressed as annual probability
D.Anecdotal stories of past incidents
E.Comparison of residual risk to risk appetite
AnswersA, C, E

Why this answer

Monetary value of potential losses (A) is correct because it translates technical risk into financial terms that board members understand, enabling informed decisions on resource allocation for risk mitigation. This aligns with the CISM focus on business-aligned risk communication, where quantitative metrics like Annualized Loss Expectancy (ALE) directly support cost-benefit analysis.

Exam trap

The trap here is that candidates often select 'Detailed technical vulnerabilities' (B) thinking it demonstrates thoroughness, but the board requires business-impact language, not technical depth.

Why the other options are wrong

B

Board members typically lack technical background; focus on business impact.

D

Anecdotes are not quantitative and may skew perception.

179
MCQhard

A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?

A.During the testing phase.
B.During the requirements gathering phase.
C.During the post-implementation review.
D.During the deployment phase.
AnswerB

Involving security during requirements gathering ensures that security controls and compliance needs are built into the system from the start. This is the most cost-effective and proactive approach, aligning with the principle of 'security by design.' It allows for risk assessment and identification of security requirements before design and development.

Why this answer

Security should be involved from the requirements gathering phase to ensure that security requirements are identified and incorporated early. This proactive approach reduces costs and risks. Later phases are for validation and verification, but they cannot compensate for missing requirements.

Exam trap

The trap here is thinking that security can be effectively added later in the project lifecycle, but early involvement is critical to avoid costly rework and vulnerabilities.

180
MCQeasy

Which of the following is the best indicator that an organization has effective information security governance?

A.Achievement of ISO 27001 certification
B.The security budget has increased year over year
C.Low number of security incidents
D.Security metrics are reviewed by the board quarterly
AnswerD

Board-level quarterly review of security metrics demonstrates that governance is actively directed and monitored at the highest level, not delegated and forgotten. This satisfies the stem's effectiveness indicator by showing accountability, oversight, and alignment between security performance and enterprise objectives.

Why this answer

(ISO 27001 certification) indicates compliance, not necessarily governance performance. Option B (security budget increased) does not guarantee effectiveness. Option C (low number of incidents) could be due to luck.

Option D (board review of metrics) demonstrates governance oversight and strategic alignment.

181
MCQhard

During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?

A.Coordinating all external and internal communications
B.Authorizing financial expenditures for incident response
C.Directing technical containment efforts
D.Preserving digital evidence for litigation
AnswerA

The communications lead owns the single authoritative voice during a major incident, coordinating internal staff messaging and external stakeholder, media, and regulator communications. This prevents conflicting statements and satisfies the stem's requirement for unified crisis messaging under CMT direction.

Why this answer

The communications lead on a Crisis Management Team (CMT) is specifically designated to own the communications function during an incident — both internal (employees, executives, board) and external (customers, media, regulators, law enforcement). This role ensures a single, consistent, approved message is delivered to all stakeholders, preventing conflicting or premature disclosures that could escalate reputational and legal exposure.

Exam trap

CISM often tests role clarity within the CMT — candidates confuse the communications lead's coordination duty with the technical, financial, or legal responsibilities owned by other CMT members.

How to eliminate wrong answers

Option B is wrong because financial authorization is the responsibility of the CFO, finance lead, or incident sponsor — not the communications lead, who typically has no budget authority. Option C is wrong because directing technical containment is the role of the technical/IT lead or incident response manager, not communications. Option D is wrong because evidence preservation is the responsibility of the forensics/legal team (often coordinated with counsel to maintain chain of custody), not the communications function.

182
Multi-Selecteasy

Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Enforcing least privilege access controls
B.Implementing intrusion detection systems
C.Discontinuing a high-risk business process
D.Purchasing cyber insurance
E.Accepting the risk in a formal statement
AnswersA, B

Least privilege restricts each account to the permissions its role requires, shrinking the attack surface and limiting blast radius if credentials are compromised. It is a preventive administrative control that lowers inherent risk rather than transferring or accepting it.

Why this answer

Option A (Enforcing least privilege access controls) is a risk mitigation control because it reduces the likelihood and impact of unauthorized access by limiting users to only the permissions required for their role, directly lowering exposure to threats. Option B (Implementing intrusion detection systems) is also a mitigation control because it detects malicious activity and enables timely response, thereby reducing the potential damage from attacks. In contrast, Option C (Discontinuing a high-risk business process) is risk avoidance, as the activity is eliminated rather than controlled.

Option D (Purchasing cyber insurance) is risk transference, shifting financial consequences to an insurer. Option E (Accepting the risk in a formal statement) is risk acceptance, where no control is implemented and the risk is knowingly retained.

Exam trap

CISM often tests the confusion between risk mitigation and the other treatment options — candidates frequently misclassify insurance as mitigation when it is actually risk transference.

183
MCQmedium

An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?

A.Storing evidence in a secure, access-controlled location.
B.Creating forensic images of all affected systems before remediation.
C.Encrypting all evidence files to prevent unauthorized access.
D.Documenting the chain of custody for all evidence collected.
AnswerD

Documenting the chain of custody provides an unbroken, auditable record of who handled each artefact, when, and for what purpose. This directly satisfies the litigation constraint in the stem, since courts require proof that evidence remained unaltered from seizure to presentation; gaps or undocumented transfers render it inadmissible regardless of technical accuracy.

Why this answer

Admissibility of digital evidence in court hinges on demonstrating that the evidence has not been tampered with from the moment of collection to presentation. The chain of custody is the legally mandated documentation that tracks every person who handled the evidence, the time and date of each transfer, and the purpose of each action. Without a complete and verifiable chain of custody, the opposing counsel can successfully argue that the evidence may have been altered, making it inadmissible regardless of how securely it was stored or imaged.

Exam trap

The trap here is that candidates confuse operational best practices (like creating forensic images or securing evidence) with the legal requirement for admissibility, which is fundamentally about proving an unbroken chain of custody through meticulous documentation.

How to eliminate wrong answers

Option A is wrong because storing evidence in a secure, access-controlled location protects its integrity but does not create the legal record required to prove that integrity in court; a secure location alone cannot rebut allegations of tampering without documented custody transfers. Option B is wrong because creating forensic images before remediation is a best practice for preserving evidence, but the images themselves are useless for litigation if the chain of custody is not documented; the image must be accompanied by a hash (e.g., SHA-256) and a custody log to be admissible. Option C is wrong because encrypting evidence files prevents unauthorized access but introduces a separate admissibility hurdle: if the encryption key is lost or the decryption process cannot be verified, the evidence may be deemed inaccessible or its integrity questioned; encryption does not replace the need for a documented chain of custody.

184
MCQmedium

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

A.Reporting to the CEO
B.Reporting to the COO
C.Reporting to the board or risk committee
D.Reporting to the CFO
AnswerC

Reporting to the board or risk committee removes the CIO's operational bias toward delivery timelines and cost, giving security initiatives independent escalation. This directly resolves the stem's conflict-of-interest constraint that causes deprioritisation under CIO reporting.

Why this answer

Reporting to the board or risk committee provides the CISO with an independent reporting line that is not subordinate to the CIO or other executives whose priorities may conflict with security. This structure ensures security concerns are elevated to a governance body with fiduciary oversight, reducing the likelihood that security initiatives are deprioritized due to operational or budgetary conflicts. It also aligns with governance best practices that separate security oversight from IT delivery.

Exam trap

CISM often tests the difference between administrative reporting (to CIO/CEO) and governance reporting (to board/risk committee); candidates may pick CEO because it sounds senior, but the board provides the independence needed to resolve conflicts of interest.

How to eliminate wrong answers

Option A is wrong because reporting to the CEO still places the CISO within the executive team where competing priorities (e.g., revenue, product deadlines) can overshadow security, and the CEO may not have the specialized oversight of a board committee. Option B is wrong because the COO is focused on operations and may prioritize uptime and efficiency over security controls, creating similar conflicts. Option D is wrong because the CFO is primarily concerned with financial performance and may view security as a cost center, making it harder to justify security investments.

185
Multi-Selectmedium

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Select 3 answers
A.Exit procedures to ensure data is returned or destroyed.
B.Performing a single annual assessment for all vendors.
C.Onboarding risk assessment based on vendor criticality and data access.
D.Requiring all vendors to have ISO 27001 certification.
E.Ongoing monitoring of vendor security posture.
AnswersA, C, E

Exit procedures guarantee that vendor-held data is returned or securely destroyed when the relationship ends, closing the offboarding gap where residual data exposure persists. This satisfies the stem's requirement for a key TPRM component by addressing the full vendor lifecycle, not just onboarding.

Why this answer

Option A is correct because an effective TPRM program must define exit procedures that ensure vendor-held data is returned or securely destroyed when the relationship ends, addressing data retention and offboarding risk. Option C is correct because onboarding risk assessments should be risk-tiered, scoped to the vendor's criticality and level of access to systems and data, rather than applying uniform treatment. Option E is correct because vendor risk is continuous, so ongoing monitoring of the vendor's security posture (for example, via security ratings, questionnaires, or attestation tracking) is needed to detect changes after onboarding.

Option B is not appropriate because a single annual assessment for all vendors ignores differing risk levels and fails to provide continuous oversight. Option D is not required because ISO 27001 certification is only one possible assurance mechanism; mandating it for all vendors is overly prescriptive and does not fit a risk-based program.

Exam trap

CISM often tests the principle of risk-based vendor management; candidates may pick 'all vendors must be ISO 27001 certified' because it sounds rigorous, but the exam expects recognition that a one-size-fits-all requirement is not effective TPRM.

186
MCQeasy

A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?

A.A detailed list of all security controls that will be implemented and their associated costs.
B.A comparison of the company's security posture to industry benchmarks and competitor practices.
C.An analysis of the potential financial impact of security incidents and how the program will mitigate those risks to protect revenue and reputation.
D.A timeline for achieving compliance with relevant regulations such as GDPR or HIPAA.
AnswerC

Executives prioritize risk and financial impact. By quantifying potential losses from incidents and showing how the security program reduces those risks, the CISO directly ties security to business objectives like revenue protection and reputation management. This approach speaks the language of the business and makes a compelling case for investment. It demonstrates that security is not just a cost center but a business enabler.

Why this answer

An analysis of potential financial impact and risk mitigation directly aligns the security program with business objectives by showing how it protects revenue and reputation. Executives are more likely to fund initiatives that clearly address business risk and demonstrate a return on investment. This approach makes the business case compelling and strategic.

Exam trap

The trap here is focusing on technical controls or compliance instead of framing the business case in terms of financial risk and business enablement, which resonates with executives.

187
MCQmedium

A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?

A.Risks whose residual risk level exceeds the organization's defined risk appetite.
B.Risks that the security team has been unable to remediate within the current fiscal year.
C.Risks that received the highest inherent risk scores before any controls were applied.
D.Risks associated with systems that support the organization's most revenue-generating business processes.
AnswerA

Escalation for formal acceptance is driven by residual risk, not inherent risk, because implemented controls already reduce exposure. Only when the remaining exposure breaches the tolerance thresholds set by executive management does the risk require a decision at board level. Risks sitting inside appetite are managed by line management under delegated authority, so this criterion correctly routes decisions to the body empowered to accept them.

Why this answer

Board-level risk acceptance is triggered when residual risk exceeds the appetite and tolerance thresholds that executive management has established. Inherent scores, business criticality, and remediation delays are inputs to analysis but do not by themselves indicate that a decision above delegated authority is required. Routing only appetite-breaching residual risks keeps the committee focused on exposures that genuinely require formal acceptance.

Exam trap

The trap here is assuming that the highest-scoring or most business-critical risks automatically go to the board, when escalation is actually governed by residual risk exceeding documented risk appetite.

188
MCQhard

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

A.Number of phishing simulations conducted
B.Percentage of IT budget allocated to security
C.Return on investment (ROI) from avoided breach costs
D.Number of security tools deployed
AnswerC

ROI from avoided breach costs translates security spending into financial terms the board already uses for capital decisions. This satisfies the stem by expressing value as quantifiable monetary return, making the budget request directly comparable to other investment proposals.

Why this answer

Return on investment (ROI) from avoided breach costs translates security spending into financial terms that the board understands, showing how investments prevent losses. This metric directly ties security to business value by quantifying the cost avoidance from prevented incidents, which is more compelling than activity-based metrics. Boards are accountable for financial performance and risk, so ROI resonates with their fiduciary responsibilities.

Exam trap

CISM often tests the difference between activity metrics (phishing simulations, tools deployed) and outcome/value metrics (ROI from avoided breach costs); candidates may pick activity metrics because they are easy to measure, but the board cares about financial impact.

How to eliminate wrong answers

Option A is wrong because the number of phishing simulations conducted is an activity metric that shows effort but not effectiveness or financial impact; it does not demonstrate value to the board. Option B is wrong because the percentage of IT budget allocated to security is a cost metric, not a value metric; it shows how much is spent, not what is gained. Option D is wrong because the number of security tools deployed is a vanity metric that does not indicate whether those tools reduce risk or cost.

189
MCQeasy

Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?

A.P3 — Medium
B.P2 — High
C.P4 — Low
D.P1 — Critical
AnswerD

P1 critical is defined by major business impact, executive notification and continuous 24/7 response. The stem's three constraints — severe impact, executive escalation and round-the-clock engagement — map precisely onto this highest severity tier, distinguishing it from P2's business-hours handling.

Why this answer

P1 (critical) incidents have the highest severity and require immediate, around-the-clock response.

190
MCQmedium

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

A.Immediately after containment
B.Only after the root cause analysis is completed
C.Within 2 weeks of incident resolution
D.Within 30 days of incident resolution
AnswerC

Holding the review within two weeks balances memory retention against operational recovery, satisfying the stem's post-resolution timing constraint. Participants still recall technical details and decisions while the incident remains relevant, yet have had sufficient time to decompress. This window also allows evidence gathering and timeline reconstruction before details fade or staff rotate.

Why this answer

Holding the lessons learned meeting within about two weeks of resolution balances memory freshness with enough time to gather facts and complete preliminary analysis. It is soon enough that details are still accurate but late enough that the team is no longer in firefighting mode. This aligns with common IR frameworks like NIST SP 800-61.

Exam trap

CISM often tests the tension between 'as soon as possible' and 'after enough analysis' — the correct answer is a middle-ground timeframe, not the extreme.

How to eliminate wrong answers

Option A is wrong because immediately after containment the team is still stabilizing the environment and lacks the full picture needed for meaningful lessons. Option B is wrong because waiting for a complete root cause analysis can take weeks or months, causing memory decay and delaying improvements. Option D is wrong because 30 days is too long — details fade, personnel move on, and corrective actions lose urgency.

191
MCQmedium

A global financial services firm is establishing an information security governance framework. The board of directors wants assurance that security risks are managed effectively across all business units. Which of the following is the MOST important element for the CISO to implement to provide this assurance?

A.A security governance committee with representation from all business units, reporting to the board.
B.A security awareness program for all employees.
C.An annual penetration test of all critical systems.
D.A centralized security operations center (SOC) that monitors all network traffic.
AnswerA

A governance committee with cross-functional representation ensures that security risks are considered in all business decisions and provides a direct reporting line to the board. This structure enables oversight, accountability, and consistent risk management across units. It is the most important element because it establishes the organizational mechanism for governance, rather than just technical controls.

Why this answer

The most important element is a security governance committee with representation from all business units, reporting to the board. This committee provides the structure for consistent risk management, oversight, and accountability across the organization. It ensures that security risks are considered in business decisions and gives the board a direct line of sight into how risks are being managed, which is essential for effective governance.

Exam trap

The trap here is focusing on technical controls like SOCs or penetration tests as the primary means of assurance, when governance requires an organizational structure that ensures oversight and accountability.

192
MCQeasy

Based on the risk register entry, what is the primary gap in the current controls?

A.The policy exists but is not enforced technically
B.MDM is not a suitable control
C.The risk score is too low to require action
D.The likelihood of occurrence is low
AnswerA

The register shows a documented policy with no technical enforcement mechanism, so the control gap is compliance rather than design. Without automated enforcement, adherence depends on user behaviour, leaving the identified risk untreated. Closing this requires a technical control that compels the required action rather than relying on the written policy alone.

Why this answer

The risk register entry indicates that a mobile device management (MDM) policy exists but is not enforced through technical controls, such as device compliance checks or automated policy application. This creates a gap because the policy remains a paper-based directive without active enforcement mechanisms like certificate-based authentication or conditional access rules, leaving devices vulnerable to non-compliance and potential data breaches.

Exam trap

The trap here is that candidates assume a policy exists means the control is effective, but CISM emphasizes that a policy without technical enforcement (e.g., via MDM or NAC) is a gap, not a control.

How to eliminate wrong answers

Option B is wrong because MDM is a suitable control for managing mobile devices; the issue is not the suitability of MDM itself but the lack of technical enforcement of the existing policy. Option C is wrong because the risk score being low does not justify inaction; the gap in controls means the residual risk may be higher than assessed, and a low score does not eliminate the need for enforcement. Option D is wrong because a low likelihood of occurrence does not address the control gap; even if likelihood is low, the absence of technical enforcement means the control is ineffective, and the risk could materialize under changing conditions.

193
MCQeasy

A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerA

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. EDR detects and responds to malicious activity, thereby reducing the chance of successful POS malware or limiting its damage. The organization is taking action to lower the risk to an acceptable level. This is a classic example of mitigation.

Why this answer

Risk mitigation is the process of implementing controls to reduce the likelihood or impact of a risk. By deploying EDR, the organization aims to detect and respond to POS malware, thereby lowering the risk. Avoidance would mean stopping the activity, transfer would involve insurance, and acceptance would mean no action.

Therefore, mitigation is the correct treatment strategy.

Exam trap

The trap here is confusing mitigation with transfer or acceptance; implementing a control reduces risk rather than shifting or tolerating it.

194
MCQhard

A multinational corporation operates in multiple jurisdictions with varying data protection laws. The CISO is establishing a governance structure to manage compliance with these laws while maintaining a consistent security posture. Which of the following is the MOST effective approach for the CISO to take?

A.Delegate compliance responsibility entirely to local business units to tailor security controls to each jurisdiction.
B.Develop a common governance framework with baseline controls, supplemented by local addenda to address specific regulatory requirements.
C.Adopt the regulatory requirements of the headquarters country as the global standard for all locations.
D.Implement a single global security policy that meets the strictest regulatory requirements across all jurisdictions.
AnswerB

This approach balances global consistency with local compliance. A common framework ensures a baseline security posture and centralized oversight, while local addenda address jurisdiction-specific laws. It is the most effective way to manage varying requirements without sacrificing enterprise-wide risk management or operational efficiency.

Why this answer

The most effective approach is a common governance framework with baseline controls and local addenda. This ensures a consistent global security posture while allowing for compliance with varying local laws. It provides centralized oversight and scalability, avoiding the pitfalls of a one-size-fits-all policy or full decentralization.

This hybrid model is a recognized best practice for multinational governance.

Exam trap

The trap here is assuming that either a single global policy or full local delegation is sufficient, when the most effective approach combines global baseline with local flexibility.

195
MCQmedium

A multinational corporation has a decentralized information security program. Each business unit manages its own security budget and controls, leading to inconsistent practices and duplicated efforts. The CISO wants to improve program efficiency and effectiveness while respecting business unit autonomy. Which of the following is the BEST approach?

A.Outsource all security functions to a managed security service provider (MSSP).
B.Centralize all security decision-making and budgets under the CISO.
C.Establish a common security framework and governance model that defines minimum standards while allowing business units flexibility.
D.Allow each business unit to continue independently but require them to report security metrics to the CISO.
AnswerC

This approach balances central governance with local autonomy. A common framework ensures consistent risk management and compliance, while flexibility allows units to address unique risks. It promotes efficiency by reducing duplication and leverages shared services. CISM supports such hybrid models to align security with business objectives across diverse environments.

Why this answer

The best approach is to establish a common security framework and governance model that sets minimum standards while allowing flexibility. This hybrid model enables consistent risk management and compliance across the organization, reduces duplication, and respects business unit autonomy. It aligns with CISM principles of balancing enterprise-wide security with business-specific needs.

Exam trap

The trap here is assuming that full centralization or full decentralization is the only solution, overlooking the benefits of a federated governance model.

196
MCQmedium

According to the exhibit, which role is responsible for conducting forensic analysis?

A.Incident Manager
B.Technical Lead
C.Legal Counsel
D.Communication Lead
AnswerB

The Technical Lead conducts the forensic analysis, gathering and examining evidence to determine how the incident occurred. This role owns the hands-on investigation, distinguishing it from the Incident Response Manager, who coordinates, and the Communications Lead, who handles messaging.

Why this answer

The Technical Lead is responsible for conducting forensic analysis because they possess the deep technical expertise required to preserve, acquire, and examine digital evidence without altering its integrity. In incident response, the Technical Lead oversees the technical team, ensuring that chain-of-custody procedures are followed and that forensic tools (e.g., FTK Imager, EnCase, or dd for disk imaging) are correctly applied to capture volatile and non-volatile data.

Exam trap

The trap here is that candidates confuse the Incident Manager's overall authority with the hands-on technical execution, assuming the manager performs all tasks, when in fact the Technical Lead is the specific role for forensic analysis in a structured incident response team.

How to eliminate wrong answers

Option A is wrong because the Incident Manager coordinates the overall response, allocates resources, and communicates with stakeholders, but does not perform hands-on forensic analysis. Option C is wrong because Legal Counsel advises on legal compliance, data privacy laws, and evidentiary admissibility, but does not execute forensic collection or examination. Option D is wrong because the Communication Lead manages internal and external messaging, public relations, and stakeholder updates, not the technical forensic investigation.

197
MCQhard

A CISO has implemented a security program based on ISO/IEC 27001. During a management review, the CIO asks how the program contributes to business value. Which of the following metrics would BEST demonstrate the program's contribution to business value?

A.Reduction in the likelihood of material breaches affecting critical business processes.
B.Number of security incidents detected and resolved within service level agreements.
C.Total number of security controls implemented across the enterprise.
D.Percentage of employees who completed security awareness training.
AnswerA

This metric directly ties security efforts to business value by focusing on the protection of critical processes. It demonstrates how the program reduces the risk of disruptions that could impact revenue, reputation, or compliance. By quantifying risk reduction in business terms, it provides a clear link between security investments and the preservation of business objectives, which resonates with executive leadership.

Why this answer

The correct answer is the reduction in likelihood of material breaches affecting critical business processes. This metric translates security efforts into business terms by focusing on risk reduction for what matters most. It demonstrates that the program is not just implementing controls but actively protecting the organization's ability to achieve its objectives, which is the essence of business value.

Exam trap

The trap here is equating activity metrics like training completion or number of controls with business value, when business value is best demonstrated by risk reduction for critical business processes.

198
Multi-Selecthard

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that the framework will effectively manage risk and comply with regulations such as GDPR and PCI DSS. Which of the following are essential components of an effective information security governance framework? (Choose two.)

Select 2 answers
A.A comprehensive set of security policies and standards.
B.A formal security awareness and training program for all employees.
C.A real-time security operations center (SOC) with 24/7 monitoring.
D.A documented risk appetite statement approved by executive management.
E.A detailed inventory of all IT assets with assigned owners.
AnswersA, D

Security policies and standards are fundamental to governance. They establish the rules and expectations for protecting information assets and ensure consistent implementation of controls. They also provide a basis for compliance and audit. Without them, security efforts are ad hoc and lack formal structure. They are a key mechanism for communicating management's directives.

Why this answer

An effective information security governance framework must include a documented risk appetite statement approved by executive management and a comprehensive set of security policies and standards. The risk appetite guides risk-based decisions and ensures alignment with business strategy, while policies and standards establish the rules and expectations for protecting information. These components provide direction, oversight, and accountability, which are the hallmarks of governance.

Exam trap

The trap here is selecting operational capabilities like a SOC or asset inventory as essential governance components, when governance is about direction and oversight, not operational execution.

199
MCQeasy

Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?

A.Data owner
B.Chief Information Security Officer (CISO)
C.Board of directors
D.Risk owner
AnswerD

The risk owner is accountable for identifying, assessing and managing risks within their business unit, owning the response decision and residual exposure. This satisfies the stem's requirement, distinguishing them from security staff who advise and from senior management who set appetite.

Why this answer

The risk owner is the individual within a business unit who is accountable for ensuring that information security risks are identified, assessed, and managed. This role owns the risk treatment plan and is responsible for implementing controls to reduce risk to an acceptable level, as defined by the organization's risk appetite.

Exam trap

The trap here is confusing the risk owner with the CISO, as candidates often assume the CISO owns all risks, but the CISO is responsible for the risk management process, not for owning specific business unit risks.

How to eliminate wrong answers

Option A is wrong because the data owner is responsible for classifying and protecting data assets, not for managing the overall risk process within a business unit. Option B is wrong because the CISO is an enterprise-level executive who oversees the information security program and risk management framework, but does not own the risks within individual business units. Option C is wrong because the board of directors provides oversight and sets risk appetite, but is not operationally responsible for identifying, assessing, and managing risks in a specific business unit.

200
MCQeasy

A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?

A.Block the IP address at the firewall.
B.Ignore the alert as it is likely a false positive.
C.Disable the web server.
D.Notify law enforcement.
AnswerA

Blocking the source IP at the firewall immediately halts the brute-force attempts, satisfying the requirement for an immediate response. It is fast, reversible and low-risk, stopping the attack at the network perimeter while preserving logs for later analysis, unlike disabling accounts or longer-term tuning.

Why this answer

The immediate response to a brute-force attack from a single external IP is to block that IP at the firewall. This stops the attack at the network perimeter, preventing further authentication attempts without affecting legitimate users (assuming the IP is not a known legitimate source). Delaying action could allow the attacker to compromise an account via password guessing, especially since common usernames are being targeted.

Exam trap

The trap here is that candidates may think notifying law enforcement is the first step, but CISM emphasizes immediate containment (blocking the IP) before escalation or external notification.

How to eliminate wrong answers

Option B is wrong because ignoring the alert could allow a successful brute-force attack, leading to account compromise; SIEM alerts for high failed login rates are a classic indicator of an active attack, not a false positive. Option C is wrong because disabling the web server would cause a denial of service for all legitimate users, which is disproportionate and unnecessary when a targeted firewall block can mitigate the threat. Option D is wrong because notifying law enforcement is not an immediate technical response; it should be done after containment and as part of the formal incident response process, not as the first action.

201
MCQhard

An organization's information security governance committee has not met for the past six months. Which of the following is the most significant risk associated with this situation?

A.Increased operational costs due to uncoordinated security investments
B.Regulatory fines from noncompliance
C.Delayed response to security incidents
D.Lack of oversight leading to misalignment with business strategy
AnswerD

Sustained absence of committee scrutiny removes the governance layer that aligns security investment with organisational objectives. Security decisions then default to operational or technical priorities, drifting from business strategy. This directly satisfies the stem's governance-failure scenario, where oversight is the control that preserves strategic alignment.

Why this answer

The governance committee's failure to meet for six months directly undermines the strategic alignment of security initiatives with business objectives. Without regular oversight, security investments and priorities may drift from the organization's risk appetite and strategic goals, leading to misallocation of resources and increased exposure to unmanaged risks. This misalignment is the most significant risk because it affects the entire security program's effectiveness and long-term viability.

Exam trap

The trap here is that candidates often confuse operational risks (like delayed incident response) with governance risks, failing to recognize that the committee's primary role is strategic oversight, not day-to-day operations.

How to eliminate wrong answers

Option A is wrong because increased operational costs from uncoordinated security investments are a consequence of poor governance, but they are a financial impact rather than the primary governance risk; the core issue is strategic misalignment, not cost overruns. Option B is wrong because regulatory fines from noncompliance are a potential outcome of specific control failures, but the committee's absence does not directly cause noncompliance—it creates a lack of oversight that may lead to noncompliance over time, not an immediate fine. Option C is wrong because delayed response to security incidents is an operational risk typically tied to incident response processes and team readiness, not directly to the governance committee's meeting cadence; the committee's role is strategic oversight, not tactical incident handling.

202
MCQhard

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

A.Data access level and service criticality
B.Contract value
C.Duration of the relationship
D.Vendor size
AnswerA

Data access level and service criticality determine potential impact if a vendor is breached, so they drive assessment priority. This satisfies the stem's prioritisation constraint by ranking vendors on inherent risk exposure rather than contract value or relationship length.

Why this answer

The highest-weighted factor in third-party risk prioritization is the combination of data access level and service criticality. This is because risk exposure is directly proportional to the sensitivity of data the vendor can access and how essential the vendor's service is to business operations. A vendor with access to regulated data (e.g., PII, PHI) or that supports a critical business function poses a significantly higher risk if compromised, regardless of contract value or vendor size.

Thus, these two dimensions determine the potential impact of a vendor-related incident, making them the primary drivers for assessment prioritization.

Exam trap

CISM often tests the misconception that financial or relationship factors (contract value, duration, vendor size) are primary risk indicators, when in fact data access and service criticality are the core determinants of third-party risk exposure.

How to eliminate wrong answers

Option B is wrong because contract value is a financial metric, not a risk indicator; a low-value contract could still involve access to highly sensitive data or critical services, while a high-value contract might be for non-critical goods with no data access. Option C is wrong because the duration of the relationship does not inherently increase risk; a long-standing vendor may have mature controls, while a new vendor might introduce unknown risks, but duration alone does not determine risk exposure. Option D is wrong because vendor size is not a reliable proxy for risk; small vendors can be highly secure, and large vendors can have significant vulnerabilities or poor security practices, so size should not be the primary factor.

203
MCQmedium

During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?

A.Notify the client whose data was accessed.
B.Revoke the contractor's access and terminate the contract.
C.Contact the contractor to ask about the activity.
D.Disable the compromised credentials and initiate forensic investigation.
AnswerD

Disabling the compromised contractor credentials immediately halts further unauthorised access to sensitive data, satisfying containment as the priority during an active incident. Forensic investigation then proceeds on preserved evidence without the attacker retaining live access, balancing eradication with evidentiary integrity.

Why this answer

When compromised credentials are identified during an incident, the immediate priority is to contain the threat by disabling the compromised credentials to prevent further unauthorized access, and then to initiate a forensic investigation to determine the scope, method, and impact of the breach. Option D correctly follows the incident response containment and investigation phases, ensuring that evidence is preserved and the attack vector is understood before any notification or contractual actions are taken.

Exam trap

The trap here is that candidates confuse 'immediate containment' with 'immediate notification or punitive action', failing to recognize that the first priority in incident management is to stop the bleeding and secure evidence, not to assign blame or notify external parties.

How to eliminate wrong answers

Option A is wrong because notifying the client before the investigation is complete could cause unnecessary panic, violate legal hold requirements, and may be premature if the scope of data access is not yet fully understood. Option B is wrong because terminating the contract immediately could destroy evidence, such as logs or system artifacts, and may be an overreaction if the contractor's credentials were stolen rather than misused by the contractor. Option C is wrong because contacting the contractor could alert a potential malicious insider or an attacker who has compromised the contractor's account, allowing them to cover their tracks or destroy evidence before forensic analysis can begin.

204
MCQhard

During a major incident, the incident response manager is coordinating containment while the crisis management team (CMT) handles business continuity decisions. A responder proposes immediately wiping and rebuilding an affected server to restore service quickly, but the server contains evidence relevant to a potential legal action. Which of the following is the MOST appropriate action for the incident response manager to take?

A.Delegate the decision entirely to the forensic investigator and proceed based on their technical recommendation alone.
B.Consult legal counsel to determine preservation obligations, then choose a containment or recovery approach that preserves evidence while restoring service.
C.Refuse to restore service until the forensic investigation is fully complete, regardless of business impact.
D.Authorize the rebuild immediately because restoring service takes precedence over evidence preservation in all incidents.
AnswerB

Legal counsel determines whether a litigation hold or preservation duty applies, and the response must respect that obligation. The manager can often restore service using alternate infrastructure, network isolation, or forensic imaging before rebuild, satisfying both operational and legal needs. Consulting counsel first ensures the chosen containment method does not inadvertently destroy evidence and keeps the response defensible.

Why this answer

When legal action is anticipated, evidence preservation becomes a formal obligation that must be balanced against service restoration. The incident response manager should engage legal counsel to confirm preservation requirements, then select a containment or recovery method that keeps evidence intact, such as imaging the server or rebuilding on alternate infrastructure. This coordinated approach protects both operational continuity and the organization's legal position, avoiding the extremes of reckless destruction or unnecessary service outage.

Exam trap

The trap here is treating service restoration and evidence preservation as mutually exclusive, when in practice legal guidance plus forensic imaging or alternate infrastructure can satisfy both obligations.

205
Multi-Selecthard

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Select 3 answers
A.Updating incident response plans and playbooks based on lessons learned
B.Activating the disaster recovery site
C.Conducting root cause analysis using techniques like 5 Whys
D.Sharing indicators of compromise with relevant ISACs
E.Implementing immediate containment measures
AnswersA, C, D

Feeding lessons learned back into plans and playbooks closes the improvement loop, ensuring the next incident is handled better. This directly satisfies the post-incident phase's objective of institutionalising corrective actions rather than merely restoring service.

Why this answer

Option A is correct because the post-incident phase includes reviewing what happened and feeding lessons learned back into the incident response plan and playbooks so future responses improve. Option C is correct because root cause analysis, often using techniques such as 5 Whys or fishbone diagrams, is a core post-incident activity that identifies the underlying cause rather than just the symptom. Option D is correct because sharing indicators of compromise with relevant Information Sharing and Analysis Centers (ISACs) is a post-incident coordination activity that helps the broader community detect and defend against the same threat.

Option B is not correct because activating the disaster recovery site is a response or recovery action, not a post-incident review activity. Option E is not correct because implementing immediate containment measures occurs during the containment phase of incident response, before the post-incident phase begins.

206
MCQeasy

A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?

A.To manage day-to-day security operations.
B.To implement security controls across the organization.
C.To approve technical security solutions.
D.To ensure security strategy aligns with business objectives and provide oversight.
AnswerD

The committee gives the CISO a forum where senior business and security stakeholders agree strategy, prioritise risk, and monitor performance. This ensures security decisions reflect business objectives and receive ongoing executive oversight rather than remaining an isolated technical function.

Why this answer

The primary purpose of an information security governance committee is to ensure that the security strategy aligns with business objectives and to provide oversight. This committee does not execute day-to-day operations or implement controls; instead, it sets direction, reviews risk posture, and ensures that security investments support organizational goals, as defined in frameworks like COBIT and ISO 38500.

Exam trap

The trap here is that candidates often confuse governance (strategic oversight and alignment) with management (tactical implementation and operations), leading them to select options that describe operational or technical tasks rather than the committee's true strategic purpose.

How to eliminate wrong answers

Option A is wrong because managing day-to-day security operations is the responsibility of operational teams (e.g., SOC, IT security staff), not a governance committee, which focuses on strategic oversight. Option B is wrong because implementing security controls is a tactical or operational activity carried out by technical teams based on policies approved by governance, not the committee's primary role. Option C is wrong because approving technical security solutions is typically a function of architecture review boards or engineering leads, while the governance committee focuses on strategic alignment and risk acceptance, not detailed technical approvals.

207
MCQmedium

After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?

A.Update the IR plan
B.Begin remediation
C.Notify law enforcement
D.Issue a legal hold
AnswerD

A legal hold must be issued first because it immediately suspends routine deletion and alteration of potentially relevant data, preserving evidence and avoiding spoliation sanctions. Subsequent forensic imaging and collection then proceed under that hold's protection.

Why this answer

Issuing a legal hold is the first action because it triggers the duty to preserve evidence and suspends normal data retention or deletion policies, ensuring that logs, disk images, and other artifacts are not destroyed. Under FRCP and similar rules, once litigation is reasonably anticipated, spoliation of evidence can lead to sanctions, so the legal hold must precede any remediation or notification. This step also formally directs custodians and IT staff to retain relevant records, creating a defensible chain of custody.

Exam trap

CISM often tests the misconception that notifying law enforcement or starting remediation is the immediate priority, but the first action in any potential litigation scenario is always to preserve evidence via a legal hold.

How to eliminate wrong answers

Option A is wrong because updating the IR plan is a post-incident improvement activity that does not preserve evidence and can wait until after the legal hold is in place. Option B is wrong because beginning remediation can alter or destroy volatile evidence (e.g., rebooting systems, deleting malware), directly conflicting with the duty to preserve. Option C is wrong because notifying law enforcement, while potentially required, does not itself impose a preservation obligation and may even be premature before internal legal hold procedures are activated.

208
MCQhard

A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?

A.Escalate the residual risk to the risk committee with a recommendation to accept the risk because the existing controls already reduce it below the original inherent score.
B.Initiate a new risk assessment to recalculate the inherent risk score, because the residual score may be inaccurate due to control effectiveness assumptions.
C.Implement additional technical controls immediately to reduce the residual risk below 12, then inform the risk committee of the change at the next quarterly meeting.
D.Present the residual risk to the risk committee with documented treatment options, including additional controls, risk transfer, or risk avoidance, and their associated costs and impacts.
AnswerD

The board policy requires escalation of residual risk above 12 for a formal treatment decision. The CISO's role is to provide the risk committee with sufficient information to choose among treatment options. Presenting the risk with options, costs, and impacts enables informed decision-making and complies with the established governance threshold, making this the most appropriate first action.

Why this answer

Because the residual risk exceeds the board-defined threshold of 12, the CISO must escalate it to the risk committee for a formal treatment decision. The most appropriate first action is to present the risk along with viable treatment options, costs, and business impacts so the committee can make an informed choice. This respects governance, ensures accountability, and provides the decision-makers with the information they need.

Exam trap

The trap here is assuming that because controls already reduced the risk from its inherent level, the residual risk can be accepted without escalation, ignoring the board's explicit threshold.

209
MCQeasy

Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?

A.To ensure attorney-client privilege is automatically applied
B.To ensure the firm is available 24/7
C.To guarantee a discounted rate
D.To reduce the time required to engage the firm during an incident
AnswerD

A retainer establishes pre-negotiated rates, scopes and call-out procedures, so the firm can be mobilised immediately rather than negotiating terms mid-incident. That directly satisfies the stem's constraint of reducing engagement time when every hour of dwell time increases damage.

Why this answer

The primary purpose of a pre-established contract with a digital forensics firm is to eliminate procurement delays during an incident. When an incident occurs, time is critical; having a signed contract in place allows the firm to be engaged immediately without waiting for legal or administrative approvals, which directly supports the incident response goal of minimizing damage and preserving evidence.

Exam trap

The trap here is that candidates confuse a secondary benefit (like cost savings or availability) with the primary operational goal of reducing engagement time, which is the core driver in incident management scenarios.

How to eliminate wrong answers

Option A is wrong because attorney-client privilege is not automatically applied by a contract; it requires specific legal agreements and actions (e.g., engaging counsel to direct the work under privilege rules), and a pre-established contract alone does not guarantee this protection. Option B is wrong while availability is a benefit, it is not the primary purpose; 24/7 availability can be arranged without a pre-established contract, and the core issue is reducing engagement time, not just availability. Option C is wrong because discounted rates are a secondary commercial benefit, not the primary purpose; the main driver is operational efficiency during an incident, not cost savings.

210
MCQhard

A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?

A.The volume of data potentially exfiltrated.
B.The source IP address of the exfiltration attempt.
C.The potential impact on business operations and regulatory compliance.
D.The method used to detect the exfiltration (e.g., SIEM alert vs. user report).
AnswerC

This is correct because severity should be based on the potential impact to the business, including financial, operational, legal, and reputational consequences. CISM emphasizes that incident severity must reflect business impact. The volume, source, and detection method are secondary to the actual or potential harm to the organization.

Why this answer

Incident severity should be determined by the potential impact on business operations, regulatory compliance, and reputation. CISM stresses that severity classification drives the response level and resource allocation. While data volume, source IP, and detection method are relevant details, they do not define severity.

The most important factor is the business impact, as it determines the urgency and scale of the response.

Exam trap

The trap here is equating the volume of data with severity, overlooking that a small breach of highly sensitive data can be far more severe than a large breach of non-sensitive data.

211
MCQhard

During a live intrusion, the incident response lead must decide how the team will communicate. The attackers are believed to be monitoring the corporate email and collaboration platform. Which of the following is the MOST appropriate action to maintain confidentiality of incident communications?

A.Continue using the existing collaboration platform but add a second factor to all responder accounts.
B.Move coordination to an out-of-band channel that was established and tested before the incident.
C.Restrict incident discussions to a distribution list limited to the core response team.
D.Encrypt all incident-related email with the organization's standard message encryption gateway.
AnswerB

If adversaries are inside the environment, any channel they can read or manipulate becomes unsafe for coordination, so the team must fall back to a pre-provisioned out-of-band capability. Pre-establishing and testing it means contact details, credentials, and access methods are already known and will work under pressure, which preserves both the confidentiality of response decisions and the integrity of the coordination process.

Why this answer

When the adversary is positioned to observe the organization's normal communication paths, coordination must shift to a channel the adversary cannot reach. An out-of-band method that was designed, provisioned, and exercised before the incident provides that assurance, keeping containment strategy, evidence handling, and executive decisions confidential while normal platforms are treated as untrusted.

Exam trap

The trap here is believing stronger authentication or tighter distribution lists protect a channel whose contents the attacker can already read.

212
MCQmedium

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

A.A single firewall with access control lists
B.Antivirus software on all endpoints
C.Physical locks on server room doors and CCTV
D.Network segmentation, intrusion detection systems, and full-disk encryption
AnswerD

These controls operate at distinct layers: segmentation limits lateral movement, intrusion detection monitors network activity, and full-disk encryption protects data at rest. Layered, independent controls across network and endpoint satisfy defence in depth, so one failure does not expose the asset.

Why this answer

Defense in depth requires multiple, layered controls across different domains so that if one fails, others still protect the asset. Network segmentation, intrusion detection systems, and full-disk encryption represent layers across network, monitoring, and data-at-rest controls, covering different attack vectors. This combination exemplifies the principle by providing preventive, detective, and protective controls that complement each other.

Exam trap

CISM often tests the definition of defense in depth; candidates may pick a single strong control (e.g., firewall) or multiple controls of the same type (e.g., locks and CCTV) instead of recognizing the need for diverse, layered controls across different domains.

How to eliminate wrong answers

Option A is wrong because a single firewall with ACLs is a single layer of defense; if the firewall is misconfigured or bypassed, there is no additional protection. Option B is wrong because antivirus on all endpoints is a single control type (endpoint protection) and does not address network or data-at-rest threats. Option C is wrong because physical locks and CCTV are both physical security controls, representing only one layer (physical) and not a multi-layered defense across domains.

213
MCQhard

An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?

A.Recommend blocking the launch until the security team completes a full independent audit of the application.
B.Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.
C.Delegate the regulatory risk decision to the business unit's legal counsel and document the outcome.
D.Advise the unit to proceed with the launch and remediate regulatory gaps in a post-launch phase.
AnswerB

Assessing the launch against the new regulatory requirements gives leadership a factual view of the exposure, and presenting treatment options with business impact lets them make an informed risk-based decision. This respects the business unit's objectives while ensuring that regulatory risk is identified, evaluated, and consciously accepted or mitigated by the accountable owners.

Why this answer

Effective risk management supports business objectives by making risk visible and manageable rather than by blocking initiatives. Assessing the launch against the new regulations and presenting treatment options with their business impact allows leadership to weigh speed against compliance exposure and make a documented, risk-aware decision within their authority.

Exam trap

The trap here is believing the security manager should either block the launch outright or defer compliance, when the correct role is to assess the risk and enable an informed business decision.

214
MCQmedium

An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?

A.Compliance with industry regulations
B.Reducing information security costs
C.Achieving the organization's strategic goals
D.Implementing the latest security technologies
AnswerC

Aligning security with business objectives ensures controls enable rather than obstruct the organisation's strategic goals, satisfying the stem's requirement for a primary driver. Security exists to support mission delivery, so strategic alignment directs investment and risk decisions toward outcomes the business actually needs.

Why this answer

The primary driver for aligning the security program with business objectives is to ensure that security initiatives directly support and enable the organization's strategic goals. Without this alignment, security becomes a cost center rather than a business enabler, and resources may be misallocated to activities that do not advance the enterprise's mission. CISM emphasizes that security governance must be integrated with business strategy to justify investment and demonstrate value to stakeholders.

Exam trap

The trap here is that candidates often mistake compliance (A) as the primary driver because it is a visible and mandatory requirement, but CISM stresses that compliance is a subset of governance, not the overarching goal of program alignment.

Why the other options are wrong

A

Compliance is a requirement but not the primary driver; the program must support business goals to be effective.

B

Cost reduction is a possible outcome but not the primary driver for alignment.

D

Adopting new technologies is a tactic, not the primary driver.

215
MCQeasy

Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?

A.Communication plan
B.Incident response plan
C.Incident response policy
D.Incident response playbook
AnswerB

The incident response plan is the governing document defining response strategy, team roles, responsibilities, escalation paths and communication procedures organisation-wide. It provides the overarching framework that individual playbooks and procedures sit beneath, satisfying the requirement for an organisation-level strategy.

Why this answer

The incident response plan (IRP) is the overarching document that defines the organization's strategy, structure, roles, and responsibilities for handling incidents end to end. It establishes who does what across the full lifecycle — preparation, detection, containment, eradication, recovery, and lessons learned. The policy sets intent at a high level, while the plan operationalizes that intent with assigned roles and coordination procedures.

Exam trap

CISM often tests the distinction between policy, plan, and playbook, and candidates frequently select 'policy' because it sounds authoritative, missing that the question asks for strategy plus roles and responsibilities, which is the plan.

How to eliminate wrong answers

Option A is wrong because a communication plan is a subordinate artifact that only addresses who communicates what, to whom, and when — it does not define overall strategy or team roles. Option C is wrong because the incident response policy is a high-level governance statement that mandates the program exists but does not detail roles, responsibilities, or operational strategy. Option D is wrong because a playbook is a tactical, incident-type-specific runbook (e.g., ransomware or phishing) that executes within the broader plan rather than defining it.

216
MCQmedium

Given the exhibit, what is the most likely classification of this incident?

A.Malware infection
B.Denial of service
C.Brute-force attack
D.Insider threat
AnswerC

Repeated failed authentication attempts from a single source against one account, followed by a successful login, indicate systematic credential guessing rather than malware or exploitation. The volume and pattern of failures distinguish brute-force activity from isolated mistyped passwords.

Why this answer

The exhibit shows a high volume of failed authentication attempts (e.g., repeated 'Login failed' events) from a single external IP address targeting multiple user accounts within a short time window. This pattern is characteristic of a brute-force attack, where an attacker systematically tries password combinations to gain unauthorized access. The incident classification is based on the specific behavior of repeated login failures, not on malware signatures or traffic flooding.

Exam trap

The trap here is that candidates may confuse a high volume of failed logins with a denial of service attack, but the key distinction is that brute-force attacks focus on authentication attempts rather than overwhelming system resources.

How to eliminate wrong answers

Option A is wrong because a malware infection typically involves the execution of malicious code, file modifications, or unusual outbound connections, not a high volume of failed authentication attempts. Option B is wrong because a denial of service attack aims to overwhelm system resources with traffic or requests, causing service unavailability, whereas the exhibit shows repeated login failures without evidence of resource exhaustion. Option D is wrong because an insider threat would involve actions by an authorized user, such as data exfiltration or privilege misuse, not repeated failed logins from an external IP address.

217
MCQeasy

Which capability maturity model (CMM) level indicates that security processes are measured and controlled?

A.Level 3: Defined
B.Level 5: Optimizing
C.Level 4: Managed
D.Level 2: Repeatable
AnswerC

Level 4 processes are quantitatively measured and controlled using metrics and statistical techniques, enabling predictable performance. This satisfies the stem's requirement by distinguishing it from Level 3, where processes are merely defined and documented, and Level 5, which adds continuous optimisation rather than measurement itself.

Why this answer

In the Capability Maturity Model (CMM), Level 4 is 'Managed,' where processes are quantitatively measured and controlled using statistical and other quantitative techniques. This level focuses on using metrics to manage and adjust processes to achieve specific performance goals.

Exam trap

CISM often tests the subtle difference between CMM levels, and candidates confuse 'Defined' (Level 3) with 'Managed' (Level 4), forgetting that Level 4 specifically involves quantitative measurement and control.

How to eliminate wrong answers

Option A is wrong because Level 3 'Defined' means processes are documented, standardized, and integrated, but not yet quantitatively measured and controlled. Option B is wrong because Level 5 'Optimizing' focuses on continuous process improvement through innovative ideas and technologies, building on the quantitative management of Level 4. Option D is wrong because Level 2 'Repeatable' indicates that basic project management processes are established to track cost, schedule, and functionality, but processes are not yet measured or controlled.

218
MCQhard

An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?

A.The risk assessment methodology is not quantitative.
B.Risk treatment responsibilities and decision authorities are not clearly defined.
C.The organization lacks a formal risk register.
D.Senior management does not review the risk assessment results.
AnswerB

When it is unclear who is responsible for making risk treatment decisions and who owns the risk, decisions can stall. Clear definition of roles, responsibilities, and decision authorities (e.g., risk owners, steering committee) ensures timely action. Without this, even well-assessed risks may languish because no one feels accountable for the next step.

Why this answer

The most likely root cause is that risk treatment responsibilities and decision authorities are not clearly defined. Effective risk management requires that each risk has an owner who is accountable for treatment decisions, and that decision-making authority is established. Without this clarity, risks may be assessed but not acted upon, causing delays and leaving high-risk items unaddressed.

Exam trap

The trap here is blaming the risk assessment methodology or lack of a register, when the real issue is often unclear ownership and decision rights.

219
MCQeasy

An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?

A.Total spending on security tools compared to the approved budget.
B.Percentage of risk treatment plans that have been implemented as scheduled.
C.Number of security incidents reported per quarter.
D.Mean time to detect (MTTD) for security incidents.
AnswerB

Risk treatment plans are the operational output of governance decisions. Tracking the percentage implemented as scheduled measures whether agreed controls are actually delivered, demonstrating that governance direction translates into executed action rather than remaining documented intent.

Why this answer

The percentage of risk treatment plans implemented as scheduled directly measures whether the governance process is translating risk decisions into action. Effective governance ensures that risk owners execute agreed-upon treatments within defined timelines, reflecting accountability and process adherence. This metric aligns with the CISM governance principle that oversight should focus on outcomes of risk management activities, not just operational metrics.

Exam trap

The CISM exam often tests the distinction between governance metrics (e.g., risk treatment implementation) and operational metrics (e.g., MTTD, incident counts), and the trap here is that candidates confuse operational efficiency with governance effectiveness, picking a metric that sounds security-relevant but does not measure process oversight.

How to eliminate wrong answers

Option A is wrong because spending against budget measures financial compliance, not governance effectiveness; a governance process can be fully funded yet fail to enforce risk treatment decisions. Option C is wrong because the number of incidents reported per quarter is an operational security metric that can be influenced by detection capabilities or reporting culture, not a direct indicator of governance process health. Option D is wrong because mean time to detect (MTTD) is a tactical incident response metric that reflects detection efficiency, not whether governance structures (e.g., steering committees, policy reviews) are functioning properly.

220
MCQhard

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

A.Accept the risk because the vendor is contractually responsible
B.Revise the contract to require the vendor to flow down security requirements to sub-suppliers
C.Perform an on-site assessment of the sub-supplier
D.Request that the vendor terminate the sub-supplier relationship
AnswerB

Contractual flow-down clauses extend security requirements to sub-suppliers, closing the nth-party gap the existing agreement leaves open. This addresses the root cause — absent contractual control — rather than merely monitoring a vendor that has no obligation to enforce sub-supplier security.

Why this answer

The core issue is that the vendor contract does not address nth-party (sub-supplier) risk, so the organization has no contractual leverage to require the vendor to manage its sub-suppliers. The best course of action is to revise the contract to include flow-down clauses that require the vendor to impose security requirements on its sub-suppliers, thereby extending the organization's security posture through the supply chain. This addresses the root cause—lack of contractual control—and is a preventive, governance-level action.

Exam trap

CISM often tests the distinction between risk acceptance, risk transfer, and risk mitigation; candidates may incorrectly choose to accept the risk because the vendor is contractually responsible, but the contract's silence on nth-party risk means the risk is not effectively transferred.

How to eliminate wrong answers

Option A is wrong because accepting the risk based on the vendor's contractual responsibility is insufficient when the contract itself does not address nth-party risk; the vendor may not be liable for sub-supplier breaches. Option C is wrong because performing an on-site assessment of the sub-supplier is a point-in-time detective control that does not provide ongoing assurance or contractual enforcement, and the organization may not have the right to assess a sub-supplier directly. Option D is wrong because requesting termination of the sub-supplier relationship is a drastic, potentially disruptive action that may not be feasible or necessary; it does not address the underlying contractual gap and could harm the business relationship.

221
MCQhard

A financial institution is integrating a newly acquired fintech startup. The startup has a very different security culture. What governance approach best ensures integration without stifling innovation?

A.Allow the startup to maintain its own security policies indefinitely
B.Force the startup to adopt all of the institution's policies immediately
C.Use a transitional risk-based approach, phasing in critical controls while allowing flexibility
D.Create a separate security team for the startup
AnswerC

A transitional risk-based approach phases in critical controls according to actual risk exposure while permitting flexibility elsewhere, satisfying the stem's dual constraint of integrating the fintech's differing security culture without stifling the innovation the acquisition was made for.

Why this answer

A transitional, risk-based governance approach lets the acquiring institution phase in critical security controls (e.g., identity, data protection, logging) while preserving the startup's agile practices in lower-risk areas. This balances the need for enterprise-wide risk alignment with the reality that abrupt policy imposition damages culture and velocity. It is the standard M&A security integration pattern recommended by ISACA and similar bodies.

Exam trap

CISM often tests the tension between security rigor and business enablement, so the trap is choosing the strictest-sounding option (immediate full adoption) instead of the balanced, risk-based governance answer that preserves business value.

How to eliminate wrong answers

Option A is wrong because allowing indefinite independence leaves the parent organization exposed to unmanaged risk and defeats the purpose of integration governance. Option B is wrong because immediate, wholesale policy adoption typically breaks the startup's delivery model, causes talent attrition, and creates compliance theater rather than real risk reduction. Option D is wrong because creating a separate security team fragments accountability and creates governance silos rather than integrating the startup into the enterprise risk framework.

222
MCQmedium

You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?

A.Restructure the compliance team into a risk management function.
B.Expand the compliance team to cover more regulations and increase auditing frequency.
C.Increase security awareness training across the organization.
D.Evolve the program to a risk-based approach that integrates threat intelligence and adapts controls dynamically, while keeping compliance as a baseline.
AnswerD

A risk-based model prioritises controls by likelihood and business impact, using threat intelligence to address supply chain attacks and APTs, and adapts dynamically as the threat landscape shifts. Compliance remains the baseline, so PCI DSS and GDPR obligations are still met while the programme becomes proactive rather than checklist-driven.

Why this answer

Evolving the program to a risk-based approach (Option D) integrates threat intelligence and dynamically adapts controls, directly addressing the need for proactive management of emerging threats while maintaining compliance as a baseline. This balances strategic evolution with the compliance team's continued role. Option A (restructuring the compliance team) risks political friction and does not inherently shift to risk management.

Option B (expanding compliance coverage) increases focus on compliance, not proactive risk. Option C (increasing awareness training) is too narrow and does not address the program's strategic direction.

223
MCQhard

A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?

A.Notification to all employees
B.Annual renewal without further review
C.Approval by the CISO only
D.A documented remediation plan with timelines and risk acceptance
AnswerD

A documented remediation plan with timelines and risk acceptance satisfies the stem's temporary non-compliance constraint by ensuring the legacy system's encryption gap is formally owned, time-bound, and reviewed. Risk acceptance transfers accountability to the appropriate authority, preventing the exception from becoming permanent, undocumented drift.

Why this answer

The most important element of an exception management process is a documented remediation plan with timelines and formal risk acceptance. This ensures that the exception is temporary, that the risk is understood and accepted by the appropriate authority, and that there is a clear path to compliance.

Exam trap

CISM often tests exception management, and candidates may focus on approval authority rather than the need for a documented remediation plan and risk acceptance, which is the core of the process.

How to eliminate wrong answers

Option A is wrong because notifying all employees is not the primary element; exceptions are typically communicated on a need-to-know basis. Option B is wrong because annual renewal without further review defeats the purpose of exception management, which requires periodic reassessment and a plan to remediate. Option C is wrong because approval by the CISO only may not be sufficient; risk acceptance should involve business stakeholders and possibly the board, depending on the risk level.

224
MCQeasy

What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

A.To determine if legal action is needed
B.To calculate the financial impact of the incident
C.To assign disciplinary actions
D.To update the incident response plan and procedures
AnswerD

Lessons learned meetings capture what worked and what failed during the incident, then feed those findings back into the incident response plan and procedures. This directly satisfies the stem's requirement for the primary purpose: systematic improvement of future response capability rather than assigning blame or closing tickets.

Why this answer

Lessons learned aims to improve future response by identifying what worked and what didn't.

225
MCQmedium

Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?

A.Phase 5: Post-Incident
B.Phase 3: Eradication
C.Phase 2: Containment
D.Phase 4: Recovery
AnswerD

Recovery depends on restoring data from backups, so an encrypted backup server removes the primary restoration path. This directly undermines Phase 4, forcing reliance on offline or immutable copies and delaying service restoration after the ransomware incident.

Why this answer

The Recovery phase (Phase 4) is most impacted when the backup server is encrypted during a ransomware incident. Without clean, unencrypted backups, the organization cannot restore systems and data to a known good state, which is the primary goal of the Recovery phase. The encryption of backups directly undermines the ability to recover, forcing the team to consider alternative recovery methods such as decryption keys, offline backups, or system rebuilds.

Exam trap

The trap here is that candidates often confuse the Recovery phase with the Eradication phase, thinking that removing the ransomware will automatically restore access to backups, but in reality, encrypted backups require separate decryption or restoration processes that are part of Recovery, not Eradication.

How to eliminate wrong answers

Option A is wrong because the Post-Incident phase (Phase 5) focuses on lessons learned, reporting, and process improvement, not on the immediate technical recovery from encrypted backups. Option B is wrong because the Eradication phase (Phase 3) involves removing malware and closing attack vectors, but the encrypted backups are a recovery obstacle, not an eradication task. Option C is wrong because the Containment phase (Phase 2) aims to isolate the incident to prevent further spread, but the backup server being already encrypted means containment does not address the loss of recovery data.

Page 2

Page 3 of 13

Page 4