Courseiva

Certified Information Security Manager CISM (CISM) — Questions 226–300

924 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
MCQeasy

Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?

A.Incident response plan
B.Incident response policy
C.Incident response playbook
D.Communication templates
AnswerC

An incident response playbook delivers the step-by-step technical instructions the stem demands, mapping specific containment, eradication and recovery actions to a defined incident type. Unlike broader plans or procedures, it prescribes exact commands and decision points, so responders execute consistent, repeatable actions under pressure.

Why this answer

C is correct because an incident response playbook provides detailed, step-by-step technical instructions for handling a specific type of security incident (e.g., ransomware, DDoS, phishing). Unlike the higher-level incident response plan, a playbook contains precise technical actions, such as commands to isolate a host, indicators of compromise (IOCs) to block, and escalation criteria tailored to a particular threat.

Exam trap

The trap here is that candidates confuse the incident response plan (strategic, high-level) with the playbook (tactical, incident-specific), often selecting the plan because it sounds like the most comprehensive document, but the question explicitly asks for 'step-by-step technical instructions' which only the playbook provides.

How to eliminate wrong answers

Option A is wrong because the incident response plan is a strategic document that outlines the overall process, roles, and coordination for incident management, not the granular technical steps for a specific incident type. Option B is wrong because the incident response policy defines high-level management intent, compliance requirements, and governance, not operational technical procedures. Option D is wrong because communication templates provide pre-formatted messages for notifying stakeholders (e.g., legal, PR, customers) but do not contain the technical steps needed to contain, eradicate, or recover from a security incident.

227
MCQhard

A security manager is reviewing the organization's information security governance framework. The board has expressed concern that security decisions are not consistently aligned with the organization's risk appetite. Which of the following would BEST address this concern?

A.Conduct an annual security awareness training for all employees to reinforce risk management principles.
B.Define and document risk appetite and tolerance levels, and integrate them into the security decision-making processes.
C.Establish a security steering committee that includes business unit leaders to review and approve security initiatives.
D.Implement a security metrics dashboard that reports the number of security incidents to the board quarterly.
AnswerB

Defining risk appetite and tolerance and embedding them into decision processes directly ensures that every security decision is evaluated against the board's risk preferences. This creates consistency and traceability, allowing the board to verify that security activities remain within agreed boundaries. It is the foundational step that enables other governance mechanisms, such as committees and metrics, to function effectively.

Why this answer

The most effective way to address the board's concern is to formally define risk appetite and tolerance levels and integrate them into security decision-making. This ensures that every security initiative is assessed against the organization's willingness to accept risk, providing consistency and a clear basis for decisions. Other measures, such as committees or dashboards, support this but do not replace the need for explicit risk appetite integration.

Exam trap

The trap here is confusing visibility and oversight mechanisms, such as steering committees or dashboards, with the actual integration of risk appetite into decision processes, which is what ensures consistent alignment.

228
MCQmedium

Which of the following is a leading indicator for security performance?

A.Patch compliance percentage
B.Mean time to recover (MTTR)
C.Number of data breaches
D.Mean time to detect (MTTD)
AnswerA

Patch compliance percentage measures activity performed before incidents occur, revealing whether vulnerability remediation is keeping pace. Unlike breach counts or incident volumes, which are lagging, it predicts future exposure, making it a leading indicator of security performance.

Why this answer

Leading indicators are proactive measures that predict future performance. Patch compliance is a leading indicator because it shows current security posture that influences future incidents.

229
MCQhard

During a merger, the acquiring company's board insists on integrating the target company's information security governance into its own within 90 days. However, the target has a significantly different risk culture and lacks documented policies. What is the most critical governance risk in this scenario?

A.The acquiring company's security team may lack the capacity to train the target's staff.
B.The target's employees may resist the new security culture.
C.The acquiring company may inadvertently accept unknown high-risk exposures.
D.There will be insufficient time to develop new security policies for the combined entity.
AnswerC

Undocumented policies and a divergent risk culture mean the acquirer cannot reliably assess what exposures it is inheriting. Rapid integration without due diligence effectively transfers unknown high-risk exposures onto the acquiring company's balance sheet and governance accountability.

Why this answer

The most critical governance risk is that the acquiring company may inadvertently inherit unknown high-risk exposures from the target company. Without documented policies and a compatible risk culture, the target's security posture is opaque, meaning the acquirer cannot assess or control inherited vulnerabilities, compliance gaps, or threat vectors. This violates the core governance principle of risk visibility and could lead to material breaches or regulatory penalties post-merger.

Exam trap

The trap here is that candidates confuse operational or cultural challenges (like training capacity or employee resistance) with governance-level risks, but the CISM exam emphasizes that governance is about the board's duty to ensure risk visibility and informed decision-making, not execution details.

How to eliminate wrong answers

Option A is wrong because training capacity is an operational resource issue, not a governance risk; governance focuses on oversight and risk management, not the logistics of staff training. Option B is wrong because employee resistance is a cultural change management challenge, not a governance risk; governance risks involve strategic decision-making and risk acceptance, not personnel attitudes. Option D is wrong because insufficient time to develop new policies is a project management constraint, not a governance risk; governance risk centers on the board's failure to identify and control unknown exposures, not the speed of policy creation.

230
MCQeasy

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

A.A board-level risk committee oversees the information security program without management involvement.
B.An executive steering committee with representatives from business units, legal, and IT meets quarterly to review program status.
C.The CISO reports to the chief legal officer (CLO).
D.The information security function reports directly to the IT operations manager.
AnswerB

An executive steering committee gives senior management direct ownership of the security programme, satisfying the accountability requirement. Cross-functional representation from business units, legal and IT ensures security decisions align with business objectives rather than remaining an isolated technical function.

Why this answer

An executive steering committee with cross-functional representation (business units, legal, IT) ensures the information security program is aligned with business objectives and provides direct accountability to senior management through regular quarterly reviews. This structure enables strategic oversight, resource allocation, and risk acceptance decisions that tie security initiatives to organizational goals, as recommended by the CISM framework for governance.

Exam trap

The trap here is that candidates may confuse operational reporting structures (like CISO reporting to CLO or IT ops) with effective governance, overlooking the need for cross-functional management oversight that directly ties security to business objectives.

How to eliminate wrong answers

Option A is wrong because a board-level risk committee without management involvement lacks the operational insight and authority to align security with day-to-day business objectives, creating a disconnect between governance and execution. Option C is wrong because reporting to the chief legal officer (CLO) can prioritize legal compliance over broader business risk management, potentially sidelining strategic alignment and senior management accountability. Option D is wrong because reporting to the IT operations manager places security under operational IT, which typically focuses on system uptime and efficiency rather than enterprise-wide risk governance, undermining the CISO's ability to influence business strategy.

231
MCQmedium

An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?

A.Escalate the vulnerability to senior management for acceptance.
B.Update the risk register with the new vulnerability.
C.Analyze the likelihood and impact of the vulnerability being exploited.
D.Select and implement controls to mitigate the vulnerability.
AnswerC

ISO 27005 sequences risk identification before risk analysis. Having identified the vulnerability, the organisation must next estimate the likelihood of exploitation and the resulting impact, which produces the risk level used for subsequent evaluation and treatment decisions.

Why this answer

According to ISO 27005, after risk identification (including discovering a new vulnerability), the next step is risk analysis, which involves assessing the likelihood and impact of the vulnerability being exploited. This analysis is required before any decision on risk treatment (e.g., mitigation, acceptance) can be made. Option C correctly identifies this sequential step in the ISO 27005 risk management process.

Exam trap

The trap here is that candidates confuse the order of the ISO 27005 phases, often jumping to risk treatment (selecting controls) or documentation (updating the register) before completing the mandatory risk analysis step.

How to eliminate wrong answers

Option A is wrong because risk acceptance is a decision made after risk evaluation (which follows risk analysis), not immediately after identification; escalating without analyzing likelihood and impact bypasses the structured ISO 27005 workflow. Option B is wrong because updating the risk register is a documentation activity that should occur after the risk has been analyzed and evaluated, not as the immediate next step after identification. Option D is wrong because selecting and implementing controls is part of risk treatment, which occurs only after risk analysis and risk evaluation have been completed, per the ISO 27005 lifecycle.

232
MCQmedium

During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?

A.Patching the firewall immediately
B.Conducting a lessons learned meeting immediately
C.Determining why the firewall was misconfigured and why the change management process failed
D.Restoring the firewall from backup
AnswerC

Best practise targets the systemic layer: why the misconfiguration occurred and why change management failed to catch it. Fixing only the firewall setting leaves the governance weakness intact, so the same class of error recurs.

Why this answer

Root cause analysis should identify not only the technical cause but also the process and management failures that allowed the misconfiguration to occur.

233
MCQhard

During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?

A.Seek partner input on what to share
B.Share all information with partners under NDA
C.Provide only non-sensitive overview to partners
D.Withhold all information until investigation ends
AnswerC

Providing only a non-sensitive overview satisfies legal counsel's confidentiality constraint while preserving partner awareness. This partial-disclosure approach shares sanitised indicators without revealing law-enforcement-sensitive details, balancing transparency with the investigation's integrity. It avoids full disclosure that could compromise the probe, and avoids total silence that would breach partner obligations.

Why this answer

It allows the incident response team to maintain necessary transparency with external partners while respecting legal counsel's directive to withhold sensitive details due to an ongoing law enforcement investigation. Providing a non-sensitive overview—such as the general nature of the incident, affected systems (without PII), and remediation timeline—fulfills partnership obligations without jeopardizing the investigation or violating chain-of-custody requirements for digital forensics.

Exam trap

The trap here is that candidates often choose Option B (share all under NDA) because they assume legal agreements override all other constraints, failing to recognize that law enforcement investigations and preservation orders take precedence over contractual confidentiality.

How to eliminate wrong answers

Option A is wrong because seeking partner input on what to share could inadvertently expose sensitive details or lead to pressure to disclose information that conflicts with legal hold or law enforcement non-disclosure orders. Option B is wrong because sharing all information under NDA still violates the legal counsel's directive; NDAs do not override law enforcement restrictions or the need to preserve evidence integrity (e.g., maintaining forensic image hashes and avoiding spoliation). Option D is wrong because withholding all information until the investigation ends can damage critical partner trust and operational coordination, especially if partners require timely threat indicators to defend their own environments.

234
MCQmedium

A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?

A.Ask the provider to complete a security questionnaire and sign a confidentiality agreement
B.Request the provider's most recent independent audit report, such as SOC 2 Type II
C.Review the provider's public marketing materials and security whitepapers
D.Conduct a penetration test of the provider's infrastructure without notifying them
AnswerB

An independent audit report, such as SOC 2 Type II, provides validated evidence that the provider's controls operated effectively over a period. It covers security, availability, and confidentiality criteria and is issued by a third-party auditor. This gives the organization reliable assurance for risk assessment and vendor management, far more than self-attestations or marketing claims.

Why this answer

Independent audit reports such as SOC 2 Type II provide validated evidence that a third-party provider's controls operated effectively over a defined period. They are prepared by a qualified auditor and cover relevant trust services criteria, giving the organization reliable assurance for risk assessment and vendor management. Self-reported materials, questionnaires, or unauthorized testing do not offer the same level of independent, ongoing verification.

Exam trap

The trap here is accepting self-reported claims or questionnaires as sufficient assurance instead of requiring independent, period-based audit evidence.

235
MCQmedium

You are the information security manager for a mid-sized e-commerce company. The company operates a web application that handles credit card transactions and stores customer data in a backend database. The incident response team has just been alerted to a potential data breach: an intrusion detection system (IDS) flagged a SQL injection attack pattern on the web application's login page. The attack originated from an external IP address (5.5.5.5) and appears to have been successful, as the IDS also detected a large outbound data transfer from the database server to another external IP (6.6.6.6) shortly after. The database server is not segmented from the web server. The company has a legal obligation to report breaches involving cardholder data within 72 hours. The incident response plan is being activated. The team includes a forensic analyst, a network engineer, and a legal advisor. The web application is currently running and serving customers. The CEO wants to minimize business disruption. Which of the following actions should the incident response team take FIRST?

A.Shut down the web application and database server immediately to stop the breach.
B.Isolate the database server from the network and block outbound traffic to the external IP.
C.Patch the SQL injection vulnerability in the web application and continue monitoring.
D.Take a full forensic image of all servers before taking any containment actions.
AnswerB

Containment precedes eradication: isolating the database server and blocking outbound traffic to 6.6.6.6 halts the active exfiltration, satisfying the 72-hour cardholder-data reporting obligation while preserving the web tier for customers. Forensic imaging and legal notification follow once data loss is stopped.

Why this answer

The immediate priority is to contain the breach by isolating the compromised database server and blocking outbound traffic to the attacker's IP (6.6.6.6). This stops the exfiltration of cardholder data, preserves evidence on the isolated server, and minimizes business disruption by keeping the web application running. Shutting down servers (Option A) would cause unacceptable downtime, while patching (Option C) or imaging (Option D) without containment would allow continued data loss.

Exam trap

The trap here is that candidates confuse 'stopping the breach' with 'shutting everything down' (Option A), failing to recognize that containment actions like network isolation can halt data loss while preserving business continuity and evidence integrity.

How to eliminate wrong answers

Option A is wrong because shutting down both servers halts business operations, violating the CEO's directive to minimize disruption, and destroys volatile evidence (e.g., network connections, memory) that the forensic analyst needs. Option C is wrong because patching the SQL injection vulnerability does not stop the ongoing exfiltration to 6.6.6.6; the attacker may still have a backdoor or active connection, and data loss continues. Option D is wrong because taking forensic images before containment allows the attacker to continue exfiltrating data during the imaging process, violating the legal obligation to stop the breach within 72 hours.

236
MCQeasy

Which governance structure is characterized by a single security team that serves the entire organization?

A.Matrix
B.Hybrid
C.Centralized
D.Decentralized
AnswerC

A centralized structure places decision-making authority and the security function within one team serving the whole organisation, directly matching the stem's single-team constraint. This contrasts with decentralized models, where security personnel report into separate business units, and federated hybrids, which distribute control while retaining a coordinating function.

Why this answer

A centralized governance model consolidates security responsibilities under one team, ensuring consistent policy enforcement and resource allocation.

237
MCQmedium

Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?

A.SOX
B.GDPR
C.PCI DSS
D.HIPAA
AnswerB

GDPR is the EU regulation that imposes data protection obligations on organisations processing personal data of EU citizens, mandating technical and organisational safeguards. It directly satisfies the stem's requirement for a regulatory mandate covering EU citizen data.

Why this answer

The General Data Protection Regulation (GDPR) is the EU regulation that mandates organizations implement data protection measures for personal data of EU citizens. It applies to any organization processing personal data of individuals in the EU, regardless of the organization's location.

Exam trap

CISM often tests regulatory frameworks, and candidates may confuse GDPR with other privacy laws like HIPAA or PCI DSS, especially when the question mentions 'personal data' without specifying EU citizens.

How to eliminate wrong answers

Option A is wrong because SOX (Sarbanes-Oxley) focuses on financial reporting and internal controls for public companies, not personal data protection. Option C is wrong because PCI DSS is a payment card industry standard for protecting cardholder data, not general personal data of EU citizens. Option D is wrong because HIPAA governs protected health information in the United States, not EU citizens' personal data.

238
MCQeasy

A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?

A.The seniority of the person who first reported the event to the service desk
B.The number of alerts the SIEM generated for the affected host in the last 24 hours
C.Whether the affected system is covered by the current cyber insurance policy
D.The predefined severity level assigned to the incident type and its assessed business impact
AnswerD

Severity levels are defined in advance against business impact criteria, so the on-call responder can classify an event consistently within minutes and trigger the agreed escalation path. This removes subjective judgement during the most chaotic phase of an incident and ensures the crisis management team is invoked only when the documented thresholds are met.

Why this answer

Incident classification must be anchored to predefined severity levels that map directly to business impact, so responders can escalate consistently and quickly. This lets the organisation activate the crisis management team at the right threshold without debate, and it aligns response effort with the value at risk rather than with incidental signals such as alert counts or reporter rank.

Exam trap

The trap here is assuming that a dramatic technical signal, such as a high alert count, automatically indicates a high-severity incident requiring executive escalation.

239
MCQeasy

An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next critical step?

A.Pay the ransom to recover data.
B.Wipe the affected servers and reimage them.
C.Notify law enforcement.
D.Restore files from clean backups.
AnswerD

Restoring from clean backups directly satisfies the recovery objective after containment, reinstating encrypted file server data with verified integrity. Backups predating the ransomware's encryption window avoid reintroducing the payload, unlike decryption attempts or paying ransoms. This restores availability, the CIA triad pillar compromised by the attack, before returning to normal operations.

Why this answer

Restore files from clean backups, as this is the most reliable recovery method after containment. Paying the ransom is discouraged and does not guarantee data recovery; notifying law enforcement can be done later; wiping and reimaging may be unnecessary if clean backups are available.

240
MCQmedium

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

A.Mean time to respond (MTTR) to incidents
B.Number of security incidents in the past quarter
C.Total cost of security incidents
D.Percentage of systems compliant with patch SLAs
AnswerD

Patch SLA compliance measures current remediation performance, so low compliance predicts unpatched exploitable systems and therefore future incidents. It is a leading indicator because it reflects exposure accumulating now, unlike lagging counts of incidents already suffered.

Why this answer

A leading indicator predicts future outcomes, whereas lagging indicators measure past events. The percentage of systems compliant with patch SLAs is a leading indicator because it reflects the current state of vulnerability management, which directly influences the likelihood of future security incidents. High compliance with patching reduces the attack surface and is a proactive measure.

Exam trap

CISM often tests the difference between leading and lagging indicators; candidates may mistakenly select MTTR or incident counts as leading because they are commonly used metrics, but they are lagging.

How to eliminate wrong answers

Option A is wrong because mean time to respond (MTTR) is a lagging indicator; it measures how quickly incidents were handled after they occurred, not future incident likelihood. Option B is wrong because the number of security incidents in the past quarter is a lagging indicator that reports historical events. Option C is wrong because total cost of security incidents is also a lagging indicator, reflecting financial impact after incidents have happened.

241
MCQmedium

A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?

A.A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.
B.A benchmark comparison showing that peer companies spend more on security.
C.A list of all security tools currently deployed with their license costs.
D.A statement that the organization will comply with the regulation by the deadline.
AnswerA

A gap assessment maps existing controls to regulatory requirements and prioritizes remediation by risk, showing executives exactly where exposure exists and how it will be addressed. This aligns security investment with compliance obligations and provides a defensible, measurable plan. It demonstrates that the program is driven by both regulatory need and business risk rather than by technology preferences.

Why this answer

A gap assessment that maps controls to regulatory requirements and prioritizes remediation by risk directly demonstrates alignment between the security program and compliance obligations. It gives executives a clear view of exposure and a plan for closure. Tool inventories, commitment statements, and peer benchmarks lack the requirement-to-control mapping needed for a risk-based implementation plan.

Exam trap

The trap here is confusing budget justification artifacts, such as peer benchmarks or tool inventories, with evidence of compliance alignment.

242
MCQeasy

An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?

A.Perform a residual risk assessment
B.Purchase additional cyber insurance to cover future breaches
C.Conduct security awareness training for all employees
D.Update the information security policy to mandate stricter controls
AnswerA

After corrective controls are implemented, a residual risk assessment determines what risk remains, confirming whether treatment reduced exposure to an acceptable level or whether further action, transfer or acceptance is required before closing the change management gap.

Why this answer

After implementing corrective controls, the next step in the risk management process is to perform a residual risk assessment. This evaluates the remaining risk after controls are applied, ensuring that the organization's risk appetite is not exceeded. Without this assessment, the organization cannot confirm whether the implemented controls are sufficient or if additional measures are needed.

Exam trap

The trap here is that candidates often confuse the order of the risk management process, selecting a corrective action (like training or policy updates) instead of the required evaluation step (residual risk assessment) that validates control effectiveness before moving to other activities.

How to eliminate wrong answers

Option B is wrong because purchasing additional cyber insurance is a risk transfer strategy, not a next step after implementing controls; it does not address the root cause or validate control effectiveness. Option C is wrong because conducting security awareness training is a preventive control that should have been part of the corrective plan, but it is not the immediate next step after implementation; the organization must first assess residual risk to determine if training alone is adequate. Option D is wrong because updating the information security policy is a governance action that may follow the residual risk assessment, but it is not the immediate next step; policy changes should be informed by the residual risk findings.

243
MCQeasy

A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?

A.Implement encryption for all data in transit
B.Accept the risk because the likelihood of interception is low
C.Purchase cyber insurance to cover potential data breach costs
D.Discontinue all electronic transmission of patient data
AnswerA

TLS encryption for data in transit directly closes the identified HIPAA gap, protecting ePHI as it crosses the internet between endpoints. It is the specific technical safeguard addressing the audit finding, and is prioritised because unencrypted transmission is an active, ongoing breach exposure.

Why this answer

HIPAA's Security Rule requires covered entities to protect ePHI in transit using encryption or an equivalent alternative, and transmitting unencrypted EHRs over the internet is a direct violation. Implementing encryption for all data in transit is the prioritized risk treatment because it directly mitigates the identified vulnerability, is technically feasible, and aligns with regulatory requirements. Other options either avoid the risk, transfer it, or disrupt operations without fixing the root cause.

Exam trap

CISM often tests risk treatment selection, and candidates may choose risk acceptance or insurance because they sound pragmatic — the trap is forgetting that regulatory compliance obligations cannot be transferred or accepted away when a direct technical fix is available.

How to eliminate wrong answers

Option B is wrong because accepting the risk ignores HIPAA's mandatory encryption safeguard and the high impact of a breach involving patient data; likelihood being 'low' does not justify non-compliance. Option C is wrong because cyber insurance transfers financial impact but does not remediate the unencrypted transmission or satisfy the regulatory requirement. Option D is wrong because discontinuing all electronic transmission of patient data is an extreme operational disruption that would cripple care delivery and is not a proportionate or necessary control.

244
MCQhard

A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?

A.Adopt a quantitative risk assessment approach using monetary values for impact and annualized loss expectancy.
B.Enhance the qualitative scale by adding more levels (e.g., Very High, High, Medium, Low, Very Low).
C.Use a risk matrix that combines likelihood and impact into a single risk score.
D.Conduct a Delphi technique exercise with subject matter experts to reach consensus on risk ratings.
AnswerA

Quantitative risk assessment uses numerical data, such as monetary values and probabilities, to calculate expected losses. This provides an objective and consistent basis for comparing risks across business units. Senior management can use metrics like annualized loss expectancy (ALE) to prioritize investments. While quantitative methods require more data and effort, they meet the requirement for objectivity and comparability better than qualitative scales.

Why this answer

A quantitative risk assessment approach using monetary values and annualized loss expectancy provides objective, numerical data that can be consistently compared across business units. This meets senior management's requirement for a more objective and consistent methodology. Qualitative enhancements like more levels, risk matrices, or Delphi exercises still rely on subjective judgments and do not offer the same level of comparability or objectivity as quantitative methods.

Exam trap

The trap here is assuming that refining a qualitative method (e.g., adding levels or using Delphi) will achieve objectivity, when in fact only quantitative methods provide numerical, comparable data.

245
MCQhard

A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?

A.Conduct a security awareness campaign focused on telehealth and cloud security.
B.Implement additional security controls for cloud and telehealth based on industry best practices.
C.Perform a new risk assessment that includes the cloud and telehealth environments.
D.Update the information security policy to include cloud and telehealth security requirements.
AnswerC

A new risk assessment is the foundational step to identify and evaluate risks introduced by cloud services, telehealth, and regulatory changes. It provides the basis for updating security controls and strategies. Without a current risk assessment, any control adjustments would be based on outdated assumptions, potentially leaving critical gaps. CISM emphasizes that risk assessment should be ongoing and triggered by significant changes.

Why this answer

The CISO should first perform a new risk assessment because significant changes such as cloud adoption, telehealth, and new regulations alter the risk landscape. A current risk assessment identifies new threats, vulnerabilities, and regulatory requirements, enabling the organization to update controls and policies effectively. This aligns with CISM's emphasis on continuous risk management as the core of an information security program.

Exam trap

The trap here is jumping to control implementation or policy updates without first reassessing risks, which can lead to misaligned security investments.

246
Multi-Selecthard

An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)

Select 2 answers
A.The external forensic firm has been formally engaged and has begun its investigation
B.The attacker's command-and-control infrastructure has been sinkholed and no new beaconing is observed from monitored networks
C.All attacker-controlled access paths and persistence mechanisms have been identified and removed
D.The chief information security officer has verbally confirmed to the board that the threat has been neutralised
E.The affected business unit has confirmed that normal transaction volumes have resumed
AnswersB, C

Sinkholing command-and-control and confirming that no hosts continue to beacon provides concrete evidence that the adversary has lost remote control of compromised systems. This is a strong, observable containment indicator because active implants would keep attempting to reach their infrastructure. It directly demonstrates that the attacker's ability to operate within the environment has been disrupted.

Why this answer

Containment is complete when the adversary can no longer operate: every access path and persistence mechanism has been removed, and command-and-control has been disrupted so no implants can receive instructions. These are verifiable technical conditions. Business resumption, executive assurances, and forensic engagement are useful signals or actions but do not prove the threat has been neutralised.

Exam trap

The trap here is accepting restored business operations or executive assurances as proof of containment, when containment is defined by the elimination of the adversary's access and control.

247
MCQmedium

An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?

A.The preference of the business unit leader who owns the revenue-generating service
B.Whether the affected system is covered by the organization's cyber insurance policy
C.The technical difficulty of restoring the service after it has been taken offline
D.The potential business impact of the containment action weighed against the risk of continued attacker activity
AnswerD

Containment always involves trade-offs: taking systems offline stops the attacker but may disrupt revenue, while leaving them online preserves service but allows further damage. The incident commander must balance these competing risks using business impact analysis and current threat intelligence. This risk-based judgment, aligned with organizational priorities, is the primary guide. Neither technical feasibility alone nor cost alone captures the full decision, which is fundamentally about acceptable risk.

Why this answer

Containment decisions require weighing the harm of the action against the harm of inaction. Taking a revenue service offline protects the enterprise from further compromise but disrupts business, while leaving it online preserves revenue but risks escalation. The incident commander uses business impact analysis, threat severity, and organizational risk tolerance to strike the right balance.

Restoration difficulty, insurance coverage, and stakeholder preference are secondary inputs, not the primary basis for the decision.

Exam trap

The trap here is letting a single consideration such as restoration effort, insurance, or a business owner's preference drive containment, when the governing criterion is balanced business and threat risk.

248
Multi-Selectmedium

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Select 3 answers
A.Automated patching of vendor systems
B.Contractual security requirements
C.Shared SOC services
D.Vendor tiering based on data access and criticality
E.Onboarding risk assessment
AnswersB, D, E

Contracts embed enforceable security obligations, breach notification duties, audit rights and liability into the vendor relationship. This gives the organisation legal leverage when a third party's controls fail, satisfying the governance requirement that risk be formally transferred and managed.

Why this answer

Contractual security requirements (B) are essential because TPRM must codify security, privacy, breach-notification, and audit obligations in vendor agreements so that controls are legally enforceable. Vendor tiering based on data access and criticality (D) is essential because it lets the organization apply proportionate due diligence, monitoring, and reassessment to vendors according to the sensitivity of data and operational dependency. Onboarding risk assessment (E) is essential because risk must be evaluated before a vendor is engaged or given access, establishing a baseline for approval, remediation, and ongoing oversight.

The unmarked options do not belong: automated patching of vendor systems (A) is an operational control the vendor itself normally performs and is not a core TPRM program element, and shared SOC services (C) are one possible assurance mechanism rather than a required component of every TPRM program.

Exam trap

The trap here is that candidates often confuse operational security controls (like patching or shared SOC) with the governance and risk management components that define a TPRM program, leading them to select options that describe how an organization secures its own environment rather than how it manages vendor risk.

249
MCQhard

A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?

A.Increase the frequency of security audits for all regional offices
B.Provide additional training to regional IT staff on the importance of security baselines
C.Allow each regional office to maintain its own security program as long as it meets minimum standards
D.Establish a mandatory global security baseline with a formal exception process requiring CISO approval for any deviation
AnswerD

A mandatory global baseline with CISO-approved exceptions closes the loophole regional staff exploited, since deviations require central sign-off rather than local self-assessment. It preserves operational flexibility through the formal exception route while enforcing the control the breach exposed as missing.

Why this answer

Establishing a mandatory global security baseline with a formal exception process ensures consistency while allowing for justified deviations that are formally approved by the CISO, addressing the root cause of non-compliance. Option A is wrong because increasing audits may detect issues but does not enforce compliance without binding standards. Option B is wrong because training alone does not ensure implementation when local IT can claim unique requirements.

Option C is wrong because allowing each office to maintain its own program perpetuates fragmentation and does not enforce a consistent baseline.

250
Multi-Selectmedium

Which TWO actions are appropriate during the containment phase of an incident involving a malware outbreak on multiple workstations?

Select 2 answers
A.Contact all users to warn them about the malware
B.Reimage all affected workstations immediately
C.Isolate infected workstations from the network
D.Notify customers about potential data breach
E.Block known malicious domains and IPs at the firewall
AnswersC, E

Isolation stops lateral movement.

Why this answer

Isolating infected workstations from the network is a primary containment action that prevents the malware from spreading laterally to other systems, limiting the scope of the incident. This is typically achieved by disconnecting network cables, disabling switch ports, or using network access control (NAC) to quarantine the affected hosts, which stops further propagation without destroying forensic evidence.

Exam trap

The trap here is that candidates often confuse containment with eradication or communication, mistakenly selecting 'reimage all affected workstations immediately' as a containment step, when in fact reimaging is an eradication action that should occur after containment and evidence collection.

251
MCQeasy

During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?

A.Files on the hard drive.
B.Network traffic logs.
C.Backup tapes.
D.Contents of RAM.
AnswerD

RAM contains highly volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Collecting RAM first is critical to preserve this evidence. This follows the order of volatility, a fundamental concept in digital forensics. Failing to capture RAM first could result in loss of crucial evidence for the investigation.

Why this answer

The order of volatility dictates that the most volatile evidence, such as RAM contents, should be collected first because it is lost when the system is powered off or rebooted. Hard drives, logs, and backups are less volatile and can be collected later. This principle ensures that critical evidence is preserved for forensic analysis.

Exam trap

The trap here is assuming that hard drive files are the most critical evidence to collect first, ignoring the rapid loss of volatile memory.

252
MCQeasy

An organization's incident response plan has not been updated in two years. Which of the following is the MOST likely consequence?

A.The plan will comply with new regulations automatically.
B.The plan will be more effective due to maturity.
C.The plan will be followed exactly as written.
D.The plan may not address current threats and technologies.
AnswerD

Threats, attack techniques and the underlying technology estate evolve continuously, so a two-year-old plan likely omits current attack vectors and no longer maps to the present environment, leaving response procedures misaligned with what the organisation now operates.

Why this answer

An incident response plan that has not been updated in two years is unlikely to account for recent changes in the threat landscape, such as new attack vectors (e.g., ransomware-as-a-service, zero-day exploits) or shifts in technology stack (e.g., cloud-native architectures, IoT devices). Without periodic review, the plan may lack updated playbooks for current malware families, fail to reference new detection tools, or omit revised containment procedures for modern network segmentation. This gap directly increases the risk of ineffective response during an actual incident.

Exam trap

The trap here is that candidates may assume a plan's maturity or compliance improves with age, but CISM emphasizes that incident response plans must be living documents updated at least annually to remain effective against evolving threats and technologies.

How to eliminate wrong answers

Option A is wrong because regulations do not automatically update a static plan; compliance requires active monitoring and revision to address new legal requirements (e.g., GDPR, CCPA amendments). Option B is wrong because a plan's effectiveness degrades over time without updates, as maturity in incident response comes from iterative testing and refinement, not from simply aging. Option C is wrong because an outdated plan is less likely to be followed exactly; teams may deviate due to missing steps for current technologies or because the plan references obsolete systems or contacts.

253
Multi-Selecthard

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Select 2 answers
A.Champions report directly to the CISO
B.Champions are rotated every six months
C.Champions act as liaisons between security and their teams
D.Champions have authority to enforce security policies
E.Champions are volunteers from development teams with additional security training
AnswersC, E

Champions functioning as liaisons create a bidirectional channel, translating security requirements into team language and surfacing development constraints to security. This embedded communication satisfies the programme's effectiveness criterion by removing the bottleneck of a central security team.

Why this answer

Option C is correct because the core value of a security champions program is that champions serve as the liaison or bridge between the central security team and their own development/product teams, translating security requirements into the team's language and feeding practical concerns back to security. Option E is correct because effective champions are typically volunteers drawn from development (or engineering) teams who receive additional security training, which gives them credibility with peers and the embedded knowledge to influence secure practices organically. Option A is incorrect because champions normally remain within their existing team and reporting line, not reporting directly to the CISO, which would undermine their embedded liaison role.

Option B is incorrect because rotating champions every six months destroys the continuity, relationship-building, and accumulated security expertise that make the program effective. Option D is incorrect because champions are influencers and advocates, not enforcers; they generally lack the authority to enforce security policies, which remains with security leadership and management.

Exam trap

CISM often tests the characteristics of effective security champions programs; candidates may incorrectly assume champions need authority to enforce policies or should report to the CISO, but the key is their embedded, voluntary, and liaison role.

254
MCQmedium

A multinational retailer's security operations center (SOC) identifies that an attacker has compromised a point-of-sale (POS) system in a European store and is moving laterally toward the payment card processing environment. The incident response manager needs to decide the FIRST action to limit business impact while preserving the ability to investigate. Which action should be taken FIRST?

A.Notify the payment card brands and law enforcement before taking any technical action.
B.Isolate the affected POS system from the network using the endpoint detection and response (EDR) tool while keeping it powered on.
C.Immediately power off the compromised POS system and remove it from the network.
D.Delete the malware files from the POS system to stop the attack immediately.
AnswerB

Network isolation via EDR contains the threat by cutting command-and-control and lateral movement paths while preserving volatile memory and running processes for forensic analysis. This balances the twin CISM goals of limiting business impact and maintaining evidence integrity, allowing investigators to collect memory, logs, and network state before any destructive action. It is the least disruptive containment step that still stops the attack from spreading to the payment card environment.

Why this answer

Isolating the endpoint through EDR keeps the system powered on, which preserves volatile evidence while stopping the attacker's ability to move laterally or maintain command and control. This approach satisfies the CISM priority of limiting business impact without compromising the investigation. Notifying external parties or deleting files before containment can let the attack spread and destroy evidence needed for scoping and root cause analysis.

Exam trap

The trap here is assuming that the fastest way to stop an attack is to power off or wipe the infected system, which actually destroys volatile evidence and impedes containment scoping.

255
MCQhard

During a major incident, the incident response team discovers that the attacker is still active in the environment and is moving laterally. The incident response manager must decide on the immediate course of action. Which of the following should be the PRIMARY consideration when determining whether to isolate affected network segments?

A.The attacker's presumed skill level and tools.
B.The cost of replacing the affected network hardware.
C.The number of security staff available to monitor the isolated segments.
D.The potential impact on business operations and critical services.
AnswerD

Isolating network segments can halt the attacker's lateral movement but may also disrupt critical business services, customer-facing systems, and revenue-generating operations. The incident response manager must weigh the security benefit of containment against the business impact, which is a core CISM principle. This decision requires understanding which systems are critical and what tolerances exist for downtime, ensuring the response aligns with organizational risk appetite.

Why this answer

In an active incident with lateral movement, the incident response manager must balance containment against business continuity. The primary consideration is the impact on business operations and critical services, because isolation can disrupt essential functions. This reflects CISM's emphasis on aligning incident response decisions with organizational risk management and business priorities, rather than purely technical or financial factors.

Exam trap

The trap here is focusing on technical or cost factors, such as attacker skill or hardware replacement, instead of the business impact that should drive containment decisions during an active incident.

256
MCQeasy

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

A.NIST SP 800-53
B.COBIT 2019
C.ISO 27001 Annex A
D.CIS Controls v8
AnswerD

CIS Controls v8 uniquely structures its safeguards into Implementation Groups IG1, IG2 and IG3, mapped to organisational risk profile and available resources. No other framework uses this tiered grouping, directly satisfying the stem's stated constraint.

Why this answer

The CIS Controls v8 (Center for Internet Security Critical Security Controls) are organized into Implementation Groups (IG1, IG2, IG3) that are tailored to organizations based on their risk profile and resources. IG1 is for small organizations with limited resources, IG2 for medium, and IG3 for large organizations with mature security programs. This structure is unique to CIS Controls.

Exam trap

CISM often tests familiarity with various frameworks; candidates may confuse CIS Controls with NIST or ISO, but the key differentiator is the Implementation Groups (IG1-IG3) unique to CIS.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-53 is a catalog of security and privacy controls for federal information systems, organized by control families, not implementation groups. Option B is wrong because COBIT 2019 is a governance framework for enterprise IT, focusing on processes and maturity levels, not implementation groups. Option C is wrong because ISO 27001 Annex A provides a list of security controls but does not define implementation groups; it is a certifiable standard.

257
Multi-Selecteasy

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Select 2 answers
A.A single, strong firewall at the network perimeter.
B.A single sign-on (SSO) solution for all applications.
C.Network segmentation to isolate critical systems.
D.Annual penetration testing as the primary security control.
E.Endpoint detection and response (EDR) on all workstations and servers.
AnswersC, E

Segmenting the network into zones with controlled inter-zone traffic limits lateral movement, so compromise of one system cannot reach critical financial systems directly. This enforces least-privilege connectivity, a core defense-in-depth layer satisfying the stem's requirement to isolate critical systems.

Why this answer

Option C is correct because network segmentation isolates critical systems (e.g., cardholder data environments) into separate VLANs or subnets with strict ACLs and firewall rules, so a breach in one zone cannot easily pivot to high-value assets, which is a core defense-in-depth layer. Option E is correct because EDR provides continuous endpoint telemetry, behavioral detection, and automated response (e.g., process isolation, host quarantine) on workstations and servers, adding a host-level detection and response layer that complements perimeter and network controls. Option A is not correct because a single perimeter firewall represents a single point of failure and a flat-trust model, contradicting defense-in-depth's requirement for multiple overlapping controls.

Option B is not correct because SSO centralizes authentication and, if compromised, can grant broad access; it is an identity convenience/control, not a layered defensive component by itself. Option D is not correct because annual penetration testing is a point-in-time assessment, not a primary preventive or detective control, and cannot substitute for continuous layered defenses.

258
MCQmedium

An organization is developing its incident response plan. The CISO wants to ensure that the plan includes provisions for communicating with external parties during and after an incident. Which of the following should be the PRIMARY consideration when defining external communication procedures?

A.Ensuring that all external communications are approved by the legal department.
B.Using social media to quickly inform the public about the incident.
C.Establishing a single point of contact for all external communications.
D.Aligning communication procedures with legal, regulatory, and contractual requirements.
AnswerD

This is correct because external communications during an incident must comply with laws, regulations, and contracts. For example, data breach notification laws require timely notification to affected parties and regulators. CISM emphasizes that incident response must align with legal and regulatory obligations. This is the primary consideration because failure to comply can result in fines and legal action.

Why this answer

External communication procedures must first ensure compliance with legal, regulatory, and contractual requirements. These obligations dictate who to notify, when, and what information to share. CISM emphasizes that incident response is not just technical but also legal and business-oriented.

While legal approval, a single point of contact, and social media are elements, they are secondary to the primary need to meet compliance obligations and protect the organization.

Exam trap

The trap here is assuming that a single point of contact is the most critical aspect, when actually the primary driver is legal and regulatory compliance.

259
MCQmedium

A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?

A.A cost-benefit analysis showing a net benefit of $1,700,000 per year from the control.
B.The residual risk of $400,000 after the control is implemented.
C.The control's annualized cost of $300,000 compared with the total asset value of the patient-records system.
D.The likelihood and impact ratings of the threat before and after the control.
AnswerA

Subtracting the $300,000 annual control cost from the $2,000,000 in loss reduction ($2,400,000 ALE minus $400,000 residual ALE) yields a net benefit of $1,700,000 per year. This cost-benefit figure directly demonstrates that the investment produces a positive return, which is the clearest financial justification for the executive committee.

Why this answer

Cost-benefit analysis translates the risk reduction into a monetary figure that decision-makers can weigh against the control's annual cost. Here the control lowers expected annual loss by $2,000,000 while costing $300,000, producing a $1,700,000 net benefit. This quantitative justification is far more persuasive to an executive committee than residual risk, asset value, or qualitative ratings alone.

Exam trap

The trap here is assuming that presenting residual risk or qualitative likelihood and impact ratings is sufficient justification, when executives approving a specific annual spend need the quantified cost-benefit comparison.

260
MCQmedium

An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?

A.The number of systems or user accounts confirmed to be affected by the incident
B.The classification of the threat actor, such as nation-state, organized crime, or insider
C.The elapsed time between initial detection and the first containment action taken by the response team
D.The potential or actual business impact of the incident on critical services and objectives
AnswerD

Escalation to the crisis management team exists to mobilize executive decision-making, communications, and resource authority when business objectives or critical services are threatened. Defining thresholds in terms of business impact aligns incident severity with the organization's risk appetite and ensures leadership engages when strategic decisions, regulatory notifications, or customer commitments are at stake.

Why this answer

Escalation criteria should reflect the consequence to the business, because the crisis management team's purpose is to make strategic decisions and commit resources when critical services, regulatory obligations, or stakeholder trust are at risk. Technical metrics such as system counts, response timing, and attribution describe the incident's mechanics or handling rather than its business significance, so they cannot reliably determine when executive engagement is warranted.

Exam trap

The trap here is assuming that escalation is driven by technical size or threat actor prestige, when it is actually driven by business impact and the need for executive decision authority.

261
MCQeasy

A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?

A.Merge all teams into one central unit
B.Implement a top-down mandate for all policies
C.Create a governance committee with representatives from each facility
D.Outsource security to a third party
AnswerC

A governance committee with facility representatives establishes federated decision-making, letting each security team retain local control while aligning policies and eliminating duplicated effort. This directly satisfies the CISO's constraints of minimal disruption and no central coordination, since authority is shared rather than imposed, and inconsistent patient data protection is resolved through agreed, cross-facility standards.

Why this answer

A governance committee with representatives from each facility establishes a federated governance model that aligns security practices across the hospital chain without restructuring teams. This approach enables consistent policy development, shared oversight, and coordination of patient data protection efforts while minimizing operational disruption, as each facility retains its existing team structure. It directly addresses the lack of central coordination and duplicate efforts by creating a collaborative decision-making body, which is a core principle of information security governance.

Exam trap

The trap here is that candidates often assume centralization (Option A) is the only way to achieve consistency, but the CISM exam emphasizes governance structures that balance coordination with minimal disruption, making a committee-based approach the correct choice over a full reorganization.

How to eliminate wrong answers

Option A is wrong because merging all teams into one central unit would cause significant operational disruption, resistance from facility-level staff, and potential loss of local context for patient data protection, which contradicts the goal of minimal disruption. Option B is wrong because implementing a top-down mandate for all policies ignores the need for buy-in from facility-level teams and may lead to non-compliance or ineffective enforcement due to lack of local adaptation, failing to improve governance sustainably. Option D is wrong because outsourcing security to a third party does not inherently improve governance; it shifts responsibility but still requires central coordination and oversight, and it introduces risks related to vendor management, data privacy, and loss of institutional knowledge.

262
Multi-Selectmedium

Which TWO of the following are common approaches to information security risk assessment?

Select 2 answers
A.Qualitative
B.Quantitative
C.Penetration testing
D.Vulnerability assessment
E.Business impact analysis
AnswersA, B

Qualitative assessment ranks risks using descriptive scales such as high, medium and low, drawing on expert judgement rather than numeric values. It satisfies the stem by being one of the two recognised risk assessment approaches, suiting scenarios where precise monetary estimates are impractical.

Why this answer

Options A and B are correct because information security risk assessment fundamentally follows two recognized methodologies: qualitative assessment (A), which uses subjective scales such as high/medium/low to rank risks based on expert judgment, and quantitative assessment (B), which assigns numeric monetary values and probabilities to calculate expected annual loss (e.g., SLE × ARO = ALE). These two approaches are the standard classifications taught in risk management frameworks such as NIST SP 800-30 and ISO/IEC 27005, and they can also be combined into a hybrid (semi-quantitative) method. Penetration testing (C) is a technical security testing technique that simulates attacks to find exploitable weaknesses, not a risk assessment approach itself.

Vulnerability assessment (D) identifies and catalogs known weaknesses but does not by itself evaluate risk in terms of likelihood and impact. Business impact analysis (E) is a separate BCP/DR activity that determines critical business functions and recovery requirements, not a general risk assessment methodology.

Exam trap

The trap here is that candidates confuse risk assessment approaches (qualitative/quantitative) with risk assessment activities (like penetration testing or vulnerability assessment), which are tools used within the assessment process but not the overarching methodology itself.

263
Multi-Selecteasy

A security audit has identified several governance weaknesses. Which TWO of the following are most likely to indicate a lack of effective information security governance? (Choose two.)

Select 2 answers
A.Risk assessments are not performed on a regular basis.
B.No formal security steering committee exists.
C.The information security policy is not available on the intranet.
D.Employees have not completed annual security awareness training.
E.Antivirus software is not updated on all endpoints.
AnswersA, B

Regular risk assessments are fundamental to governance to ensure risk is managed.

Why this answer

A is correct because regular risk assessments are a foundational requirement of information security governance, as they ensure that security controls remain aligned with evolving threats and business objectives. Without periodic risk assessments, the organization cannot demonstrate due diligence or maintain an accurate risk profile, which is a direct indicator of governance failure.

Exam trap

ISACA often tests the distinction between governance (strategic oversight, risk management, committee structures) and operational controls (training, patching, policy distribution), leading candidates to mistake operational deficiencies for governance weaknesses.

264
MCQhard

A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?

A.Ignore the individual risks as they are low priority
B.Use a risk aggregation model to assess cumulative impact and consider enterprise-level controls
C.Accept the risk because the probability of all occurring simultaneously is negligible
D.Treat each individual risk separately with minimal controls
AnswerB

A risk aggregation model quantifies cumulative impact across correlated low-likelihood, low-impact risks, exposing the combined exposure that siloed assessments miss. Enterprise-level controls then address that aggregate exposure, satisfying the stem's requirement to manage risks whose significance emerges only collectively rather than individually.

Why this answer

Risk aggregation models are specifically designed to quantify the cumulative impact of multiple low-level risks that, when combined, exceed the enterprise's risk appetite. This approach aligns with the CISM domain of Information Security Risk Management, where enterprise-level controls (e.g., centralized monitoring, compensating controls) are necessary to address systemic risk that individual risk treatments cannot mitigate. The key insight is that the combined probability of correlated or cascading events may be higher than the product of individual probabilities, especially when risks share common root causes.

Exam trap

The trap here is that candidates mistakenly apply the 'low probability, low impact' rule from individual risk assessment and ignore the need for aggregation, failing to recognize that the sum of many small risks can exceed the enterprise risk tolerance.

How to eliminate wrong answers

Option A is wrong because ignoring low-impact, low-probability risks violates the principle of risk aggregation; such risks can collectively create a significant exposure, especially if they share a common vulnerability or threat vector. Option C is wrong because accepting risk based on the assumption that the probability of all occurring simultaneously is negligible ignores the possibility of correlated events, where one risk triggers another, or where a single threat exploits multiple vulnerabilities at once. Option D is wrong because treating each individual risk separately with minimal controls fails to address the cumulative effect and may leave the enterprise exposed to a cascading failure that no single control can prevent.

265
MCQhard

A CISO is reviewing the organization's risk management process. The board has asked how the CISO ensures that security risks are managed within the organization's risk appetite. Which activity BEST demonstrates this?

A.Purchasing cyber insurance to transfer residual risks that exceed the organization's tolerance.
B.Implementing a risk register that lists all identified risks and their owners.
C.Defining risk appetite and tolerance levels, and monitoring key risk indicators against them.
D.Conducting an annual risk assessment and presenting the results to the board.
AnswerC

This is correct because CISM defines risk appetite as the amount of risk an organization is willing to accept. By defining appetite and tolerance, and monitoring key risk indicators (KRIs), the CISO can demonstrate that risks are being kept within those bounds. This is an ongoing governance activity that provides the board with assurance that risk management is proactive and aligned with business objectives.

Why this answer

The correct answer is defining risk appetite and tolerance levels and monitoring key risk indicators against them. In CISM, risk appetite is set by the board and communicated to management. The CISO ensures that security risks are managed within that appetite by establishing tolerance thresholds and monitoring KRIs.

This provides continuous assurance that risks are within acceptable limits and that treatment decisions are aligned with business objectives.

Exam trap

The trap here is equating a risk register or annual assessment with ongoing management within risk appetite, when appetite definition and KRI monitoring are the key governance activities.

266
MCQeasy

An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?

A.The third-party cloud hosting provider's account manager
B.The legal counsel or chief legal officer
C.The security operations center (SOC) shift lead
D.The IT service desk manager
AnswerB

Legal counsel holds authority over what may be disclosed publicly and what must be reported to regulators, balancing statutory obligations, privilege, and liability. Public statements and regulatory notifications carry legal consequences, so the incident manager must route these decisions through legal. Counsel also determines whether attorney-client privilege should be invoked to protect investigation details from later discovery.

Why this answer

Decisions about public statements and regulatory disclosures require legal authority because they carry statutory, contractual, and liability implications. Legal counsel evaluates notification deadlines, privilege, and the accuracy of messaging. Technical roles supply facts, and vendors supply their own obligations, but neither can authorize the organization's external communications or regulatory filings during an incident.

Exam trap

The trap here is equating technical incident leadership with authority over external communications, when legal counsel owns disclosure decisions.

267
Multi-Selectmedium

An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)

Select 2 answers
A.Disciplining all employees who clicked the phishing link to reinforce security awareness.
B.Increasing the security budget for the next fiscal year without linking it to specific findings.
C.Immediately deleting all affected mailboxes to remove any remaining malicious content.
D.Assigning corrective actions with owners and due dates based on identified gaps.
E.Documenting root cause, timeline, and response effectiveness in a formal after-action report.
AnswersD, E

Assigning corrective actions with clear owners and due dates converts findings into accountable, trackable improvements. Without ownership and deadlines, lessons learned remain observations rather than changes. This step ensures the post-incident review produces measurable risk reduction and closes the loop on identified weaknesses, which is essential for continuous improvement of the incident response program.

Why this answer

Translating lessons learned into improvement requires both documentation and accountability. A formal after-action report records root cause, timeline, and response effectiveness, while assigning corrective actions with owners and due dates ensures findings are acted upon and tracked. Together they create a measurable, repeatable improvement cycle.

Punitive measures, evidence deletion, or untargeted budget increases do not achieve this objective.

Exam trap

The trap here is equating post-incident activity with punishment or spending, when the real objective is documented findings tied to owned, tracked corrective actions.

268
Multi-Selectmedium

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Select 2 answers
A.Type and sensitivity of data the vendor accesses
B.Vendor's geographic location
C.Number of employees at the vendor
D.Vendor's annual revenue
E.Criticality of the vendor's service to business operations
AnswersA, E

The type and sensitivity of data a vendor accesses directly determines the potential impact of a breach, making it a primary tiering factor. This satisfies the stem's requirement by tying risk tier to data criticality rather than contract value or vendor size.

Why this answer

Option A is correct because the type and sensitivity of the data a vendor accesses directly drives the inherent risk of a data breach or regulatory violation, making it a primary factor in tiering (e.g., PII, PHI, or PCI data raises the tier). Option E is correct because the criticality of the vendor's service to business operations determines the impact of a vendor failure or outage on the organization's ability to function, which is a core dimension of vendor risk tiering. In contrast, Option B (geographic location) can influence risk but is not a primary tiering factor by itself and is often a sub-factor under data and operational considerations.

Option C (number of employees) and Option D (annual revenue) are vendor size metrics that do not directly reflect the risk the vendor poses to the organization's data or operations, so they are not the most appropriate determinants.

Exam trap

CISM often tests vendor risk tiering factors; candidates may be tempted to select easily quantifiable factors like revenue or employee count, but the exam expects focus on data sensitivity and business criticality.

269
MCQhard

An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?

A.$120,000; the project cost exceeds the annual benefit and should be rejected outright.
B.$40,000; the project should be approved because any reduction in high-impact risk is always cost-justified.
C.$120,000; the manager should compare it with the project cost and consider qualitative factors before recommending treatment.
D.$160,000; the project is justified because the reduction equals the current annualized loss expectancy.
AnswerC

The current annualized loss expectancy is 0.04 × $4,000,000 = $160,000, and after the project it is 0.01 × $4,000,000 = $40,000, giving an expected annual risk reduction of $120,000. Because the $900,000 project cost exceeds a single year's benefit, the manager must weigh multi-year benefit, risk appetite, regulatory requirements, and non-quantifiable impacts before recommending the investment. This is a sound risk-treatment analysis.

Why this answer

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence. Before the project the value is $160,000; after it is $40,000; the expected annual risk reduction is $120,000. The manager should treat this as one input, comparing it with the project cost and weighing qualitative and regulatory factors before recommending treatment.

Exam trap

The trap here is treating the residual annualized loss expectancy or the pre-control value as the benefit instead of subtracting the post-control value from the pre-control value.

270
MCQhard

A financial institution is restructuring its information security governance to comply with a new regulatory requirement that mandates a formal risk appetite statement. The board has conflicting views on the level of risk to accept. Which of the following should the information security manager do to facilitate the definition of risk appetite?

A.Recommend adopting the risk appetite levels used by a peer financial institution.
B.Facilitate a workshop with business leaders to map risk tolerance to strategic goals.
C.Draft a risk appetite statement and ask the CISO to approve it on behalf of the board.
D.Propose a quantitative risk appetite based on the organization's technology risk metrics.
AnswerB

Mapping risk tolerance to strategic goals translates the board's conflicting abstract views into concrete, business-aligned thresholds, producing the formal risk appetite statement the regulator mandates. A workshop with business leaders secures the ownership and consensus that a purely security-driven definition would lack.

Why this answer

Risk appetite must be aligned with the organization's strategic objectives and business goals, not dictated by external benchmarks or technology metrics alone. Facilitating a workshop with business leaders ensures that risk tolerance is mapped to strategic goals, which is a governance requirement under frameworks like COBIT and ISO 31000. This collaborative approach directly addresses the board's conflicting views by enabling informed, consensus-driven decision-making.

Exam trap

The trap here is that candidates often choose a technical or quantitative approach (Option D) or a shortcut (Option C), failing to recognize that risk appetite definition is a governance process requiring board-level strategic alignment, not a technical or delegated decision.

How to eliminate wrong answers

Option A is wrong because blindly adopting a peer institution's risk appetite levels ignores the unique risk profile, regulatory environment, and strategic objectives of the organization, which violates the principle of risk ownership and tailored governance. Option C is wrong because drafting a risk appetite statement and having the CISO approve it bypasses the board's fiduciary responsibility to define and approve risk appetite, undermining the governance hierarchy and regulatory compliance. Option D is wrong because proposing a quantitative risk appetite based solely on technology risk metrics neglects qualitative factors, business context, and strategic alignment, which are essential for a holistic risk appetite statement.

271
MCQmedium

During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?

A.Implement compensating controls to reduce the risk
B.Accept the risk as a cost of doing business
C.Avoid the risk by decommissioning the system
D.Purchase cyber insurance to transfer the risk
AnswerA

Compensating controls directly address the unpatched vulnerabilities without requiring remediation the legacy system cannot support, reducing likelihood while preserving daily payment operations. Because the system is critical and cannot be patched, mitigation through alternative safeguards satisfies the risk-reduction requirement better than avoidance, transfer, or acceptance.

Why this answer

Implementing compensating controls, such as network segmentation, application-layer firewalls, or intrusion detection systems (IDS), directly reduces the residual risk of exploiting unpatched vulnerabilities in the legacy payment system without disrupting its critical daily operations. This aligns with the CISM principle that when a risk cannot be remediated (e.g., due to system criticality or vendor end-of-life), compensating controls are the primary treatment to bring risk within the organization's appetite.

Exam trap

The trap here is that candidates often confuse risk transfer (insurance) with risk mitigation, failing to recognize that insurance does not address the technical vulnerability itself, and that acceptance is only appropriate after a cost-benefit analysis shows residual risk is within tolerance.

How to eliminate wrong answers

Option B is wrong because accepting the risk as a cost of doing business is inappropriate when the likelihood of exploitation is high and the system is critical; acceptance is typically reserved for low-likelihood, low-impact risks after other treatments have been considered. Option C is wrong because avoiding the risk by decommissioning the system would halt daily operations, which is not feasible for a system critical to business continuity; avoidance is only viable when the function can be replaced or eliminated without severe operational impact. Option D is wrong because purchasing cyber insurance transfers the financial impact but does not reduce the likelihood or technical exploitability of the unpatched vulnerabilities; insurance is a risk transfer mechanism, not a primary treatment for high-likelihood technical risks.

272
MCQeasy

Which of the following is the primary purpose of communicating risk assessment results to senior management?

A.To comply with regulatory requirements
B.To enable informed decision-making about risk acceptance
C.To assign blame for security failures
D.To justify the security budget
AnswerB

Risk assessment results give senior management the likelihood and business impact figures needed to decide whether to accept, transfer, mitigate or avoid each risk. Communication therefore exists to support informed risk acceptance decisions at the level holding accountability for organisational risk.

Why this answer

The primary purpose of communicating risk assessment results to senior management is to provide the necessary information for informed decision-making regarding risk acceptance, transfer, or mitigation. Senior management holds the authority to accept residual risk based on a clear understanding of the potential impact and likelihood, which is a core tenet of the CISM framework for information security risk management.

Exam trap

The trap here is that candidates often confuse the operational goal of 'justifying the budget' (Option D) with the strategic governance purpose of 'enabling risk acceptance decisions,' but CISM emphasizes that risk communication to senior management is fundamentally about obtaining informed risk acceptance, not securing funding.

How to eliminate wrong answers

Option A is wrong because while regulatory compliance (e.g., GDPR, SOX) may require documentation of risk assessments, it is not the primary purpose; compliance is a secondary benefit, not the core driver for communication to senior management. Option C is wrong because risk assessment communication is a forward-looking, constructive process aimed at managing risk, not a retrospective exercise to assign blame for security failures, which would undermine trust and collaboration. Option D is wrong because although risk assessment results can support budget justifications, the primary purpose is to enable risk acceptance decisions, not to serve as a budget advocacy tool; budget justification is a downstream outcome, not the immediate objective.

273
MCQhard

A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?

A.Create separate monitoring programs for each regulation
B.Outsource compliance to a third-party
C.Focus only on the strictest regulation
D.Map common controls to multiple regulations
AnswerD

Mapping common controls to multiple regulations lets one control satisfy overlapping GDPR, CCPA and PCI DSS requirements, eliminating duplicate evidence collection and testing. This satisfies the efficiency constraint by reducing assessment effort while maintaining demonstrable compliance across all three frameworks.

Why this answer

Mapping common controls to multiple regulations lets the organization satisfy GDPR, CCPA, and PCI DSS through a unified control set, eliminating duplicated evidence collection, testing, and reporting. Many controls (access management, encryption, logging, incident response) overlap heavily across these frameworks, so a single mapped control can demonstrate compliance with several regulations at once. This is the standard 'control harmonization' approach recommended in GRC practice.

Exam trap

CISM often tests the misconception that the 'strictest regulation' subsumes all others — candidates pick option C, but regulations have non-overlapping obligations, so harmonization via control mapping is the efficient answer.

How to eliminate wrong answers

Option A is wrong because separate programs per regulation multiply cost, effort, and audit fatigue while producing redundant evidence for overlapping controls. Option B is wrong because outsourcing compliance does not remove the organization's legal accountability — the regulator still holds the company responsible, and outsourcing alone does not create an efficient monitoring program. Option C is wrong because focusing only on the strictest regulation ignores requirements unique to the others (e.g., CCPA's consumer rights, GDPR's data subject access requests) and creates compliance gaps.

274
MCQmedium

A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?

A.Conduct a full penetration test of the external attack surface and report findings to the board.
B.Immediately update all security policies to reflect ISO/IEC 27001 requirements and distribute them to staff.
C.Define and obtain board approval for an information security charter that articulates the mandate, authority, and scope of the security function.
D.Deploy an enterprise SIEM and begin centralising log collection from critical systems.
AnswerC

A formally approved charter establishes the security programme's mandate, authority, and scope, and is the foundational governance artifact that ties security activity to board-level oversight and business objectives. Without an approved charter, subsequent policies, metrics, and reporting lack legitimacy and authority. This aligns with CISM's emphasis on establishing governance before executing controls or measurement.

Why this answer

Effective information security governance begins with a board-approved charter that defines the security function's mandate, authority, and scope. This artifact legitimises subsequent strategy, policy, metrics, and control investment, and ensures alignment with business objectives and regulatory obligations. Technical deployments, testing, and policy updates are downstream activities that should reflect the governance framework rather than precede it.

Exam trap

The trap here is assuming that acquiring technology or performing assessments demonstrates governance, when governance actually begins with a formally approved mandate and scope.

275
MCQeasy

A security analyst detects an unusual spike in outbound traffic from a database server. Which of the following is the FIRST step in the incident response process?

A.Confirm the incident as a true positive
B.Isolate the server from the network
C.Identify the root cause of the traffic spike
D.Notify senior management
AnswerA

Confirming the incident as a true positive validates that the outbound traffic spike is genuinely malicious rather than benign, such as a backup or replication job. This satisfies the first-step requirement by preventing wasted response effort before containment or eradication actions are initiated.

Why this answer

In the NIST SP 800-61 incident response lifecycle, the first phase is preparation, followed by detection and analysis. The spike in outbound traffic is an indicator of compromise (IoC), but before any containment or eradication steps, the analyst must confirm that the alert is a true positive—not a false positive caused by a legitimate application update, backup replication, or monitoring tool. This validation typically involves correlating the traffic with known baselines, checking source/destination IPs against threat intelligence feeds, and reviewing logs to rule out benign causes.

Exam trap

The trap here is that candidates confuse the urgency of a potential breach with the structured incident response process, jumping to containment (isolate) or root cause analysis before verifying the alert is a true positive.

How to eliminate wrong answers

Option B is wrong because isolating the server from the network is a containment step that occurs after the incident is confirmed; premature isolation can disrupt legitimate services and destroy forensic evidence. Option C is wrong because identifying the root cause is part of the analysis and eradication phases, which follow confirmation and containment in the incident response process. Option D is wrong because notifying senior management is a communication step that typically happens after the incident is confirmed and its severity assessed, not as the very first action.

276
MCQeasy

A retail company's security operations center receives an alert that a point-of-sale terminal is communicating with a known malicious command-and-control domain. The analyst confirms the connection is active. According to incident response best practices, which action should the analyst take FIRST?

A.Isolate the affected terminal from the network while preserving evidence for investigation
B.Run a full antivirus scan on the terminal and wait for it to complete before taking further action
C.Document the alert details and escalate to management before taking any technical action
D.Immediately power off the terminal to terminate the malicious connection
AnswerA

The immediate priority on confirming active malicious communication is to stop the spread and cut the attacker's control channel. Isolating the terminal halts data exfiltration and lateral movement while keeping the device's state intact for forensic examination. Preserving evidence alongside containment ensures the organization can still determine scope and root cause. This balanced first step protects the business without destroying the information needed to understand the intrusion.

Why this answer

Once malicious command-and-control activity is confirmed, containment is the immediate priority because an active channel enables exfiltration and further intrusion. Isolating the terminal severs that channel without destroying the volatile and stored evidence investigators require. Powering off, scanning in place, or delaying action for documentation all leave the attacker connected or degrade evidence.

The correct sequence is to contain first, then analyze and eradicate, keeping forensic integrity intact throughout.

Exam trap

The trap here is choosing power-off or scanning as the fastest way to stop malware, when those actions either destroy evidence or leave the attacker's channel open.

277
Multi-Selecthard

A global retailer is establishing an information security governance framework. The CISO must ensure that the framework addresses both internal and external requirements. Which THREE of the following are essential components of an effective information security governance framework? (Choose three.)

Select 3 answers
A.A real-time security incident dashboard for the security operations center.
B.A defined risk appetite statement approved by senior management.
C.A detailed inventory of all hardware assets with firmware versions.
D.Clearly assigned roles and responsibilities for information security.
E.A process for monitoring compliance with legal and regulatory requirements.
AnswersB, D, E

A risk appetite statement, approved by senior management, is essential because it sets the boundaries for risk-taking and guides security decisions. It ensures that security activities align with business objectives and provides a basis for measuring whether risks are acceptable. Without it, governance lacks direction and accountability.

Why this answer

An effective governance framework must include strategic elements: a risk appetite statement approved by senior management, clearly assigned roles and responsibilities, and a compliance monitoring process. These components provide direction, accountability, and assurance. Operational tools like asset inventories and incident dashboards are important but do not constitute governance; they support execution under the framework.

Exam trap

The trap here is confusing operational security tools and activities with governance components, which are strategic and oversight-oriented.

278
Multi-Selecthard

A financial services firm has just contained a breach in which an attacker exfiltrated customer records from a database server. Legal counsel advises the incident manager that the matter will likely result in litigation and regulatory inquiry. Which TWO actions should the incident manager take to preserve the evidentiary value of the affected server? (Choose two.)

Select 2 answers
A.Allow the database administrator to resume normal backups on the server to maintain recovery capability.
B.Delete the attacker's malware binaries to prevent accidental execution during the investigation.
C.Capture a forensic image of the server's volatile memory and disk before any remediation or reboot occurs.
D.Rebuild the server from a known-good image immediately to restore service and eliminate attacker persistence.
E.Document the chain of custody for all collected evidence, recording who handled it, when, and for what purpose.
AnswersC, E

Order of volatility dictates that memory contents, running processes, network connections, and encryption keys are lost on shutdown or reboot. Capturing a forensic image of both RAM and disk preserves the most perishable evidence first, maintaining the chain of custody and enabling later analysis. Without this step, critical artifacts such as active sessions and injected code may be permanently destroyed before remediation begins.

Why this answer

Preserving evidence in a matter destined for litigation and regulatory scrutiny requires capturing volatile and non-volatile data before any remediation and maintaining rigorous chain-of-custody records. These two actions protect admissibility and demonstrate due diligence. Rebuilding the server, deleting malware, or resuming backups would overwrite or destroy artifacts, weakening both the legal case and the organization's regulatory defensibility.

Exam trap

The trap here is prioritizing rapid service restoration over evidence preservation, when in litigation-bound incidents the order of volatility and chain of custody must come first.

279
MCQeasy

A company's incident response plan defines roles for the incident response team, but during a recent tabletop exercise it became clear that no one had authority to make binding decisions about shutting down production systems. Which of the following should be established to resolve this gap?

A.A service level agreement with the managed security service provider guaranteeing faster response.
B.An increase in the security operations centre's monitoring coverage and alert thresholds.
C.A more detailed technical runbook describing how to shut down each production system.
D.A documented decision-making authority and escalation path approved by executive management.
AnswerD

The gap is governance, not technology. Someone must hold pre-delegated authority to make high-impact calls such as taking production offline, and that authority must be documented and endorsed by executives so it is recognized during a crisis. A clear escalation path also tells responders whom to wake at 3 a.m. and who owns the final call when business and security priorities conflict.

Why this answer

Incident response authority is a governance matter that must be defined before a crisis. Documenting who may authorize disruptive actions, and how disagreements escalate, gives responders clear decision rights approved at the executive level. Without it, even well-detected incidents stall while teams wait for permission, and the organization loses the time that containment depends on.

Exam trap

The trap here is responding to a missing-authority finding with more technical procedures or monitoring instead of a governance decision about who may act.

280
MCQmedium

Which of the following is the PRIMARY benefit of having a formal policy exception management process?

A.Eliminating all security risks
B.Reducing the number of security policies
C.Ensuring consistent treatment of exceptions with proper risk acceptance
D.Automating policy enforcement
AnswerC

A formal exception process routes every deviation through the same assessment, approval and documentation steps, so risk is knowingly accepted by the appropriate authority rather than absorbed silently. This consistency and traceable risk acceptance is the primary benefit the stem asks for.

Why this answer

A formal exception management process ensures that every deviation from policy is documented, risk-assessed, approved by the appropriate authority, and time-bound, producing consistent and auditable risk acceptance. This gives the organization visibility into its true risk posture and prevents ad hoc, undocumented exceptions that could be exploited or cited in an audit. The primary benefit is governance consistency, not risk elimination.

Exam trap

CISM often tests the confusion between 'managing exceptions' and 'eliminating risk' — candidates pick A because it sounds aspirational, but governance frameworks never promise risk elimination, only consistent, documented risk acceptance.

How to eliminate wrong answers

Option A is wrong because no process can eliminate all security risks — exceptions inherently accept residual risk, and the goal is to manage it, not erase it. Option B is wrong because exception management does not reduce the number of policies; it governs deviations from them. Option D is wrong because automating policy enforcement is a technical control function, not the primary benefit of an exception process — automation may even conflict with exceptions if not designed to honor them.

281
MCQeasy

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

A.Personnel Security (PS)
B.Identification and Authentication (IA)
C.System and Communications Protection (SC)
D.Access Control (AC)
AnswerB

NIST SP 800-53's Identification and Authentication (IA) family directly governs user identity verification and credential management, satisfying the stem's requirement for the control family addressing user identification and authentication. IA controls cover authenticator management, identity proofing and session authentication, making it the precise match rather than access control or audit families.

Why this answer

The Identification and Authentication (IA) family in NIST SP 800-53 covers user identification, authentication, and credential management.

282
Multi-Selectmedium

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

Select 2 answers
A.Number of firewall rules changed
B.Mean time to detect (MTTD) and mean time to respond (MTTR)
C.Number of employees who completed security training
D.Security investment vs. loss avoidance
E.Patch compliance percentage
AnswersB, D

MTTD and MTTR measure how quickly the security programme detects and contains incidents, translating technical operations into resilience outcomes. These satisfy the board-level reporting constraint by conveying programme effectiveness in business-relevant terms rather than raw alert volumes.

Why this answer

Option B (MTTD and MTTR) is correct because these metrics quantify how quickly the security operations function detects and contains incidents, directly expressing the programme's operational effectiveness in business-relevant terms the board can track over time. Option D (security investment vs. loss avoidance) is correct because it frames security spending against avoided financial impact, giving the board a cost-benefit view of risk reduction that supports governance and funding decisions. The unmarked options are too tactical or activity-based for board-level reporting: firewall rule changes (A) and patch compliance percentage (E) are operational/technical metrics, and training completion counts (C) measure activity rather than outcome or risk reduction.

Exam trap

CISM often tests the difference between operational metrics and strategic/board-level metrics — candidates pick patch compliance or training completion because they sound security-relevant, but boards need outcome and financial-impact measures.

283
MCQhard

Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?

A.Employees should have been trained to recognize phishing emails.
B.The email filter vendor did not provide adequate support.
C.The security team did not have a change management process for security control configurations.
D.The incident response plan was not followed during the incident.
AnswerC

The root cause is a governance gap: no change management process governed security control configuration changes, so the email filter misconfiguration went unreviewed. Documenting this management failure addresses the underlying control weakness rather than the phishing symptom.

Why this answer

The technical cause is the phishing email, the process failure is the lack of review of email filter configurations, and the management/governance failure is the absence of a change management process for security controls.

284
MCQeasy

Which of the following is the PRIMARY purpose of an incident response plan?

A.To assign blame for security failures
B.To prevent all security incidents from occurring
C.To provide a systematic method for responding to incidents
D.To meet regulatory compliance requirements
AnswerC

An incident response plan defines the structured, repeatable phases — preparation, detection, containment, eradication, recovery and lessons learned — that guide responders. This systematic method reduces confusion and ad hoc decisions during incidents, which is its primary purpose.

Why this answer

The primary purpose of an incident response plan is to establish a structured, systematic methodology for detecting, containing, eradicating, and recovering from security incidents. This ensures that the organization can minimize damage, reduce recovery time and costs, and preserve evidence for forensic analysis. Without a predefined plan, responses become ad hoc, increasing the likelihood of errors and extended downtime.

Exam trap

ISACA often tests the distinction between primary purpose and secondary benefits; candidates mistakenly choose regulatory compliance (Option D) because they confuse a common driver for implementing a plan with its fundamental operational objective.

How to eliminate wrong answers

Option A is wrong because assigning blame is counterproductive and not a goal of incident response; the focus is on learning and improving processes, not on fault-finding. Option B is wrong because incident response plans are designed to manage incidents that occur, not to prevent them; prevention is the domain of risk management and security controls. Option D is wrong because while regulatory compliance may be a benefit, it is not the primary purpose; the core objective is to effectively manage incidents to protect the organization's assets and operations.

285
MCQhard

An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?

A.Ensuring the forensics firm has signed a non-disclosure agreement
B.Negotiating a fixed price for the investigation
C.Requiring the forensics firm to report findings directly to the CEO
D.Issuing a legal hold and making forensic copies of affected systems before remediation
AnswerD

Issuing a legal hold preserves potentially relevant data and suspends routine deletion, while forensic copies capture the affected systems' state before remediation alters or destroys artefacts. This satisfies the admissibility constraint by maintaining an unbroken chain of custody and preserving original evidence for legal proceedings.

Why this answer

Preserving the chain of custody and ensuring forensic copies are made before remediation is critical for evidence admissibility. Legal hold ensures that relevant data is preserved.

286
Multi-Selecthard

A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)

Select 2 answers
A.Recording only qualitative ratings and omitting any quantitative data.
B.Reassessing all risks annually using a newly selected framework each cycle.
C.Adopting a common risk taxonomy and standardized likelihood and impact scales.
D.Allowing each business unit to define its own risk scoring methodology.
E.Documenting assessment criteria and assumptions in a repeatable methodology.
AnswersC, E

A shared taxonomy and calibrated scales ensure that a 'high likelihood' means the same thing in the finance unit as in the plant operations unit, making assessments comparable across the enterprise and allowing aggregation into an organizational risk profile. Without this consistency, ratings from different units cannot be meaningfully combined or trended.

Why this answer

Comparability across units and over time depends on consistent definitions and repeatable methods. A common taxonomy with calibrated scales lets assessments be aggregated, while a documented methodology lets different assessors and different years produce ratings that can be meaningfully compared. Local scoring variation, purely qualitative records, and rotating frameworks all undermine that consistency.

Exam trap

The trap here is assuming that flexibility and local ownership improve risk management, when uncoordinated scoring methods actually prevent the aggregation and trending that executive reporting requires.

287
MCQhard

A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?

A.Composite risk score based on threat, vulnerability, and control assessments.
B.Number of security incidents per quarter.
C.Mean time to detect (MTTD) incidents.
D.Percentage of employees who completed security training.
AnswerA

A composite risk score aggregates threat, vulnerability and control assessments into a single weighted measure, so it reflects residual risk reduction across the whole programme. Individual metrics such as patch compliance or incident counts capture only one dimension and cannot demonstrate overall effectiveness.

Why this answer

A composite risk score aggregates threat, vulnerability, and control assessment data into a single metric that directly reflects the organization's residual risk posture. This metric is the most holistic indicator of program effectiveness because it quantifies how well security controls reduce the likelihood and impact of threats exploiting vulnerabilities, aligning with the CISM focus on risk management.

Exam trap

The trap here is that candidates confuse operational metrics (incident count, MTTD, training completion) with risk-based metrics, assuming any positive trend in a security metric automatically indicates reduced overall risk, when only a composite risk score directly measures risk reduction.

How to eliminate wrong answers

Option B is wrong because the number of security incidents per quarter is a lagging indicator that does not measure risk reduction; a low incident count could result from luck or under-detection, not effective controls. Option C is wrong because Mean Time to Detect (MTTD) measures detection speed, not overall risk reduction; an organization could detect incidents quickly but still have high residual risk due to weak preventive controls. Option D is wrong because the percentage of employees who completed security training measures awareness activity, not risk reduction; training completion does not guarantee behavior change or control effectiveness against specific threats.

288
MCQmedium

A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?

A.Engage external legal counsel to interpret the law’s requirements.
B.Implement encryption for all data at rest and in transit across the enterprise.
C.Conduct a gap analysis between the law’s requirements and the current security controls.
D.Update the information security policy to reference the new law.
AnswerC

A gap analysis is the logical first step because it identifies where the current program falls short of the legal requirements. Without understanding the gaps, the CISO cannot prioritize investments, assign resources or develop a credible compliance roadmap. The analysis provides the factual basis for all subsequent decisions, ensuring that remediation efforts target actual deficiencies rather than assumptions.

Why this answer

The first step in achieving compliance is to understand the difference between what the law requires and what the organization currently does. A gap analysis produces that understanding by mapping requirements to existing controls, identifying deficiencies and highlighting areas where evidence is missing. This allows the CISO to prioritize remediation, allocate budget and build a realistic compliance plan before making technical or policy changes.

Exam trap

The trap here is jumping to a visible technical or legal action instead of first measuring the organization’s current state against the new legal requirements.

289
MCQeasy

Which document should be reviewed and updated at least annually?

A.Vendor contracts
B.Incident response plan
C.Network topology diagram
D.User manuals
AnswerB

The incident response plan documents contacts, roles, escalation paths and procedures that change as systems, personnel and threats evolve. Annual review satisfies the stem's requirement by keeping response actions current and validated, ensuring the plan remains executable during a live incident.

Why this answer

The incident response plan is a living document that must be reviewed and updated at least annually to reflect changes in the organization's environment, threat landscape, and lessons learned from incidents. Regular updates ensure that contact information, escalation procedures, and response strategies remain current and effective. This annual review is a core requirement of frameworks like NIST SP 800-61 and ISO 27001.

Exam trap

CISM often tests the misconception that any security document must be updated annually, but the incident response plan is specifically highlighted because it directly affects response effectiveness and is a common audit finding.

How to eliminate wrong answers

Option A is wrong because vendor contracts are typically reviewed at renewal or when terms change, not necessarily annually. Option C is wrong because network topology diagrams are updated as the network changes, not on a fixed annual schedule. Option D is wrong because user manuals are updated when software or procedures change, not annually.

290
Multi-Selectmedium

Which TWO of the following are key components of an information security governance framework? (Choose two.)

Select 2 answers
A.Security policy and standards.
B.Intrusion detection system (IDS) configuration.
C.Firewall rule set.
D.Payment Card Industry Data Security Standard (PCI DSS) compliance report.
E.Risk management process.
AnswersA, E

Security policy and standards translate management's risk appetite into enforceable directives, defining acceptable use, control baselines and accountability. They are the foundational governance artefacts that direct and constrain security activity, satisfying the framework's requirement for documented direction and measurable compliance criteria.

Why this answer

Security policy and standards are foundational components of an information security governance framework because they establish the high-level direction, principles, and mandatory requirements that guide the organization's security posture. The risk management process is equally critical as it provides a structured methodology for identifying, assessing, and treating risks, ensuring that security decisions are aligned with business objectives and risk appetite. Together, they form the strategic and operational backbone of governance, enabling accountability and continuous improvement.

Exam trap

The trap here is that candidates confuse operational security controls (like IDS configuration or firewall rules) or compliance outputs (like PCI DSS reports) with the strategic governance components, which are policy, standards, and risk management processes.

291
MCQhard

A multinational organisation suffers a breach affecting customers in several jurisdictions. The incident response manager must coordinate notification obligations while the investigation is still ongoing and facts are incomplete. Which of the following is the MOST appropriate approach?

A.Engage legal counsel to map jurisdictional notification requirements and issue notices as facts are confirmed, meeting each deadline
B.Delegate all notification decisions to the public relations team to ensure consistent messaging across markets
C.Notify every customer in all markets immediately, regardless of whether their data was affected
D.Wait until the investigation is fully complete so that a single, comprehensive notification can be issued to all affected parties
AnswerA

Notification duties vary by jurisdiction in scope, timing, and recipients, so legal expertise is essential to map them accurately. Issuing notices progressively as facts are confirmed satisfies statutory deadlines while avoiding premature or inaccurate disclosures. This approach balances regulatory compliance, customer transparency, and the practical reality that breach investigations evolve over time.

Why this answer

Cross-border breaches trigger overlapping notification regimes with different thresholds, recipients, and deadlines. Legal counsel must map those obligations, and notices should be issued progressively as facts are confirmed so each jurisdiction's deadline is met without publishing inaccurate information. This balances compliance with the reality of an incomplete investigation.

Exam trap

The trap here is believing that a breach should be fully investigated before any notification is made, when statutory clocks often start at the moment of awareness.

292
MCQmedium

A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?

A.Increase all alert thresholds to reduce volume
B.Tune SIEM rules to eliminate known false positives
C.Hire additional security analysts to handle the load
D.Disable all non-critical alert categories
AnswerB

Tuning SIEM rules to eliminate known false positives reduces alert volume so genuine detections, such as the missed lateral movement alert, are no longer buried. This directly addresses the root cause of analyst fatigue and satisfies the primary improvement requirement, restoring trust in the monitoring capability.

Why this answer

The root cause of the missed critical alert is alert fatigue caused by a high volume of false positives. Tuning SIEM correlation rules to eliminate known false positives directly reduces noise while preserving detection of genuine threats like lateral movement. This is the primary, sustainable action that improves signal-to-noise ratio without weakening detection coverage.

Exam trap

CISM often tests the misconception that more staff or higher thresholds solve alert fatigue — the correct answer is almost always to improve detection quality through tuning, not to blunt or bypass the detection mechanism.

How to eliminate wrong answers

Option A is wrong because raising all alert thresholds indiscriminately suppresses both false positives and true positives, increasing the risk of missing real attacks — the opposite of the goal. Option C is wrong because hiring more analysts addresses capacity but not the underlying noise problem; analysts will still be overwhelmed and may continue to ignore alerts. Option D is wrong because disabling all non-critical alert categories removes detection coverage entirely for those categories, which could include the lateral movement alert that was missed, creating blind spots.

293
MCQhard

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

A.Standardized and documented security processes
B.Ad-hoc security processes
C.Quantitative measurement of process effectiveness
D.Continuous process optimization
AnswerA

CMM Level 3 requires defined, organisation-wide standardised processes, not the ad hoc or per-project approaches of Levels 1 and 2. Documented security processes applied consistently across the enterprise satisfy this definition, evidencing the institutionalisation the stem's maturity goal demands.

Why this answer

CMM Level 3 is defined as 'Defined' — the organization has standardized, documented processes that are communicated and followed across the enterprise, rather than relying on individual heroics. At this level, process assets exist (policies, procedures, templates) and projects tailor them from a shared organizational set. This is the capability the organization must demonstrate to claim Level 3.

Exam trap

CISM often tests the CMM level definitions by swapping adjacent levels — the trap is confusing Level 3 (Defined, standardized processes) with Level 4 (Quantitatively Managed, metrics) or Level 5 (Optimizing, continuous improvement).

How to eliminate wrong answers

Option B is wrong because ad-hoc, chaotic processes describe CMM Level 1 (Initial), where success depends on individual effort and there is no repeatable process. Option C is wrong because quantitative measurement of process effectiveness is the hallmark of CMM Level 4 (Managed), where statistical and quantitative techniques are applied to process performance. Option D is wrong because continuous process optimization is CMM Level 5 (Optimizing), where the organization focuses on incremental and innovative improvement of processes based on quantitative feedback.

294
MCQhard

A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?

A.Implement data classification and strict role-based access controls
B.Conduct continuous monitoring and logging of all system activities
C.Encrypt all data at rest and in transit using strong algorithms
D.Negotiate service-level agreements (SLAs) with cloud provider for uptime
AnswerA

Data classification identifies which records fall under each jurisdiction's data protection laws, and role-based access controls enforce least privilege across those categories. This satisfies the low-residual-risk appetite by limiting exposure of regulated personal data held in the multinational CRM.

Why this answer

The risk appetite allows only low residual risk, meaning controls must directly reduce the likelihood or impact of a data breach to an acceptable level. Data classification and strict role-based access controls (RBAC) are the most critical because they enforce least-privilege access to personal data, directly mitigating the primary risk of unauthorized exposure across jurisdictions with varying data protection laws. Without proper classification and RBAC, even encryption or monitoring cannot prevent an authorized user from improperly accessing or exfiltrating data, leaving residual risk above the low threshold.

Exam trap

The trap here is that candidates often select encryption (Option C) as the most critical control because it is a strong technical safeguard, but they overlook that encryption does not address the risk of authorized users misusing data, which is the primary driver of residual risk in a multi-jurisdictional environment with strict compliance requirements.

How to eliminate wrong answers

Option B is wrong because continuous monitoring and logging are detective controls that identify breaches after they occur, but they do not reduce the likelihood or impact of unauthorized access to meet a low residual risk appetite; they only provide visibility. Option C is wrong because encryption protects data confidentiality if data is intercepted or stolen, but it does not prevent authorized users from misusing access or violating data protection laws, so residual risk from insider threats remains high. Option D is wrong because SLAs for uptime address availability and business continuity, not data protection or compliance with privacy laws, and thus have no direct effect on the residual risk of unauthorized data access or legal non-compliance.

295
Multi-Selectmedium

Which THREE of the following are key performance indicators (KPIs) for an information security program?

Select 3 answers
A.Number of security awareness training completions per quarter.
B.Total number of security staff.
C.Percentage of critical vulnerabilities remediated within SLA.
D.Average number of firewall rules per device.
E.Mean time to respond (MTTR) to incidents.
AnswersA, C, E

Indicates program reach.

Why this answer

The number of security awareness training completions per quarter directly measures the reach and effectiveness of the human-centric security program, which is a key driver for reducing phishing and social engineering risks. This KPI aligns with the NIST SP 800-50 framework for security awareness and training metrics, as it tracks behavioral adoption rather than just policy existence.

Exam trap

ISACA CISM often tests the distinction between resource metrics (like staff count) and true performance indicators (like remediation rates or response times), and the trap here is that candidates mistake operational metrics (firewall rules) for program-level KPIs.

296
MCQeasy

An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?

A.Developing a formalized insider threat program with clear roles and responsibilities.
B.Conducting annual security awareness training for all employees.
C.Implementing two-factor authentication for all critical systems.
D.Deploying endpoint detection and response (EDR) software on all systems.
AnswerA

A formalised insider threat programme establishes accountable ownership, defined roles and repeatable detection, response and monitoring processes. This directly addresses the governance gap exposed by the breach, giving the board assurance that insider risk is now managed rather than ad hoc.

Why this answer

A formalized insider threat program with clear roles and responsibilities is the first governance improvement because it establishes a structured framework for detecting, preventing, and responding to insider threats. Unlike tactical controls, this program defines ownership, escalation paths, and policy integration, directly addressing the board's request for governance improvements rather than just technical fixes.

Exam trap

The trap here is that candidates often confuse tactical security controls (like MFA or EDR) with governance improvements, failing to recognize that the board's request specifically targets the need for a structured program with defined accountability, not just additional technology layers.

How to eliminate wrong answers

Option B is wrong because annual security awareness training is a general awareness measure that does not specifically address the governance gap exposed by an insider threat breach; it lacks the role-based accountability and programmatic structure needed for governance. Option C is wrong because implementing two-factor authentication is a technical access control that mitigates credential theft but does not address the governance failure in managing insider risks, such as policy enforcement or role definitions. Option D is wrong because deploying endpoint detection and response (EDR) software is a detective technical control that focuses on post-compromise detection, not the proactive governance framework required to define roles, responsibilities, and oversight for insider threat management.

297
MCQeasy

An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?

A.Information security standard
B.Information security policy
C.Information security procedure
D.Information security guideline
AnswerB

The information security policy is a high-level document that defines the organization's overall security direction, objectives, and responsibilities. It is typically approved by senior management and serves as the foundation for all other security documents, making it the correct choice for the committee's expectation.

Why this answer

The information security policy is the foundational governance document that articulates the organization's security direction, objectives, and management commitment. It is approved by senior management and mandates the creation of supporting standards, procedures, and guidelines. This aligns with CISM's emphasis on policy as the top-level driver of the security program.

Exam trap

The trap here is confusing the policy with lower-level documents like standards or procedures, which are derived from the policy but do not define overall direction.

298
MCQmedium

An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?

A.Express security risks in business impact terms and integrate them into the enterprise risk register using common scales.
B.Convert all security risks into a single aggregate score and report only that score to ERM.
C.Report security risks separately to the CISO only, keeping ERM focused on financial and operational risks.
D.Report only risks that have already materialized as incidents so ERM deals with confirmed events.
AnswerA

Translating security risk into business impact, such as revenue loss, regulatory penalty, or service disruption, and recording it on the enterprise's common scales allows ERM to compare and aggregate it with other risk types. This integration supports enterprise prioritization and gives executives a coherent view of total risk exposure.

Why this answer

Integrating security risk into ERM requires translating technical exposure into business impact and using the enterprise's common scales so that cyber risk can be compared, aggregated, and prioritized alongside other risk types. This gives executives a unified view while preserving enough detail for ownership and treatment decisions.

Exam trap

The trap here is assuming that security risk is too technical for ERM and should stay in a separate report, when the real requirement is translation into business impact on shared scales.

299
MCQhard

An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?

A.Monitor network traffic for anomalies.
B.Remove each backdoor individually using forensics.
C.Rebuild all affected systems from trusted backups after ensuring the attack vector is closed.
D.Isolate compromised segments from the rest of the network.
AnswerC

Rebuilding from trusted backups eliminates all persistent backdoor artefacts, including hidden accounts and modified binaries, that malware removal alone cannot guarantee. Closing the attack vector first prevents immediate reinfection during restoration, satisfying the requirement to fully eradicate an APT's multiple footholds rather than partially remediate them.

Why this answer

Rebuilding all affected systems from trusted backups ensures that any backdoors, rootkits, or persistence mechanisms left by the APT are completely removed. This approach is the most effective because APTs often deploy multiple, redundant backdoors that may not all be discovered through individual removal. Closing the attack vector first prevents re-infection during the rebuild process.

Exam trap

The CISM exam often tests the distinction between containment (isolating segments) and eradication (removing the threat), and candidates mistakenly choose isolation as the final step instead of recognizing that eradication requires complete system rebuild from trusted media.

How to eliminate wrong answers

Option A is wrong because monitoring network traffic for anomalies is a detection and containment activity, not an eradication strategy; it does not remove the backdoors already present. Option B is wrong because removing each backdoor individually using forensics is unreliable against a sophisticated APT, which may have hidden or redundant backdoors that are not all discoverable, leading to incomplete eradication. Option D is wrong because isolating compromised segments is a containment measure that limits lateral movement but does not eliminate the backdoors from the affected systems, leaving the organization vulnerable to future exploitation.

300
MCQmedium

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

A.Number of phishing simulation campaigns per year
B.Click rate trend over multiple simulation cycles
C.Pass rate on phishing simulation knowledge test
D.Number of employees who report phishing emails
AnswerB

Click rate trend across successive simulation cycles reveals whether user behaviour genuinely improves over time, rather than reflecting a single campaign's snapshot. A sustained downward trend evidences durable learning, whereas one-off completion or report counts can be inflated by transient awareness or repeat reporting.

Why this answer

The click rate trend over multiple simulation cycles best measures long-term effectiveness because it shows whether employee behavior is improving over time. A declining trend indicates that the awareness program is successfully reducing susceptibility to phishing. Other metrics like number of campaigns or test pass rates do not directly reflect real-world behavior change.

Exam trap

CISM often tests the confusion between activity metrics (e.g., number of campaigns) and outcome metrics (e.g., click rate trend), where the former measures effort and the latter measures effectiveness.

How to eliminate wrong answers

Option A is wrong because the number of campaigns per year measures activity, not effectiveness. Option C is wrong because a knowledge test pass rate measures theoretical understanding, not actual behavior in real phishing scenarios. Option D is wrong because the number of employees who report phishing emails is a positive indicator but does not directly measure the reduction in successful phishing attempts; it could be high even if click rates remain high.

Page 3

Page 4 of 13

Page 5