Courseiva

Certified Information Security Manager CISM (CISM) — Questions 526600

871 questions total · 12pages · All types, answers revealed

Page 7

Page 8 of 12

Page 9
526
MCQeasy

Based on the exhibit, which role is responsible for notifying affected users about the phishing attack?

A.Technical Lead
B.Legal Counsel
C.Incident Response Manager
D.Communications Lead
AnswerD

The communications lead handles internal and external communications.

Why this answer

The Communications Lead is responsible for notifying affected users about the phishing attack because this role manages external and internal communications, including user notifications, during an incident. In the exhibit, the Communications Lead is explicitly assigned the task of 'Notify affected users' under the communication plan, ensuring timely and accurate messaging to reduce further risk.

Exam trap

ISACA often tests the misconception that the Incident Response Manager handles all communications, but the trap here is that the IR Manager delegates user notification to the Communications Lead to maintain separation of duties and focus on technical containment.

How to eliminate wrong answers

Option A is wrong because the Technical Lead focuses on technical remediation (e.g., isolating systems, analyzing logs) and does not handle user notifications, which is a communications function. Option B is wrong because Legal Counsel advises on regulatory compliance and liability but does not directly notify users; their role is to review messaging for legal risk, not to execute the notification. Option C is wrong because the Incident Response Manager coordinates the overall response and decision-making but delegates user notification to the Communications Lead to avoid bottlenecks and ensure specialized handling.

527
MCQmedium

An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?

A.Follow industry benchmarks without adjustment
B.Use a risk-based approach aligned to business impact
C.Prioritize based on the cost of security controls
D.Allocate budget equally across all security domains
AnswerB

Risk-based prioritization ensures investments address the highest risks.

Why this answer

A risk-based approach aligns security investments with the organization's risk appetite, ensuring resources are directed to the most critical areas.

528
MCQeasy

Which security team role is primarily responsible for defining and maintaining security architecture standards?

A.GRC analyst
B.Security analyst
C.Penetration tester
D.Security architect
AnswerD

The security architect defines security architecture and standards.

Why this answer

The security architect designs the security architecture, ensuring that security controls are integrated into systems and networks.

529
MCQeasy

An organization has an incident response plan that designates a primary and alternate incident response team. During a simulated ransomware attack, the primary team is unavailable. What should the alternate team do FIRST?

A.Contact the primary team members for instructions.
B.Declare a disaster and escalate to senior management.
C.Execute the incident response plan as documented.
D.Assess the situation and then activate the plan.
AnswerD

Assessment first ensures appropriate response based on current conditions.

Why this answer

The alternate team must first assess the situation to understand the scope, impact, and validity of the ransomware attack before activating the plan. This aligns with the NIST SP 800-61 incident response lifecycle, where detection and analysis precede containment, eradication, and recovery. Jumping directly to execution without assessment could lead to inappropriate response actions, such as isolating systems that are not affected or failing to preserve critical forensic evidence.

Exam trap

The trap here is that candidates often confuse 'activating the plan' with 'executing the plan immediately,' but CISM emphasizes that assessment is a mandatory first step before any plan activation to ensure the response is appropriate for the specific incident.

How to eliminate wrong answers

Option A is wrong because the primary team is unavailable by design in this scenario, and contacting them for instructions would cause unnecessary delay and violate the purpose of having an alternate team. Option B is wrong because declaring a disaster and escalating to senior management is premature; the incident must first be assessed to determine if it meets the disaster declaration criteria, which typically involve significant business impact or data loss. Option C is wrong because executing the incident response plan as documented without first assessing the situation ignores the need to tailor the response to the specific ransomware variant, affected systems, and current network state, which could lead to ineffective or harmful actions.

530
MCQeasy

Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?

A.CIS Controls v8
B.COBIT 2019
C.ISO 27001 Annex A
D.NIST SP 800-53
AnswerA

CIS Controls v8 uses IG1 (basic), IG2 (intermediate), and IG3 (advanced) for prioritization.

Why this answer

The CIS Controls v8 framework is uniquely structured around Implementation Groups (IG1, IG2, IG3) to provide a prioritized, risk-based approach to security control implementation. IG1 represents basic cyber hygiene for organizations with limited resources, IG2 adds more advanced controls for those with moderate risk, and IG3 includes comprehensive controls for high-risk environments. This tiered structure directly aligns with the CISM focus on aligning security controls with business risk and resource constraints.

Exam trap

The trap in the CISM exam is that candidates often confuse the CIS Controls Implementation Groups with NIST SP 800-53's impact-based baselines (Low, Moderate, High), but the key distinction is that IG1/IG2/IG3 are risk-prioritized tiers based on organizational resources and threat exposure, not just data impact levels.

How to eliminate wrong answers

Option B (COBIT 2019) is wrong because it is a governance and management framework focused on IT processes and objectives, not a control framework structured around Implementation Groups; it uses a capability maturity model and process reference model instead. Option C (ISO 27001 Annex A) is wrong because it is a list of control objectives and controls for an Information Security Management System (ISMS), but it does not define Implementation Groups; organizations must determine applicability based on their own risk assessment, not a predefined tiered grouping. Option D (NIST SP 800-53) is wrong because it provides a comprehensive catalog of security and privacy controls for federal information systems, organized by control families (e.g., Access Control, Audit and Accountability), not by Implementation Groups; it uses baselines (Low, Moderate, High) but these are impact-based, not risk-prioritized tiers like IG1/IG2/IG3.

531
MCQmedium

A multinational corporation must comply with both GDPR and CCPA. Which governance approach is most effective?

A.Create a single rigid unified policy applicable everywhere
B.Develop a unified data protection framework with regional adjustments
C.Implement separate compliance programs for each regulation
D.Outsource compliance to a third-party service provider
AnswerB

This approach balances consistency with flexibility to address local regulations.

Why this answer

A unified data protection framework with regional adjustments allows the organization to maintain consistent governance principles while accommodating specific legal requirements of GDPR (e.g., data subject rights, 72-hour breach notification) and CCPA (e.g., opt-out rights, broader definition of personal information). This approach aligns with the CISM domain of Information Security Governance by enabling scalable, risk-based compliance without duplicating efforts or creating conflicts between policies.

Exam trap

The trap here is that candidates often choose Option C (separate programs) thinking it ensures full compliance, but CISM emphasizes governance efficiency and risk management, where a unified framework with regional adjustments is the most effective approach to avoid duplication and control conflicts.

How to eliminate wrong answers

Option A is wrong because a single rigid unified policy cannot simultaneously satisfy GDPR's strict consent and data portability requirements and CCPA's opt-out and service provider definitions, leading to non-compliance in one or both jurisdictions. Option C is wrong because implementing separate compliance programs for each regulation creates silos, increases operational complexity, and misses opportunities for shared controls (e.g., data mapping, access controls) that could reduce cost and risk. Option D is wrong because outsourcing compliance to a third-party service provider transfers accountability but not liability; the corporation remains ultimately responsible under both GDPR (Article 28) and CCPA (Section 1798.140), and third parties may not have the necessary context for nuanced regional adjustments.

532
Multi-Selectmedium

A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?

Select 2 answers
A.Aligns security spending with business objectives
B.Provides a defensible justification for security investments
C.Eliminates the need for qualitative analysis
D.Ensures compliance with all applicable regulations
E.Reduces the total number of security controls needed
AnswersA, B

Correct; risk assessment helps prioritize based on business impact.

Why this answer

A risk-based approach ensures that security spending is directed toward mitigating the risks that most threaten the institution's critical business objectives, such as protecting customer financial data or ensuring transaction integrity. By prioritizing initiatives based on assessed risk levels, the organization directly links security investments to business value, avoiding waste on low-priority controls.

Exam trap

The trap here is that candidates may confuse the purpose of risk assessment results—which is to prioritize based on business impact—with compliance or control reduction, leading them to select options like D or E that sound plausible but are not primary benefits of a risk-based approach.

533
MCQmedium

A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?

A.Detailed logs of all security incidents from the past week
B.List of all vulnerabilities found during the last scan
C.Top security risks and key performance indicators with trends
D.Full results of the latest phishing simulation
AnswerC

Provides actionable insight at a strategic level.

Why this answer

C-suite executives need high-level strategic insights, not operational details. Top risks and key metrics (e.g., risk posture, critical incidents) are suitable for a dashboard.

534
MCQmedium

An organization is updating its security policies. After drafting the policy, which step should occur NEXT?

A.Stakeholder consultation
B.Training and awareness
C.Approval by management
D.Legal review
AnswerD

Legal review is the next logical step.

Why this answer

Legal review ensures the policy complies with applicable laws and regulations before seeking approval.

535
MCQhard

A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?

A.Number of policy violations
B.Percentage of employees who completed training
C.Number of security incidents reported
D.Phishing simulation click rate
AnswerC

Number of security incidents reported - Correct. A high number of reported incidents demonstrates employee engagement and a willingness to report, which is a key indicator of a positive security culture.

Why this answer

The best metric for indicating a positive security culture is the number of security incidents reported. A high number of reported incidents demonstrates employee engagement, vigilance, and trust in the reporting process. This proactive behavior is a stronger indicator of a positive culture than metrics like phishing click rates, which primarily measure specific awareness effectiveness.

536
MCQeasy

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

A.Business-enabling controls
B.Critical controls first
C.Compensating controls
D.Defense-in-depth
AnswerD

Defense-in-depth uses multiple layers of defense to protect assets.

Why this answer

Defense-in-depth (option D) is the correct approach because it implements multiple, overlapping layers of security controls (e.g., firewalls, IDS/IPS, endpoint protection, access controls) so that if one layer fails or is bypassed, subsequent layers continue to provide protection. This layered strategy reduces the likelihood of a single point of failure compromising the entire security posture, aligning with the CISM principle of risk mitigation through redundancy.

Exam trap

The trap here is that candidates often confuse 'compensating controls' (which are alternative controls for a specific requirement or deficiency) with the broader 'defense-in-depth' strategy. In the CISM context, defense-in-depth is the layered approach that uses multiple controls to provide redundancy, so that if one fails, others still provide protection. Compensating controls are a subset used when primary controls cannot be implemented, not the overall layered strategy.

How to eliminate wrong answers

Option A is wrong because business-enabling controls are designed to support business objectives (e.g., enabling remote access) rather than providing redundant layers of defense; they focus on functionality, not compensating for failures. Option B is wrong because 'critical controls first' refers to prioritizing implementation of the most important controls (e.g., from the CIS Critical Security Controls), but it does not inherently ensure multiple layers or compensation if one fails—it's a prioritization strategy, not a layered defense model. Option C is wrong because compensating controls are specific alternative controls used when a primary control cannot be implemented (e.g., using additional logging instead of encryption), but they are not a comprehensive layered approach; defense-in-depth encompasses multiple layers, including compensating controls as one possible element, not the overarching strategy.

537
MCQmedium

An organization is implementing a new cloud-based ERP system. Which of the following is the MOST important action for the information security manager to ensure alignment with the organization's risk appetite?

A.Conduct a risk assessment to identify and evaluate risks associated with the cloud deployment.
B.Review the cloud provider's SOC 2 report for compliance with relevant regulations.
C.Negotiate contract terms including data protection clauses with the cloud provider.
D.Develop a detailed access control policy specifically for the cloud ERP system.
AnswerA

A risk assessment directly aligns security measures with risk appetite.

Why this answer

Conducting a risk assessment (A) is the most important action because it directly evaluates the cloud ERP deployment against the organization's risk appetite, identifying, analyzing, and evaluating risks such as data exposure, vendor lock-in, and compliance gaps. This foundational step ensures that subsequent controls, contracts, and policies are aligned with the acceptable level of risk, as defined by the organization's risk tolerance thresholds.

Exam trap

The trap here is that candidates often confuse operational due diligence (like reviewing SOC 2 reports or negotiating contracts) with the strategic governance action of aligning with risk appetite, which must start with a risk assessment to define the baseline for all subsequent decisions.

How to eliminate wrong answers

Option B is wrong because reviewing a SOC 2 report is a due diligence activity that assesses the cloud provider's controls, but it does not inherently align the deployment with the organization's specific risk appetite; it only verifies compliance with predefined criteria. Option C is wrong because negotiating contract terms, while important for legal protection, occurs after risks are identified and does not ensure alignment with risk appetite without a prior risk assessment to inform those terms. Option D is wrong because developing a detailed access control policy is a tactical control implementation that addresses a subset of risks, but it does not provide the strategic alignment with risk appetite that a comprehensive risk assessment achieves.

538
MCQhard

You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?

A.Hire two additional security analysts to improve monitoring and incident response.
B.Implement a formal vulnerability management program with defined remediation SLAs based on risk severity.
C.Increase cyber liability insurance coverage to $5 million to cover potential breach costs.
D.Rewrite the web application using a secure development framework to eliminate vulnerabilities.
AnswerB

This directly addresses the failure to remediate known vulnerabilities, ensuring timely fixes.

Why this answer

A formal vulnerability management program with defined remediation SLAs directly addresses the root cause: the known vulnerability was not patched due to competing priorities. By tying remediation timelines to risk severity (e.g., critical vulnerabilities patched within 7 days, high within 30 days), the company operationalizes its 'moderate' risk appetite and ensures that penetration test findings are acted upon before they can be exploited. This is the most cost-effective approach given the limited budget, as it leverages existing staff and processes rather than requiring new hires or expensive rewrites.

Exam trap

ISACA often tests the misconception that increasing insurance or hiring more staff is the primary solution to a risk management failure, when in fact the core issue is the lack of a process to enforce remediation of known vulnerabilities within the organization's risk appetite.

How to eliminate wrong answers

Option A is wrong because hiring two additional security analysts improves monitoring and incident response but does not fix the underlying issue of unpatched vulnerabilities; the attacker exploited a known vulnerability that should have been remediated, not a detection gap. Option C is wrong because increasing cyber liability insurance to $5 million only transfers financial risk after a breach, it does not prevent recurrence of the vulnerability exploitation and violates the principle of reducing risk to an acceptable level. Option D is wrong because rewriting the web application using a secure development framework is a long-term, high-cost solution that exceeds the limited budget and does not address the immediate need to remediate existing vulnerabilities; it also ignores the fact that the current application is already in production and needs a process for ongoing vulnerability management.

539
Multi-Selectmedium

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Select 2 answers
A.Immediate patching of all vulnerabilities within 24 hours.
B.Vulnerability disclosure program for external researchers.
C.Penetration testing of all applications annually.
D.Regular vulnerability scanning of all systems.
E.Risk-based prioritization of vulnerabilities for remediation.
AnswersD, E

Scanning identifies vulnerabilities.

Why this answer

Vulnerability management includes regular scanning and a prioritization process to remediate based on risk. Patching is part of remediation, but scanning and prioritization are foundational.

540
MCQhard

An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?

A.WinHex
B.dd command
C.FTK Imager
D.Memory dump tool (e.g., winpmem)
AnswerD

Memory dump tools are designed to capture volatile data from RAM.

Why this answer

Volatile data from memory is best captured using a dedicated memory acquisition tool like winpmem or similar. FTK Imager and WinHex are primarily for disk imaging. The dd command is used for disk copying, not memory.

Memory dumps capture volatile data.

541
MCQmedium

Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?

A.Mean time to respond (MTTR)
B.Patch compliance percentage
C.Mean time to detect (MTTD)
D.Number of security incidents
AnswerA

MTTR indicates how quickly the organization responds to incidents.

Why this answer

Mean time to respond (MTTR) directly measures how quickly incidents are contained and remediated.

542
MCQeasy

Which role is primarily responsible for developing and maintaining the organization's security architecture?

A.Security Analyst
B.GRC Analyst
C.Security Architect
D.Penetration Tester
AnswerC

The Security Architect designs security structures and ensures they align with business needs.

Why this answer

The security architect designs and oversees the implementation of security architecture.

543
MCQmedium

A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?

A.Implement technical controls
B.Develop policies based on industry standards
C.Perform a risk assessment
D.Use the COBIT framework
AnswerD

COBIT is designed for governance and alignment of IT with business objectives.

Why this answer

The COBIT framework (Control Objectives for Information and Related Technologies) is specifically designed to bridge the gap between IT governance and business goals, providing a comprehensive set of controls and processes that align security program objectives with enterprise strategy. Unlike other options, COBIT directly addresses governance, risk management, and performance measurement in a way that ensures the security program supports business objectives rather than operating in isolation.

Exam trap

The trap here is that candidates often choose 'Perform a risk assessment' (Option C) because risk assessment is a foundational security activity, but the question asks for the 'best approach' to ensure alignment with business objectives, which requires a governance framework like COBIT that systematically links risk management to strategy, not just a one-time assessment.

How to eliminate wrong answers

Option A is wrong because implementing technical controls without first understanding business objectives and risk appetite can lead to misaligned security measures that either over-constrain operations or leave critical assets unprotected. Option B is wrong because developing policies based solely on industry standards (e.g., ISO 27001, NIST) may achieve compliance but does not inherently ensure alignment with the company's specific business goals, strategic priorities, or risk tolerance. Option C is wrong because performing a risk assessment is a critical input to alignment but is a tactical activity, not a governance framework; it identifies risks but does not provide the structured governance mechanisms to continuously align security program decisions with business objectives.

544
MCQmedium

A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?

A.Review additional logs to confirm
B.Escalate to the incident response manager
C.Immediately block the source IP
D.Quarantine the affected system
AnswerA

Reviewing additional logs provides context and helps confirm whether the alert represents a true incident.

Why this answer

The analyst must first validate the alert by reviewing additional logs (e.g., firewall, proxy, DNS, or endpoint logs) to confirm whether the SIEM alert represents a true positive. Jumping to containment or escalation without confirmation risks unnecessary disruption and false alarms, which violates the incident response principle of 'verify before acting.' The SIEM may have triggered on a benign pattern (e.g., a large file transfer to a trusted cloud service), and only correlated log analysis can establish intent and context.

Exam trap

The trap here is that candidates confuse 'immediate containment' (a later step in incident response) with 'initial validation,' leading them to choose a disruptive action like blocking or quarantining before confirming the alert is a true positive.

How to eliminate wrong answers

Option B is wrong because escalating to the incident response manager without first confirming the alert is premature; escalation should occur only after the analyst has validated the alert as a true positive and gathered initial evidence. Option C is wrong because immediately blocking the source IP could disrupt legitimate business operations if the alert is a false positive, and it destroys forensic evidence (e.g., netflow data, active connections) needed for further analysis. Option D is wrong because quarantining the affected system is a containment action that should only be taken after confirming malicious activity; premature quarantine can cause unnecessary downtime and may not be appropriate for a potential false positive.

545
Multi-Selectmedium

Which TWO actions are essential during the detection and analysis phase of incident response?

Select 2 answers
A.Notify law enforcement
B.Disconnect affected systems
C.Determine the scope of the incident
D.Rebuild systems
E.Identify indicators of compromise (IOCs)
AnswersC, E

Correct: Scope assessment is essential to understand impact.

Why this answer

Determining the scope of the incident (C) is essential during the detection and analysis phase because it defines the boundaries of the compromise—identifying which systems, data, and users are affected. This step is critical for prioritizing response actions and preventing the incident from spreading further. Without scope determination, subsequent containment and eradication efforts may be misdirected or incomplete.

Exam trap

ISACA often tests the distinction between phases of the incident response lifecycle (NIST SP 800-61), and the trap here is confusing containment actions (like disconnecting systems) with detection and analysis actions, leading candidates to select Option B instead of focusing on scope determination and IOC identification.

546
MCQeasy

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

A.Chief Information Security Officer
B.Incident response manager
C.External legal counsel
D.Board of directors
AnswerC

External legal counsel is a vendor contact often needed during incidents.

Why this answer

Third-party contacts such as legal firms, forensic investigators, PR agencies, and insurance providers are essential for incident response. Internal contacts are separate.

547
MCQhard

A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?

A.Conduct quarterly penetration tests
B.Achieve 95% scan coverage of assets
C.Reduce mean time to remediate critical vulnerabilities by 30%
D.Increase the number of scans by 20%
AnswerC

Directly measures improvement in reducing vulnerability exposure.

Why this answer

Mean time to remediate critical vulnerabilities directly measures risk reduction, as faster remediation lowers exposure.

548
Multi-Selectmedium

A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?

Select 2 answers
A.Compliance cost avoidance
B.Breach cost avoidance
C.Mean time to respond (MTTR) improvements
D.Phishing simulation click rate
E.Number of vulnerabilities discovered
AnswersA, B

Shows how the tool reduces costs related to regulatory compliance (e.g., fines, audits).

Why this answer

Senior leadership cares about financial impact. Breach cost avoidance and compliance cost avoidance directly demonstrate value by reducing potential losses.

549
MCQmedium

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

A.Requiring that key vendors include security requirements in contracts with their subcontractors
B.Performing on-site audits of all third parties
C.Accepting the risk since it is outside the organization's control
D.Conducting annual assessments of all direct vendors only
AnswerA

Cascading requirements help mitigate nth-party risk.

Why this answer

Nth-party risk refers to risks from suppliers of your suppliers. Contractual requirements that cascade down the supply chain are essential to manage this risk.

550
MCQeasy

What is the first step in the security policy development lifecycle?

A.Gap analysis
B.Legal review
C.Drafting the policy
D.Stakeholder consultation
AnswerA

Correct: Identifies needs first.

Why this answer

Gap analysis identifies missing or inadequate controls before drafting new policies.

551
MCQmedium

A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?

A.Proceed with restoration from the most recent backup to restore operations quickly.
B.Rebuild the servers from scratch and restore from an offline backup taken before the compromise.
C.First, clean the backup repository and verify integrity before restoring to prevent re-infection.
D.Engage law enforcement before any restoration activities.
AnswerB

This ensures no malware is reintroduced and the backup is trusted.

Why this answer

Restoring from an offline backup taken before the compromise ensures that the restored data is free of the ransomware and that the backup itself was not encrypted or tampered with. Since the attacker had administrative credentials, any online backup repository could have been accessed and compromised, making offline backups the only trustworthy source. This approach also eliminates the risk of re-infection by rebuilding the servers from scratch, ensuring no residual malware remains.

Exam trap

The trap here is that candidates may assume a backup repository can be cleaned or verified as safe, overlooking that an attacker with administrative credentials could have compromised the backup system itself, making offline backups the only reliable recovery source.

How to eliminate wrong answers

Option A is wrong because restoring from the most recent backup, even if it appears intact, risks re-infection if the backup repository was accessed by the attacker using administrative credentials; the ransomware may have encrypted or corrupted the backup files, or the backup may contain the initial infection vector. Option C is wrong because cleaning the backup repository and verifying integrity before restoration is insufficient if the attacker had administrative credentials—they could have planted persistent malware or altered backup metadata, and cleaning does not guarantee the repository is free of compromise; offline backups are the only safe source. Option D is wrong because engaging law enforcement before restoration is not the immediate priority; while notification may be required, delaying restoration increases downtime and business impact, and law enforcement typically does not prohibit restoration from offline backups.

552
MCQhard

During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?

A.Implement additional controls immediately
B.Document the risk as accepted
C.Escalate the residual risk to senior management
D.Reassess the risk using a different methodology
AnswerC

Why this answer

When residual risk exceeds the risk appetite threshold after planned controls, the security manager cannot simply accept or ignore it; the risk must be escalated to senior management because they hold the authority to decide whether to accept the risk, allocate additional budget for further controls, or adjust the risk appetite. This aligns with the CISM domain of Information Security Risk Management, where risk acceptance is a management decision, not an operational one.

Exam trap

The trap here is that candidates confuse operational risk acceptance (which a manager can do for low risks) with management-level risk acceptance required when residual risk exceeds the appetite threshold, leading them to incorrectly choose Option B.

Why the other options are wrong

A

While additional controls may be an option, the immediate next step is to escalate and get a decision.

B

Acceptance requires authorization from management, not unilateral action by the security manager.

D

Changing methodology may give different numbers but doesn't address the underlying issue.

553
MCQeasy

After a security incident, which step should be taken first?

A.Recovery
B.Lessons learned
C.Containment
D.Eradication
AnswerC

Correct: Immediate containment stops the incident from spreading.

Why this answer

In incident management, containment is the immediate priority after detection because it stops the spread of the threat and limits damage. Without containment, the attacker may continue to move laterally, exfiltrate data, or destroy evidence, making recovery and eradication ineffective. CISM emphasizes that containment must precede eradication and recovery to preserve forensic integrity and reduce business impact.

Exam trap

ISACA CISM often tests the misconception that eradication or recovery should come first because candidates confuse the urgency of removing the threat with the logical sequence of incident response phases.

How to eliminate wrong answers

Option A is wrong because recovery (restoring systems to normal operation) cannot safely occur until the threat is contained and eradicated; attempting recovery first risks re-infection or further damage. Option B is wrong because lessons learned is a post-incident review activity that occurs after containment, eradication, and recovery are complete, not as the first step. Option D is wrong because eradication (removing malware, closing backdoors) requires containment first to ensure the attacker cannot re-enter or cause additional harm during the removal process.

554
MCQhard

After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?

A.Transfer the risk through insurance
B.Accept the residual risk as a business decision
C.Document the risk and escalate to senior management for acceptance
D.Implement additional controls regardless of cost
AnswerC

Formal escalation ensures informed decision-making and proper risk acceptance.

Why this answer

The risk manager should document the risk and escalate to senior management for formal acceptance. Acceptance requires approval at an appropriate level. Simply accepting without documentation is not proper.

Implementing controls regardless of cost ignores cost-benefit. Transferring via insurance does not address residual risk that already exceeds appetite.

555
MCQeasy

Based on the incident response policy exhibit, which phase should include notifying external stakeholders such as law enforcement?

A.Recovery
B.Post-Incident
C.Detection
D.Containment
AnswerB

Post-incident includes reporting and lessons learned, which may involve external notifications.

Why this answer

B is correct because the post-incident phase is the appropriate time to notify external stakeholders such as law enforcement, as it occurs after containment and eradication are complete. During this phase, the incident is fully documented, evidence is preserved, and legal obligations (e.g., breach notification laws like GDPR Article 33 or HIPAA Breach Notification Rule) are fulfilled. Notifying law enforcement earlier could compromise forensic integrity or operational continuity, so it is deliberately deferred to the post-incident stage.

Exam trap

ISACA often tests the misconception that law enforcement must be notified immediately upon detection, but the correct timing is after containment and eradication to avoid compromising evidence and operational response.

How to eliminate wrong answers

Option A is wrong because the recovery phase focuses on restoring systems to normal operations, not on external notifications; law enforcement involvement would disrupt recovery efforts. Option C is wrong because the detection phase is about identifying potential incidents via alerts (e.g., from SIEM or IDS), not about stakeholder communication; premature notification could lead to false alarms. Option D is wrong because the containment phase aims to isolate the incident to prevent further damage (e.g., via network segmentation or host isolation), and involving law enforcement at this stage could interfere with rapid containment actions.

556
MCQeasy

During an incident investigation, the incident response team needs to collect volatile data from a compromised server. Which of the following data should be collected FIRST?

A.Contents of system memory (RAM)
B.Network connection logs from the firewall
C.Contents of the hard drive
D.Event logs from the system
AnswerA

Memory is the most volatile and should be captured first.

Why this answer

Volatile data, such as the contents of system memory (RAM), is lost when the system is powered off. Collecting RAM first preserves evidence of running processes, network connections, and encryption keys that would otherwise be destroyed. This follows the order of volatility (RFC 3227), which mandates capturing the most volatile data first.

Exam trap

The trap here is that candidates often prioritize persistent data like hard drive contents or logs, mistakenly thinking they are more important, but the order of volatility dictates that transient data in RAM must be captured first to avoid permanent loss.

How to eliminate wrong answers

Option B is wrong because network connection logs from the firewall are non-volatile and stored on a separate device, so they can be collected later without risk of loss. Option C is wrong because the contents of the hard drive are non-volatile and can be imaged after the system is powered down, but collecting it first would risk overwriting volatile data in RAM. Option D is wrong because event logs from the system are stored on the hard drive and are non-volatile; they can be collected after volatile data has been captured.

557
MCQeasy

Which governance model is characterized by a single, centralized security team that serves the entire organization?

A.Centralized
B.Federated
C.Decentralized
D.Hybrid
AnswerA

Correct: Single team serves entire organization.

Why this answer

Centralized governance consolidates security resources and authority under one team, ensuring consistent policy enforcement and streamlined management.

558
Multi-Selecteasy

Which TWO of the following are primary objectives of information security governance? (Choose two.)

Select 2 answers
A.Eliminate all information security risks.
B.Align security strategy with business goals.
C.Maximize profitability through security investments.
D.Ensure accountability for security decisions.
E.Achieve compliance with all applicable regulations.
AnswersB, D

Core objective of governance.

Why this answer

Information security governance's primary objective is to ensure that security strategy is aligned with business goals, enabling the organization to protect assets while supporting its mission. This alignment is achieved through governance frameworks like COBIT or ISO 38500, which mandate that security investments and controls are directly tied to business objectives, not isolated technical measures.

Exam trap

The trap here is that candidates confuse compliance (Option E) with governance, but CISM emphasizes that governance is about strategic alignment and accountability, not just meeting regulatory checklists, which is a common misconception in exam questions.

559
MCQmedium

Which of the following best describes the primary purpose of a security program's governance framework?

A.To implement technical security controls
B.To provide oversight and alignment with business objectives
C.To conduct vulnerability assessments
D.To manage security incidents
AnswerB

Why this answer

The primary purpose of a security program's governance framework is to provide oversight and ensure that security activities are aligned with business objectives, risk appetite, and regulatory requirements. It establishes the policies, roles, and accountability structures that guide decision-making, rather than directly executing technical tasks. This alignment is critical for the program to be sustainable and supported by executive management.

Exam trap

The trap here is that candidates confuse the governance framework with the operational security program itself, mistakenly selecting a tactical activity (like implementing controls or managing incidents) instead of recognizing that governance is the strategic oversight layer that directs and constrains those activities.

Why the other options are wrong

A

Technical controls are operational, not governance.

C

Vulnerability assessments are part of ongoing operations.

D

Incident management is a process within the program.

560
MCQhard

A CISO is preparing the security budget for the next fiscal year. The current IT budget is $10 million. For a mature security program, what is the recommended security budget range?

A.$500,000 to $750,000
B.$1 million to $1.5 million
C.$100,000 to $200,000
D.$2 million to $3 million
AnswerB

Correct. 10-15% of $10 million is $1-1.5 million.

Why this answer

Best practice for a mature security program is to allocate 10-15% of the IT budget to security. For a $10 million IT budget, that is $1 million to $1.5 million.

561
MCQmedium

When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?

A.Ignore the MTD and focus solely on incident eradication
B.Continue incident response until full recovery
C.Declare a disaster immediately without further analysis
D.Escalate to the BC/DR team for possible activation of continuity plans
AnswerD

This triggers BC/DR processes to protect business operations.

Why this answer

If the MTD is at risk, the incident response team should escalate to BC/DR to activate continuity or recovery plans. This ensures business functions are restored.

562
Drag & Dropmedium

Order the steps for implementing a security awareness training program.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Training programs start with needs assessment, then content development, delivery, evaluation, and continuous improvement.

563
Multi-Selecthard

Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)

Select 2 answers
A.Chief Information Security Officer (CISO)
B.Security analyst
C.Chief Executive Officer (CEO)
D.Help desk manager
E.Network administrator
AnswersA, C

CISO leads the technical response and advises on security matters.

Why this answer

The CMT typically includes the CEO and CISO, among others, to make strategic decisions.

564
MCQeasy

Which of the following is the most significant risk in this architecture?

A.Segmentation of network zones
B.Admin access via VPN and jump host
C.Use of TLS 1.3 for encryption
D.Direct SQL authentication from application server to database
AnswerD

If app server is compromised, database can be accessed directly.

Why this answer

Direct SQL authentication from the application server to the database bypasses any centralized authentication or service account management, creating a single point of failure for credential compromise. If the application server is breached, an attacker can extract hardcoded or stored database credentials and gain unfettered access to the database, leading to potential data exfiltration or destruction. This risk is magnified because direct SQL authentication often uses static, long-lived credentials without the layered controls (e.g., MFA, session auditing) that would be present in a more robust authentication path.

Exam trap

The trap here is that candidates often mistake a common security control (like TLS 1.3 or VPN) for a risk, or they fail to recognize that direct SQL authentication is a dangerous architectural flaw that bypasses all centralized authentication and authorization controls.

How to eliminate wrong answers

Option A is wrong because segmentation of network zones is a security control that reduces risk by isolating traffic and limiting lateral movement; it is not a risk but a mitigation. Option B is wrong because admin access via VPN and jump host is a standard, secure practice that enforces encrypted tunnels and a controlled bastion host, reducing the attack surface for administrative actions. Option C is wrong because use of TLS 1.3 for encryption is a strong, modern cryptographic protocol that provides confidentiality and integrity for data in transit; it is a security enhancement, not a risk.

565
Multi-Selecthard

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

Select 3 answers
A.Assess impact on existing controls
B.Immediately enforce all changes regardless of cost
C.Outsource compliance to a single vendor
D.Monitor regulatory updates from authorities
E.Update policies and controls accordingly
AnswersA, D, E

Determines required adjustments.

Why this answer

Monitoring regulatory changes, assessing impact, and updating controls are critical to maintaining compliance.

566
MCQhard

After a data breach, the CISO is updating the incident response plan. Which of the following is MOST critical to include?

A.Communication templates for stakeholders
B.Technical forensic procedures
C.Root cause analysis methodology
D.Legal hold instructions for data preservation
AnswerA

Effective communication is vital to control damage and meet legal obligations.

Why this answer

After a data breach, the incident response plan must prioritize clear, consistent communication to manage stakeholder expectations, regulatory notifications, and legal repercussions. Communication templates ensure that notifications to customers, regulators, and executives are accurate, timely, and compliant with breach notification laws (e.g., GDPR Article 33, state-specific 72-hour requirements). Without predefined templates, the response team risks delays or inconsistent messaging, which can exacerbate reputational damage and legal liability.

Exam trap

CISM often tests the distinction between strategic plan components (like communication templates) and tactical/operational details (like forensic procedures or root cause analysis), tempting candidates to choose a technically detailed option that is not the most critical for the plan's immediate post-breach effectiveness.

How to eliminate wrong answers

Option B is wrong because technical forensic procedures are operational details typically documented in a separate forensic playbook or standard operating procedure, not in the high-level incident response plan; the plan should reference the need for forensics but not include the step-by-step commands or tools. Option C is wrong because root cause analysis methodology is part of the post-incident review phase, not the immediate response phase; including it in the plan would clutter the critical response steps and delay time-sensitive actions. Option D is wrong because legal hold instructions are a legal process managed by the legal team and are typically covered in a data preservation policy or legal hold notice, not in the incident response plan itself; the plan should note the requirement to preserve evidence but not the detailed hold instructions.

567
MCQmedium

A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?

A.Select appropriate security controls
B.Conduct vulnerability scanning
C.Identify potential threat sources
D.Identify and classify information assets
AnswerD

Asset identification is foundational to any risk assessment.

Why this answer

In the risk assessment process, the first step is to identify and classify information assets because you cannot assess risks to assets you haven't identified. For a cloud-based system storing sensitive customer data, this means cataloging data types (e.g., PII, financial records), their locations (e.g., specific cloud storage buckets), and their classification levels (e.g., confidential, restricted) before any threat or vulnerability analysis can be meaningfully performed.

Exam trap

The trap here is that candidates often confuse the order of risk assessment steps, mistakenly thinking that identifying threats (Option C) comes first because threats are the 'active' element, but CISM emphasizes that asset identification is the foundational step that drives all subsequent analysis.

How to eliminate wrong answers

Option A is wrong because selecting security controls is a risk treatment step that occurs after risks have been assessed and prioritized, not at the beginning of the assessment. Option B is wrong because vulnerability scanning is a technical activity that identifies weaknesses in existing systems, but it cannot be effectively scoped or targeted without first knowing which assets are in scope and their classification. Option C is wrong because while identifying threat sources is important, it logically follows asset identification; you must know what assets you are protecting before you can determine which threats are relevant to those specific assets.

568
MCQhard

An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?

A.Isolate affected endpoints from the network while preserving memory
B.Disable user accounts
C.Block known malicious IPs
D.Reimage all endpoints
AnswerA

Correct: Contains the threat and preserves forensic data.

Why this answer

Isolating affected endpoints preserves volatile memory evidence needed to analyze fileless malware.

569
MCQhard

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

A.Consolidate all security tools
B.Conduct a comprehensive risk assessment of the target
C.Merge the security teams into one reporting structure
D.Standardize security policies immediately
AnswerB

Risk assessment provides the basis for all integration decisions.

Why this answer

A comprehensive risk assessment of the target company's environment identifies integration risks and informs the integration plan. Option A is premature without understanding risks. Option C and D are tactical steps that should follow risk assessment.

570
MCQeasy

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

A.To ensure compliance with regulations
B.To assign accountability to individuals
C.To track the budget for security initiatives
D.To measure the effectiveness of security controls
AnswerD

KPIs provide quantifiable measures of control performance and program outcomes.

Why this answer

KPIs are designed to provide measurable evidence of how well the security program is achieving its objectives, specifically by quantifying the effectiveness of security controls. For example, a KPI like 'mean time to detect (MTTD)' directly measures the performance of detection controls, enabling data-driven decisions on control improvements. This aligns with the CISM focus on governance and performance management, not just compliance or budgeting.

Exam trap

The trap here is that candidates often confuse KPIs with compliance metrics or operational tasks, mistakenly thinking the primary purpose is to ensure regulatory adherence rather than to measure and improve the effectiveness of security controls.

How to eliminate wrong answers

Option A is wrong because compliance with regulations is a baseline requirement, not the primary purpose of KPIs; KPIs measure performance beyond mere compliance, such as control effectiveness. Option B is wrong because assigning accountability is a function of roles and responsibilities within the governance structure, not a direct purpose of KPIs, which are metrics, not assignment tools. Option C is wrong because tracking the budget for security initiatives is a financial management activity, typically measured by cost-related metrics (e.g., cost per incident), not the primary purpose of KPIs, which focus on operational and strategic effectiveness.

571
Multi-Selectmedium

A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?

Select 2 answers
A.Phishing simulation click rate
B.Average patch deployment time
C.Number of firewall rules
D.Security investment vs. loss avoidance
E.Mean time to respond (MTTR)
AnswersD, E

Demonstrates financial ROI.

Why this answer

Mean time to respond (MTTR) and security investment vs. loss avoidance are strategic metrics that inform risk management and resource allocation.

572
Multi-Selecteasy

Which TWO of the following are typically considered key components of an information security governance framework?

Select 2 answers
A.Adoption of a formal risk management process
B.Scheduling of regular penetration tests
C.Establishment of a performance measurement system
D.Development of a detailed incident response plan
E.Implementation of specific technical controls
AnswersA, C

Risk management is a foundational governance component.

Why this answer

Correct: A and C. A formal risk management process (A) is a fundamental component of an information security governance framework as it ensures risks are identified, assessed, and managed. A performance measurement system (C) is also key for evaluating the effectiveness of governance activities and aligning them with organizational objectives.

Options B, D, and E are more operational or tactical in nature and are not typically considered core governance components.

573
MCQhard

During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?

A.Establish a policy review committee with business unit representatives to align policy with operational needs.
B.Provide additional security awareness training focused on policy requirements.
C.Escalate non-compliance to senior management for disciplinary action.
D.Increase the frequency of automated policy compliance checks.
AnswerA

Involving stakeholders increases buy-in and practical compliance.

Why this answer

The most effective way to improve compliance is to align the policy with operational realities by involving business unit representatives in a policy review committee. When policies conflict with business processes, users will bypass them; adjusting the policy to be both secure and practical increases voluntary adherence. This addresses the root cause—policy misalignment—rather than treating symptoms like lack of awareness or enforcement.

Exam trap

The trap here is that candidates often choose awareness training (B) as a quick fix, but CISM emphasizes that non-compliance due to policy misalignment requires policy revision, not just more training or enforcement.

How to eliminate wrong answers

Option B is wrong because additional awareness training assumes the non-compliance stems from ignorance, but the audit found the policy is not being followed despite likely existing training; the core issue is policy impracticality, not lack of knowledge. Option C is wrong because escalating non-compliance for disciplinary action treats the symptom (violations) without fixing the underlying policy that may be unworkable, and it can damage trust and reduce reporting of genuine issues. Option D is wrong because increasing automated compliance checks only detects violations more frequently but does not address why business units are not following the policy; it may even increase friction and shadow IT if the policy remains misaligned.

574
MCQeasy

Which of the following is the PRIMARY purpose of an information security risk assessment?

A.To eliminate all identified risks
B.To identify and evaluate risks in terms of likelihood and impact
C.To comply with regulatory requirements
D.To assign blame for security incidents
AnswerB

Why this answer

The primary purpose of an information security risk assessment is to identify and evaluate risks in terms of their likelihood and impact. This process enables an organization to prioritize risks and determine appropriate risk treatment options, such as mitigation, transfer, acceptance, or avoidance, based on a clear understanding of the risk landscape. Without this evaluation, any subsequent risk management decisions would lack a defensible basis.

Exam trap

The trap here is that candidates often confuse the purpose of a risk assessment with the purpose of risk treatment or compliance, leading them to select 'comply with regulatory requirements' as the primary purpose, when in fact compliance is a secondary benefit, not the core objective.

Why the other options are wrong

A

Eliminating all risks is impractical and not the primary purpose; risk assessment informs risk treatment decisions.

C

Compliance may be a driver but is not the primary purpose; the core is informed decision-making.

D

Risk assessment is proactive, not punitive.

575
MCQmedium

After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?

A.Implement a regulatory framework as the baseline
B.Maintain separate frameworks until a natural convergence occurs
C.Adopt the security framework of the acquiring company
D.Develop a new framework incorporating strengths from both companies
AnswerD

Fosters buy-in and leverages existing capabilities.

Why this answer

Merging two distinct security cultures requires a deliberate, collaborative approach that leverages the best practices from both organizations. Developing a new framework that incorporates strengths from both companies ensures buy-in from stakeholders and creates a unified governance structure that is tailored to the combined entity's risk profile, rather than imposing one side's culture or waiting for an uncertain natural convergence.

Exam trap

The trap here is that candidates often assume the acquiring company's framework should dominate (Option C) due to organizational hierarchy, but CISM emphasizes that effective governance requires cultural integration and stakeholder alignment, not unilateral imposition.

How to eliminate wrong answers

Option A is wrong because implementing a regulatory framework as the baseline (e.g., ISO 27001 or NIST CSF) provides a compliance foundation but does not address the cultural integration or operational differences between the two companies, potentially leading to resistance or gaps in governance. Option B is wrong because maintaining separate frameworks until a natural convergence occurs is passive and risky; it prolongs security inconsistencies, creates blind spots in oversight, and fails to establish a unified governance structure in a timely manner. Option C is wrong because adopting the security framework of the acquiring company ignores the acquired company's existing controls and cultural strengths, which can cause friction, loss of institutional knowledge, and non-compliance with legacy requirements.

576
MCQhard

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

A.Slower incident response
B.Inconsistent security levels across business units
C.Higher cost of compliance
D.Duplication of controls
AnswerB

Inconsistency can create security gaps and regulatory non-compliance.

Why this answer

Decentralized governance leads to inconsistent security levels across business units, which is a major regulatory and risk concern. Option A is possible but less critical. Option C may increase but is a consequence.

Option D may be slower but inconsistent security is more fundamental.

577
Multi-Selecteasy

Which TWO components are essential for an effective information security governance framework?

Select 2 answers
A.Implementation of an intrusion detection system
B.Detailed technical configuration guides
C.Board-level oversight of security programs
D.Alignment of security program with business objectives
E.Daily threat intelligence feeds
AnswersC, D

Governance requires board accountability and oversight to ensure security is prioritized.

Why this answer

Board-level oversight and alignment with business objectives are foundational to governance, ensuring security is integrated into organizational strategy.

578
Multi-Selecteasy

Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)

Select 2 answers
A.Restore normal business operations
B.Eradicate the root cause of the incident
C.Preserve evidence for legal proceedings
D.Prevent the incident from spreading to other systems
E.Limit the scope and impact of the incident
AnswersD, E

Containment includes isolating affected systems to prevent spread.

Why this answer

The primary goals of the containment phase are to limit the scope and impact of the incident (E) and prevent it from spreading to other systems (D). These actions aim to stop further damage and isolate affected resources. Eradication (B) is a separate phase, preserving evidence (C) is important but not a primary containment goal, and restoring normal operations (A) belongs to the recovery phase.

579
MCQmedium

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

A.Configuration management
B.Intrusion detection system (IDS)
C.Network segmentation
D.Vulnerability scanning
AnswerC

Segmenting the vulnerable application restricts access and reduces risk while patching is delayed.

Why this answer

Compensating controls provide alternative protection when a primary control cannot be applied. Network segmentation limits the blast radius and reduces the attack surface until patching can occur.

580
MCQeasy

What is the primary purpose of a vulnerability management program?

A.To enforce access control policies
B.To detect and respond to security incidents
C.To manage third-party security risks
D.To identify, assess, and remediate security weaknesses in systems
AnswerD

This is the core function of vulnerability management.

Why this answer

Vulnerability management aims to identify, classify, and remediate vulnerabilities to reduce the attack surface.

581
MCQmedium

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

A.Percentage of budget spent on security
B.Number of security patches applied
C.Number of security policies created
D.Mean time to detect incidents
AnswerD

MTTD measures the program's effectiveness in identifying threats, demonstrating proactive value.

Why this answer

Mean time to detect (MTTD) incidents is a direct measure of the security program's effectiveness in identifying threats, which demonstrates its value by showing how quickly the organization can respond to potential breaches. Metrics like budget percentage (A), patches applied (B), or policies created (C) are operational or input-focused and do not reflect the program's outcome or business impact.

582
MCQeasy

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

A.Immediately mandate compliance with a new enterprise-wide security policy.
B.Develop a minimum security standard (MSS) and a phased implementation roadmap based on risk.
C.Centralize all security operations and disband local teams.
D.Adopt the most mature subsidiary's program as the enterprise standard.
AnswerB

Provides baseline while allowing flexibility and phased adoption.

Why this answer

Correct answer is B because developing a minimum security standard (MSS) and a phased implementation roadmap based on risk allows each subsidiary to implement controls based on their unique risk profiles while ensuring a common baseline. This approach balances flexibility with control, respects varying maturity levels, and avoids disruption. Option A (immediate enterprise-wide policy) ignores diverse operational processes and may cause resistance.

Option C (centralize all security operations) is costly and impractical given the budget and local teams. Option D (adopt the most mature subsidiary's program) may not fit the context of less mature units.

583
Multi-Selecteasy

Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?

Select 2 answers
A.Time to patch critical vulnerabilities
B.Number of successful phishing simulations
C.Number of vendors with SOC 2 reports
D.Number of unresolved security incidents
E.Percentage of employees completing security training
AnswersA, D

Patch latency is a key indicator of vulnerability risk.

Why this answer

The time to patch critical vulnerabilities directly measures the organization's exposure window to known exploits, which is a leading indicator of cybersecurity risk. A longer patch time increases the likelihood of a successful attack, making it a key risk indicator (KRI) for vulnerability management.

Exam trap

The trap here is that candidates often confuse KRIs with KPIs, selecting metrics like training completion or phishing simulation results because they seem risk-related, but KRIs must directly measure the likelihood or impact of a risk event, not the performance of a control.

584
MCQeasy

Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?

A.Blocking the IP may be ineffective against dynamic IPs
B.The SOC manager may not receive notifications in time
C.Automatic approval may cause unnecessary disruption on false positives
D.The trigger severity is too low
AnswerC

Without manual validation, false positives can lead to business impact.

Why this answer

An automated response policy that approves blocking actions without human validation can trigger unnecessary disruption when false positives occur. Even if the severity threshold is appropriate, the lack of a verification step means legitimate traffic may be blocked, impacting business operations. The primary risk is not the effectiveness of the block but the operational impact of automated decisions on benign events.

Exam trap

The trap here is that candidates focus on the technical effectiveness of the block (dynamic IPs) or the severity threshold, rather than recognizing that the automated approval itself—without human-in-the-loop—is the primary risk, as it can cause business disruption from false positives.

How to eliminate wrong answers

Option A is wrong because dynamic IPs are a secondary concern; the primary risk is false positives causing disruption, not the block's effectiveness against IP rotation. Option B is wrong because the SOC manager's notification timing is a procedural issue, not the primary risk of the automated response policy itself. Option D is wrong because the trigger severity being too low could increase false positives, but the core risk is the automatic approval mechanism, not the severity threshold—adjusting severity does not eliminate the risk of false positives causing disruption.

585
MCQmedium

Which of the following is the FIRST step in the security policy development lifecycle?

A.Gap analysis
B.Legal review
C.Approval
D.Stakeholder consultation
AnswerA

Gap analysis identifies what policies are needed.

Why this answer

The lifecycle begins with gap analysis to identify missing or outdated policies before drafting or approval.

586
MCQhard

Refer to the exhibit. A security analyst reviews the ACL on the organization's border router. Based on the exhibit, which of the following is the MOST significant governance concern?

A.The ACL is applied to the outbound interface, which is ineffective for blocking inbound attacks.
B.The ACL does not include filtering for outbound traffic, which may allow spoofed internal IPs to exit the network.
C.The ACL permits any traffic after denying specific IP ranges, creating a security gap.
D.The ACL permits all traffic from private IP addresses, which could allow internal IP spoofing.
AnswerB

Outbound filtering (ingress filtering) is missing, which is a governance oversight.

Why this answer

The ACL shown only filters inbound traffic on the border router's external interface. Without an outbound ACL (or an inbound ACL on the internal interface), spoofed packets with internal source IP addresses can exit the network, enabling IP spoofing attacks that bypass anti-spoofing best practices (RFC 2827, BCP 38). This is a governance concern as it violates the principle of preventing source address spoofing, which is a fundamental security control for network perimeter defense.

Exam trap

The trap here is that candidates focus on the inbound ACL's content (denying private IPs) and miss the governance issue of missing outbound anti-spoofing controls, which is a classic CISM governance concern about policy compliance rather than just ACL syntax.

How to eliminate wrong answers

Option A is wrong because applying the ACL to the outbound interface is not inherently ineffective; the exhibit shows the ACL is applied inbound on the external interface, which is standard for filtering inbound traffic. Option C is wrong because the ACL explicitly denies specific IP ranges before permitting any traffic, which is a standard implicit deny at the end of an ACL; the 'permit any' after denies does not create a security gap if the denies are correctly placed. Option D is wrong because the ACL does not permit all traffic from private IP addresses; it denies specific private ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and permits any other traffic, which is correct for inbound filtering but does not address outbound spoofing.

587
MCQmedium

During the identification phase of incident response, which of the following is the MOST reliable indicator of a security incident?

A.A network administrator notices unusual traffic patterns.
B.An employee reports slow computer performance.
C.A vendor sends a vulnerability disclosure.
D.Antivirus software detects a known malware signature.
AnswerD

Direct evidence of malware infection.

Why this answer

Antivirus software detecting a known malware signature is the most reliable indicator because it uses signature-based detection, which matches file hashes or byte sequences against a known database of malicious code. This provides definitive, automated evidence of a security incident with minimal false positives, unlike subjective or ambiguous observations.

Exam trap

The trap here is that candidates may confuse 'reliability' with 'timeliness' or 'breadth,' choosing ambiguous indicators like unusual traffic patterns because they seem proactive, while overlooking that definitive, automated detection (antivirus signature match) provides the highest confidence for confirming an incident.

How to eliminate wrong answers

Option A is wrong because unusual traffic patterns are subjective and can result from legitimate activities like large file transfers or misconfigurations, requiring further analysis to confirm an incident. Option B is wrong because slow computer performance is a common symptom of many non-security issues such as resource exhaustion, disk fragmentation, or outdated hardware, and is not a reliable indicator of compromise. Option C is wrong because a vendor vulnerability disclosure describes a potential weakness that may not have been exploited yet; it indicates a risk, not an active security incident.

588
MCQhard

A security manager is developing metrics for the C-suite dashboard. Which combination of metrics would provide the best view of security program effectiveness, including both leading and lagging indicators?

A.Breach count and number of security tools deployed
B.Phishing click rate and mean time to detect (MTTD)
C.Patch compliance and number of vulnerabilities identified
D.Number of security incidents and percentage of budget spent
AnswerB

Phishing click rate is a leading indicator of user awareness; MTTD is a lagging indicator of detection capability.

Why this answer

Phishing click rate is a leading indicator that measures user awareness and proactive security posture, while mean time to detect (MTTD) is a lagging indicator that reflects the efficiency of detection processes. Together, they provide a balanced view of program effectiveness for executive oversight.

589
MCQmedium

A company's incident response team is conducting a tabletop exercise. They are discussing the steps after containment to prevent recurrence. The facilitator asks: 'What is the MOST important next step after containing an incident?' The team considers several options.

A.Identify the root cause of the incident
B.Update the incident response plan with lessons learned
C.Forensically image all affected systems
D.Notify law enforcement about the incident
AnswerA

Root cause analysis is essential to prevent recurrence by addressing the underlying vulnerability or process gap.

Why this answer

After containment, the most critical step is identifying the root cause to understand how the incident occurred and to implement effective remediation measures. Without root cause analysis, the organization cannot ensure that the same vulnerability or attack vector will not be exploited again, making containment temporary at best. This aligns with the NIST SP 800-61 incident response lifecycle, which places eradication and recovery after containment, driven by root cause identification.

Exam trap

A common misconception in incident response is that updating the incident response plan or conducting lessons learned is the immediate next step after containment. However, the CISM framework emphasizes that root cause analysis must precede any plan updates to ensure the changes address the actual vulnerability and prevent recurrence.

How to eliminate wrong answers

Option B is wrong because updating the incident response plan with lessons learned is a post-incident activity that occurs after the full investigation, eradication, and recovery phases are complete, not immediately after containment. Option C is wrong because forensic imaging is a step taken during the investigation phase to preserve evidence, but it is not the 'most important next step' after containment; root cause analysis is the priority to prevent recurrence. Option D is wrong because notifying law enforcement is a discretionary legal or regulatory step that may be taken after the incident is fully understood and evidence is preserved, but it does not directly address preventing recurrence of the incident.

590
MCQhard

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

A.Prioritize initiatives based on security team capacity
B.Align security initiatives with the organization's strategic business objectives
C.Base the roadmap on the latest industry threat intelligence
D.Create the roadmap based on compliance requirements only
AnswerB

Directly aligning ensures security supports business.

Why this answer

Roadmaps should be derived from business objectives to ensure relevance and executive support.

591
MCQmedium

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

A.Difficulty in achieving economies of scale for security operations
B.Lack of skilled security personnel in some business units
C.Increased cost due to duplication of security tools
D.Inconsistent enforcement of security policies across business units
AnswerD

Decentralized structures often lead to varying levels of security maturity and policy adherence, creating gaps that attackers can exploit.

Why this answer

In a decentralized model, inconsistent security practices across business units can lead to gaps in protection and difficulty in enforcing enterprise-wide standards.

592
MCQmedium

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

A.The provider's certifications and SOC 2 reports
B.The provider's data center locations
C.The provider's market share and brand reputation
D.The provider's pricing compared to competitors
AnswerA

Independent audits validate security measures.

Why this answer

The provider's certifications and independent audits provide objective evidence of security controls, which is critical for trust.

593
Multi-Selecteasy

Which THREE of the following are typically included in an information security program budget?

Select 3 answers
A.Incident response retainer
B.Security awareness training materials
C.Vulnerability assessment tools
D.Marketing and advertising campaigns
E.Employee salaries
AnswersA, B, C

External service cost part of program.

Why this answer

Options A, B, and C are correct as they are common line items in an information security program budget. Incident response retainers cover external support for security incidents, security awareness training materials are essential for educating employees, and vulnerability assessment tools are used to identify weaknesses. Option D (marketing) is not a security cost, and Option E (employee salaries) is typically part of operational budgets, not the specific security program budget.

594
MCQhard

A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?

A.Assign different compliance teams for each regulation
B.Implement a harmonized control framework that maps to all regulations
C.Adopt a single regulatory framework and ignore others
D.Create separate governance committees for each regulation
AnswerB

Streamlines compliance and reduces duplication.

Why this answer

A harmonized control framework (e.g., ISO 27001, NIST CSF) maps common controls across multiple regulations (e.g., GDPR, PCI DSS, SOX), reducing duplication and conflict. This aligns with the board's limited risk appetite by providing a single, consistent set of controls that satisfy all requirements, avoiding the inefficiency and potential gaps of siloed approaches.

Exam trap

The trap here is that candidates may think separate teams or committees provide deeper specialization, but CISM emphasizes that governance must be integrated and risk-aligned, not fragmented, to avoid control conflicts and inefficiencies.

How to eliminate wrong answers

Option A is wrong because assigning different compliance teams for each regulation creates silos, leading to duplicated effort, inconsistent control application, and increased risk of conflicting interpretations. Option C is wrong because adopting a single regulatory framework and ignoring others violates legal obligations, exposing the institution to fines and audit failures. Option D is wrong because separate governance committees for each regulation fragment oversight, causing coordination overhead and potential policy conflicts that undermine a unified risk posture.

595
Multi-Selecthard

Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)

Select 3 answers
A.Social media posts from employees
B.Industry information sharing groups
C.Vendor vulnerability databases
D.Open-source intelligence (OSINT)
E.Internal network traffic logs
AnswersB, C, D

Information sharing groups (e.g., ISACs) provide curated threat intelligence from peer organizations.

Why this answer

Industry information sharing groups (Option B) are a valid source of threat intelligence because they provide curated, actionable data on emerging threats, indicators of compromise (IOCs), and attack patterns from peer organizations. This intelligence is directly applicable during incident response to identify known adversary tactics, techniques, and procedures (TTPs) and to correlate findings with ongoing incidents.

Exam trap

ISACA CISM often tests the distinction between operational data (logs) and external threat intelligence, leading candidates to incorrectly select internal logs as a threat intelligence source instead of recognizing them as evidence for detection and analysis.

596
MCQhard

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

A.Revise the policy to accommodate the business need
B.Escalate to the board for approval
C.Increase monitoring of excepted systems
D.Reject all future exceptions for that control
AnswerA

Correct: Revising policy addresses root cause.

Why this answer

Addressing root causes reduces reliance on exceptions and strengthens the security posture.

597
MCQeasy

Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?

A.The policy does not specify quarterly review of access rights.
B.The data owner did not approve the exceptions.
C.Contractors should not have any access to financial systems.
D.Lack of documentation for approved exceptions.
AnswerD

The policy requires documented exceptions, which are missing.

Why this answer

The policy requires documented exceptions for any access granted outside standard provisioning rules. The security manager observed that contractors had access without such documentation, which directly violates the governance requirement for maintaining an audit trail of approved exceptions. Without this documentation, the organization cannot demonstrate that access was properly authorized, creating a compliance gap.

Exam trap

The trap here is that candidates may focus on who approved the access (Option B) rather than recognizing that the core governance deficiency is the lack of documentation for approved exceptions, which is a distinct control requirement.

How to eliminate wrong answers

Option A is wrong because the policy does not necessarily require quarterly reviews; the deficiency is specifically about undocumented exceptions, not the frequency of access reviews. Option B is wrong because the data owner may have approved the exceptions, but the failure to document them is the governance deficiency; approval without documentation still violates policy. Option C is wrong because contractors can be granted access to financial systems if exceptions are properly documented and approved; the policy does not categorically prohibit contractor access.

598
MCQhard

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

A.Vendor's insurance certificate
B.Annual self-assessment questionnaire only
C.Contractual security requirements and right to audit
D.SOC 2 Type II report without contractual clauses
AnswerC

Correct. Contracts should include security requirements and audit rights for high-risk vendors.

Why this answer

For vendors handling sensitive customer data, the contract must include security requirements such as data protection clauses, incident notification timelines, and the right to audit. This ensures contractual enforceability of security controls.

599
Multi-Selectmedium

An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?

Select 2 answers
A.Determining acceptable risk levels
B.Analyzing threats and vulnerabilities
C.Monitoring incident response plans
D.Evaluating the effectiveness of existing controls
E.Selecting controls to mitigate risks
AnswersB, D

This is a core activity in risk identification and analysis.

Why this answer

Analyzing threats and vulnerabilities is a core step in the risk assessment process, as defined by the NIST SP 800-30 and ISO 31000 frameworks. This activity identifies potential threat sources and existing vulnerabilities that could be exploited, enabling the calculation of likelihood and impact for risk scenarios.

Exam trap

The trap here is confusing risk assessment (identify/analyze) with risk treatment (select controls) or risk evaluation (set acceptable levels), leading candidates to pick A or E instead of focusing on the core assessment activities B and D.

600
Multi-Selecthard

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Select 3 answers
A.Annual reassessment of the vendor's security controls
B.Contractual requirement for data encryption
C.Periodic review of vendor's security certifications (e.g., SOC 2)
D.One-time onboarding risk assessment
E.Continuous monitoring of vendor's external attack surface
AnswersA, C, E

Annual reassessment is part of ongoing monitoring cycle.

Why this answer

Ongoing monitoring includes continuous assessment of security posture. Annual reassessment is part of the cycle, but ongoing monitoring includes more frequent checks. Contractual requirements are set during onboarding, not monitored ongoing.

Exit procedures are for termination.

Page 7

Page 8 of 12

Page 9