Courseiva

Certified Information Security Manager CISM (CISM) — Questions 376–450

924 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
MCQhard

Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?

A.Conducting a new risk assessment
B.Creating a detailed report for senior management
C.Updating the incident response plan and playbooks based on findings
D.Assigning blame to responsible parties
AnswerC

Updating plans and playbooks converts lessons-learned findings into revised procedures, directly satisfying the stem's requirement for effective future incident response. Unlike awareness or reporting changes, this closes the loop by embedding corrective actions into documented, repeatable steps responders follow under pressure, ensuring the same failures are not repeated.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements and update the IR plan, not just document or blame.

377
MCQmedium

A financial services firm's incident response team has contained a credential-stuffing attack that compromised several customer accounts. The CISO asks the incident manager to determine what should happen next before the team stands down. Which action BEST aligns with CISM incident management practices?

A.Conduct a post-incident review to capture lessons learned and update controls and the response plan.
B.Reimage all customer account systems and rotate every credential in the environment without further analysis.
C.Escalate the incident to law enforcement and suspend all customer-facing services pending investigation.
D.Immediately close the incident ticket and release the response team so normal operations can resume.
AnswerA

After containment, eradication, and recovery, CISM emphasizes performing a post-incident review to identify root causes, evaluate the effectiveness of the response, and feed improvements back into the incident response plan and security controls. This is the correct next step because it transforms the incident into actionable organizational learning rather than simply returning to a normal state without any improvement.

Why this answer

The post-incident review is a core CISM activity that converts a contained incident into organizational improvement. It examines root cause, response effectiveness, and gaps, then updates the incident response plan and controls. Simply closing the ticket, over-escalating, or blindly reimaging systems skips the analysis needed to prevent recurrence and strengthen the security program.

Exam trap

The trap here is assuming the incident ends at containment, when CISM expects a formal post-incident review to drive improvements.

378
MCQmedium

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

A.Breach count and associated financial impact
B.Mean time to detect (MTTD) for incidents
C.Number of firewall rule changes per month
D.Percentage of employees who completed training
AnswerA

Breach count and financial impact express security posture in business terms the board governs, satisfying the dashboard's need for concise, decision-relevant data. Operational metrics such as patch latency lack the strategic framing a one-page executive view requires.

Why this answer

For a one-page executive dashboard, the board needs metrics that communicate business risk and financial impact in a language they understand. Breach count and associated financial impact (A) directly translates security performance into business terms — number of breaches and their monetary cost — which is what boards care about for fiduciary oversight. This metric ties security directly to organizational risk and financial exposure, making it the most relevant for executive-level reporting.

Exam trap

CISM often tests audience-appropriate metrics — candidates pick operational/technical metrics (MTTD, firewall changes) for executive dashboards when boards require business-risk and financial-impact metrics.

How to eliminate wrong answers

Option B is wrong because MTTD is an operational metric that, while important, is too technical and granular for a board-level one-page dashboard — it belongs in security operations reporting. Option C is wrong because firewall rule changes per month is a low-level operational activity metric with no direct business risk or financial context, irrelevant to the board. Option D is wrong because training completion percentage is a compliance/awareness metric that, while useful, does not convey business risk or financial impact at the executive level.

379
MCQmedium

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

A.Report to the Chief Financial Officer (CFO)
B.Report to the Chief Information Officer (CIO)
C.Report to the board of directors or audit committee
D.Report to the Chief Operating Officer (COO)
AnswerC

Reporting to the board or audit committee gives security direct access to governing authority, free from operational conflicts inherent in reporting through IT or finance. This structural independence enables escalation, budget influence and objective oversight of management's risk decisions.

Why this answer

For information security to be independent and influential, the CISO should report to the board of directors or audit committee (C). This reporting line ensures the security function is not subordinate to IT operations (which it must oversee) and gives it direct access to the highest governance body, enabling objective oversight and adequate resourcing. Independence is critical because the CISO must be able to raise risk concerns without conflicts of interest from IT management.

Exam trap

CISM often tests reporting-line independence — candidates choose CIO reporting as 'IT-savvy' when the correct answer is board/audit committee reporting to ensure objectivity and governance influence.

How to eliminate wrong answers

Option A is wrong because reporting to the CFO places security under financial management, which may prioritize cost control over risk mitigation and lacks the governance authority of the board. Option B is wrong because reporting to the CIO creates a conflict of interest — the CISO would be overseeing the same IT organization it must independently assess, compromising objectivity. Option D is wrong because reporting to the COO embeds security in operations, reducing independence and potentially subordinating security to operational efficiency goals.

380
MCQmedium

During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?

A.The communication logs between team members
B.The chain of custody for the backup media
C.The forensic tools used in the investigation
D.The incident response plan version used during the incident
AnswerB

Chain of custody documentation records who handled the backup media, when, and how, proving evidence integrity. Without it, encrypted media may be ruled inadmissible, undermining litigation. It directly satisfies the stem's requirement to preserve documentation critical for potential legal proceedings.

Why this answer

Chain of custody documentation is essential to prove the integrity and admissibility of digital evidence in court.

381
MCQeasy

An organization's information security strategy is being developed. The CISO wants to ensure that the strategy supports business objectives while managing risk. Which of the following should be the PRIMARY input to the strategy development process?

A.Industry best practice frameworks such as ISO/IEC 27001.
B.The IT department's technology roadmap.
C.The latest vulnerability scan reports.
D.The organization's business strategy and objectives.
AnswerD

The business strategy and objectives are the primary input because they define what the organization aims to achieve, and security must enable those goals. By starting with business strategy, the CISO ensures that security initiatives are relevant, prioritized, and funded appropriately. Without this input, the security strategy risks being disconnected from business needs and perceived as a cost center rather than an enabler.

Why this answer

The primary input to security strategy development must be the organization's business strategy and objectives. This ensures that security efforts are directly tied to what the business is trying to achieve, enabling risk management that supports rather than hinders business goals. Other inputs, such as frameworks or technical reports, are secondary and should be used to inform implementation once the business direction is clear.

Exam trap

The trap here is selecting a technical or compliance input, such as vulnerability reports or frameworks, as the primary driver, when the business strategy should always come first to ensure alignment.

382
Multi-Selecteasy

Which TWO of the following are primary responsibilities of the board of directors in information security governance?

Select 2 answers
A.Approving the organization's information security risk appetite.
B.Implementing security controls to mitigate identified risks.
C.Designing the technical security architecture for the organization.
D.Holding executive management accountable for the effectiveness of the security program.
E.Conducting internal security audits of the information systems.
AnswersA, D

Setting risk appetite is a board-level governance duty: it defines how much information security risk the organisation is willing to accept, which then bounds management's strategy and controls. This satisfies the stem's requirement for a primary board responsibility rather than an operational task delegated to management.

Why this answer

Option A is correct because setting and approving the organization's information security risk appetite is a core governance responsibility of the board, which defines how much risk the enterprise is willing to accept in pursuit of its objectives. Option D is correct because the board provides oversight by holding executive management accountable for the effectiveness of the security program, ensuring security aligns with business strategy and risk tolerance. Options B, C, and E are incorrect because implementing security controls, designing technical security architecture, and conducting internal security audits are operational and technical activities delegated to management, security architects, and internal audit or assurance functions, not the board itself.

Exam trap

A common pitfall in CISM questions is confusing the board's strategic governance duties (approving risk appetite, holding management accountable) with management's operational tasks (implementing controls, designing architecture).

383
MCQhard

A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?

A.Reduction of the mean time to detect (MTTD) security incidents
B.Cost savings from consolidating security tools
C.Achieving a target capability maturity model (CMM) level
D.Alignment with current and upcoming regulatory requirements
AnswerD

Regulatory requirements define mandatory obligations with fixed deadlines, so prioritising against them prevents penalties and licence risk. This satisfies the stem's primary-driver requirement because, in a highly regulated industry with frequent changes, compliance gaps carry existential consequences that override discretionary initiatives, anchoring the roadmap to non-negotiable external mandates.

Why this answer

In a highly regulated industry with frequent regulatory changes, the primary driver for prioritizing security initiatives must be alignment with current and upcoming regulatory requirements, because non-compliance creates legal, financial, and reputational risk that can halt business operations. The CISO's roadmap must map security investments to regulatory obligations first, then layer in maturity and efficiency improvements. This ensures the security program directly supports the business's ability to operate legally and competitively.

Exam trap

CISM often tests the difference between strategic drivers (business/regulatory alignment) and operational metrics (MTTD, cost, CMM levels) — candidates frequently pick the most 'security-sounding' technical answer instead of the business-aligned governance answer.

How to eliminate wrong answers

Option A is wrong because reducing MTTD is a tactical operational metric, not a strategic prioritization driver — it improves detection but does not address the mandatory compliance obligations that define the business's risk exposure in a regulated industry. Option B is wrong because cost savings from tool consolidation is a financial efficiency goal, not a risk-driven priority; in a regulated environment, cutting tools that support compliance could increase risk and penalties. Option C is wrong because achieving a target CMM level is a maturity aspiration, not a business driver — CMM levels are internal benchmarks and do not by themselves satisfy regulators or align with the business strategy the way regulatory mapping does.

384
MCQmedium

A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?

A.Report the non-compliance to the board of directors and request their intervention.
B.Revise the policy to extend the training deadline to 60 days to improve compliance.
C.Implement a technical control that blocks network access for employees who have not completed training.
D.Conduct a root cause analysis to determine why employees are not completing the training.
AnswerD

Before implementing solutions, the CISO must understand the reasons for non-compliance. Root cause analysis can reveal issues such as lack of awareness, inconvenient training times, or ineffective content. This ensures that the chosen remedy addresses the actual problem and is more likely to succeed.

Why this answer

Conducting a root cause analysis is the essential first step. It identifies why employees are not completing the training, allowing the CISO to implement targeted and effective solutions. This approach is consistent with continuous improvement and ensures that resources are used efficiently.

Exam trap

The trap here is jumping to a technical enforcement or policy change without diagnosing the underlying reasons for non-compliance.

385
MCQhard

After a merger, the combined organization has two different risk tolerance levels: one entity is risk-averse, the other is risk-taking. What is the best governance action?

A.Adopt the less restrictive risk tolerance
B.Maintain separate risk tolerance levels for each legacy entity
C.Adopt the more conservative risk tolerance across the board
D.Reassess risk appetite and approve a single unified statement
AnswerD

Two conflicting tolerance levels cannot coexist under one governance framework, so the board must reassess and approve a single unified risk appetite statement. This resolves the divergence and gives both merged entities one authoritative benchmark for consistent risk decisions.

Why this answer

After a merger, maintaining two separate risk tolerance levels creates governance fragmentation and prevents a unified security posture. The correct action is to reassess the combined organization's risk appetite and approve a single unified statement, as this aligns with the CISM principle that risk governance must be cohesive across the entire enterprise. This ensures consistent risk management decisions, resource allocation, and policy enforcement, avoiding conflicts that could lead to security gaps or regulatory non-compliance.

Exam trap

The trap here is that candidates assume the more conservative risk tolerance is always safer, but CISM emphasizes that risk governance must be based on a deliberate reassessment of the new entity's combined risk appetite, not a simple default to the lowest common denominator.

How to eliminate wrong answers

Option A is wrong because adopting the less restrictive risk tolerance exposes the combined organization to unacceptable residual risk, potentially violating compliance requirements and increasing the likelihood of security incidents. Option B is wrong because maintaining separate risk tolerance levels for each legacy entity perpetuates siloed governance, leading to inconsistent security controls and conflicting risk decisions that undermine the merger's objective of unified operations. Option C is wrong because adopting the more conservative risk tolerance across the board may be overly restrictive, stifling business agility and innovation without considering the new entity's strategic objectives, and it fails to address the need for a deliberate reassessment of risk appetite.

386
MCQeasy

A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?

A.Avoid the risk by discontinuing online services
B.Transfer the risk through cyber insurance
C.Accept the risk
D.Mitigate the risk by implementing stronger access controls
AnswerD

Stronger access controls restrict who can reach personal data, directly lowering the probability of another unauthorised disclosure. Mitigation addresses the likelihood dimension the question specifies, unlike acceptance, avoidance or transfer, which do not reduce recurrence.

Why this answer

Mitigating the risk by implementing stronger access controls directly reduces the likelihood of a similar breach by addressing the root cause—weak or insufficient access management. This is the most appropriate response because the risk manager wants to reduce the probability of recurrence, which is the definition of risk mitigation. It is a targeted, proportionate control rather than an extreme business change or a financial transfer.

Exam trap

The trap is conflating risk transfer (insurance) with risk reduction; candidates often pick insurance because it sounds responsible, but insurance only addresses financial impact, not the likelihood of recurrence.

How to eliminate wrong answers

Option A is wrong because avoiding the risk by discontinuing online services is a drastic business decision that eliminates the activity entirely, which is not proportionate or practical for most organizations and goes beyond reducing likelihood. Option B is wrong because transferring the risk through cyber insurance does not reduce the likelihood of a similar incident; it only shifts the financial impact. Option C is wrong because accepting the risk means taking no action, which fails to address the requirement to reduce the likelihood of future incidents.

387
MCQmedium

During a security audit, several deviations from policy are found. What should the security manager do first?

A.Accept the risk and move on
B.Investigate the root cause of the deviations
C.Update the policies immediately
D.Take disciplinary action against responsible employees
AnswerB

Investigating root cause determines why deviations occurred, distinguishing systemic control failures from isolated human error. This satisfies the audit scenario by directing remediation at the underlying cause, preventing recurrence rather than merely correcting individual findings.

Why this answer

The security manager must first investigate the root cause of the deviations to understand why the policy was not followed. This aligns with the corrective action phase of the incident response lifecycle, where identifying the underlying issue (e.g., misconfigured access controls, lack of awareness, or technical gaps) is essential before implementing any remediation. Without root cause analysis, subsequent actions like policy updates or disciplinary measures may address symptoms rather than the actual problem, leading to recurring non-compliance.

Exam trap

The trap here is that candidates often jump to 'update the policy' (Option C) because they assume the policy is outdated, but CISM emphasizes that policy deviations are typically symptoms of deeper issues, and immediate updates without root cause analysis can create compliance gaps or bypass the formal policy lifecycle.

How to eliminate wrong answers

Option A is wrong because accepting risk without understanding the root cause violates the principle of risk management; deviations may indicate a systemic vulnerability that requires mitigation, not acceptance. Option C is wrong because updating policies immediately without investigating why the existing policy was bypassed could introduce new inconsistencies or fail to address the actual control failure (e.g., a misconfigured SIEM rule rather than a policy gap). Option D is wrong because taking disciplinary action before root cause analysis is premature and could demoralize staff if the deviation resulted from inadequate training, unclear policy language, or a technical flaw (e.g., a firewall rule that conflicts with the policy).

388
Multi-Selecthard

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Select 2 answers
A.Technology costs for security tools and infrastructure.
B.Legal fees for contract reviews.
C.Marketing budget for security awareness campaigns.
D.Office renovation for security operations center.
E.Personnel costs for security staff salaries and benefits.
AnswersA, E

Security tools and infrastructure are capital and operating outlays that directly enable detective, preventive and corrective capabilities. Without them, no control can be operated, making technology spend a core, recurring line item alongside staffing and services in any mid-sized security budget.

Why this answer

Option A is correct because a security budget must include technology costs for security tools and infrastructure such as firewalls, IDS/IPS, SIEM, endpoint protection, and related hardware/software licensing and maintenance. Option E is correct because personnel costs for security staff salaries and benefits are a core, recurring component of any security budget, covering roles like security analysts, engineers, and managers. Legal fees for contract reviews (B) are typically part of general legal or procurement budgets, not the security budget, unless tied to a specific security incident or compliance matter.

A marketing budget for security awareness campaigns (C) is usually categorized under marketing or HR/training, though awareness is security-related, it is not a standard security budget line. Office renovation for a security operations center (D) is a capital facilities expense, not a typical recurring security budget component.

389
MCQmedium

A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerD

Deploying a virtual patch and increasing monitoring reduces the likelihood that the vulnerability will be successfully exploited while the organization works toward a permanent fix. The risk source still exists, but compensating controls lower the exposure to an acceptable level. This is the defining characteristic of mitigation: reducing likelihood or impact through controls rather than eliminating, transferring, or simply accepting the exposure.

Why this answer

The organization is reducing the likelihood of exploitation through compensating technical controls while a permanent remedy is unavailable, which is the essence of risk mitigation. Avoidance would require removing the vulnerable function, transfer would require an insurer or contractual party to absorb the loss, and acceptance would mean taking no action. Virtual patching and monitoring modify the risk itself.

Exam trap

The trap here is labelling compensating controls as risk acceptance because the vulnerability cannot be patched, when any control that actively lowers likelihood or impact constitutes mitigation.

390
Multi-Selecthard

A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)

Select 2 answers
A.Permit each acquired business unit to retain its existing policies until the next scheduled audit cycle.
B.Delegate policy ownership entirely to each regional CISO and require only annual attestation of compliance.
C.Map the global policy framework to applicable external standards and regulations, and maintain a traceability matrix showing coverage per jurisdiction.
D.Publish a single global security policy set with mandatory controls and allow documented local exceptions approved through a formal risk acceptance process.
E.Adopt the strictest regulation from any jurisdiction as the single global standard for all business units.
AnswersC, D

A traceability matrix demonstrates how each policy requirement satisfies applicable laws and standards in every jurisdiction, providing evidence for auditors and regulators. It also reveals overlaps and conflicts early, so the framework can be adjusted before local assessments. This makes consistency and compliance verifiable rather than assumed, which is essential across diverse regulatory environments.

Why this answer

Consistency and compliance are achieved by pairing a mandatory global policy baseline with a governed exception path, and by mapping that baseline to applicable laws and standards through a traceability matrix. The exception process keeps local regulatory constraints visible and formally accepted, while the matrix provides audit evidence of coverage. Together they let the CISO standardise controls without ignoring jurisdictional differences.

Exam trap

The trap here is believing that either full centralisation or full delegation solves multi-jurisdiction compliance, when the workable model is a common baseline with documented, traceable local exceptions.

391
MCQeasy

Which of the following is the primary purpose of an Information Security Program?

A.To implement the latest security technologies
B.To align security with business objectives and manage risk
C.To comply with all applicable regulations
D.To eliminate all security risks
AnswerB

An Information Security Programme exists to align security investment with business objectives and manage risk to acceptable levels. Frameworks, controls and policies are mechanisms serving that end. This option names the governance and risk-management purpose that defines the programme's primary function, rather than a narrower technical or compliance outcome.

Why this answer

The primary purpose of an Information Security Program is to align security initiatives with business objectives and manage risk to an acceptable level. While technology implementation, compliance, and risk elimination are components, they are means to the end of supporting the organization's mission and risk appetite. A program that does not align with business goals will lack executive support and fail to prioritize resources effectively.

Exam trap

ISACA often tests the misconception that an Information Security Program is primarily about technology or compliance, when in fact it is a governance mechanism to align security with business strategy and manage risk.

Why the other options are wrong

A

Technology is a tool, not the program's purpose.

C

Compliance is a component, not the primary purpose.

D

Eliminating all risks is impossible and impractical.

392
MCQeasy

An organization has recently experienced a data breach that resulted in the loss of customer personally identifiable information (PII). The board of directors is concerned about the effectiveness of the information security governance program. Which of the following should the CISO recommend as the MOST important action to improve governance?

A.Conduct a post-incident review to identify root causes and update security policies and controls accordingly.
B.Implement a new security awareness training program for all employees.
C.Terminate the employees responsible for the breach to demonstrate accountability.
D.Increase the security budget to purchase additional security technologies.
AnswerA

A post-incident review is critical for learning from the breach and improving governance. It identifies root causes, evaluates the effectiveness of existing controls and policies, and recommends improvements. This action directly addresses the board's concern by demonstrating a commitment to continuous improvement and strengthening the governance framework based on real-world events. It also helps prevent future incidents.

Why this answer

Conducting a post-incident review is the most important action because it systematically identifies what went wrong and how to improve policies, controls, and governance. It provides the board with assurance that the organization is learning from the incident and taking concrete steps to prevent recurrence, which is a key aspect of effective governance.

Exam trap

The trap here is assuming that a breach always requires more technology, training, or personnel action, when the first step should be to understand the root cause through a structured review.

393
Multi-Selectmedium

A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)

Select 2 answers
A.Reviewing and approving the enterprise risk register and accepting residual risks.
B.Approving the information security policy and risk appetite statement.
C.Performing vulnerability scans on internal network segments.
D.Monitoring security dashboards and triaging alerts on a daily basis.
E.Configuring and tuning intrusion detection system (IDS) signatures.
AnswersA, B

Reviewing and approving the risk register and formally accepting residual risk are governance responsibilities. They require authority to decide what level of risk the organization will tolerate and to hold risk owners accountable. This oversight ensures that risk decisions are made consistently and at the appropriate level, rather than being delegated to operational teams who implement controls.

Why this answer

Governance involves setting direction, defining risk tolerance, and providing oversight, which includes approving policy and risk appetite and reviewing and accepting residual risks. Operational tasks such as configuring IDS signatures, monitoring dashboards, and running vulnerability scans execute the strategy and controls defined by governance, and are therefore not governance responsibilities.

Exam trap

The trap here is equating any security-related activity with governance; governance is about direction, approval, and oversight, not the hands-on execution of controls.

394
MCQmedium

A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?

A.Recommend immediate decommissioning of the legacy application.
B.Transfer the risk by purchasing additional cyber insurance coverage.
C.Compare the assessed risk exposure to the board's risk tolerance and present treatment options with residual risk estimates.
D.Accept the risk and document it in the risk register pending next year's assessment.
AnswerC

The board has defined a clear risk tolerance threshold, so the CISO's first duty is to determine whether the assessed risk exceeds that threshold and, if so, present treatment options that bring residual risk within tolerance. This aligns security decisions with business objectives and gives the board the comparative information it needs to approve a treatment strategy.

Why this answer

Because the board has articulated a specific risk tolerance threshold, the CISO must first evaluate the assessed risk against that threshold and then present treatment options with their residual risk implications. This ensures the recommendation is grounded in the organization's stated appetite and supports a defensible, business-aligned decision rather than an arbitrary technical fix.

Exam trap

The trap here is assuming that any high-risk finding automatically justifies a technical remedy such as decommissioning or insurance, when the governing step is comparing the exposure to the board's stated tolerance.

395
MCQhard

A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?

A.Highlighting that competitors are using the same tool
B.Comparing the tool's cost to industry averages for similar tools
C.Demonstrating how the tool reduces the likelihood and impact of a potential breach, translating to expected loss avoidance
D.Emphasizing the tool's advanced features and technical capabilities
AnswerC

Quantifying reduced breach likelihood and impact as expected loss avoidance converts security benefit into financial terms executives already use for investment decisions. This risk-based quantification directly justifies the tool against its cost, unlike compliance or technical arguments that do not demonstrate measurable business value.

Why this answer

A CISO justifies security investment in business language: risk reduction expressed as expected loss avoidance. Option C frames the tool in terms of reduced likelihood and impact of a breach, which translates directly into financial terms (ALE = SLE × ARO) that executives and the board can evaluate against cost. This aligns security spend with business risk appetite and demonstrates ROI rather than technical merit.

Exam trap

CISM often tests the difference between technical justification (features, peer adoption, price benchmarking) and business justification (quantified risk reduction and expected loss avoidance), so candidates who pick the 'advanced features' option confuse engineering merit with business value.

How to eliminate wrong answers

Option A is wrong because 'competitors use it' is a bandwagon argument (argumentum ad populum) that does not quantify risk reduction for this organization and may not match its threat profile or risk appetite. Option B is wrong because comparing cost to industry averages addresses price benchmarking, not value — a tool can be cheap relative to peers yet still not justify itself if it does not reduce this organization's specific risks. Option D is wrong because emphasizing advanced features is a technology-centric pitch; features are inputs, not outcomes, and executives fund outcomes (loss avoidance, compliance, resilience), not feature lists.

396
MCQmedium

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

A.Include security requirements in the contract
B.Perform a risk assessment of the vendor
C.Request the vendor's SOC 2 report
D.Conduct an onsite audit of the vendor
AnswerB

Assessing the vendor's risk before engagement establishes whether its controls, data handling and PII exposure are acceptable, and determines the due diligence depth required. Contracting or onboarding first would commit the organisation before understanding residual risk, violating vendor lifecycle best practice.

Why this answer

The first step in the vendor lifecycle is to perform a risk assessment of the vendor (B). Before any contractual, audit, or documentation requests, the organization must understand the risk the vendor poses based on the data it will access (employee PII) and the criticality of the service. This risk assessment determines the appropriate level of due diligence, contractual controls, and ongoing monitoring — it drives all subsequent steps.

Exam trap

CISM often tests the sequence of vendor lifecycle steps — candidates jump to due diligence artifacts (SOC 2, contracts) when the risk assessment must come first to determine what diligence is appropriate.

How to eliminate wrong answers

Option A is wrong because including security requirements in the contract comes after the risk assessment determines what requirements are needed — you cannot draft appropriate controls without first knowing the risk. Option C is wrong because requesting a SOC 2 report is a due diligence activity that follows the risk assessment, which determines whether a SOC 2 is sufficient or additional evidence is needed. Option D is wrong because an onsite audit is a deep-dive due diligence step reserved for high-risk vendors, and it should only be conducted after the risk assessment identifies the need.

397
Multi-Selectmedium

An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)

Select 2 answers
A.Limiting access to the risk register to only the information security team
B.Assigning a risk owner for each entry who is accountable for treatment and monitoring
C.Reviewing and updating risk entries on a defined schedule and upon significant changes
D.Populating the register exclusively with technical vulnerabilities identified by scanners
E.Removing all risks that have been accepted by senior management to reduce clutter
AnswersB, C

Assigning a risk owner establishes clear accountability for managing each risk. The owner ensures that treatment plans are executed, residual risk is monitored, and status is reported. Without ownership, risks may languish without action or oversight. This is a fundamental requirement for an effective risk register and supports governance and auditability.

Why this answer

An effective risk register requires ongoing maintenance through scheduled and event-driven reviews, and clear assignment of risk owners who are accountable for treatment and monitoring. These two practices ensure the register stays current, actionable, and aligned with governance requirements. Removing accepted risks, restricting access, or limiting entries to technical vulnerabilities would reduce its value and completeness.

Exam trap

The trap here is treating the risk register as a static list of technical findings rather than a living, owned, and broadly scoped governance tool.

398
MCQeasy

A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?

A.Document the residual risk in the risk register and continue monitoring it on the normal reporting cycle.
B.Escalate the residual risk to senior management as a risk above the approved appetite.
C.Revise the risk appetite statement so the current residual risk falls within acceptable limits.
D.Immediately implement additional controls and then report the change in risk level.
AnswerB

When residual risk exceeds the documented risk appetite, the gap is a governance issue that must be escalated to the risk owners and senior management who set the appetite. They are accountable for deciding whether to fund additional controls, accept the deviation, or change business plans. Informing them first ensures the decision is made at the appropriate authority level.

Why this answer

Risk appetite defines the amount of risk leadership is willing to accept in pursuit of objectives. When residual risk exceeds that boundary, the information security manager's first obligation is to escalate the exception to senior management, who own the decision to remediate, accept, or adjust strategy. Acting unilaterally or rewriting the appetite statement would bypass proper governance.

Exam trap

The trap here is choosing immediate remediation or quietly adjusting the appetite statement, when the governance-correct first step is escalating the appetite breach to the accountable executives.

399
Multi-Selecteasy

Which TWO of the following are essential components of an information security program charter?

Select 2 answers
A.List of specific security tools to be deployed.
B.Roles and responsibilities of key stakeholders.
C.Vendor selection criteria.
D.Program scope and objectives.
E.Detailed budget allocation.
AnswersB, D

Assigning roles and responsibilities names who owns, operates and oversees the security programme, satisfying the charter's need for clear accountability. It establishes decision rights and reporting lines across stakeholders, ensuring governance duties are not left ambiguous as the programme is authorised and resourced.

Why this answer

The information security program charter is a high-level document that establishes the authority, scope, and governance of the security program. Roles and responsibilities of key stakeholders (Option B) are essential because they define accountability and decision-making authority, ensuring the program has clear ownership and oversight. Program scope and objectives (Option D) are equally essential as they set the boundaries and goals of the security program, aligning it with business strategy and risk appetite.

Exam trap

ISACA often tests the distinction between strategic governance documents (charter) and operational or tactical artifacts (tool lists, budgets, vendor criteria), leading candidates to select detailed implementation items that are not part of the charter's high-level scope.

400
MCQhard

A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?

A.Requiring each business unit to achieve ISO/IEC 27001 certification within one year.
B.Establishing a central security operations center (SOC) that monitors all business units.
C.Implementing a single security toolset across all business units to ensure uniformity.
D.Defining clear roles, responsibilities, and decision rights between central and business unit security teams.
AnswerD

In a federated governance model, clear roles, responsibilities, and decision rights are essential to avoid confusion, duplication, and conflict. This ensures that central and business unit teams understand who decides what, how policies are set, and how exceptions are handled. Without this clarity, federated models often fail due to ambiguity and turf battles. It is the most critical factor because it provides the framework for consistent yet flexible security management.

Why this answer

A federated governance model balances central oversight with business unit autonomy. The most critical factor is defining clear roles, responsibilities, and decision rights, which prevents confusion and ensures consistent application of security policies while allowing local flexibility. Other options focus on technology, compliance, or centralization, which do not address the core governance challenge.

Without clear decision rights, federated models often stall.

Exam trap

The trap here is equating federated governance with centralization or compliance mandates, rather than focusing on decision rights and accountability.

401
MCQhard

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

A.The organization is in a highly regulated industry with strict compliance mandates
B.The organization's IT budget is very large
C.The organization has a low number of security incidents historically
D.The organization has a high risk tolerance
AnswerA

Regulatory mandates such as PCI DSS, HIPAA or GDPR compel demonstrable controls, audits and evidence, forcing sustained security spend regardless of appetite. This external obligation, rather than general maturity alone, most plausibly justifies allocating 12% of the IT budget.

Why this answer

A 12% security budget allocation is most likely supported by a highly regulated industry with strict compliance mandates (A). Regulatory requirements (e.g., HIPAA, PCI DSS, GDPR, SOX) mandate specific security controls, audits, and reporting, forcing organizations to invest significantly in security to avoid penalties and maintain compliance. This external pressure justifies and sustains higher security spending compared to discretionary investment.

Exam trap

CISM often tests drivers of security investment — candidates may choose 'large IT budget' or 'low incidents' when the correct driver is regulatory/compliance pressure that mandates spending.

How to eliminate wrong answers

Option B is wrong because a large IT budget does not inherently justify a high security percentage — budget size alone does not drive security investment; risk and compliance requirements do. Option C is wrong because a low number of historical incidents would typically reduce perceived risk and could lead to lower security investment, not support a high allocation. Option D is wrong because high risk tolerance generally leads to lower security investment, as the organization is willing to accept more risk — it does not support a 12% allocation.

402
Multi-Selecthard

A CISO is establishing a security governance framework for a decentralized organization where each business unit operates independently. The CISO wants to ensure that security policies are consistently applied while respecting business unit autonomy. Which two actions are MOST appropriate to achieve this? (Choose two.)

Select 2 answers
A.Implement a centralized security policy that mandates compliance from all business units
B.Develop a set of high-level security principles and allow business units to tailor implementation
C.Allow each business unit to develop its own security policies independently without central oversight
D.Establish a security steering committee with representatives from each business unit
E.Outsource all security operations to a managed security service provider (MSSP) to ensure uniformity
AnswersB, D

This approach provides a common security foundation while accommodating the unique needs of each business unit. High-level principles ensure consistency in risk management and compliance, while tailored implementation allows business units to address their specific risks and operational contexts. It strikes a balance between central governance and local autonomy, which is essential in a decentralized organization. The CISO can monitor adherence through metrics and audits, ensuring that the tailored implementations meet the principles.

Why this answer

Establishing a security steering committee with business unit representatives and developing high-level security principles with tailored implementation both balance central governance with local autonomy. The committee fosters collaboration and shared decision-making, while the principles provide a consistent framework that business units can adapt to their specific contexts. Together, they enable consistent risk management without stifling the flexibility required in a decentralized organization.

Exam trap

The trap here is assuming that either strict centralization or complete decentralization is the answer, when a hybrid governance approach is most effective.

403
MCQeasy

An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?

A.Request an extension of the original project timeline from the vendor and continue monitoring.
B.Update the risk register to reflect the increased residual risk and report the treatment shortfall to the risk committee.
C.Close the original risk entry and open a new one describing the delayed identity governance implementation.
D.Reassign the identity governance project to the security team so it can be completed faster.
AnswerB

When an approved treatment is not progressing, the residual risk is higher than the committee believed when it accepted the plan. The security manager's first duty is to restore accurate risk visibility by updating the register and informing the same governance body that approved the treatment. This keeps decision-makers able to re-evaluate acceptance, reallocate resources, or approve interim compensating controls based on current facts.

Why this answer

Risk treatment plans are approved on the basis of projected residual risk, so slippage changes the factual basis of that approval. The security manager must first update the risk register and notify the risk committee, enabling it to decide whether to fund acceleration, accept the higher exposure temporarily, or mandate compensating controls. Execution and vendor actions come after risk visibility is restored.

Exam trap

The trap here is jumping to a project recovery action such as reassignment or vendor negotiation, when the immediate obligation is to restore accurate risk reporting to the body that approved the treatment.

404
MCQhard

A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?

A.Assess the extent of the breach.
B.Engage a public relations firm.
C.Notify affected customers.
D.Perform a root cause analysis.
AnswerA

Containment stops further loss but does not establish notification duties. Regulators require timely, accurate breach notification, and scope determines which individuals and authorities must be told. Assessing the extent of the breach therefore precedes notification, remediation and any public communication.

Why this answer

After containing a breach, the immediate next priority is to assess the extent of the breach — determining what data was exposed, how many records, which systems, and whether the breach is ongoing. This assessment is a prerequisite for every subsequent legal and regulatory obligation, including notification timelines and scope. Without knowing the extent, the organization cannot accurately notify regulators or affected parties within mandated windows.

Exam trap

CISM often tests the sequencing of incident response steps, and candidates frequently jump to customer notification or PR because those feel urgent, ignoring that legal notification obligations depend on first establishing the breach's scope.

How to eliminate wrong answers

Option B is wrong because engaging a public relations firm is a reputational response that should follow, not precede, understanding the breach scope — and it is not a legal or regulatory priority. Option C is wrong because notifying affected customers must happen within regulatory timelines, but only after the extent and nature of the breach are determined; premature notification without facts can be inaccurate and legally problematic. Option D is wrong because root cause analysis is a later forensic step aimed at preventing recurrence, not the immediate legal/regulatory next action after containment.

405
MCQhard

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

A.The VPN broker itself is misconfigured
B.A legitimate user forgot their password
C.An attacker has compromised a remote employee's device and is brute-forcing the admin account
D.The alert is a false positive due to SIEM rule threshold
AnswerC

A compromised remote endpoint tunnelling through the trusted VPN broker would present that broker's source IP while the attacker brute-forces the admin account, explaining the SIEM alert. This satisfies the stem's constraint that the source IP belongs to a legitimate VPN service.

Why this answer

A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.

Exam trap

The trap here is that candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.

How to eliminate wrong answers

Option A is wrong because a misconfigured VPN broker would typically cause connectivity issues or authentication failures, not generate brute-force alerts against an admin account from a trusted IP. Option B is wrong because a legitimate user forgetting their password would result in a few failed login attempts, not a sustained brute-force pattern that triggers a SIEM alert. Option D is wrong because the alert is not a false positive; the SIEM rule threshold is correctly identifying anomalous brute-force behavior from a trusted source, which is a known attack vector.

406
Multi-Selecteasy

Which THREE of the following are components of a security operations center (SOC)?

Select 3 answers
A.Vulnerability scanning
B.Response
C.Security monitoring
D.Security awareness training
E.Detection
AnswersB, C, E

Response is one of the three SOC components, covering the actions taken once an event is confirmed as an incident, such as containment, eradication and recovery. It complements detection and monitoring within the SOC's operating model.

Why this answer

A SOC is built around the core functions of detection, response, and continuous security monitoring, so options B, C, and E are correct. Detection (E) covers identifying malicious activity through tools such as SIEM correlation rules, IDS/IPS alerts, and endpoint telemetry, which is a primary SOC responsibility. Response (B) covers incident handling activities like triage, containment, eradication, and recovery, which SOC analysts perform once an incident is detected.

Security monitoring (C) is the ongoing 24x7 collection and analysis of logs and alerts from firewalls, endpoints, and network devices that feeds detection and response. Vulnerability scanning (A) is typically a vulnerability management function, and security awareness training (D) is a human-risk/GRC program, so neither is a core SOC component.

407
MCQhard

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

A.Eliminating the requirement for a dedicated security team
B.Reducing the need for automated security testing tools
C.Reducing the frequency of penetration testing
D.Ensuring security is considered during the design and development phases
AnswerD

Champions sit within development teams, so they embed threat modelling, secure coding and abuse-case thinking into design and sprint work before code is written. This satisfies the stem's design-and-development constraint, shifting security left rather than relying on post-hoc testing or central gate reviews.

Why this answer

Security champions act as liaisons, promoting secure coding practices and facilitating communication between security and development, thereby integrating security earlier.

408
MCQmedium

During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?

A.Determine the scope of the breach by analyzing accessed resources.
B.Reset the password and re-enable the account immediately.
C.Notify the affected users and customers.
D.Delete the compromised account from the system.
AnswerA

Establishing the breach scope identifies every account, resource and dataset the attacker touched, which is required before containment, eradication or notification decisions. Acting on the single known account alone risks leaving persistence mechanisms and additional compromised credentials undiscovered.

Why this answer

The immediate priority after discovering a compromised account is to determine the scope of the breach by analyzing which resources the account accessed. This involves reviewing authentication logs, file access records, and data transfer logs to identify the extent of data exfiltration and potential lateral movement. Without this analysis, the team cannot contain the incident effectively or understand what data was compromised, which is a fundamental step in incident response per NIST SP 800-61.

Exam trap

The trap here is that candidates often confuse 'immediate containment' with 'immediate password reset or account deletion,' failing to recognize that the first step must be forensic analysis to understand the full impact before taking irreversible actions.

How to eliminate wrong answers

Option B is wrong because resetting the password and re-enabling the account immediately could allow the attacker to regain access if other persistence mechanisms (e.g., backdoor accounts, session tokens) are still active, and it bypasses the need to preserve forensic evidence. Option C is wrong because notifying affected users and customers should only occur after the scope is fully understood and containment is in place; premature notification can cause panic, legal exposure, and hinder the investigation. Option D is wrong because deleting the compromised account destroys forensic evidence (e.g., logs of lateral movement, privilege escalation) and may disrupt the investigation's ability to trace the attacker's actions or identify other compromised accounts.

409
MCQeasy

In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?

A.Legal counsel
B.Communications lead
C.Incident response manager
D.Executive sponsor
AnswerB

The communications lead owns external messaging, translating technical incident details into statements for customers, regulators and the media. This satisfies the stem's coordination constraint by centralising stakeholder communication, preventing engineers or executives from issuing conflicting accounts. Unlike the incident commander, who directs containment and recovery, this role carries no operational authority over remediation.

Why this answer

The communications lead handles external messaging to ensure consistency and accuracy.

410
MCQeasy

Which of the following is the primary responsibility of the board of directors in information security governance?

A.Implementing day-to-day security operations
B.Conducting vulnerability assessments
C.Setting risk appetite and overseeing security governance
D.Writing security policies
AnswerC

The board owns governance, not operational security. Setting the organisation's risk appetite defines how much risk is acceptable, and overseeing governance ensures security aligns with strategy. This satisfies the stem's governance-level responsibility, distinct from management's implementation duties.

Why this answer

The board of directors' primary responsibility in information security governance is setting the organization's risk appetite and overseeing security governance to ensure it aligns with business objectives. The board defines how much risk the organization is willing to accept, approves the security strategy, and monitors management's execution — it does not perform operational or policy-writing tasks. This ensures security is governed at the highest level and integrated with business strategy.

Exam trap

CISM often tests the board's strategic governance role versus management's operational role — candidates may pick 'writing security policies' because it sounds authoritative, but policy authoring is a management function while risk appetite setting is a board function.

How to eliminate wrong answers

Option A is wrong because implementing day-to-day security operations is an operational responsibility belonging to the CISO, SOC, and IT teams — boards do not run operations. Option B is wrong because conducting vulnerability assessments is a technical execution task performed by security engineers and analysts, not by the board; the board may receive summary results but does not conduct assessments. Option D is wrong because writing security policies is a management-level task performed by security leadership and subject-matter experts; the board approves the overarching policy framework but does not author detailed policies.

411
MCQeasy

What is the PRIMARY purpose of a security champions program?

A.To embed security advocates in non-security teams to promote security best practices
B.To enforce security policies through peer pressure
C.To conduct security audits of other teams
D.To replace the security team in development projects
AnswerA

Security champions are staff embedded within development, operations, and other non-security teams who advocate secure practises locally. This satisfies the stem's primary purpose by scaling security influence through existing team members rather than centralised security staff alone.

Why this answer

The primary purpose of a security champions program is to embed security advocates within non-security teams (e.g., development, operations) to promote security best practices (A). Champions are team members with an interest in security who receive additional training and act as liaisons between the security team and their functional teams, scaling security awareness and enabling earlier risk identification without adding headcount.

Exam trap

CISM often tests the collaborative nature of security champions — candidates may select enforcement or audit roles when the correct purpose is advocacy, education, and embedding security into non-security teams.

How to eliminate wrong answers

Option B is wrong because enforcing policies through peer pressure is not the purpose — champions promote best practices through collaboration and education, not coercion, which would undermine trust and adoption. Option C is wrong because conducting security audits is the role of the security team or internal audit, not champions — champions are advocates, not auditors, and auditing their own teams would create conflicts. Option D is wrong because replacing the security team in development projects is not the goal — champions augment and support the security team, not replace it; the security team retains accountability for security outcomes.

412
MCQmedium

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

A.High degree of autonomy needed by business units with diverse needs
B.Minimal security budget
C.Low regulatory requirements
D.Uniform security across all business units
AnswerA

A hybrid model distributes decision rights, letting central governance set baseline policy while business units retain autonomy over their own controls. This satisfies the stem's constraint directly: diverse units needing high autonomy cannot be governed effectively by a single centralised authority.

Why this answer

A hybrid security governance model combines centralized standards and oversight with decentralized execution, making it most appropriate when business units need a high degree of autonomy to address diverse needs (e.g., different regulatory regimes, customer segments, or technology stacks). The hybrid model lets the center set baseline policies and risk appetite while allowing units to tailor controls to their specific contexts. This balance is the strongest argument for adopting hybrid over fully centralized or fully decentralized models.

Exam trap

CISM often tests the trade-off between centralization (uniformity, cost efficiency) and decentralization (autonomy, local fit) — candidates may pick 'uniform security' as a reason for hybrid, but uniformity is the argument for centralization, while autonomy with diverse needs is the argument for hybrid.

How to eliminate wrong answers

Option B is wrong because a minimal security budget favors a centralized model, which reduces duplication and leverages economies of scale — hybrid models can be more expensive due to coordination overhead and duplicated tooling. Option C is wrong because low regulatory requirements reduce the need for strict centralized compliance controls, but they do not specifically favor hybrid — if anything, low regulation with uniform needs favors decentralization or centralization depending on other factors, not hybrid. Option D is wrong because uniform security across all business units is the classic argument for a centralized model, where one team defines and enforces consistent controls; hybrid is chosen precisely when uniformity is not desired or feasible.

413
Multi-Selecteasy

Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?

Select 2 answers
A.Number of security policies approved.
B.Mean time to detect (MTTD) security incidents.
C.Employee satisfaction score from annual survey.
D.Percentage of critical systems patched within 30 days.
E.Percentage of security budget spent on tools.
AnswersB, D

Mean time to detect measures how quickly monitoring and alerting capabilities identify security incidents, directly evidencing the programme's detective effectiveness. As a quantifiable KPI, MTTD satisfies the stem's requirement for performance measurement, unlike qualitative artefacts such as policy documents or risk registers, which indicate governance inputs rather than operational security performance.

Why this answer

Option B is correct because Mean Time to Detect (MTTD) is a recognized operational security KPI that quantifies how quickly an organization identifies security incidents, directly reflecting the effectiveness of monitoring, SIEM, and detection capabilities. Option D is correct because the percentage of critical systems patched within 30 days is a vulnerability-management KPI that measures how promptly known vulnerabilities are remediated, a core indicator of an information security program's preventive effectiveness. Option A is not a true effectiveness KPI because counting approved policies measures documentation activity, not whether controls actually reduce risk or improve security outcomes.

Option C is unrelated to security program performance, as employee satisfaction is an HR metric rather than a security indicator. Option E is a budgeting/spending ratio that describes resource allocation, not the effectiveness of the security program's controls or outcomes.

Exam trap

CISM often tests the confusion between activity metrics (policies approved, budget spent) and outcome-based KPIs (MTTD, patch compliance), tempting candidates to pick easily countable but non-meaningful numbers.

414
MCQhard

An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?

A.A qualitative analysis using a defined likelihood and impact scale with calibrated subject matter expert judgment.
B.A quantitative analysis using annualized loss expectancy derived from industry breach cost benchmarks.
C.A hybrid analysis that assigns monetary values to every identified ERP risk regardless of data availability.
D.A control gap analysis mapped to ISO/IEC 27002 that ranks risks by the number of missing controls.
AnswerA

Qualitative analysis with a defined likelihood and impact scale suits the limited historical data and the two-week window, because it relies on calibrated expert judgment rather than statistical loss data. It still produces a defensible, repeatable ranking of ERP risks when the scales and calibration criteria are documented, meeting the executives' need for prioritized results quickly.

Why this answer

When historical loss data is scarce and results are needed quickly, a qualitative analysis with documented likelihood and impact scales and calibrated expert judgment is the most practical and defensible choice. It produces a consistent ranking without fabricating quantitative precision, and the documented scales allow reviewers to understand and challenge how each ERP risk was rated.

Exam trap

The trap here is equating defensibility with quantitative precision, when in a data-poor, time-constrained situation a well-calibrated qualitative method is more defensible than fabricated numbers.

415
MCQeasy

Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?

A.Incident response playbook
B.Communication templates
C.Incident response policy
D.Incident response plan
AnswerA

A playbook provides prescriptive, step-by-step technical procedures for a specific incident type, such as ransomware or phishing. This contrasts with the broader incident response plan, which sets policy, roles and lifecycle phases rather than granular remediation actions.

Why this answer

An incident response playbook provides detailed, step-by-step technical procedures for handling specific incident types (e.g., ransomware, DDoS, phishing). Unlike higher-level documents, playbooks contain actionable commands, tool-specific instructions, and decision trees that guide responders through containment, eradication, and recovery. This granularity ensures consistent and efficient execution during an active security event.

Exam trap

ISACA CISM often tests the distinction between a plan (strategic, high-level) and a playbook (tactical, step-by-step), causing candidates to mistakenly choose the incident response plan because it sounds more comprehensive.

How to eliminate wrong answers

Option B (Communication templates) is wrong because they focus on predefined messaging for stakeholders (e.g., customers, regulators), not on technical remediation steps. Option C (Incident response policy) is wrong because it defines high-level governance, roles, and compliance requirements, not the tactical actions for a specific incident type. Option D (Incident response plan) is wrong because it outlines the overall organizational approach, escalation paths, and coordination procedures, but lacks the detailed, incident-specific technical steps found in a playbook.

416
MCQmedium

After containing a security incident, the team conducts a root cause analysis. They find the breach originated from a compromised third-party vendor account. What is the most effective long-term mitigation?

A.Increase logging on vendor accounts
B.Change all passwords manually
C.Implement vendor access reviews and enforce MFA
D.Terminate the vendor relationship
AnswerC

Vendor access reviews and enforced MFA address the compromised third-party credential vector directly, removing standing access and adding a possession factor that stolen passwords alone cannot satisfy. This is a durable governance and identity control, unlike one-off remediation, and satisfies the long-term mitigation requirement.

Why this answer

Implementing vendor access reviews and enforcing MFA addresses the root cause of unauthorized access.

417
MCQmedium

An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?

A.Conduct a root cause analysis and update risk assessment
B.Implement multi-factor authentication for all systems
C.Disable email links and attachments
D.Increase the frequency of security awareness training
AnswerA

A root cause analysis identifies why existing controls fail to stop social engineering, and the risk assessment is then updated to reflect the true threat exposure. This evidence-based step precedes selecting or tuning new controls.

Why this answer

A root cause analysis (RCA) is the correct first step because it identifies the specific weaknesses in people, processes, or technology that allowed the social engineering attacks to bypass existing controls. Updating the risk assessment based on RCA findings ensures that remediation efforts are prioritized against actual threats, rather than applying generic fixes. This aligns with the CISM principle that program management decisions must be data-driven and risk-based.

Exam trap

The trap here is that candidates often jump to a technical or training solution (B, C, or D) without first performing a root cause analysis, failing to recognize that the CISM framework requires a risk-based, diagnostic approach before implementing any control change.

How to eliminate wrong answers

Option B is wrong because implementing multi-factor authentication (MFA) for all systems is a broad technical control that does not address the root cause of social engineering—it may reduce credential theft but does not prevent manipulation of authorized users. Option C is wrong because disabling email links and attachments is a drastic, operational disruption that ignores other vectors (e.g., phone calls, SMS, in-person) and fails to address the underlying human or process gaps. Option D is wrong because increasing the frequency of security awareness training without first analyzing why current training failed may reinforce ineffective content; training must be tailored to the specific attack patterns identified in the RCA.

418
MCQmedium

A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?

A.Focus only on phishing simulations for all staff
B.Deliver the same annual training to all employees
C.Provide secure coding training to developers and social engineering awareness to executives
D.Create a single module covering all topics for everyone
AnswerC

Tailoring content to each role's actual threat exposure ensures relevance: developers need secure coding practise against injection flaws, while executives face targeted social engineering and business email compromise. Generic training for all staff fails to address these distinct risk profiles.

Why this answer

Option C is correct because role-based training tailors security education to the specific risks and responsibilities of different job functions. Developers need secure coding practices to prevent vulnerabilities like SQL injection or XSS, while executives are prime targets for social engineering and need awareness of executive-specific threats like whaling and business email compromise. This approach ensures that training is relevant, engaging, and effective in mitigating the most pertinent risks for each group.

Exam trap

CISM often tests the misconception that a single, comprehensive training program for all employees is sufficient, but role-based training is essential to address specific risks and responsibilities.

How to eliminate wrong answers

Option A is wrong because focusing only on phishing simulations for all staff ignores the diverse risks faced by different roles, such as secure coding for developers or social engineering for executives, and phishing simulations alone do not provide comprehensive role-based training. Option B is wrong because delivering the same annual training to all employees is a one-size-fits-all approach that fails to address the unique security responsibilities and threats associated with different job functions, which is the essence of role-based training. Option D is wrong because creating a single module covering all topics for everyone is essentially the same as generic training; it does not tailor content to specific roles, leading to information overload and reduced relevance, which undermines the effectiveness of the security awareness program.

419
MCQhard

A multinational corporation is designing its information security governance framework. The board has requested a single metric that best indicates the effectiveness of the security program. Which metric would BEST satisfy this request?

A.Percentage of systems compliant with security baseline.
B.Number of security incidents reported per month.
C.Mean time to detect (MTTD) security events.
D.Percentage of security controls achieving their intended outcomes as validated by testing.
AnswerD

Testing validates whether controls actually work, so this metric measures realised effectiveness rather than activity or coverage. It directly answers the board's request for a single outcome-based indicator, unlike counts of incidents, policies or training completion, which reflect effort or exposure rather than governance performance.

Why this answer

The best metric because it directly measures whether security controls are functioning as designed, which is the ultimate indicator of security program effectiveness. Unlike input or activity metrics, this outcome-based metric validates that controls achieve their intended purpose, aligning with the board's need for a single, high-level effectiveness measure.

Exam trap

The trap here is that candidates often confuse activity or compliance metrics (like baseline compliance or incident counts) with effectiveness metrics, failing to recognize that the board needs a direct measure of whether controls actually work, not just that they exist or are followed.

How to eliminate wrong answers

Option A is wrong because compliance with a security baseline measures adherence to a standard, not the actual effectiveness of the security program; a system can be compliant yet still be vulnerable if the baseline is outdated or insufficient. Option B is wrong because the number of security incidents reported per month is a lagging indicator that can be influenced by reporting culture and detection capabilities, not a direct measure of control effectiveness. Option C is wrong because mean time to detect (MTTD) measures detection speed, not whether controls prevent or mitigate events; a short MTTD does not indicate that controls are achieving their intended outcomes.

420
MCQmedium

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

A.Updating the IR plan and playbooks based on lessons learned
B.Sharing indicators of compromise with an ISAC
C.Revising the IR policy
D.Conducting a tabletop exercise
AnswerA

Updating the IR plan and playbooks translates lessons learned into revised procedures, contacts and decision criteria, ensuring the next response benefits from the post-incident review. This satisfies the stem's requirement directly, since documentation changes are the mechanism by which findings actually alter future incident handling.

Why this answer

Updating the IR plan and playbooks based on lessons learned is the definitive post-incident activity that directly incorporates findings from the after-action review into the operational documentation. This ensures the plan reflects actual gaps or improvements identified during the incident, making it actionable for future events. Without this update, the plan remains static and fails to evolve with the organization's threat landscape.

Exam trap

The trap here is that candidates confuse 'revising the IR policy' (a high-level governance document) with 'updating the IR plan and playbooks' (the operational, detailed documentation that directly incorporates lessons learned), leading them to choose the broader, less actionable option.

How to eliminate wrong answers

Option B is wrong because sharing indicators of compromise with an ISAC is a threat intelligence sharing activity that supports broader community defense, not a post-incident activity to update the organization's own IR plan. Option C is wrong because revising the IR policy is a higher-level governance change that typically occurs less frequently and is not the immediate step for capturing specific operational lessons learned from a single incident. Option D is wrong because conducting a tabletop exercise is a proactive testing activity used to validate the plan, not a post-incident activity to document and apply lessons learned from a real incident.

421
MCQmedium

During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?

A.Delete the malware files from the system.
B.Reset passwords for all user accounts.
C.Update antivirus signatures.
D.Reimage all affected systems from known-good backups.
AnswerD

Reimaging from known-good backups replaces every file, registry entry and persistence mechanism with a verified clean state. This guarantees complete removal of the threat, satisfying eradication's requirement that no residual malicious code survives on affected systems.

Why this answer

Reimaging all affected systems from known-good backups is the most critical action during the eradication phase because it ensures complete removal of the threat, including any rootkits, persistence mechanisms, or hidden malware that may survive simple file deletion or signature-based scans. This approach eliminates the risk of residual compromise, as the system is restored to a trusted state from a verified backup, which is essential for environments where the integrity of the operating system and applications cannot be guaranteed after an incident.

Exam trap

The trap here is that candidates often choose to delete malware files or update antivirus signatures because they focus on the immediate threat removal, but fail to recognize that these actions cannot guarantee complete eradication of deeply embedded or persistent malware, which is why reimaging is the definitive step in the eradication phase.

How to eliminate wrong answers

Option A is wrong because simply deleting malware files does not remove registry entries, scheduled tasks, or other persistence mechanisms that may re-infect the system, and it fails to address potential rootkits that hide files from the operating system. Option B is wrong because resetting passwords is a containment and recovery action that addresses credential compromise, but it does not remove the threat itself; the attacker's backdoor or malware may still be present on the system. Option C is wrong because updating antivirus signatures is a preventive measure that helps detect known threats, but it does not guarantee removal of unknown or polymorphic malware, and it cannot clean systems that have been deeply compromised at the kernel level.

422
Multi-Selecthard

Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)

Select 2 answers
A.Business continuity plan
B.Risk appetite and tolerance
C.Data classification scheme
D.Risk assessment methodology
E.Vulnerability scanning process
AnswersB, D

ISACA defines risk appetite and tolerance as core programme components: they express how much risk the organisation is willing to pursue or retain, and they bound every subsequent assessment, treatment and acceptance decision within the risk management framework.

Why this answer

ISACA defines risk appetite and tolerance (B) as key components because they establish the amount of risk an organization is willing to accept in pursuit of its objectives, providing the criteria against which risks are evaluated and prioritized. A risk assessment methodology (D) is also essential, as it defines the structured approach (e.g., identifying, analyzing, and evaluating risks per frameworks like ISO 31000 or NIST RMF) used to determine likelihood and impact consistently across the enterprise. Together, these two elements form the governance and analytical backbone of an information risk management program.

By contrast, a business continuity plan (A) is a response/recovery capability, a data classification scheme (C) is a supporting control/inventory tool, and vulnerability scanning (E) is a technical detection activity — all valuable, but none are the core program components ISACA identifies.

Exam trap

CISM often tests whether candidates can separate core risk management program components (appetite/tolerance, assessment methodology) from supporting controls and response plans (BCP, data classification, vulnerability scanning) — the trap is picking operational controls that feel risk-related but are not structural components.

423
MCQeasy

Which document should be created FIRST when establishing an information security program?

A.Information security policy
B.Risk assessment report
C.Incident response plan
D.Business continuity plan
AnswerA

The information security policy is the foundational document, stating management's intent, scope and principles before any standards, procedures or controls are drafted. Creating it first ensures all subsequent program artefacts align with approved direction, satisfying the stem's sequencing requirement.

Why this answer

The information security policy is the foundational document that establishes management's intent, direction, and support for the security program. It defines the scope, objectives, and responsibilities, and all other security documents (risk assessments, incident response plans, BCPs) derive their authority and alignment from this policy. Without an approved policy, subsequent activities lack governance and executive backing.

Exam trap

ISACA often tests the sequence of program development, and the trap here is that candidates mistake a risk assessment (Option B) as the first step because it seems logical to 'know your risks first,' but the policy must precede it to define the risk management framework and governance.

Why the other options are wrong

B

Risk assessment is informed by policy.

C

Incident response is a later operational plan.

D

BCP is related but separate and typically follows policy.

424
MCQeasy

A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?

A.Require a security risk assessment as a gate in the system development life cycle (SDLC).
B.Deploy a vulnerability scanner across the development environment.
C.Create a security awareness campaign for project managers.
D.Perform an annual penetration test on all production systems.
AnswerA

Embedding a security risk assessment as a formal gate in the SDLC ensures that security requirements are identified, evaluated, and addressed before projects proceed. This integrates security into project workflows rather than adding it after deployment. It also creates consistent, auditable evidence of due diligence. The other options are either reactive, incomplete, or address only part of the problem, making them less effective for systematic integration.

Why this answer

Integrating security into the SDLC through a formal risk assessment gate ensures that security requirements are considered at the right time, with accountability and documentation. It transforms security from an afterthought into a standard project step, enabling consistent risk-based decisions. The other activities are valuable but do not create the structured, repeatable integration the CISO is seeking.

Exam trap

The trap here is confusing post-deployment testing or awareness activities with true SDLC integration, which requires a defined process gate and documented risk assessment.

425
MCQmedium

A financial services company is updating its information security policies to reflect a new regulation. The CISO must ensure the policies are effectively communicated and enforced. Which action is MOST important to achieve this?

A.Include the policies in the employee handbook and require new hires to sign them during onboarding.
B.Obtain executive management approval and communicate the policies with mandatory training and acknowledgment.
C.Ask department managers to verbally brief their teams on the policy changes during staff meetings.
D.Publish the updated policies on the corporate intranet and send an email announcement to all staff.
AnswerB

This is correct because CISM emphasizes that policies must be approved by executive management to have authority, and then communicated through training and acknowledgment to ensure understanding and compliance. Mandatory training and acknowledgment create accountability and provide evidence of enforcement. This combination ensures the policies are not just published but actively adopted across the organization.

Why this answer

The correct answer is to obtain executive approval and communicate with mandatory training and acknowledgment. In CISM, policy governance requires that policies are authorized at the highest level and then effectively communicated. Training ensures employees understand their responsibilities, and acknowledgment provides evidence of compliance.

This approach ensures the policies are enforced and can be audited, which is essential for regulatory compliance.

Exam trap

The trap here is assuming that simply publishing or emailing policies is enough to ensure compliance, when active training and acknowledgment are required for enforcement.

426
MCQmedium

A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?

A.Mitigate by reducing the RTO to 1 hour through process automation
B.Transfer the risk by purchasing business interruption insurance
C.Accept the risk because the RTO is shorter than the MTD
D.Avoid the risk by replacing the system with a more reliable one
AnswerA

The RTO of 4 hours exceeds the 2-hour MTD, so the system cannot recover within tolerable downtime. Reducing the RTO to 1 hour through automation brings recovery inside the MTD, directly satisfying the stem's constraint and closing the gap.

Why this answer

The current RTO of 4 hours exceeds the MTD of 2 hours, meaning the system cannot be restored within the maximum tolerable downtime, resulting in unacceptable business impact. Reducing the RTO to 1 hour through process automation brings recovery time well within the MTD, effectively mitigating the risk to an acceptable level. This aligns with the risk management principle of applying controls to close the gap between RTO and MTD.

Exam trap

The trap here is that candidates mistakenly think accepting risk is valid when RTO is shorter than MTD, but the question presents the opposite scenario (RTO > MTD), making acceptance inappropriate; ISACA often tests this precise reversal to catch those who confuse RTO and MTD relationships.

How to eliminate wrong answers

Option B is wrong because transferring risk via business interruption insurance does not address the fundamental issue that the system cannot be restored within the MTD; insurance compensates for financial loss but does not prevent operational impact or data loss during the outage. Option C is wrong because accepting the risk is only appropriate when the RTO is shorter than the MTD, but here the RTO (4 hours) is longer than the MTD (2 hours), creating an unacceptable risk exposure. Option D is wrong because avoiding the risk by replacing the system is an extreme and costly measure that is not necessary when a less disruptive mitigation (reducing RTO) can achieve compliance with the MTD.

427
MCQeasy

A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?

A.The CISO, because they own the information security programme and are accountable for its policies.
B.The internal audit function, because it independently verifies that policy requirements are being met.
C.The IT operations manager, because they implement most of the technical controls described in the policy.
D.Executive management, because the policy sets enterprise-wide security expectations and demonstrates top-level commitment.
AnswerD

Information security policy applies across the whole organisation and must reflect the governing body's risk appetite and direction. Approval by executive management gives the policy the authority needed to compel compliance from every business unit and signals that security is a corporate priority, which is the governance expectation for the top-level policy document.

Why this answer

The top-level information security policy sets expectations for the entire organisation and expresses management's risk appetite, so it must be approved by executive management. This provides the authority for enforcement and demonstrates visible commitment. The CISO drafts and maintains it, IT implements it, and internal audit independently assesses compliance against it.

Exam trap

The trap here is assuming the CISO, as programme owner, is also the correct approval authority for the enterprise-wide policy.

428
Multi-Selectmedium

Which of the following are key components of an effective information security program? (Select TWO.)

Select 2 answers
A.State-of-the-art security tools and technologies
B.A risk management framework
C.Security awareness and training programs
D.A large security operations center
E.Compliance with all applicable laws
AnswersB, C

Why this answer

A risk management framework is a key component because it provides a structured, repeatable process for identifying, assessing, and mitigating information security risks. It ensures that security investments and controls are aligned with business objectives and risk appetite, rather than being ad hoc or technology-driven. Without a risk management framework, an information security program lacks the foundational governance to prioritize threats and allocate resources effectively.

Exam trap

The trap here is that candidates often mistake operational components (like a SOC or advanced tools) or compliance outcomes as foundational pillars, whereas CISM emphasizes that governance through a risk management framework and the human element via security awareness are the true core components of a sustainable program.

Why the other options are wrong

A

Tools are important but not a key component; the program must include processes and people.

D

Size is not a key component; effectiveness matters more.

E

Compliance is a goal, not a component of the program itself.

429
MCQeasy

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?

A.Incident response playbook
B.Incident response policy
C.Incident response plan
D.Communication templates
AnswerA

Playbooks translate the incident response plan into documented, step-by-step procedures for a specific incident category, such as ransomware or data breach. This granular, scenario-specific detail is precisely what the stem requests, distinguishing playbooks from broader plans, policies and general procedures.

Why this answer

Playbooks are specific to incident types (e.g., ransomware) and provide step-by-step guidance, whereas the IR plan is a high-level document and policy sets overall intent.

430
Multi-Selecteasy

Which TWO of the following are PRIMARY goals of incident management according to industry best practices?

Select 2 answers
A.Restore normal operations as quickly as possible
B.Minimize business disruption
C.Document all steps for compliance
D.Assign blame to the responsible party
E.Increase the security budget
AnswersA, B

Rapid restoration of normal operations is a primary incident management goal because it directly limits the duration of adverse impact. This satisfies the stem's requirement for best-practise goals by focusing on returning the organisation to its pre-incident service level, rather than root-cause analysis or long-term remediation.

Why this answer

Option A is correct because a primary goal of incident management, as defined in frameworks such as ITIL and NIST SP 800-61, is to restore normal service operation as quickly as possible while maintaining service quality. Option B is correct because minimizing the adverse impact on business operations and users is the other core objective, ensuring that disruptions to critical business functions are reduced. Documentation (C) is a supporting activity that aids auditing and post-incident review, but it is not a primary goal.

Assigning blame (D) is counterproductive and contradicts the blameless post-mortem culture recommended by best practices. Increasing the security budget (E) is a possible organizational outcome but is not a goal of the incident management process itself.

Exam trap

The trap here is that candidates often confuse 'documentation' or 'compliance' as primary goals, but ISACA CISM emphasizes that operational restoration and business disruption minimization are the top priorities, with documentation being a supporting process that must not delay recovery.

431
MCQeasy

Which role is primarily responsible for designing and reviewing an organization's security architecture?

A.Security analyst
B.GRC analyst
C.Security architect
D.SOC analyst
AnswerC

The security architect owns the design and review of security architecture, translating business and risk requirements into structural controls. This directly satisfies the stem's design-and-review responsibility, distinguishing the role from operational security engineers who implement and run the resulting controls.

Why this answer

The security architect is the role accountable for designing, documenting, and reviewing the organization's security architecture, including reference models, control frameworks, and technology standards. This role translates business and risk requirements into structural security designs and validates that implementations conform to them.

Exam trap

CISM often tests role confusion — candidates pick 'security analyst' because it sounds broad, missing that architecture design and review is a distinct, senior accountability.

How to eliminate wrong answers

Option A is wrong because security analysts focus on monitoring, triage, and operational analysis rather than architecture design. Option B is wrong because GRC analysts handle governance, risk, and compliance activities such as policy tracking and audit evidence, not technical architecture. Option D is wrong because SOC analysts perform real-time detection and response in the security operations center, an operational rather than architectural function.

432
MCQhard

During a major incident, the incident response team has contained the threat but recovery is taking longer than expected. The business continuity manager reports that the manual workaround in place will fail within four hours due to capacity limits. Which action should the incident manager take FIRST?

A.Instruct the business continuity manager to extend the manual workaround beyond its documented capacity limits.
B.Direct the recovery team to work overtime and compress testing steps to accelerate system restoration.
C.Suspend incident communications until the recovery team confirms a new restoration estimate.
D.Escalate the recovery timeline risk to the crisis management team (CMT) so it can decide on activating the business continuity plan.
AnswerD

When containment is achieved but recovery threatens to exceed the tolerance of manual workarounds, the decision to invoke the business continuity plan involves enterprise trade-offs beyond the incident response team's authority. Escalating to the CMT ensures executives can authorize alternate processing sites, customer communications, or resource commitments before the workaround fails, preventing an avoidable operational outage.

Why this answer

Containment success does not end the incident if recovery cannot be completed within the tolerance of interim workarounds. The imminent failure of the manual workaround is a business continuity trigger that exceeds the incident response team's authority. Escalating to the CMT enables executives to authorize continuity plan activation, alternate processing, and stakeholder communications before the workaround collapses.

Exam trap

The trap here is treating containment as the end of the incident manager's decision scope, when recovery risk crossing business tolerance requires executive escalation.

433
MCQeasy

An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerA

Applying the vendor patch reduces the likelihood that the vulnerability can be exploited, which lowers the overall risk exposure while the business activity continues. This is the defining characteristic of risk mitigation: implementing controls to reduce likelihood or impact. Patching is a classic preventive control within a vulnerability management program.

Why this answer

Risk mitigation involves applying controls that reduce the likelihood or impact of a risk while allowing the underlying business activity to continue. Patching a known vulnerability lowers the probability of exploitation, so it falls squarely into the mitigation category rather than avoidance, transfer, or acceptance, each of which describes a fundamentally different treatment approach.

Exam trap

The trap here is conflating any security action with avoidance or acceptance, when the decisive question is whether the action reduces exposure while the activity continues.

434
MCQhard

A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?

A.Outsource compliance management to a third-party consultant
B.Develop a unified compliance framework that maps controls to multiple regulations
C.Prioritize compliance based on the most stringent regulation
D.Assign separate teams to manage each regulation
AnswerB

A unified framework maps common controls once and cross-references them to GDPR, CCPA and PCI DSS, eliminating duplicated evidence and conflicting interpretations. It satisfies the overlapping-requirements constraint by managing obligations through a single control set rather than separate, parallel compliance programmes.

Why this answer

A unified compliance framework maps common controls to multiple regulatory requirements (GDPR, CCPA, PCI DSS), eliminating duplicated effort, reducing gaps, and providing a single source of truth for auditors. This is the standard 'compliance harmonization' or 'control mapping' approach recommended by ISACA and industry frameworks such as the Unified Compliance Framework (UCF) and NIST SP 800-53 mappings. It allows one control implementation to satisfy several regulations simultaneously.

Exam trap

CISM often tests whether candidates confuse 'prioritize the strictest regulation' with true harmonization — the trap is that the strictest regulation rarely covers all obligations, so picking C leaves compliance gaps that a mapped framework would catch.

How to eliminate wrong answers

Option A is wrong because outsourcing compliance management does not resolve overlapping or conflicting requirements — the organization still owns the risk and accountability, and a consultant cannot substitute for an integrated internal control framework. Option C is wrong because prioritizing only the 'most stringent' regulation creates gaps: GDPR, CCPA, and PCI DSS have different scopes (privacy vs. payment card data), so satisfying one does not satisfy the others, and 'most stringent' is subjective across domains. Option D is wrong because separate teams per regulation create silos, duplicate controls, inconsistent evidence, and higher cost — the opposite of the efficiency a unified framework delivers.

435
Multi-Selecteasy

During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)

Select 2 answers
A.Identifying indicators of compromise.
B.Restoring systems from backup.
C.Notifying regulatory bodies.
D.Applying security patches.
E.Determining the scope of the incident.
AnswersA, E

Indicators of compromise are the forensic artefacts—anomalous log entries, unusual network connections, unexpected file hashes—that confirm an incident is occurring. Identifying them during detection and analysis scopes the event, distinguishes malicious activity from benign noise, and drives containment decisions, directly satisfying the phase's requirement to validate and characterise the incident.

Why this answer

Option A is correct because identifying indicators of compromise (IOCs) — such as unusual network connections, unexpected file hashes, registry changes, or anomalous login patterns — is a core detection and analysis activity that confirms whether an incident has occurred and characterizes the threat. Option E is correct because determining the scope of the incident (which hosts, accounts, data, and network segments are affected, and how far the compromise has spread) is essential during detection and analysis to understand impact and guide containment decisions. Options B, C, and D do not belong here: restoring systems from backup is a recovery-phase (post-containment/eradication) activity, notifying regulatory bodies is typically a post-incident or reporting/coordination activity, and applying security patches is a remediation/eradication or preventive maintenance action rather than part of detection and analysis.

436
MCQmedium

In a security awareness program, which training approach is most appropriate for software developers?

A.Secure coding practices and common vulnerabilities
B.Social engineering awareness for executives
C.Incident response procedures
D.General security awareness training covering phishing
AnswerA

Developers introduce vulnerabilities through code, so secure coding practices and common vulnerabilities (for example injection or insecure deserialisation) target the exact skills their role demands. Generic awareness content would not address the technical mechanisms they must apply daily.

Why this answer

Software developers need role-specific training on secure coding practices and common vulnerabilities such as OWASP Top 10 issues, injection flaws, and insecure deserialization, because they directly write and maintain code that introduces or prevents these flaws. Generic awareness training does not address their actual responsibilities.

Exam trap

CISM often tests audience-appropriateness — candidates pick generic phishing awareness because it is the most familiar training, missing that developers require secure coding content specific to their role.

How to eliminate wrong answers

Option B is wrong because social engineering awareness for executives targets leadership, not developers, and does not address code-level risk. Option C is wrong because incident response procedures are relevant to IR teams and responders, not the primary training need for developers writing code. Option D is wrong because general phishing awareness, while useful, is baseline training and does not equip developers to prevent vulnerabilities in the software they build.

437
MCQmedium

An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?

A.Conducting annual security awareness training
B.Implementing a decentralized security model
C.Developing a multi-year security roadmap tied to business strategy
D.Hiring a CISO with a technical background
AnswerC

A multi-year security roadmap tied to business strategy translates board objectives into sequenced security initiatives with measurable milestones, giving governance a mechanism to verify that security investment and priorities remain aligned with organisational goals over time.

Why this answer

A multi-year security roadmap tied to business strategy is the governance practice that best ensures security activities align with business objectives. The roadmap translates business goals and risk appetite into sequenced security initiatives, budgets, and milestones, giving the board a mechanism to direct and monitor alignment over time.

Exam trap

The trap is choosing a plausible-sounding operational or staffing action (training, hiring a CISO) over the governance artifact; CISM tests that alignment is achieved through strategic planning tools like a business-linked roadmap, not through controls or personnel alone.

How to eliminate wrong answers

Option A is wrong because annual security awareness training is a tactical control that addresses human risk but does not align the security programme with business strategy or provide governance-level direction. Option B is wrong because a decentralized security model fragments accountability and often increases misalignment with business objectives, whereas governance alignment requires centralized strategy with clear ownership. Option D is wrong because hiring a CISO with a technical background is a staffing decision; while a CISO is important, technical depth alone does not create strategic alignment — the roadmap and governance process do.

438
MCQeasy

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

A.Performing technical vulnerability assessments
B.Approving specific security tools and technologies
C.Conducting daily security monitoring activities
D.Setting the strategic direction and oversight of the security programme
AnswerD

The board owns governance, not implementation. Setting strategic direction and overseeing the security programme aligns security with business objectives and risk appetite, which is the board's primary governance duty rather than operational or technical decisions.

Why this answer

The board of directors is responsible for governance, not operations. Its primary security governance duty is to set the strategic direction for the security programme and provide oversight to ensure it aligns with business objectives and risk appetite. Technical execution is delegated to management and security staff.

Exam trap

The trap is that operational-sounding options (vulnerability assessments, tool approval, monitoring) feel security-relevant, so candidates pick them; CISM consistently tests that the board's role is strategic direction and oversight, never hands-on execution.

How to eliminate wrong answers

Option A is wrong because performing technical vulnerability assessments is an operational task executed by security engineers or analysts, not a board-level governance responsibility. Option B is wrong because approving specific security tools and technologies is a tactical management decision; the board sets strategy and risk tolerance, not product selections. Option C is wrong because conducting daily security monitoring is a hands-on operational activity performed by the SOC, far below the board's governance scope.

439
MCQeasy

An organization is defining the composition of its incident response team. Which role is PRIMARILY responsible for coordinating communication with the media and the public during a high-profile incident?

A.The public relations or communications lead.
B.The legal counsel.
C.The IT operations director.
D.The incident response manager.
AnswerA

The communications lead owns the organization's external messaging, including media statements, public disclosures, and stakeholder updates. During a high-profile incident, this role works with legal, executive leadership, and the incident response manager to ensure accurate, consistent, and timely communication while protecting the organization's reputation and meeting disclosure obligations.

Why this answer

External communication during a high-profile incident belongs to a designated communications or public relations lead who can align messaging with legal requirements and executive direction. This separation keeps technical responders focused on containment and recovery while ensuring the organization speaks with one consistent voice. Legal counsel reviews for risk, and the incident response manager supplies accurate technical context, but neither owns the media and public communication role.

Exam trap

The trap here is assuming the incident response manager or legal counsel handles all incident communication, when external media and public messaging is a distinct communications function.

440
MCQeasy

Which of the following best describes a key benefit of a centralized information security governance model?

A.Greater autonomy for business units
B.Reduced need for executive oversight
C.Consistent enforcement of security policies and standards
D.Faster adaptation to local business needs
AnswerC

Centralised governance places policy ownership and enforcement authority with one body, so the same standards apply uniformly across every business unit. This directly satisfies the stem's requirement for a key benefit: eliminating the inconsistent, locally varied controls that fragmented, devolved governance models inevitably produce across an organisation.

Why this answer

A centralized information security governance model concentrates policy-making, standards, and oversight in a single function (typically the CISO's office), which produces consistent enforcement of security policies and standards across the entire enterprise. This consistency is the primary benefit because it eliminates the variance and gaps that arise when business units interpret security requirements independently. It also enables uniform risk appetite, metrics, and reporting to the board.

Exam trap

CISM often tests the trade-off between centralization and decentralization — candidates who equate 'centralized' with 'better responsiveness' or 'less oversight' pick A, B, or D, missing that consistency of enforcement is the defining benefit.

How to eliminate wrong answers

Option A is wrong because greater autonomy for business units is a benefit of a decentralized (federated) governance model, not a centralized one — centralization reduces autonomy in exchange for consistency. Option B is wrong because centralization increases, not reduces, the need for executive oversight: a single governance body requires strong board and CISO sponsorship to enforce enterprise-wide policy. Option D is wrong because faster adaptation to local business needs is a strength of decentralized or hybrid models, where local units can tailor controls; centralized models are typically slower to adapt locally because changes must flow through the central function.

441
MCQmedium

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

A.Conduct a root cause analysis to determine why controls failed.
B.Increase the frequency of control testing.
C.Report the findings to management and accept the risk.
D.Implement compensating controls immediately.
AnswerA

Root cause analysis identifies why the controls failed before remediation, satisfying the need to address underlying deficiencies rather than symptoms. Auditors expect corrective action to be risk-based; understanding causation lets the security manager reassess the risk assessment and prioritise fixes, preventing recurrence across the control set.

Why this answer

When controls are found ineffective, the security manager must first conduct a root cause analysis to identify why the controls failed. This aligns with the CISM's emphasis on corrective action based on understanding the underlying failure, such as misconfigured firewall rules, outdated signature databases, or improper access control lists (ACLs). Without this analysis, any subsequent remediation (like implementing compensating controls or increasing testing frequency) may address symptoms rather than the actual cause, leading to recurring failures.

Exam trap

The trap here is that candidates often jump to 'implement compensating controls' (Option D) as a quick fix, but CISM emphasizes that the first step must always be to understand the failure through root cause analysis before selecting any corrective action.

How to eliminate wrong answers

Option B is wrong because increasing the frequency of control testing does not fix the underlying failure; it only detects the same failure more often, wasting resources without addressing the root cause (e.g., a flawed SIEM correlation rule or a misapplied patch). Option C is wrong because reporting findings and accepting risk prematurely bypasses the obligation to first investigate and remediate the control failure; risk acceptance is a decision made after understanding the failure's impact and likelihood, not as an immediate first step. Option D is wrong because implementing compensating controls immediately may introduce new complexity or false sense of security without knowing why the original controls failed (e.g., adding a WAF without fixing a broken IDS rule could leave other attack vectors open).

442
Multi-Selectmedium

An information security program must include elements to ensure continuous improvement. Which TWO of the following are MOST essential for continuous improvement?

Select 2 answers
A.Annual risk assessment
B.Quarterly board meetings
C.Monthly patching
D.Post-incident reviews
E.Regular security awareness training
AnswersA, D

Risk assessment identifies evolving threats and areas for improvement.

Why this answer

Annual risk assessments are essential for continuous improvement because they systematically identify, evaluate, and prioritize changes in the threat landscape, business objectives, and regulatory requirements. This process ensures the information security program adapts to new risks and aligns with organizational goals, driving iterative enhancements. Without a periodic risk assessment, the program would lack a data-driven foundation for prioritizing improvements.

Exam trap

The trap is confusing operational activities (patching, training) with the strategic feedback mechanisms (annual risk assessment, post-incident review) that are required for continuous improvement in an information security program as per CISM's governance framework.

443
MCQmedium

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

A.Number of security incidents reported
B.Percentage of systems with critical vulnerabilities
C.Average patch deployment time
D.Number of security awareness training completions
AnswerB

Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.

Why this answer

The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.

Exam trap

The trap here is that candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.

Why the other options are wrong

A

Lagging indicator; board prefers leading indicators of risk.

C

Operational detail; not strategic.

D

Activity metric, not outcome.

444
MCQeasy

Which of the following is the BEST example of a board-level security metric?

A.Security investment versus loss avoidance
B.Vulnerability scan completion rate
C.Number of firewall rules implemented
D.Percentage of employees who completed security training
AnswerA

Comparing security investment against loss avoidance frames security as a financial trade-off, which is the language boards use to judge value. It satisfies the board-level metric constraint by tying spend to risk reduction, unlike operational indicators such as vulnerability counts.

Why this answer

Board-level metrics should reflect impact on business objectives and financial performance. Investment vs. loss avoidance directly ties security spending to business value.

445
Multi-Selectmedium

Which THREE of the following are considered key components of an incident response plan?

Select 3 answers
A.Post-incident review process
B.Communication escalation matrix
C.Roles and responsibilities
D.Network diagrams
E.Disaster recovery procedures
AnswersA, B, C

A post-incident review captures lessons learned, root cause and corrective actions after containment, feeding improvements back into the plan. It satisfies the requirement for a key component by ensuring the response matures, rather than treating incident closure as the endpoint.

Why this answer

A post-incident review process (A) is a key component because it captures lessons learned, root-cause analysis, and corrective actions after an incident is contained and eradicated, feeding continuous improvement back into the plan. A communication escalation matrix (B) is essential because it defines who is notified, in what order, within what timeframes, and through which channels (e.g., phone, email, pager) during an incident, ensuring timely stakeholder and management engagement. Roles and responsibilities (C) are a core element because they assign clear ownership of incident response activities — such as incident commander, communications lead, and forensics analyst — preventing confusion and gaps during an active incident.

Network diagrams (D) are useful reference artifacts for troubleshooting and scoping, but they are supporting documentation rather than a defining component of an incident response plan. Disaster recovery procedures (E) belong to the disaster recovery plan (DRP) and business continuity planning, which address restoring critical systems and operations after major disruptions, not the structured detection, containment, eradication, and recovery workflow of incident response.

Exam trap

ISACA CISM often tests the distinction between incident response plan components and supporting artifacts or adjacent processes, so candidates mistakenly select network diagrams or disaster recovery procedures as key components when they are merely supplementary or belong to a different domain.

446
MCQhard

After a phishing attack, an organization's incident response team identifies that the attacker gained access to an email account and sent internal spear-phishing emails. What is the BEST immediate containment action?

A.Disable the compromised account
B.Reset all user passwords
C.Block the attacker's IP address at the firewall
D.Increase email filtering rules
AnswerA

Disabling the compromised account immediately halts the attacker's ability to send further internal spear-phishing emails and access mailbox data, directly satisfying the stem's containment requirement. It revokes active sessions and blocks authentication, severing the attacker's foothold before lateral movement or additional phishing can occur.

Why this answer

Disabling the compromised account immediately stops the attacker from using the authenticated session to send further internal spear-phishing emails. This containment action directly cuts off the attacker's foothold within the email system, preventing lateral movement and further compromise of other users. It is the fastest way to halt the ongoing attack without disrupting the entire user base.

Exam trap

The trap here is that candidates often choose 'Reset all user passwords' thinking it is a comprehensive security measure, but it fails to immediately terminate the attacker's active session and can cause operational chaos, whereas disabling the compromised account is the precise, immediate containment step required in incident response.

How to eliminate wrong answers

Option B is wrong because resetting all user passwords is a broad, disruptive action that does not immediately stop the attacker's active session; the attacker could continue sending emails until the password change propagates, and it may cause unnecessary downtime for legitimate users. Option C is wrong because the attacker is using a legitimate internal email account, so blocking an external IP address at the firewall does not prevent the attacker from sending emails from within the organization's own mail server. Option D is wrong because increasing email filtering rules is a preventive measure that does not stop an already-compromised account from being used; the attacker can bypass filters by sending emails internally, which often bypass external filtering rules.

447
Multi-Selecthard

A CISO is developing a set of metrics to report to the board on the effectiveness of the information security governance program. Which of the following metrics would BEST demonstrate that security governance is aligned with business objectives? (Choose two.)

Select 2 answers
A.Total security budget as a percentage of IT budget.
B.Percentage of security initiatives that are directly linked to business strategy objectives.
C.Number of security incidents reported to the board.
D.Percentage of business units that have a representative on the security governance committee.
E.Average time to remediate critical vulnerabilities.
AnswersB, D

This metric directly measures alignment by showing how many security projects support business goals. A high percentage indicates that security is not operating in isolation but is contributing to the organization's strategic aims. It provides the board with evidence that security investments are prioritized based on business value, which is a core principle of effective governance.

Why this answer

The two metrics that best demonstrate alignment with business objectives are the percentage of security initiatives linked to business strategy and the percentage of business units represented on the security governance committee. These metrics show that security activities are driven by business goals and that governance includes cross-functional input, ensuring decisions are aligned with organizational needs. They provide the board with tangible evidence of strategic integration.

Exam trap

The trap here is selecting operational or financial metrics, such as incident counts or budget percentages, which are easy to measure but do not prove that security governance is aligned with business strategy.

448
Multi-Selecthard

A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)

Select 2 answers
A.The name of the auditor who reviewed the risk.
B.The risk owner accountable for managing the risk.
C.The specific technical vulnerability that generated the risk.
D.The assessed likelihood and impact of the risk.
E.The date the risk was first identified.
AnswersB, D

A named risk owner is essential because risk treatment requires accountability. Without an owner, remediation actions may stall, and no one is responsible for monitoring changes in likelihood or impact. The owner ensures that the risk is assessed, treated and reported appropriately, and provides a clear point of contact for auditors and management. This element directly supports decision-making and follow-through.

Why this answer

A risk owner and assessed likelihood and impact are essential because they enable accountability and prioritization. The owner ensures action is taken, while likelihood and impact ratings allow the CISO to compare risks and decide on treatment. Other details, such as identification date, auditor name or a specific vulnerability, may be useful for context but do not directly drive risk treatment decisions.

Exam trap

The trap here is including descriptive or historical details that seem relevant but do not actually support the decision to treat, transfer, avoid or accept a risk.

449
MCQeasy

A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?

A.The amount and type of risk that the organization is willing to pursue or retain to achieve its objectives.
B.The residual risk that remains after all reasonable controls have been implemented.
C.The process of identifying, analyzing and evaluating risks to determine their significance.
D.The maximum level of risk that the organization can tolerate before exceeding its risk tolerance.
AnswerA

Risk appetite is a strategic statement of how much risk the organization is willing to accept in pursuit of its goals. It guides decision-making by setting boundaries for risk-taking and helps ensure that security investments align with business objectives. It is broader than tolerance and provides the context within which specific tolerances and thresholds are defined.

Why this answer

Risk appetite expresses the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. It is a strategic, governance-level concept that sets the boundaries for risk-taking and guides decisions about security investments and risk treatment. It is distinct from tolerance, which defines acceptable variation, and from assessment or residual risk, which are operational concepts.

Exam trap

The trap here is confusing risk appetite with risk tolerance or with operational risk concepts such as assessment and residual risk.

450
Multi-Selecteasy

Which of the following are key components of an information security program? (Select TWO)

Select 2 answers
A.A set of security policies and standards
B.A network architecture diagram
C.A risk management process
D.An incident response log
AnswersA, C

Why this answer

A set of security policies and standards is a key component because it establishes the governance framework that defines acceptable use, access control, and compliance requirements for the entire organization. Without documented policies and standards, the security program lacks the authoritative baseline to enforce controls or measure effectiveness. These documents are the foundation for all other security activities, including training, audits, and incident response.

Exam trap

The trap here is that candidates often confuse operational artifacts (like network diagrams or logs) with programmatic components, failing to recognize that the core of an information security program is the governance and risk management framework, not the technical outputs or diagrams.

Why the other options are wrong

B

This is a technical artifact, not a core program component.

D

This is an operational record, not a program component.

Page 5

Page 6 of 13

Page 7