Courseiva

Certified Information Security Manager CISM (CISM) — Questions 451–525

924 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQmedium

A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?

A.Require all external communications to be handled exclusively by the legal department without input from security or communications staff.
B.Designate a single, pre-authorized spokesperson and require all external communications to flow through a defined approval chain.
C.Publish the full incident response plan on the corporate intranet so all employees understand the communication process.
D.Grant every member of the incident response team authority to speak with external parties to speed up information sharing.
AnswerB

A single pre-authorized spokesperson with a defined approval chain ensures consistent, legally reviewed messaging and prevents conflicting statements to regulators, law enforcement, and media. This directly addresses the CISO's need for coordinated and defensible external communications before, during, and after a high-severity breach, and it aligns with CISM guidance on incident communication roles and escalation paths.

Why this answer

Coordinated external communication during a high-severity breach requires a single pre-authorized spokesperson and a defined approval chain. This ensures messages to regulators, law enforcement, and media are consistent, legally reviewed, and technically accurate. Empowering everyone to speak or relying solely on one department creates confusion, legal exposure, and inconsistent messaging that can worsen the incident's impact.

Exam trap

The trap here is assuming that faster, decentralized communication is always better, when uncontrolled external statements during a breach often create legal and reputational harm.

452
MCQhard

An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?

A.Implement new security controls based on industry best practices.
B.Conduct a maturity assessment of the current program.
C.Increase the security awareness training budget.
D.Revise the information security policy.
AnswerB

A maturity assessment first establishes the programme's current capability baseline against a recognised model, exposing gaps before any remediation is proposed. This satisfies the stem's requirement to improve effectiveness by grounding changes in measured evidence rather than assumption.

Why this answer

Before making any changes, the security manager must first understand the current state of the program. A maturity assessment (e.g., using the CMMI or COBIT framework) evaluates the effectiveness, gaps, and capability levels of existing processes and controls. This baseline ensures that subsequent improvements are targeted and justified, rather than arbitrary or misaligned with the organization's actual needs.

Exam trap

ISACA often tests the principle that assessment must precede action; the trap here is that candidates may jump to implementing controls or revising policies as a quick fix, ignoring the foundational step of measuring current maturity to ensure changes are evidence-based and effective.

Why the other options are wrong

A

This may introduce unnecessary controls without understanding existing gaps.

C

Training is important but not the first step; assessment should precede resource allocation.

D

Policy revision may be needed, but first understand the program's strengths and weaknesses.

453
Drag & Dropmedium

Arrange the steps for deploying a security patch to critical servers in a production environment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Patch management involves identification, testing, backup, deployment, and verification.

454
MCQmedium

During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?

A.Hourly
B.Only at milestone events
C.Every 4 hours
D.Daily
AnswerA

Hourly sitreps match the tempo a P1 ransomware crisis demands, where encryption spreads and containment decisions change rapidly. Executives need current impact and recovery status to authorise escalation and communications, so a fixed hourly cadence prevents stale information during the critical early containment window.

Why this answer

For P1 incidents, hourly sitreps keep executives informed of rapidly evolving situations.

455
Drag & Dropmedium

Arrange the steps for performing a vulnerability scan on a network segment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Vulnerability scanning requires authorization, configuration, execution, analysis, and prioritization.

456
MCQhard

During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?

A.Implement a virtual patch through an intrusion prevention system (IPS)
B.Recompile the software with additional security controls
C.Immediately disable the software across the organization
D.Deploy a vendor patch as soon as it becomes available
AnswerA

A virtual patch via IPS enforces signature or behavioural rules at the network layer, blocking exploitation attempts against the unpatched zero-day without modifying the vulnerable software itself. This satisfies the short-term constraint, since no vendor fix exists yet, buying time until the vendor releases and the organisation deploys a permanent patch.

Why this answer

A virtual patch via an IPS provides immediate, temporary protection against a zero-day vulnerability by inspecting traffic for exploit patterns or anomalous behavior and blocking malicious payloads before they reach the vulnerable software. This buys time for the organization to assess the risk and plan a permanent fix without disrupting operations, as the IPS can be updated with signatures or rules specific to the newly discovered vulnerability.

Exam trap

The trap here is that candidates often confuse 'short-term' with 'permanent' solutions, mistakenly choosing D (vendor patch) as the immediate action, when in fact the correct short-term response is to implement a compensating control like a virtual patch to reduce risk while awaiting the vendor's official fix.

How to eliminate wrong answers

Option B is wrong because recompiling the software with additional security controls is not feasible for a zero-day vulnerability in a widely used commercial or third-party application, as the source code is typically unavailable and recompilation would require extensive development, testing, and deployment time, making it impractical for short-term response. Option C is wrong because immediately disabling the software across the organization would cause significant operational disruption and is an overly drastic measure that should only be considered if the vulnerability is actively exploited and no other mitigation exists, not as a first short-term action. Option D is wrong because deploying a vendor patch as soon as it becomes available is a long-term remediation step, not a short-term action; the vendor patch may take days or weeks to develop and test, leaving the organization exposed in the interim.

457
MCQmedium

An organization's incident response plan includes a call tree. During an incident, the primary contact is unreachable. What should happen?

A.Escalate to senior management
B.Use a different communication method like email
C.Wait for the primary to become available
D.Move to the next person in the call tree
AnswerD

Moving to the next person in the call tree preserves the escalation sequence the plan defines, ensuring the incident is reported without delay when the primary contact is unreachable. The call tree exists precisely to provide redundant notification paths, so following the next listed contact satisfies the plan's availability constraint rather than improvising alternatives.

Why this answer

A call tree is designed to ensure rapid, sequential notification during an incident. If the primary contact is unreachable, the plan should automatically move to the next person in the call tree to maintain the speed and reliability of the notification process. This avoids delays that could compromise incident response SLAs.

Exam trap

The trap here is that candidates may think waiting or escalating is safer, but the core of incident management is to maintain the notification chain without delay, so moving to the next person in the call tree is the correct action per standard incident response frameworks.

How to eliminate wrong answers

Option A is wrong because escalating to senior management bypasses the call tree's purpose of rapid, tiered notification and may overload management with routine notifications. Option B is wrong because using a different communication method like email does not solve the unreachability of the primary contact and can introduce delays or missed notifications. Option C is wrong because waiting for the primary to become available violates the incident response principle of timely action and could allow the incident to escalate.

458
MCQeasy

Which of the following is a leading indicator of security program effectiveness?

A.Number of security incidents
B.Number of data breaches
C.Phishing click rate
D.Mean time to detect (MTTD)
AnswerC

Phishing click rate measures user susceptibility before an actual breach occurs, making it predictive rather than historical. It satisfies the stem's demand for a leading indicator by revealing a control weakness (security awareness) that precedes and forecasts future incident likelihood, unlike lagging metrics such as breach counts.

Why this answer

A leading indicator predicts future security outcomes rather than measuring past events. Phishing click rate measures how susceptible users are to social engineering and is a forward-looking predictor of potential compromise, making it a leading indicator. By contrast, incident counts, breach counts, and MTTD are lagging indicators because they describe events that have already occurred or been detected.

Exam trap

CISM often tests the leading vs. lagging distinction by offering operational metrics like MTTD that feel proactive but are actually lagging because they measure events already in progress.

How to eliminate wrong answers

Option A is wrong because the number of security incidents is a lagging indicator — it counts events that already happened. Option B is wrong because the number of data breaches is also lagging; it measures realized loss events after the fact. Option D is wrong because MTTD, while operationally useful, is a lagging indicator of detection capability since it measures time to detect incidents that have already occurred.

459
Multi-Selectmedium

Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)

Select 2 answers
A.Vendor security assessment ratings
B.Risk scenarios with likelihood and impact ratings
C.Detailed results of control testing
D.Risk treatment recommendations
E.Complete asset inventory
AnswersB, D

Risk scenarios with likelihood and impact ratings translate identified threats into structured, comparable entries, letting the report rank exposures objectively. This satisfies the best-practise requirement that a risk assessment report quantify and prioritise risk rather than merely list assets or controls.

Why this answer

Option B is correct because a risk assessment report must document identified risk scenarios together with their likelihood and impact ratings, which are the core analytical outputs that let stakeholders understand and prioritize each risk. Option D is correct because the report should provide risk treatment recommendations (such as mitigate, transfer, avoid, or accept) so decision-makers know how each identified risk should be addressed. Options A, C, and E are not key components of a risk assessment report: vendor security assessment ratings belong to third-party/vendor risk management artifacts, detailed control testing results are outputs of control testing or audit reports, and a complete asset inventory is an input to the risk assessment process rather than a required section of the report itself.

Exam trap

The trap here is that candidates often confuse the risk assessment report's output (risk scenarios and treatment recommendations) with inputs or supporting data (vendor ratings, control testing details, asset inventory), leading them to select options that are part of the process but not the final report.

460
MCQeasy

A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?

A.Use the asset's purchase value to determine priority
B.Assess the business impact of each asset's compromise
C.Perform a vulnerability scan and prioritize based on findings
D.Review historical incident reports for each asset
AnswerB

Business impact analysis ranks assets by the operational, financial and regulatory harm their compromise would cause. This satisfies the prioritisation criterion by tying assessment effort to consequence severity, ensuring the most critical assets receive attention first rather than being ranked by convenience or cost.

Why this answer

The best approach to prioritize assets for risk assessment is to assess the business impact of each asset's compromise because risk management focuses on the potential harm to business objectives, not on financial cost or technical vulnerabilities. Business impact analysis (BIA) evaluates criticality based on factors like revenue loss, regulatory penalties, and operational downtime, directly aligning asset priority with organizational risk appetite.

Exam trap

The trap here is that candidates often confuse 'asset value' with 'purchase cost' (Option A) or mistake technical severity (Option C) for business criticality, failing to recognize that risk management prioritization must be driven by business impact analysis, not by financial or technical metrics alone.

How to eliminate wrong answers

Option A is wrong because purchase value does not reflect the asset's criticality to business operations; a low-cost server hosting a critical database may have far higher impact than an expensive but non-essential workstation. Option C is wrong because vulnerability scan findings indicate technical weaknesses but ignore the business context; a high-severity vulnerability on a low-impact asset may be less urgent than a medium-severity vulnerability on a mission-critical system. Option D is wrong because historical incident reports only show past events, which may not capture emerging threats or changes in asset criticality, and can lead to reactive rather than proactive prioritization.

461
MCQhard

A healthcare organization's information security program has a risk register with several high-risk items. The CISO is allocating budget for risk treatment. Which of the following is the MOST important factor when deciding whether to mitigate, transfer, or accept a risk?

A.Regulatory requirements for the specific risk.
B.The organization's risk appetite and tolerance levels.
C.The cost of the control versus the potential financial impact of the risk.
D.The likelihood and impact ratings from the risk assessment.
AnswerB

Risk appetite and tolerance define how much risk the organization is willing to accept in pursuit of its objectives. They provide the criteria for determining whether a risk should be mitigated, transferred, or accepted. Without considering these, decisions may not align with business strategy and could lead to excessive risk-taking or unnecessary spending.

Why this answer

The organization's risk appetite and tolerance levels are the most important factor because they establish the boundaries for acceptable risk. They guide whether to mitigate, transfer, or accept a risk, ensuring that decisions align with business strategy. Other factors like cost, likelihood, and regulations inform the decision but do not override the fundamental risk appetite.

Exam trap

The trap here is focusing on quantitative factors like cost or likelihood/impact while overlooking that risk appetite and tolerance provide the qualitative framework for all risk treatment decisions.

462
MCQmedium

A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?

A.Risk avoidance
B.Risk mitigation
C.Risk acceptance
D.Risk transfer
AnswerB

Implementing MFA reduces the likelihood of exploitation by adding a second authentication factor, lowering the inherent risk while retaining the activity. Mitigation treats risk through controls rather than transferring, avoiding or accepting it, matching the risk owner's decision.

Why this answer

Implementing multi-factor authentication (MFA) reduces the likelihood or impact of a security risk by adding additional authentication factors (e.g., something you know, something you have, something you are) beyond a weak password. This directly aligns with risk mitigation, which seeks to decrease the residual risk to an acceptable level through controls. The decision does not eliminate the risk entirely (avoidance), accept it without action, or transfer it to a third party.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk avoidance' because both involve implementing controls, but avoidance means eliminating the activity or technology entirely, whereas mitigation reduces but does not eliminate the risk.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean not implementing the online banking platform or removing the authentication module entirely, which is not the case. Option C is wrong because risk acceptance would involve acknowledging the risk and taking no further action, whereas MFA is an active control. Option D is wrong because risk transfer would involve shifting the financial impact of the risk to another party (e.g., via insurance or outsourcing), not implementing a technical control like MFA.

463
Multi-Selecteasy

Which TWO elements are key components of a security culture measurement program?

Select 2 answers
A.Number of security policies
B.Vulnerability scan frequency
C.Phishing simulation click rates
D.Firewall log size
E.Training completion rates
AnswersC, E

Phishing simulation click rates measure actual employee behaviour against realistic lures, revealing susceptibility that self-reported awareness misses. This satisfies the measurement programme by providing an empirical behavioural indicator of security culture strength and the effectiveness of awareness initiatives.

Why this answer

A security culture measurement program focuses on gauging how people think and behave regarding security, so phishing simulation click rates (C) are a key component because they provide a behavioral metric of how susceptible employees are to real-world social-engineering attacks. Training completion rates (E) are also a key component because they measure the reach and engagement of security awareness education, which is a foundational driver of culture. The other options are technical or volume-based operational metrics rather than culture indicators: the number of security policies (A) reflects documentation, not employee mindset; vulnerability scan frequency (B) is a vulnerability-management cadence metric; and firewall log size (D) is a raw technical/logging volume measure, none of which directly assess human security attitudes or behaviors.

Exam trap

CISM often tests the distinction between technical/operational security metrics (scan frequency, log volume, policy counts) and human-behavioral culture metrics, tricking candidates into selecting control-existence measures instead of behavior-change measures.

464
MCQmedium

A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?

A.Reporting to the CEO or board of directors
B.Reporting to the risk committee
C.Reporting to the CIO
D.Reporting to the chief legal officer
AnswerA

Reporting directly to the CEO or board gives information security a direct line to executive authority, free from operational conflicts held by IT or business units it must oversee. This structural separation preserves independence, ensuring security decisions and risk escalations are not subordinated to the functions being controlled.

Why this answer

For the information security function to have true independence and authority, it must not report to an executive whose objectives it is expected to audit or control. Reporting to the CEO or board of directors gives the CISO organizational independence from IT operations and the authority to enforce security policy across the enterprise. This structure is widely recommended by ISACA and regulatory frameworks for financial services firms.

Exam trap

CISM often tests the misconception that reporting to the risk committee or CIO provides sufficient independence, when true independence requires a reporting line outside IT operations.

How to eliminate wrong answers

Option B is wrong because reporting to the risk committee, while providing some oversight, may still subordinate security to risk management priorities and does not guarantee the same level of authority as board/CEO reporting. Option C is wrong because reporting to the CIO creates a conflict of interest — the CIO owns IT delivery and operations, and security must be able to independently assess and challenge IT. Option D is wrong because reporting to the chief legal officer subordinates security to legal priorities and can dilute the CISO's operational authority over security controls.

465
MCQhard

An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?

A.Delete all compromised data to prevent further exposure.
B.Conduct a thorough impact assessment to determine the scope and nature of the data involved.
C.Publicly announce the breach on the company website to demonstrate transparency.
D.Immediately send a blanket notification to all customers regardless of jurisdiction.
AnswerB

Before notifying regulators or affected individuals, the organization must understand exactly what data was compromised, how many records, and which jurisdictions are affected. This impact assessment informs legal notification obligations and the content of notifications. It is a critical step to ensure accurate and compliant reporting, and it aligns with CISM's emphasis on risk assessment and legal coordination during incident recovery.

Why this answer

After containment and eradication, the next critical step in a data breach involving PII is to assess the scope and impact. This assessment identifies which data elements were exposed, how many individuals are affected, and which jurisdictions' laws apply. It provides the factual basis for legal notification decisions and ensures that notifications are accurate, timely, and compliant with varying regulatory requirements.

Exam trap

The trap here is rushing to notify customers or the public without first determining the scope of the breach, which can lead to non-compliant or inaccurate notifications and unnecessary panic.

466
MCQhard

After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?

A.Increased audit findings
B.Regulatory fines for noncompliance
C.Inaccurate risk profile leading to uninformed decisions
D.Higher insurance premiums
AnswerC

Stale assessments no longer reflect current threats, vulnerabilities or asset values, so the recorded risk profile diverges from reality. This noncompliance with the annual review requirement directly satisfies the stem's consequence: decisions are made on outdated data, misdirecting controls and remediation funding.

Why this answer

C is correct because the primary purpose of a risk assessment is to provide an accurate, current risk profile that informs security decisions and resource allocation. When the assessment is two years out of date, the organization lacks visibility into new threats, vulnerabilities, and changes in the threat landscape, leading to uninformed decisions that can result in security gaps and increased exposure. This directly undermines the risk management process, making it the most significant consequence of noncompliance with the annual review policy.

Exam trap

The trap here is that candidates often focus on tangible, immediate consequences like fines or audit findings, but CISM emphasizes that the most significant impact of noncompliance is the erosion of the risk management process itself—specifically, the inability to make informed decisions based on an accurate risk profile.

How to eliminate wrong answers

Option A is wrong because increased audit findings are a secondary outcome of noncompliance, not the most significant consequence; audits may flag the missing review, but the core harm is the degraded decision-making capability. Option B is wrong because regulatory fines for noncompliance depend on specific legal or contractual requirements (e.g., GDPR, PCI DSS), and while possible, they are not guaranteed and are less impactful than the systemic failure to maintain an accurate risk profile. Option D is wrong because higher insurance premiums may result from a poor risk posture, but they are a financial consequence that follows from the underlying inaccurate risk profile, not the primary risk management failure itself.

467
MCQhard

An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?

A.File a report with the information available and provide updates as the investigation progresses.
B.Request an extension from the SEC because the investigation is ongoing.
C.Delay reporting until the investigation is complete to ensure accuracy.
D.Report the incident only if materiality is confirmed at the end of the investigation.
AnswerA

SEC rules permit filing with incomplete details provided you amend promptly, so filing within the 4-business-day deadline satisfies the reporting constraint while updates cover the ongoing investigation. Waiting for full findings breaches the deadline; silence is not an option.

Why this answer

Regulatory deadlines must be met even if information is incomplete; disclose what is known and update later.

468
MCQeasy

An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?

A.Develop a security awareness training program.
B.Identify business strategy and risk appetite.
C.Design the security architecture based on industry frameworks.
D.Conduct a comprehensive risk assessment.
AnswerB

Aligning security with business objectives requires first understanding the organisation's strategic direction and its tolerance for risk. Identifying business strategy and risk appetite establishes the foundation on which all subsequent security decisions, controls and priorities are built.

Why this answer

Identifying business strategy and risk appetite is the most critical first step because the information security program must be designed to support the organization's objectives and operate within the risk tolerance defined by leadership. Without this alignment, subsequent security controls and investments may conflict with business goals or fail to address the risks the organization is willing to accept. This ensures that security is a business enabler rather than a technical silo.

Exam trap

The trap here is that candidates often mistake conducting a comprehensive risk assessment (Option D) as the first step, but without a defined risk appetite and business strategy, the assessment lacks the context needed to evaluate risk severity and prioritize remediation effectively.

How to eliminate wrong answers

Option A is wrong because developing a security awareness training program is an operational control that should be implemented only after the program's strategic direction, risk appetite, and governance structure are defined; starting with training assumes a baseline of security culture that does not yet exist. Option C is wrong because designing security architecture based on industry frameworks (e.g., NIST, ISO 27001) without first understanding the business strategy and risk appetite can lead to over-engineering or misalignment, wasting resources on controls that do not address the organization's specific risk profile. Option D is wrong because conducting a comprehensive risk assessment requires a predefined risk appetite and business context to determine which risks are acceptable and which require mitigation; without this, the assessment lacks the criteria to prioritize findings effectively.

469
Multi-Selecthard

Which THREE of the following are best practices for handling evidence during an incident investigation?

Select 3 answers
A.Document all actions taken during evidence collection.
B.Maintain a chain of custody log.
C.Analyze evidence directly on live systems to avoid delays.
D.Create a forensic image of the affected systems.
E.Store evidence in its original location to avoid disturbance.
AnswersA, B, D

Contemporaneous documentation records every action, tool and timestamp during collection, preserving evidential integrity and enabling the investigation to be reconstructed and defended. This satisfies the best-practice requirement for accountability and auditability throughout the incident investigation.

Why this answer

Option A is correct because documenting every action taken during evidence collection creates an auditable record that preserves the integrity and admissibility of the evidence, showing exactly who did what and when. Option B is correct because a chain of custody log tracks the seizure, transfer, and storage of evidence, ensuring it has not been tampered with and remains admissible in legal or disciplinary proceedings. Option D is correct because creating a forensic image (a bit-for-bit copy, typically verified with a hash such as MD5 or SHA-256) allows analysis to be performed on the copy while preserving the original evidence in its unaltered state.

Option C is not a best practice because analyzing evidence directly on live systems can alter timestamps, memory contents, and file metadata, destroying or contaminating potential evidence; analysis should be done on forensic copies. Option E is not a best practice because evidence should be collected, documented, and stored securely in a controlled location rather than left in place, where it could be modified, lost, or compromised.

Exam trap

The trap here is that candidates may confuse 'analyze evidence directly on live systems' (Option C) as acceptable for speed, but CISM emphasizes preservation of evidence integrity over expedience, and 'store evidence in its original location' (Option E) may seem logical but violates the principle of securing evidence in a controlled chain of custody.

470
MCQeasy

A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?

A.Report the vulnerability to the payment card brand immediately
B.Implement a web application firewall in front of the point-of-sale system
C.Validate the risk and determine its priority based on likelihood and impact
D.Purchase a cyber insurance policy to cover potential card replacement costs
AnswerC

The risk treatment process begins with validating the identified risk and prioritizing it using criteria such as likelihood, impact, and alignment with risk appetite. Only after the risk is confirmed and ranked can appropriate treatment options be evaluated. This ensures resources are directed to the most significant risks first and that treatment decisions are justified and consistent.

Why this answer

The risk treatment process starts with validating the identified risk and prioritizing it based on likelihood, impact, and risk appetite. Only after the risk is confirmed and ranked can the organization evaluate treatment options such as mitigation, transfer, avoidance, or acceptance. Jumping directly to a control, insurance, or external reporting bypasses this essential prioritization step and may misallocate resources.

Exam trap

The trap here is selecting an action that sounds responsible, such as implementing a control or reporting externally, without first validating and prioritizing the risk.

471
MCQmedium

An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?

A.Eradicate the malware and restore systems
B.Perform root cause analysis
C.Conduct a lessons learned meeting
D.Notify regulatory authorities
AnswerA

Containment stops spread but leaves malicious artefacts resident. Eradication removes malware, persistence mechanisms, and compromised accounts, after which systems are restored from trusted backups. This follows the incident management lifecycle sequence, so eradication and restoration is the next step after containment.

Why this answer

After containment, the next priority is eradication of the threat to remove all traces of the malware and restore systems securely.

472
MCQeasy

What is the primary function of a Security Operations Center (SOC)?

A.Designing the security architecture
B.Developing security policies and standards
C.Conducting security awareness training
D.Continuous monitoring, detection, and response to security threats
AnswerD

A SOC's core purpose is round-the-clock visibility: correlating telemetry, detecting anomalous activity and orchestrating response. This continuous monitoring and response capability distinguishes it from governance, architecture or compliance functions, directly satisfying the stem's demand for the primary operational function.

Why this answer

A SOC's primary mission is continuous monitoring of security telemetry, detecting threats, and coordinating response actions. It operates 24/7 using SIEM, EDR, and threat intelligence to identify and triage incidents in real time. This detection-and-response focus distinguishes the SOC from architecture, policy, or training functions.

Exam trap

CISM often tests the boundary between operational security functions (SOC monitors and responds) and governance/design functions (architecture, policy), so candidates who associate 'security' broadly with the SOC pick options A or B.

How to eliminate wrong answers

Option A is wrong because designing security architecture is the responsibility of security architects, often within a security architecture or engineering team, not the SOC. Option B is wrong because developing policies and standards is a governance function performed by the CISO office or security management, not the SOC's operational monitoring role. Option C is wrong because security awareness training is delivered by the security awareness or HR/training function, not the SOC, which focuses on monitoring and response.

473
Multi-Selectmedium

A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)

Select 2 answers
A.Weekly vulnerability scans
B.Role-based access control (RBAC) with least privilege
C.Single sign-on (SSO) implementation
D.Encryption of data at rest
E.Input validation and sanitization
AnswersB, E

RBAC with least privilege enforces authorisation at the application layer, restricting each identity to only the functions its role requires. This limits the blast radius of compromised credentials or insider misuse, satisfying defence-in-depth by adding an access-control layer independent of perimeter and network defences.

Why this answer

Option B (RBAC with least privilege) is correct because it enforces authorization by granting users only the minimum permissions needed for their roles, directly limiting the blast radius of compromised accounts and insider misuse—a core preventive control in any defense-in-depth strategy. Option E (input validation and sanitization) is correct because it defends against injection flaws such as SQLi, XSS, and command injection by rejecting or neutralizing untrusted input at the application boundary, addressing the most common application-layer attack vector. Together these controls cover both access control and secure input handling, which are foundational application security layers.

Option A is not among the marked answers because periodic vulnerability scans are detective/assessment activities that identify issues rather than directly preventing exploitation. Option C is not marked because SSO centralizes authentication and improves usability but does not by itself enforce least privilege or stop injection attacks. Option D is not marked because encryption at rest protects stored data confidentiality but does not prevent application-layer attacks like injection or privilege abuse.

Exam trap

CISM often tests the distinction between preventive controls (RBAC, input validation) and detective or convenience controls (scans, SSO, encryption at rest), tricking candidates into selecting broad-sounding options that do not directly stop the most likely application attacks.

474
MCQhard

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

A.Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms
B.Accept the risk because the CSP has strong security certifications and the likelihood of a breach is low
C.Cancel the cloud migration and build a new private data center in a compliant location
D.Transfer the risk by purchasing cyber insurance that covers regulatory fines
AnswerA

Dedicated HSMs place cryptographic key custody under the organisation's control, while contractual region restrictions enforce data residency, directly addressing both identified gaps. Because the board's low risk appetite demands mitigation to an acceptable level, these controls reduce the CSP-dependent risks rather than merely accepting or transferring them.

Why this answer

It directly addresses the root causes: data residency non-compliance and lack of control over encryption keys. Requiring dedicated hardware security modules (HSMs) and restricting data storage to approved regions through contractual terms ensures that the organization retains control over key management and meets regulatory requirements. This aligns with the low risk appetite and the board's mandate to mitigate risks to an acceptable level.

Option B (accept the risk) is incorrect because it contradicts the board's mandate to mitigate all risks, and certifications alone do not guarantee compliance.

Option C (cancel migration) is too drastic and costly; the organization can achieve compliance with the CSP rather than abandoning the cloud migration.

Option D (transfer risk via insurance) does not achieve regulatory compliance; fines may still be imposed regardless of insurance coverage.

Exam trap

Candidates may mistakenly believe that accepting risk is viable when the CSP has strong certifications, but the board's mandate requires mitigation, not acceptance.

475
MCQeasy

Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?

A.Insider threat: jsmith intentionally exfiltrated data
B.Attacker compromised jsmith's credentials, established C2, and exfiltrated data
C.Network scan from 10.0.0.45 triggered false positives
D.Malware downloaded on jsmith's workstation and exfiltrated data
AnswerB

Pattern matches credential compromise, C2, and exfiltration.

Why this answer

The correct sequence is that an attacker compromised jsmith's credentials, established command-and-control (C2) communication, and then exfiltrated data. The alerts show a brute-force or credential-stuffing attempt from an external IP (10.0.0.45) against jsmith's account, followed by an outbound C2 beacon (e.g., DNS or HTTP) from jsmith's workstation, and finally a large data transfer to an external destination. This matches the typical kill chain: initial access via compromised credentials, persistence via C2, and data exfiltration as the final objective.

Exam trap

ISACA often tests the distinction between a network scan and a targeted credential attack; the trap here is that candidates see the same source IP (10.0.0.45) and assume it's a scan, but the specific sequence of authentication failures followed by C2 and exfiltration indicates a successful compromise, not a reconnaissance scan.

How to eliminate wrong answers

Option A is wrong because the alerts show an external IP (10.0.0.45) initiating the authentication attempts, not an internal user acting maliciously; insider threat would show internal anomalies like abnormal access times or data transfers to internal shares, not external C2 beacons. Option C is wrong because a network scan from 10.0.0.45 would generate multiple connection attempts to various ports/IPs, not a targeted credential attack against a single user followed by C2 traffic and data exfiltration; the specific sequence of authentication failures, beaconing, and data transfer indicates a targeted compromise, not a scan. Option D is wrong because malware downloaded on jsmith's workstation would typically show a file download event (e.g., HTTP GET to a malicious URL) before C2 activity, but the first alert is authentication failures, suggesting credential compromise occurred before any malware delivery; the sequence starts with credential attacks, not download events.

476
Drag & Dropmedium

Order the steps for a risk assessment process according to ISACA's risk management framework.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment starts with identification, then analysis, evaluation, treatment, and continuous monitoring.

477
MCQmedium

In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?

A.To update the incident response plan and playbooks based on findings.
B.To provide a final report to regulators and law enforcement.
C.To assign blame for the incident and take disciplinary action.
D.To calculate the total financial loss from the incident.
AnswerA

Conducting lessons learned within two weeks, while details remain fresh, enables prompt revision of the incident response plan and playbooks. This directly satisfies the stem's primary purpose, embedding findings into documented procedures before organisational memory fades.

Why this answer

The main goal is to improve future incident response by identifying what worked and what didn't.

478
MCQhard

During a security incident, the incident response team discovers that an attacker has exfiltrated data via an encrypted tunnel over HTTPS. Which log source is MOST likely to provide evidence of the exfiltration?

A.Web server access logs
B.Firewall logs
C.Intrusion detection system (IDS) logs
D.Proxy logs
AnswerD

Proxy logs can show all HTTPS traffic, including destinations and data sizes.

Why this answer

Proxy logs are the most likely source because they can record the full URL and HTTP headers of HTTPS requests, including the destination host and path, even though the payload is encrypted. Since the attacker exfiltrated data over an encrypted tunnel, the proxy log can show the outbound connection to the command-and-control server or data storage endpoint, providing evidence of the exfiltration activity.

Exam trap

The trap here is that candidates often choose firewall logs or IDS logs because they think network-level logs will show the exfiltration, but they forget that HTTPS encryption hides the application-layer details, making proxy logs (with SSL inspection) the only reliable source for evidence of the exfiltration.

How to eliminate wrong answers

Option A is wrong because web server access logs only record requests to the web server itself, not outbound connections from internal hosts to external servers, so they would not capture the exfiltration traffic. Option B is wrong because firewall logs typically record source/destination IPs and ports but not the full URL or application-layer details, and HTTPS encryption hides the payload, making it difficult to identify data exfiltration from firewall logs alone. Option C is wrong because intrusion detection system (IDS) logs rely on signature or anomaly detection, and encrypted HTTPS traffic often bypasses IDS inspection unless SSL/TLS decryption is in place, which is not assumed in this scenario.

479
MCQhard

A global financial services firm is aligning its information security program with the COBIT framework. The board wants assurance that IT risks are governed effectively. Which COBIT component is MOST directly responsible for ensuring that IT risk management activities are aligned with enterprise risk management?

A.MEA03 Managed Compliance with External Requirements
B.DSS05 Managed Security Services
C.EDM03 Ensured Risk Optimization
D.APO12 Managed Risk
AnswerC

EDM03 is a governance domain process in COBIT that ensures IT-related risk management is aligned with enterprise risk management and that risk appetite is understood and communicated. It directly addresses board-level oversight of risk optimization, making it the most direct component for aligning IT risk with enterprise risk.

Why this answer

EDM03 is part of the governance domain in COBIT and specifically ensures that IT risk management is integrated with enterprise risk management, including setting risk appetite and tolerance. This directly addresses the board's need for assurance that IT risks are governed effectively and aligned with overall enterprise risk.

Exam trap

The trap here is assuming that any risk-related process, such as APO12, fulfills the governance requirement, when only the evaluate, direct, and monitor domain provides board-level alignment.

480
MCQeasy

An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?

A.Implement a security incident response plan
B.Perform regular vulnerability scans
C.Involve business stakeholders in the security steering committee
D.Conduct annual security awareness training
AnswerC

A security steering committee containing business stakeholders aligns the information security programme with business objectives by giving business owners direct governance input into risk decisions, priorities and funding. This satisfies the stem's alignment goal, unlike purely technical measures that lack business representation and accountability.

Why this answer

Involving business stakeholders in the security steering committee ensures that security initiatives are directly aligned with business objectives, as stakeholders provide input on risk tolerance, regulatory requirements, and strategic goals. This collaborative governance model allows the security program to prioritize resources and controls based on business impact, rather than operating in isolation. It is the most effective approach because it integrates security decision-making with business planning, which is a core principle of the CISM framework.

Exam trap

The trap here is that candidates often choose a technical or operational control (like vulnerability scans or incident response) because they seem directly related to security, but CISM emphasizes that strategic alignment with business objectives requires governance-level involvement, not just technical activities.

How to eliminate wrong answers

Option A is wrong because implementing a security incident response plan is a reactive operational measure that addresses how to handle breaches, not how to align the security program with business objectives. Option B is wrong because performing regular vulnerability scans is a technical assessment activity that identifies system weaknesses but does not involve business input or strategic alignment. Option D is wrong because conducting annual security awareness training is a compliance and education activity that reduces human risk but does not directly link security program governance to business goals.

481
Multi-Selecthard

A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)

Select 2 answers
A.Rate every OT risk using only the maximum potential financial loss to keep scoring consistent.
B.Record each risk with an owner, inherent and residual ratings, and the linked business process or asset.
C.Exclude risks that already have compensating controls from the register to reduce noise.
D.Aggregate all OT findings into a single enterprise risk to simplify board reporting.
E.Map each OT risk to the relevant regulatory, contractual, or safety obligation it could affect.
AnswersB, E

Assigning an owner, documenting inherent and residual ratings, and linking to the affected process or asset makes the register actionable. Ratings show how controls change exposure, and linkage enables prioritization based on business impact. Without these elements, the register becomes a list that cannot drive treatment decisions or accountability in an OT context where safety and availability matter.

Why this answer

An effective risk register captures ownership, inherent and residual ratings, and business linkage, and it maps risks to the obligations they could affect. These practices enable prioritization and accountability. Aggregating findings, using only financial impact, or excluding controlled risks all reduce the register's usefulness for managing OT exposure where safety and availability are critical.

Exam trap

The trap here is treating a risk register as a simplified summary rather than a granular, owned, and obligation-linked inventory.

482
MCQeasy

Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?

A.Reporting to the CIO
B.Reporting to the head of legal
C.Reporting to the CEO or board of directors
D.Reporting to the CFO
AnswerC

Reporting to the CEO or board removes subordination to the CIO or other IT leaders whose delivery priorities may conflict with security, preserving independent oversight. Direct board access also aligns security strategy with business objectives, satisfying both stem constraints.

Why this answer

Reporting to the CEO or board ensures the CISO has the authority and independence to influence security strategy without conflicting priorities from IT operations.

483
MCQhard

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

A.All IGs simultaneously
B.IG3
C.IG1
D.IG2
AnswerC

IG1 defines the foundational cyber hygiene safeguards achievable with limited resources and no dedicated security staff, matching the small business constraint. Prioritising IG1 addresses the most prevalent attack vectors first, providing essential protection before progressing to IG2 or IG3.

Why this answer

CIS Controls v8 defines Implementation Group 1 (IG1) as the foundational set of safeguards appropriate for small organizations with limited cybersecurity resources and low data sensitivity. IG1 covers essential hygiene controls (inventory, patching, access control, malware defenses) that provide the highest risk reduction per unit of effort. A small business should implement IG1 first and only progress to IG2/IG3 as resources and risk profile grow.

Exam trap

CISM often tests the misconception that 'more controls equals better security,' leading candidates to select IG3 as the most comprehensive answer when the question explicitly describes a resource-constrained small business.

How to eliminate wrong answers

Option A is wrong because attempting all IGs simultaneously is impractical for a resource-constrained small business and contradicts the risk-prioritized, incremental design of the CIS Implementation Groups. Option B is wrong because IG3 is intended for organizations facing sophisticated threats (e.g., large enterprises, critical infrastructure) and assumes IG1 and IG2 are already fully implemented. Option D is wrong because IG2 builds on IG1 and is aimed at organizations with moderate resources and risk; skipping IG1 to start at IG2 leaves foundational safeguards unaddressed.

484
MCQmedium

Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?

A.NIST SP 800-53
B.CIS Controls v8
C.COBIT 2019
D.ISO 27001 Annex A
AnswerB

CIS Controls v8 uniquely structures its prioritised safeguards into Implementation Groups IG1, IG2 and IG3, matched to organisational risk and resources. No other framework in the stem's options offers this explicit IG-based prioritisation, directly satisfying the stated requirement.

Why this answer

CIS Controls v8 is uniquely structured around Implementation Groups (IG1, IG2, IG3), which prioritize safeguards based on organizational size, resources, and risk. No other major framework uses this exact IG tiering model. The question's mention of 'prioritized set of controls based on implementation groups' is a direct signature of CIS Controls v8.

Exam trap

CISM often tests framework confusion — candidates who memorize 'NIST = controls' or 'ISO = security' without understanding the unique IG tiering of CIS Controls v8 will pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-53 organizes controls into baselines (Low, Moderate, High) tied to FIPS 199 impact categories, not Implementation Groups. Option C is wrong because COBIT 2019 is a governance and management framework focused on IT processes and maturity levels, not a prioritized control catalog with IGs. Option D is wrong because ISO/IEC 27001 Annex A provides a flat set of 93 controls (in the 2022 revision) without an IG-style tiering mechanism.

485
MCQhard

A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?

A.Number of security architects, SOC analyst headcount, and security tool count
B.Mean time to detect (MTTD), mean time to respond (MTTR), and number of breaches
C.Number of security incidents, percentage of systems patched, and security awareness training completion rate
D.Phishing click rate, number of vendor assessments completed, and security budget spent
AnswerB

MTTD and MTTR measure detection and response capability, while breach count shows realised impact, together covering the programme's operational effectiveness. This combination gives the board outcome and capability insight rather than raw technical volume, satisfying the meaningful overview requirement.

Why this answer

MTTD, MTTR, and number of breaches directly measure how quickly the security program detects and contains incidents and how often it fails, which is what a board needs to judge effectiveness. These are outcome-oriented metrics tied to risk, not activity counts. They translate technical operations into business-relevant resilience indicators.

Exam trap

CISM often tests the distinction between activity/input metrics (tools, headcount, budget) and outcome/effectiveness metrics (MTTD, MTTR, breaches) — candidates pick busy-sounding operational stats that do not answer the board's risk question.

How to eliminate wrong answers

Option A is wrong because headcount and tool counts are input/resource metrics, not effectiveness measures — more tools and staff do not prove better security. Option C is wrong because incident count, patch percentage, and training completion are operational hygiene metrics; they are useful to the CISO but do not directly show detection/response capability or breach impact to the board. Option D is wrong because phishing click rate, vendor assessments, and budget spent are activity and spend metrics that measure effort, not outcomes, and budget spent is especially misleading as a success indicator.

486
MCQhard

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

A.Cost of security incidents as a percentage of revenue
B.Percentage of security incidents detected within defined SLAs
C.Number of security training hours per employee
D.Customer satisfaction survey scores on data protection
AnswerB

Percentage of security incidents detected within defined SLAs measures operational efficiency of the security function itself, which maps directly to COBIT's Internal Processes perspective. It satisfies the board's need for a balanced scorecard metric reflecting process capability and execution, rather than financial, customer or learning-and-growth outcomes.

Why this answer

The 'Internal Processes' perspective of a balanced scorecard focuses on the efficiency and effectiveness of internal operational processes. The percentage of security incidents detected within defined SLAs directly measures the performance of the security monitoring and incident response processes, which are core internal processes in a COBIT-based information security program.

Exam trap

In this CISM question, the trap is that candidates confuse 'Internal Processes' with 'Learning and Growth' (training hours) or 'Financial' (cost metrics), failing to recognize that SLAs directly measure the operational effectiveness of security processes themselves in a COBIT-based program.

How to eliminate wrong answers

Option A is wrong because 'Cost of security incidents as a percentage of revenue' is a financial metric, aligning with the 'Financial' perspective, not 'Internal Processes'. Option C is wrong because 'Number of security training hours per employee' is a learning and growth metric, measuring human capital development, not internal process efficiency. Option D is wrong because 'Customer satisfaction survey scores on data protection' is a customer perspective metric, focusing on external stakeholder perception, not internal operational processes.

487
Multi-Selectmedium

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that security risks are managed effectively and that the program aligns with regulatory requirements. Which TWO elements are MOST critical for the CISO to define as part of this governance framework? (Choose two.)

Select 2 answers
A.A process for reporting security metrics and risk posture to the board on a regular basis.
B.A list of all security tools deployed across the enterprise with their versions and patch levels.
C.The annual security budget with line-item allocations for each department.
D.Detailed technical procedures for incident response and disaster recovery.
E.Security roles and responsibilities for the board, executives, and business units.
AnswersA, E

A regular reporting process is critical for governance because it provides the board with the information needed to oversee security risks and ensure alignment with business objectives. It enables informed decision-making and accountability. Without consistent reporting, the board cannot assess the effectiveness of the security program or fulfill its fiduciary duties, and the CISO cannot demonstrate that risks are being managed in line with regulatory expectations.

Why this answer

Defining security roles and responsibilities and establishing a regular reporting process are the most critical elements of a governance framework because they establish accountability and provide the board with the necessary information for oversight. Roles ensure that decision-making authority is clear, while reporting enables the board to monitor risk and compliance. Together, they form the foundation for effective governance and assurance.

Exam trap

The trap here is confusing operational artifacts like tool inventories or incident response procedures with governance elements, which focus on accountability and oversight.

488
MCQmedium

An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?

A.P2 — High
B.P4 — Low
C.P1 — Critical
D.P3 — Medium
AnswerC

P1 Critical is reserved for incidents causing major business disruption, such as encrypted critical servers halting operations. It triggers immediate escalation, full crisis team activation and continuous response until resolved, matching the severity criteria stated in the stem.

Why this answer

A ransomware attack that encrypts critical servers and causes major business disruption is a critical incident, warranting a P1 priority. P1 incidents are reserved for those with severe impact on business operations, requiring immediate response and escalation. The encryption of critical servers directly threatens the organization's ability to operate, making P1 the appropriate severity level.

Exam trap

The trap is underestimating the severity of a ransomware attack on critical servers, leading candidates to choose P2 or P3 instead of recognizing the major business disruption as P1.

How to eliminate wrong answers

Option A is wrong because P2 (High) is for significant incidents that impact important functions but do not cause major business disruption or affect critical servers; the described scenario is more severe. Option B is wrong because P4 (Low) is for minor incidents with negligible impact, which is clearly not the case here. Option D is wrong because P3 (Medium) is for moderate incidents that cause limited disruption, whereas this ransomware attack has major business disruption, elevating it to P1.

489
MCQmedium

During an incident investigation, the response team discovers that the attacker exploited a known vulnerability for which a patch was available but not applied. What should be the team's primary focus during the recovery phase?

A.Applying the missing patch and ensuring all systems are updated.
B.Disciplining the employee responsible for patch management.
C.Conducting a lessons-learned meeting.
D.Reporting the incident to law enforcement.
AnswerA

Applying the missing patch closes the exploited vulnerability, satisfying the recovery phase's requirement to restore secure operations. Patching alone, however, does not address the root cause: the failed patch-management process that left the flaw unpatched. Recovery must also verify no persistence remains before returning systems to production.

Why this answer

The primary goal of the recovery phase is to restore secure operations and prevent recurrence. Applying the missing patch directly remediates the exploited vulnerability, eliminating the attacker's entry point and hardening the system against future exploitation of that specific CVE. This aligns with the NIST SP 800-61 recovery step of 'removing artifacts and restoring systems to a secure state'.

Exam trap

The trap here is that candidates confuse the recovery phase with the post-incident activity phase, choosing 'lessons learned' (Option C) instead of the immediate technical fix required to restore a secure state.

How to eliminate wrong answers

Option B is wrong because the immediate priority is technical remediation, not HR actions; discipline is a separate organizational process that occurs after recovery and does not restore security. Option C is wrong because a lessons-learned meeting is part of the post-incident activity phase, not the recovery phase, and does not directly address the active vulnerability. Option D is wrong because reporting to law enforcement is a legal/compliance step that may run in parallel but does not fix the exploited vulnerability or restore system integrity.

490
MCQhard

An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:

A.Update the information security policy
B.Establish a centralized security oversight function
C.Increase security awareness training frequency
D.Conduct a risk assessment for each department
AnswerB

Inconsistent control application across departments stems from fragmented ownership. A centralized security oversight function standardises policy enforcement, monitoring and accountability across all business units, directly satisfying ISO 27001's requirement for consistent control operation organisation-wide rather than leaving each department to interpret controls independently.

Why this answer

The core issue is inconsistent control application across departments, which indicates a lack of governance and oversight rather than a policy or awareness deficiency. Establishing a centralized security oversight function directly addresses this by creating a single authority to enforce, monitor, and standardize control implementation, ensuring alignment with ISO 27001 requirements for management commitment and resource allocation (Clause 5.1 and 7.1). This corrective action provides the necessary organizational structure to drive consistent execution, which is the most effective long-term solution.

Exam trap

The trap here is that candidates confuse the symptom (inconsistent application) with the root cause (lack of governance), leading them to choose awareness training or policy updates, which are tactical fixes rather than strategic corrective actions.

Why the other options are wrong

A

Policy likely exists; issue is execution.

C

Training addresses knowledge, not enforcement.

D

Risk assessment would identify gaps but not fix consistency.

491
MCQmedium

BankOne has a mature security governance program but recently failed a regulatory audit because the board had not formally approved the risk appetite statement. The CISO argues that risk appetite is reviewed annually and was verbally approved. To prevent recurrence, what governance change is most effective?

A.Automate risk appetite monitoring
B.Reduce the number of risk indicators
C.Document all board approvals in minutes
D.Require board resolution for risk appetite annually
AnswerD

A board resolution creates a formal, auditable record of approval, satisfying the regulatory requirement that the board itself owns risk appetite. Annual review alone lacks documented authority, so mandating resolution closes the governance gap the audit identified.

Why this answer

The core issue is the lack of formal, documented board approval of the risk appetite statement, which is a governance requirement. A formal board resolution, passed and recorded annually, creates an auditable record that satisfies regulatory scrutiny and ensures the board's explicit ownership of risk tolerance. This directly addresses the audit failure by moving from informal verbal approval to a legally binding, documented governance process.

Exam trap

The trap here is that candidates confuse operational improvements (like automating monitoring or reducing indicators) with governance-level fixes, failing to recognize that the audit failure was due to a lack of formal, documented board approval, not a deficiency in the monitoring or reporting process.

How to eliminate wrong answers

Option A is wrong because automating risk appetite monitoring addresses ongoing measurement and reporting, not the root cause of missing formal board approval; it does not create the required documentation of the board's decision. Option B is wrong because reducing the number of risk indicators would weaken the monitoring framework and does not solve the documentation or approval gap. Option C is wrong because while documenting approvals in minutes is better than verbal approval, it is less formal and auditable than a dedicated board resolution; minutes may not capture the specific language of the risk appetite statement or the board's explicit vote, and they can be challenged as insufficient for regulatory compliance.

492
Multi-Selecthard

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Select 2 answers
A.Allowing the firm to make independent decisions on containment
B.Having the firm report directly to the media
C.Maintaining chain of custody for all evidence
D.Defining the scope of work and evidence handling procedures
E.Ensuring the firm uses only proprietary tools
AnswersC, D

Chain of custody preserves evidence integrity so it remains admissible in legal or disciplinary proceedings. When an external firm handles artefacts, unbroken documented transfer records satisfy the evidentiary constraint the scenario demands, preventing challenges to forensic findings.

Why this answer

Option C is correct because maintaining chain of custody is essential when an external forensics firm handles evidence; documented, unbroken custody records ensure the evidence remains admissible in legal or disciplinary proceedings and prevents tampering or spoliation. Option D is correct because a clear scope of work plus agreed evidence-handling procedures define what the firm will investigate, how it will collect and preserve data, and what deliverables and timelines apply, preventing misunderstandings and unauthorized actions. The unmarked options do not belong: A is wrong because containment decisions should remain with the incident response team or management under the organization's authority, not be delegated independently to the forensics firm; B is wrong because media communications must go through the organization's designated spokesperson or PR/legal team, not the external firm; and E is wrong because requiring only proprietary tools is unnecessary and can hinder analysis, whereas validated, forensically sound tools and documented methods are what matter.

493
MCQeasy

A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?

A.Conduct a detailed cost-benefit analysis to convince the risk owner to upgrade, but do not escalate until the analysis is complete.
B.Accept the risk owner's decision and update the risk register to reflect the deferred treatment with a note of the risk owner's acceptance.
C.Implement a compensating control, such as strong application-layer encryption, to reduce the residual risk to an acceptable level without upgrading TLS.
D.Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
AnswerD

The risk owner's refusal exceeds their delegated authority because the risk appetite statement permits moderate residual risk only with CRO approval. Escalating to the risk management committee routes the accept, mitigate or defer decision to the body mandated to resolve it.

Why this answer

When a risk owner refuses to accept a risk that exceeds the organization's stated risk appetite and the risk owner also refuses to treat it, the information security manager must escalate through the defined governance channel — here, the risk management committee. The risk appetite statement only permits moderate residual risk with explicit CRO approval, so the head of network operations cannot unilaterally defer a high-rated regulatory risk. Escalation ensures the decision is made at the appropriate authority level with full visibility of regulatory and reputational exposure.

Exam trap

CISM often tests the misconception that a risk owner's decision is always final — candidates forget that risk acceptance authority is bounded by the organization's risk appetite and must be escalated when exceeded.

How to eliminate wrong answers

Option A is wrong because waiting for a cost-benefit analysis before escalating delays governance when the risk already exceeds appetite and the risk owner has refused treatment — escalation should not be contingent on further analysis. Option B is wrong because the risk owner cannot accept a risk that exceeds the documented risk appetite; only the CRO or risk management committee can authorize that acceptance. Option C is wrong because implementing a compensating control unilaterally bypasses the risk owner and the governance process, and application-layer encryption may not satisfy the specific regulatory mandate for TLS 1.3 in transit.

494
MCQmedium

A multinational corporation is implementing a risk-based approach to information security governance. The chief information security officer (CISO) has been asked to prioritize security initiatives based on business impact. Which of the following actions should the CISO take FIRST to align security governance with business objectives?

A.Enforce multifactor authentication (MFA) for all remote access.
B.Implement a compliance management tool to track regulatory requirements.
C.Deploy a security information and event management (SIEM) system to centralize log analysis.
D.Conduct a business impact analysis (BIA) to identify critical processes and their security requirements.
AnswerD

A business impact analysis identifies which processes are critical and the security requirements each demands, giving the CISO the business-context foundation needed to prioritise initiatives by impact. Without this, risk ranking lacks alignment with actual business objectives and critical dependencies.

Why this answer

Conducting a business impact analysis (BIA) is the foundational step in a risk-based governance approach because it identifies critical business processes, their recovery time objectives (RTOs), and the specific security requirements needed to protect them. Without this analysis, the CISO cannot align security initiatives with business impact, as the BIA directly links security controls to the organization's most valuable assets and operational priorities.

Exam trap

The trap here is that candidates often confuse tactical security controls (like MFA or SIEM) with the strategic governance step of first understanding business impact, leading them to select a technically correct but sequentially premature answer.

How to eliminate wrong answers

Option A is wrong because enforcing MFA for all remote access is a tactical control that should be prioritized based on BIA findings, not implemented first without understanding which processes and data are most critical. Option B is wrong because implementing a compliance management tool addresses regulatory tracking but does not establish the business impact or risk prioritization needed to align security governance with business objectives. Option C is wrong because deploying a SIEM system centralizes log analysis for detection and response, but it is a reactive measure that should be scoped and prioritized after the BIA identifies which systems and data require monitoring.

495
MCQhard

A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?

A.Accept the residual risk with formal sign-off from senior management
B.Adjust the risk appetite to 'moderate' to align with the residual risk
C.Transfer the risk by taking out an insurance policy
D.Approve additional controls to lower residual risk regardless of cost
AnswerA

Where further reduction costs $1 million and exceeds the expected benefit, the risk owner accepts the residual risk with formal senior management sign-off. This satisfies the stem's constraint of a low risk appetite against an uneconomic control.

Why this answer

The risk owner has determined that the cost to further reduce the residual risk ($1 million) exceeds the expected benefit, making additional controls economically unjustifiable. Since the company's risk appetite is 'low' for operational risks but the residual risk is 'high', the most appropriate action is to formally accept the residual risk with senior management sign-off, as this documents the decision and acknowledges the deviation from the stated risk appetite. This aligns with the CISM principle that risk acceptance is a valid treatment option when the cost of mitigation outweighs the benefit, provided it is approved at the appropriate level.

Exam trap

The trap here is that candidates confuse 'risk acceptance' with 'ignoring the risk' or assume that a low risk appetite always mandates mitigation, failing to recognize that formal acceptance with senior sign-off is a legitimate and required response when cost-benefit analysis shows mitigation is not justified.

How to eliminate wrong answers

Option B is wrong because adjusting the risk appetite to 'moderate' to align with the residual risk is a reactive and inappropriate approach; risk appetite should be set by the board based on strategic objectives, not changed to justify a single risk assessment outcome. Option C is wrong because transferring the risk via insurance does not reduce the residual risk rating; it only shifts the financial impact, and the high-speed trading platform's operational risk (e.g., latency, system failure) may not be fully insurable or cost-effective given the premium. Option D is wrong because approving additional controls regardless of cost violates the principle of cost-benefit analysis; the question explicitly states the cost exceeds the expected benefit, making this option economically unsound and contrary to risk management best practices.

496
MCQmedium

During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?

A.Copy the evidence to a shared network folder so legal, HR, and IT can all review it as needed
B.Maintain a documented chain of custody, hash the images, and store them in a restricted evidence repository
C.Allow the employee to continue working normally while quietly monitoring activity to gather more evidence
D.Delete the laptop image after extracting only the relevant pricing files to reduce storage and privacy risk
AnswerB

Forensic evidence must remain admissible and defensible, which requires verifiable integrity and unbroken custody. Hashing the images at acquisition proves they were not altered, while a documented chain of custody records every transfer, and a restricted repository prevents tampering. Because litigation is still undecided, preserving evidence in this rigorous manner keeps all options open. This approach satisfies both internal investigation needs and potential legal proceedings without prejudging the outcome.

Why this answer

When litigation is undecided, the safest course is to preserve evidence so it remains usable in any proceeding. Hashing the forensic images at acquisition, documenting every transfer in a chain of custody, and storing copies in a restricted repository together establish integrity and control. These steps prevent alteration, support authentication, and keep access limited.

Continued monitoring without preservation, selective deletion, or broad sharing all risk destroying or contaminating evidence before legal counsel determines the organization's position.

Exam trap

The trap here is treating the investigation as purely internal and skipping formal evidence controls, when undecided litigation makes chain of custody and hashing essential from the first acquisition.

497
MCQmedium

An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?

A.Automate security compliance monitoring across all business units.
B.Update the information security policy to mandate compliance.
C.Conduct a risk assessment to identify gaps and prioritize remediation.
D.Implement additional security controls across all business units.
AnswerC

A risk assessment establishes which control gaps matter most and their business impact, giving the CISO evidence to prioritise remediation across business units. Acting on audit findings without this analysis risks misallocating limited resources to lower-impact issues.

Why this answer

Conducting a risk assessment first (Option C) is the correct initial step because it systematically identifies where controls are failing or missing across business units, quantifies the associated risks, and prioritizes remediation based on business impact. Without this foundational analysis, any subsequent actions—such as automation, policy updates, or new controls—would lack direction and could waste resources on low-priority areas. This aligns with the CISM program lifecycle, where risk assessment drives all other program improvements.

Exam trap

ISACA often tests the principle that a risk assessment must precede any control implementation or policy change, tempting candidates to jump to automation or enforcement actions without first understanding the specific gaps.

How to eliminate wrong answers

Option A is wrong because automating compliance monitoring without first understanding which controls are inconsistently applied and why would simply automate the detection of known gaps without addressing root causes or prioritizing fixes. Option B is wrong because updating the policy to mandate compliance does not address the underlying issue of inconsistent application; it only reiterates requirements without providing a mechanism to identify or remediate the specific gaps. Option D is wrong because implementing additional controls across all business units without a prior risk assessment could introduce unnecessary complexity, increase costs, and fail to target the actual weaknesses, potentially creating new compliance gaps.

498
MCQeasy

A CISO is developing an information security governance framework for a financial institution. Which of the following is the PRIMARY purpose of such a framework?

A.Minimize risks to an acceptable level
B.Align security with business objectives
C.Ensure compliance with regulatory requirements
D.Deploy the latest security technologies
AnswerB

Governance exists to direct security investment and decisions toward organisational goals, not to serve technology for its own sake. Aligning security with business objectives ensures controls enable strategy and satisfy regulatory obligations, which is the framework's primary purpose for a financial institution.

Why this answer

The primary purpose of an information security governance framework is to align security initiatives with business objectives, ensuring that security investments and activities directly support the organization's strategic goals. For a financial institution, this alignment ensures that security governance drives value, manages risk in context of business priorities, and enables informed decision-making by leadership.

Exam trap

The trap here is that candidates often confuse the tactical goal of risk reduction (Option A) with the strategic purpose of governance, but CISM emphasizes that governance is about aligning security with business objectives, not just minimizing risk.

How to eliminate wrong answers

Option A is wrong because minimizing risks to an acceptable level is an outcome of risk management, not the primary purpose of governance; governance sets the structure for risk management but focuses on strategic alignment. Option C is wrong because ensuring compliance with regulatory requirements is a tactical obligation, not the primary purpose; governance frameworks incorporate compliance but are broader, aiming to integrate security with business strategy. Option D is wrong because deploying the latest security technologies is an operational activity, not a governance purpose; governance defines policies and oversight, not specific technology choices.

499
MCQmedium

You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?

A.Outsource the training to a third-party provider.
B.Increase the frequency of reminder emails from monthly to weekly.
C.Implement a learning management system (LMS) to track completion.
D.Redesign the training to be role-specific and mandate completion in the security governance framework with consequences for non-compliance.
AnswerD

Mandating completion within the security governance framework with consequences directly addresses the enforcement gap left by HR's reminder-only approach, satisfying the board's regulatory risk concern. Role-specific redesign tackles the relevance complaint driving the 60% rate, embedding accountability rather than relying on generic annual modules.

Why this answer

It addresses both the root cause (irrelevant training) and the governance gap (lack of enforcement). By redesigning training to be role-specific, employees see direct relevance, which improves engagement and retention. Mandating completion within the security governance framework and attaching consequences (e.g., access revocation) creates accountability, directly driving compliance from 60% toward the board's target.

Exam trap

The trap here is that candidates often mistake tracking (Option C) for enforcement, failing to recognize that governance requires both visibility and consequences to drive compliance.

How to eliminate wrong answers

Option A is wrong because outsourcing to a third-party provider does not fix the core issues of relevance or enforcement; it merely shifts the same generic content to another vendor, and without governance authority, compliance may remain low. Option B is wrong because increasing reminder frequency from monthly to weekly only amplifies a failed communication tactic; it does not address employee motivation or enforce consequences, so it is unlikely to move compliance beyond 60%. Option C is wrong because implementing an LMS to track completion provides visibility but no enforcement mechanism; without mandating completion and attaching consequences, tracking alone does not compel behavior change.

500
Multi-Selecthard

An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)

Select 2 answers
A.The user's browser history.
B.The IP address of the sending server.
C.The malicious URL or attachment hash.
D.The user's personal phone number.
E.The company's public website.
AnswersB, C

The sending server's IP address is a network-based indicator enabling blocking at perimeter controls and correlation with other phishing campaigns. It supports rapid containment, letting the team trace infrastructure used to deliver the credential-harvesting message and identify related inbound threats.

Why this answer

Option B is correct because the IP address of the sending server is a network-based IOC that can be used to block or monitor the source of the phishing email and correlate it with other attacks. Option C is correct because the malicious URL or attachment hash provides a host- or file-based IOC that can be used to detect the payload, block it at email/web gateways, and search for other victims. Option A is not a prioritized IOC for this scenario because browser history is user activity data that may be noisy and is not directly tied to the phishing infrastructure.

Option D is not an IOC because a personal phone number is not a technical artifact of the compromise. Option E is not an IOC because the company's public website is a legitimate asset, not an indicator of malicious activity.

Exam trap

The trap here is that candidates may confuse post-compromise artifacts (like browser history) with primary IOCs, or think that personal information (phone number) or the company's own website are relevant indicators, when in fact the core IOCs for a phishing email are the sender's IP and the malicious payload identifier.

501
MCQeasy

Which of the following is the most important factor for ensuring the long-term success of an information security program?

A.Deployment of advanced security technologies.
B.Comprehensive security awareness training.
C.Strong support from top management.
D.Regular penetration testing.
AnswerC

Sustained funding, resourcing and enforcement of security policy depend on executive sponsorship; without top-management backing, controls erode as competing priorities displace them. This directly satisfies the long-term success constraint in the stem, which technical measures alone cannot guarantee.

Why this answer

Strong support from top management is the most important factor because it ensures the information security program receives adequate budget, organizational authority, and strategic alignment with business objectives. Without executive sponsorship, even the best technical controls can be undermined by resource constraints, policy non-compliance, or lack of cross-departmental cooperation. The CISM framework emphasizes that governance and leadership commitment are foundational to sustaining a security program over time.

Exam trap

The trap here is that candidates often mistake operational effectiveness (e.g., training or testing) for strategic success, overlooking that without top management support, no security initiative can be sustained or enforced across the organization.

Why the other options are wrong

A

Technology is a tool, not the foundation; it requires management support to be effective.

B

Training is important but not the most critical factor; without management support, training may lack resources.

D

Penetration testing is a tactical activity; it does not ensure program success without executive backing.

502
MCQmedium

In a third-party risk management programme, what is the primary purpose of vendor tiering?

A.To assign responsibility for vendor management to different teams
B.To prioritize which vendors require more rigorous security assessments
C.To ensure all vendors receive the same level of oversight
D.To determine the vendor's pricing structure
AnswerB

Tiering classifies vendors by risk and criticality, so assessment effort and due diligence depth are proportionate. This directly satisfies the programme's constraint of focusing rigorous security assessments on the vendors that pose the greatest risk to the organisation.

Why this answer

Vendor tiering is a risk-based classification process that segments third parties according to the criticality of the data they handle, the level of access they have to systems, and the potential business impact of a breach or failure. The primary purpose is to allocate limited security assessment resources efficiently by focusing the most rigorous due diligence, contractual controls, and ongoing monitoring on the highest-risk vendors. This ensures that oversight is proportionate to risk rather than uniform, which is a core CISM principle.

Exam trap

CISM often tests the misconception that vendor tiering is about equalizing oversight or administrative convenience, when the correct answer always ties back to risk-based prioritization of security assessments.

How to eliminate wrong answers

Option A is wrong because assigning responsibility to different teams is an organizational design decision, not the purpose of tiering; tiering may inform who manages a vendor, but that is a downstream effect, not the primary goal. Option C is wrong because tiering explicitly rejects the idea of identical oversight for all vendors; the entire point is to differentiate and apply more scrutiny to higher-risk relationships. Option D is wrong because pricing structure is a commercial and procurement concern, not a security risk management objective; tiering is based on risk factors such as data sensitivity and access, not cost.

503
MCQmedium

After an incident is contained and eradicated, the incident response team conducts a post-incident review. Which of the following is the PRIMARY objective of this review?

A.Update security policies
B.Determine the financial impact
C.Assign blame to the responsible parties
D.Identify process improvements
AnswerD

The post-incident review exists to convert lessons from the response into corrective actions, strengthening future capability. Identifying process improvements satisfies that objective by addressing gaps in detection, escalation and containment, rather than assigning blame or merely documenting the event.

Why this answer

The primary objective of a post-incident review is to identify process improvements that enhance the organization's incident response capabilities. This aligns with the CISM focus on continuous improvement, ensuring that lessons learned are captured and applied to prevent recurrence or improve future response efficiency.

Exam trap

The trap here is that candidates often confuse a secondary outcome (like updating policies) with the primary objective, failing to recognize that the review's core purpose is process improvement, not documentation or blame.

How to eliminate wrong answers

Option A is wrong because updating security policies is a possible outcome of the review, not the primary objective; the core goal is to analyze the incident response process itself for improvements. Option B is wrong because determining the financial impact is typically part of the containment and eradication phase or a separate forensic accounting activity, not the central purpose of the post-incident review. Option C is wrong because assigning blame is counterproductive and contrary to the 'no-blame' culture essential for effective incident response; the review focuses on systemic weaknesses, not individual fault.

504
Multi-Selecthard

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Select 3 answers
A.Mean time to detect (MTTD)
B.Patch compliance percentage
C.Phishing simulation click rate
D.Number of data breaches
E.Access review completion rate
AnswersB, C, E

Patch compliance percentage measures preventive maintenance before exploitation occurs, satisfying the stem's leading-indicator requirement. Unlike breach counts or incident volumes, which record events already realised, it tracks control effectiveness prospectively, giving the CISO an early signal of exposure reduction across Microsoft Entra ID-managed and on-premises estates.

Why this answer

Leading indicators are forward-looking metrics that measure the strength of preventive and detective controls before incidents occur. B (Patch compliance percentage) is correct because it quantifies how much of the environment is protected against known vulnerabilities, predicting future exploit risk. C (Phishing simulation click rate) is correct because it measures current user susceptibility to social engineering, forecasting the likelihood of future successful phishing compromises.

E (Access review completion rate) is correct because it reflects whether least-privilege and entitlement hygiene processes are being executed, reducing future unauthorized-access risk. A (MTTD) is a detective/operational metric that measures how quickly incidents are found after they occur, and D (number of data breaches) is a lagging outcome metric that reports incidents that already happened, so neither is a leading indicator.

505
MCQeasy

Which of the following is the PRIMARY purpose of a security awareness program?

A.To reduce human-related security risks
B.To achieve compliance with regulatory requirements
C.To increase the security team's visibility
D.To document training completion for audits
AnswerA

Awareness programmes target the human attack surface — phishing susceptibility, weak handling of credentials and data — by changing behaviour so employees recognise and report threats. Reducing human-related risk is the primary outcome; compliance evidence and culture are secondary byproducts.

Why this answer

The primary purpose of a security awareness program is to reduce human-related security risks by educating employees about threats, policies, and safe behaviors. Since humans are often the weakest link in security, awareness programs aim to change behavior and culture to prevent incidents like phishing, social engineering, and data mishandling. While compliance, visibility, and documentation are secondary benefits, the core objective is risk reduction.

Exam trap

CISM often tests the distinction between primary and secondary purposes, tempting candidates to choose compliance or documentation as the main goal when the core objective is risk reduction.

How to eliminate wrong answers

Option B is wrong because achieving compliance with regulatory requirements is a secondary outcome, not the primary purpose; compliance may mandate awareness training, but the ultimate goal is risk reduction. Option C is wrong because increasing the security team's visibility is not the objective of an awareness program; awareness is about educating the workforce, not promoting the security team. Option D is wrong because documenting training completion for audits is an administrative byproduct, not the primary purpose; the focus is on changing behavior and reducing risk, not just record-keeping.

506
MCQmedium

An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?

A.Data breach playbook
B.Ransomware playbook
C.Credential compromise playbook
D.Insider threat playbook
AnswerC

Phishing that yields unauthorised account access is credential compromise, so the credential compromise playbook prescribes password resets, session revocation, MFA enforcement and account monitoring. A malware or data breach playbook would not address the stolen-credential vector that enabled the intrusion.

Why this answer

Credential compromise incidents, such as account takeover via phishing, are handled by the credential compromise playbook.

507
Multi-Selectmedium

An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)

Select 2 answers
A.Identification and Authentication (IA)
B.Configuration Management (CM)
C.System and Communications Protection (SC)
D.Audit and Accountability (AU)
E.Access Control (AC)
AnswersA, E

Identification and Authentication (IA) governs verifying user identities before granting access, directly underpinning access control decisions. It satisfies the access control relationship by ensuring only authenticated subjects reach protected resources, complementing the Access Control (AC) family.

Why this answer

Option E, Access Control (AC), is correct because the AC family in NIST SP 800-53 is explicitly dedicated to controlling access to systems and information, covering policies, account management, access enforcement, least privilege, and separation of duties. Option A, Identification and Authentication (IA), is correct because IA controls establish and verify user, device, and process identities, which is the prerequisite for enforcing access control decisions. Together, AC and IA form the core of logical access control in the NIST control catalog.

Option B, Configuration Management (CM), addresses baselines and change control rather than who may access resources. Option C, System and Communications Protection (SC), focuses on boundary protection, cryptography, and network security mechanisms. Option D, Audit and Accountability (AU), deals with logging, monitoring, and review of activity, not with granting or denying access.

508
MCQhard

A security program lacks executive support. What is the best strategy to gain support?

A.Hire a security consultant to advise
B.Implement quick-win security improvements
C.Show risk quantification in business terms
D.Threaten regulatory fines for non-compliance
AnswerC

Quantifying risk in financial and business-impact terms translates security exposure into language executives already use for investment decisions, making the programme's value and consequences concrete. This directly addresses the missing executive support by aligning security with business objectives.

Why this answer

C is correct because executive stakeholders prioritize business outcomes over technical details. By quantifying risks in financial terms (e.g., potential loss exposure, ROI of mitigation), the security manager aligns with the organization's strategic language, making the case for investment compelling and actionable. This approach directly addresses the root cause—lack of perceived business value—rather than relying on technical arguments or fear.

Exam trap

ISACA CISM tests the misconception that technical demonstrations or fear-based tactics (like regulatory threats) are more effective than business-aligned communication, when in reality, executives require risk expressed in financial terms to justify resource allocation.

How to eliminate wrong answers

Option A is wrong because hiring a consultant may provide expertise but does not inherently build executive buy-in; it can even be seen as an external cost without demonstrated internal alignment. Option B is wrong because quick-win improvements, while visible, often address low-impact risks and can create a false sense of security, failing to address the systemic lack of executive engagement. Option D is wrong because threatening regulatory fines introduces a negative, adversarial tone that can damage trust and collaboration; executives may view it as coercion rather than a partnership in risk management.

509
MCQhard

During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?

A.Engage the forensics firm under the direction of legal counsel.
B.Have the forensics firm work independently to maintain objectivity.
C.Ensure the forensics firm signs a non-disclosure agreement only.
D.Have the forensics firm report directly to the CISO.
AnswerA

Engaging the forensics firm under legal counsel's direction extends attorney-client privilege to the firm's work product, satisfying the stem's privilege-preservation constraint. Counsel retains the vendor, directs the investigation, and receives findings, so communications and deliverables fall within privilege rather than becoming discoverable business records.

Why this answer

Engaging the forensics firm under the direction of legal counsel is the best practice because it extends attorney-client privilege to the investigation. When counsel directs the work, communications and findings are protected as work product, preventing disclosure in litigation. This is a foundational principle in incident response legal strategy.

Exam trap

The trap here is that candidates confuse confidentiality (NDA) with legal privilege, or assume operational independence (reporting to CISO) is acceptable, when only attorney-directed engagement preserves privilege under evidentiary rules.

How to eliminate wrong answers

Option B is wrong because having the forensics firm work independently to maintain objectivity would break the privileged relationship; independent work without legal direction creates discoverable evidence. Option C is wrong because a non-disclosure agreement only protects confidentiality, not legal privilege; it does not shield the investigation from being subpoenaed. Option D is wrong because having the forensics firm report directly to the CISO bypasses legal counsel, making the investigation subject to discovery as ordinary business records.

510
Multi-Selectmedium

An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)

Select 2 answers
A.A requirement that all technical details of the incident be shared publicly in real time
B.A list of all employees' personal mobile numbers for emergency mass texting
C.A policy that only the CEO may speak to any stakeholder during an incident
D.Predefined communication templates for different stakeholder groups and incident types
E.Designated spokespersons and approval workflows for external communications
AnswersD, E

Predefined templates accelerate communication during high-pressure incidents and ensure consistent, accurate messaging. They reduce the risk of ad hoc statements that could create legal or reputational problems. CISM recommends preparing templates for internal staff, customers, regulators, and media in advance. This directly improves the organization's ability to communicate effectively when time and attention are constrained.

Why this answer

An effective incident communication plan includes prepared templates for different audiences and incidents, plus designated spokespersons with clear approval workflows. Templates speed response and ensure consistency, while spokesperson designation and approval controls prevent unauthorized or harmful statements. Collecting personal contact data, mandating real-time technical disclosure, or centralizing all communication in one executive do not constitute sound communication planning and can introduce privacy, security, or operational problems.

Exam trap

The trap here is equating more communication with better communication, leading to choices that over-share, over-centralize, or collect unnecessary personal data.

511
Multi-Selecteasy

Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)

Select 2 answers
A.Performing vulnerability scans
B.Implementing security controls
C.Ensuring security strategy aligns with business goals
D.Approving the information security risk appetite
E.Conducting daily security monitoring
AnswersC, D

The board owns strategic direction, so it must ensure the information security programme supports and enables business objectives rather than existing as an isolated technical function. This alignment duty is a core governance responsibility, distinct from the operational execution delegated to management.

Why this answer

Option C is correct because the board of directors is responsible for governance, which means ensuring that the organization's information security strategy is aligned with and supports the overall business goals and objectives. Option D is correct because setting and approving the organization's risk appetite—the amount and type of risk it is willing to accept—is a core governance responsibility that belongs to the board, which then guides management's security decisions. Options A, B, and E are incorrect because performing vulnerability scans, implementing security controls, and conducting daily security monitoring are operational, hands-on tasks carried out by security practitioners and management, not by the board of directors.

Exam trap

The trap here is that candidates confuse governance (board-level strategic oversight) with management (operational execution), leading them to select tactical activities like vulnerability scanning or control implementation as board responsibilities.

512
MCQmedium

During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?

A.Purchase an automated compliance platform and import the existing control descriptions.
B.Increase the frequency of vulnerability scanning across all internet-facing systems.
C.Define control objectives, assign owners, and establish metrics and testing that evidence whether each control operates effectively.
D.Require business units to attest annually that they comply with all security policies.
AnswerC

Effectiveness requires a stated objective, an accountable owner, and evidence that the control works as designed over time. Metrics and periodic testing, such as control self-assessments or independent testing, create that evidence and let the programme identify failing or redundant controls and report meaningful assurance to leadership.

Why this answer

Demonstrating effectiveness requires more than counting implemented controls. Each control needs a defined objective tied to risk, a named owner, and measurable evidence from testing or monitoring that it operates as intended. That structure lets the programme detect failures, remove redundant effort, and give leadership defensible assurance, which inventories and attestations alone cannot provide.

Exam trap

The trap here is equating control implementation or tooling with proven control effectiveness, when effectiveness requires objectives, ownership, and evidence of operation.

513
MCQmedium

An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?

A.Reboot all servers to clear the ransomware
B.Immediately pay the ransom demand
C.Isolate affected systems from the network
D.Notify all customers immediately
AnswerC

Isolating affected systems cuts command-and-control and lateral movement paths, preventing the ransomware from spreading to further hosts before eradication and recovery begin. This satisfies the stem's requirement for a key playbook step, and preserves the isolated systems for later forensic examination.

Why this answer

Ransomware playbooks should include isolating infected systems to prevent spread, as containment is a priority.

514
Multi-Selectmedium

Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)

Select 2 answers
A.IR team roster
B.Incident response policy
C.Incident response plan
D.Communication templates
E.Vendor contacts list
AnswersB, C

An incident response policy supplies the mandated authority, scope and governance framework that best practice requires before any procedural or technical capability is built. It defines roles, escalation thresholds and management commitment, satisfying the programme's foundational requirement. Without it, plans and playbooks lack approved direction, so this option is a required component.

Why this answer

Option B (Incident response policy) is correct because best-practice frameworks such as NIST SP 800-61 and ISO/IEC 27035 require a formally approved policy that establishes the authority, scope, objectives, and management commitment for the incident response capability. Option C (Incident response plan) is correct because the plan is the documented, actionable set of procedures—roles, phases (preparation, detection and analysis, containment, eradication, recovery, post-incident activity), and escalation paths—that operationalizes the policy. The remaining items are supporting artifacts rather than required programme components: an IR team roster (A), communication templates (D), and a vendor contacts list (E) are useful appendices or resources referenced by the plan, but they are not themselves mandatory components of an incident response programme.

Exam trap

A common trap in CISM is distinguishing between the policy (the 'what' and 'why') and the plan (the 'how'), leading candidates to select operational items like contact lists or templates instead of the mandatory governance components.

515
MCQeasy

An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?

A.Aligns security investments with business priorities
B.Reduces the number of security incidents
C.Increases employee awareness of security policies
D.Ensures compliance with regulatory requirements
AnswerA

Embedding security risk management in strategic planning ties control selection and spending to the business objectives and risk appetite the organisation has already prioritised, so security investments directly support business priorities rather than being justified in isolation after the fact.

Why this answer

Integrating security risk management into strategic planning ensures that security investments are directly tied to the organization's business priorities and risk appetite. This alignment allows for optimal allocation of resources to protect the most critical assets and processes, rather than spending on generic or low-priority controls. The primary benefit is that security becomes a business enabler, not a cost center, by focusing on what matters most to the organization's objectives.

Exam trap

The trap here is that candidates often confuse operational benefits (like incident reduction or compliance) with the strategic, business-alignment benefit that is the core purpose of integrating risk management into planning.

How to eliminate wrong answers

Option B is wrong because reducing the number of security incidents is an operational outcome of effective controls, not the primary strategic benefit of integrating risk management into planning; incidents can still occur despite alignment. Option C is wrong because increasing employee awareness is a tactical training or communication activity, not a strategic planning outcome, and it does not directly tie security to business goals. Option D is wrong because ensuring compliance with regulatory requirements is a baseline necessity and a tactical obligation, but it is not the primary benefit of strategic integration; compliance alone does not guarantee alignment with business objectives or optimized investment.

516
MCQmedium

A multinational corporation has just detected a ransomware attack that encrypted critical files on a file server. The incident response team has been activated. Which of the following should be the FIRST action taken by the team?

A.Restore encrypted files from backup
B.Reboot the file server to clear the encryption
C.Isolate the affected systems from the network
D.Notify law enforcement
AnswerC

Isolating the affected systems from the network contains the ransomware before it spreads laterally to other hosts and shares. This directly satisfies the stem's priority of limiting damage during an active attack, since encryption is ongoing and every additional minute of connectivity risks further file encryption and potential exfiltration.

Why this answer

The first priority in ransomware incident response is containment to prevent the encryption from spreading to other systems. Isolating the affected file server from the network (e.g., disabling the network interface or disconnecting the cable) stops the ransomware from communicating with its command-and-control server and encrypting additional shares. This aligns with the NIST SP 800-61 containment strategy and ensures that the incident response team can safely preserve forensic evidence before any remediation.

Exam trap

The trap here is that candidates often choose 'Restore from backup' first because it seems like a direct fix, but CISM emphasizes containment before eradication or recovery to limit damage and preserve forensic integrity.

How to eliminate wrong answers

Option A is wrong because restoring from backup before containment risks re-encrypting the restored files if the ransomware is still active on the network, and it may overwrite forensic evidence. Option B is wrong because rebooting the file server does not clear encryption—ransomware encrypts files at rest using asymmetric cryptography, and a reboot simply restarts the OS without reversing the encryption; it may also trigger the ransomware to encrypt additional data on startup. Option D is wrong because notifying law enforcement is a secondary step that should occur after containment and evidence preservation, and premature notification can delay critical containment actions.

517
Multi-Selectmedium

Which TWO of the following are key components of an effective incident response plan?

Select 2 answers
A.A clear chain of command and escalation procedures.
B.Automatic detection and response tools.
C.Predefined response scripts for every possible incident.
D.A communication plan for internal and external stakeholders.
AnswersA, D

A defined chain of command with escalation procedures ensures incidents are routed to the right authority quickly, preventing confusion, duplicated effort and delayed decisions. It establishes clear ownership and communication paths, which are essential for coordinated, timely response across technical and management teams.

Why this answer

Option A is correct because an effective incident response plan must define a clear chain of command and escalation procedures, ensuring that roles, decision authority, and handoff paths (for example, from Tier 1 to Tier 2 to the IR lead) are unambiguous during a high-pressure event. Option D is correct because a communication plan for internal and external stakeholders governs who is notified, when, and through which channels, covering obligations such as breach notification to regulators, customers, and law enforcement, and preventing conflicting or premature disclosures. Options B and C are not key components: automated detection and response tools are supporting technologies that enable the plan rather than constituting it, and predefined scripts for every possible incident are impractical since incidents vary and rigid scripts can hinder adaptive response.

Exam trap

ISACA often tests the distinction between the plan's structural components (like chain of command and communication plans) and operational tools or overly rigid scripts, tempting candidates to select automatic tools or exhaustive scripts as key components when they are not foundational to the plan's design.

518
MCQhard

A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?

A.NIST Cybersecurity Framework
B.PCI DSS
C.COBIT 2019
D.ISO 27001
AnswerC

COBIT 2019 provides a governance and management framework that explicitly links IT and security objectives to enterprise strategy through its governance system design, satisfying the agency's need to align security with mission and strategic objectives rather than only operational controls.

Why this answer

COBIT 2019 is specifically designed as an IT governance framework that aligns IT (including security) with enterprise strategic objectives. It provides a comprehensive governance system with principles, enablers, and performance management to ensure that IT delivers value and mitigates risks in line with business goals. Unlike security-focused frameworks, COBIT emphasizes governance and management of enterprise IT, making it ideal for tying security to the agency's mission.

Exam trap

CISM often tests the distinction between governance and management frameworks, and candidates may incorrectly select ISO 27001 or NIST CSF because they are well-known security standards, but the question specifically asks for a governance framework that ties security to strategic objectives, which is COBIT's primary strength.

How to eliminate wrong answers

Option A is wrong because the NIST Cybersecurity Framework is primarily a risk-based cybersecurity framework for improving critical infrastructure security; it focuses on identifying, protecting, detecting, responding, and recovering from cyber threats, but does not provide a full governance structure to align security with strategic objectives. Option B is wrong because PCI DSS is a prescriptive standard for protecting payment card data, applicable only to organizations handling cardholder data, and does not address governance alignment with mission. Option D is wrong because ISO 27001 is an information security management system standard that focuses on establishing, implementing, maintaining, and continually improving security controls, but it is not a governance framework for aligning IT with enterprise strategy.

519
MCQhard

A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?

A.All groups simultaneously
B.Implementation Group 3 (IG3)
C.Implementation Group 1 (IG1)
D.Implementation Group 2 (IG2)
AnswerC

IG1 includes basic cyber hygiene controls that prevent common attacks like ransomware.

Why this answer

CIS Controls v8 Implementation Group 1 (IG1) represents the foundational cyber hygiene controls that every organization — especially those with limited resources and high ransomware exposure — should implement first. IG1 controls are designed to be achievable with minimal expertise and cover the most impactful safeguards like inventory, patching, and access control. Prioritizing IG1 ensures the organization closes the most exploitable gaps before moving to IG2 and IG3.

Exam trap

CISM often tests whether candidates understand that IG1 is the mandatory starting point regardless of organization size or sector; candidates incorrectly assume a financial institution must jump to IG3 due to regulatory pressure.

How to eliminate wrong answers

Option A (All groups simultaneously) is wrong because it ignores the resource constraint and the entire purpose of the IG tiering model, which exists specifically to sequence implementation. Option B (IG3) is wrong because IG3 is designed for organizations with mature security programs, dedicated security teams, and high-value assets — implementing it first would overwhelm limited resources. Option D (IG2) is wrong because IG2 builds on IG1; skipping IG1 leaves foundational hygiene gaps that ransomware actors routinely exploit (e.g., unpatched systems, missing MFA).

520
MCQhard

A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?

A.Block the destination IP address at the firewall
B.Escalate the alert to the incident response team immediately
C.Verify the alert by correlating with other log sources
D.Perform a full antivirus scan on all endpoints
AnswerC

Correlating the signature match with other log sources confirms whether the C2 traffic is genuine or a false positive, satisfying the need to validate before escalation. This verification step distinguishes malicious beaconing from legitimate outbound connections prior to containment.

Why this answer

A SIEM alert based on a signature match is an indicator, not confirmed compromise; signature-based detection can produce false positives. The most appropriate next step is to verify the alert by correlating with other log sources — such as DNS logs, proxy logs, endpoint telemetry, and NetFlow — to determine whether the C2 communication is real and to understand its scope. Only after validation should the analyst escalate, block, or remediate, ensuring incident response resources are not wasted on false positives.

Exam trap

CISM often tests the impulse to take immediate containment action (block, escalate, scan) instead of first validating the alert through correlation, which is the correct triage step.

How to eliminate wrong answers

Option A is wrong because blocking the destination IP before verification could disrupt legitimate business traffic and may tip off an attacker; containment should follow confirmation. Option B is wrong because immediate escalation without validation can overwhelm the IR team with false positives and violates the triage principle of the incident response lifecycle. Option D is wrong because a full antivirus scan on all endpoints is a broad, disruptive remediation action that is premature before the alert is validated and scoped.

521
MCQhard

After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?

A.Establish a policy that legacy systems must be upgraded annually.
B.Disconnect the legacy system from the network immediately.
C.Implement a process for periodic reassessment of accepted risks.
D.Require immediate remediation of all legacy systems.
AnswerC

The breach occurred because an accepted risk was never revisited as the threat landscape and asset criticality changed. Periodic reassessment ensures accepted risks remain valid, triggering re-evaluation or treatment when conditions shift, directly closing the governance gap that allowed the legacy vulnerability to persist.

Why this answer

Risk acceptance is not a one-time decision; it must be periodically reassessed to account for changes in the threat landscape, business context, or compensating controls. The breach exploited a known vulnerability that was accepted two years ago, indicating the risk environment has shifted (e.g., new exploit code, increased attacker interest). Implementing a periodic reassessment process ensures that accepted risks are re-evaluated against current threats and vulnerabilities, allowing the organization to either renew acceptance, apply mitigations, or retire the system.

Exam trap

The trap here is that candidates confuse risk acceptance with a permanent decision, failing to recognize that accepted risks must be periodically re-evaluated as part of a continuous risk management process.

How to eliminate wrong answers

Option A is wrong because a blanket annual upgrade policy is impractical for legacy systems that may lack vendor support or compatible upgrades, and it does not address the root cause of failing to reassess risk. Option B is wrong because immediately disconnecting the legacy system may disrupt critical business operations without a planned migration or compensating control, and it is a reactive rather than programmatic improvement. Option D is wrong because requiring immediate remediation of all legacy systems is often infeasible due to cost, operational dependencies, or lack of patches, and it ignores the risk management principle of prioritizing based on current risk appetite.

522
MCQeasy

A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?

A.Verify the alert and assess scope
B.Disconnect all network cables
C.Notify law enforcement
D.Reimage affected systems
AnswerA

Verifying the alert and assessing scope confirms whether the IDS detection is a genuine compromise and determines which systems are affected. Acting on unvalidated alerts risks wasted containment effort, while scope assessment directs subsequent containment, eradication and recovery priorities.

Why this answer

The immediate priority upon receiving an IDS alert is to verify the alert's validity and assess the scope of the potential breach. This ensures the incident response team does not waste resources on false positives and can accurately determine the affected systems, data, and network segments before taking containment actions. Verification typically involves correlating the IDS signature with actual packet captures, logs, and system telemetry to confirm malicious activity.

Exam trap

The trap here is that candidates confuse 'immediate response' with 'containment' and choose a drastic action like disconnecting cables, forgetting that verification and scope assessment must precede any containment to avoid destroying evidence and causing unnecessary downtime.

How to eliminate wrong answers

Option B is wrong because disconnecting all network cables is a drastic, uncontrolled containment action that can cause unnecessary business disruption, destroy volatile evidence (e.g., active network connections, memory-resident malware), and may violate legal hold requirements. Option C is wrong because notifying law enforcement is a secondary step that occurs after the incident is confirmed, scoped, and legal counsel is consulted; premature notification can compromise internal investigation and evidence handling. Option D is wrong because reimaging affected systems destroys all forensic evidence (logs, malware binaries, registry artifacts) and prevents root cause analysis, which is critical for preventing recurrence and meeting compliance obligations.

523
MCQhard

A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?

A.The number of similar risks already identified in the risk register
B.The cost of the control compared to the asset's book value
C.The technical severity rating from the vulnerability scanner
D.The organization's risk appetite and tolerance
AnswerD

Risk appetite and tolerance define the amount and type of risk the organization is willing to accept in pursuit of its objectives. Treatment decisions must align with these thresholds. Without this context, a control decision may be inappropriate even if technically sound. This makes risk appetite and tolerance the primary factor guiding whether to accept, mitigate, transfer, or avoid the risk.

Why this answer

Risk treatment must be driven by the organization's risk appetite and tolerance, because these express how much risk leadership is willing to accept while pursuing objectives. Technical severity, control cost, and risk counts inform the analysis, but they do not determine acceptability. The chosen treatment should bring residual risk within tolerance and remain consistent with regulatory and business obligations.

Exam trap

The trap here is assuming that technical severity or control cost alone dictates risk treatment, rather than the organization's risk appetite and tolerance.

524
Multi-Selecthard

An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?

Select 3 answers
A.Ensuring that champions have authority to stop releases with critical vulnerabilities.
B.Rotating champions every quarter to maximize exposure.
C.Allocating dedicated time for champions to participate in security activities.
D.Providing advanced security training tailored to their development role.
E.Selecting champions only from senior management.
AnswersA, C, D

Granting champions authority to halt releases with critical vulnerabilities embeds security into the delivery pipeline rather than leaving it advisory. This satisfies the programme's aim of improving application security by ensuring identified flaws are remediated before production, giving champions real influence.

Why this answer

Option A is correct because giving champions the authority to halt releases containing critical vulnerabilities provides them with real enforcement power, ensuring security issues are remediated before deployment rather than merely reported. Option C is correct because champions need formally allocated time to attend training, perform threat modeling, triage findings, and mentor peers; without dedicated capacity, security work is deprioritized against delivery deadlines. Option D is correct because role-tailored advanced training (for example secure coding in the languages and frameworks the champion actually uses, plus SAST/DAST tooling) equips champions to give credible, context-specific guidance to their teams.

Option B is not a success factor because quarterly rotation destroys the accumulated expertise and relationships that make champions effective, and it is not required for broad exposure. Option E is not a success factor because champions should be respected hands-on engineers embedded in development teams, not senior managers whose distance from code limits their technical influence.

Exam trap

CISM often tests program design principles; candidates select 'rotation' or 'senior management' options thinking they improve governance, but both undermine the grassroots, embedded nature of effective champion programs.

525
MCQeasy

An organization plans to implement ISO/IEC 27001 to formalize its information security management system. Which step is most critical to ensure successful implementation?

A.Conduct a comprehensive risk assessment
B.Obtain commitment from top management
C.Develop detailed information security policies
D.Train all employees on security awareness
AnswerB

ISO/IEC 27001 implementation demands resources, cross-functional authority and cultural change, all of which only top management can mandate. Without visible executive sponsorship, the ISMS scope, funding and accountability stall at departmental level, so securing that commitment is the prerequisite the standard's Plan-Do-Check-Act cycle depends on.

Why this answer

ISO/IEC 27001 requires top management to demonstrate leadership and commitment (Clause 5.1) as the foundation for the entire ISMS. Without executive buy-in, resources, authority, and cross-functional support are lacking, making risk assessments, policies, and training ineffective. The standard mandates management approval for the information security policy and ensures alignment with business objectives, which is the most critical success factor.

Exam trap

The trap here is that candidates often choose 'Conduct a comprehensive risk assessment' because it is the technical heart of ISO 27001, but CISM emphasizes that governance and management commitment must precede any technical or operational activities for the ISMS to be sustainable.

How to eliminate wrong answers

Option A is wrong because while a comprehensive risk assessment is required (Clause 6.1), it cannot be effectively performed or acted upon without prior top management commitment to allocate resources and enforce remediation. Option C is wrong because developing detailed information security policies is an operational step that follows management's strategic direction and approval; policies without executive sponsorship often lack enforcement and become shelfware. Option D is wrong because training all employees on security awareness is important for culture (Clause 7.3), but it is a downstream activity that depends on management establishing the ISMS framework and providing the necessary budget and authority.

Page 6

Page 7 of 13

Page 8