Courseiva

Certified Information Security Manager CISM (CISM) — Questions 601–675

924 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
MCQmedium

A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?

A.Select appropriate security controls
B.Conduct vulnerability scanning
C.Identify potential threat sources
D.Identify and classify information assets
AnswerD

Risk assessment begins with identifying and classifying the information assets the cloud system will hold, since sensitivity and value drive every subsequent threat, vulnerability, and impact analysis. Without an asset inventory, later likelihood and impact ratings lack a defensible basis.

Why this answer

In the risk assessment process, the first step is to identify and classify information assets because you cannot assess risks to assets you haven't identified. For a cloud-based system storing sensitive customer data, this means cataloging data types (e.g., PII, financial records), their locations (e.g., specific cloud storage buckets), and their classification levels (e.g., confidential, restricted) before any threat or vulnerability analysis can be meaningfully performed.

Exam trap

The trap here is that candidates often confuse the order of risk assessment steps, mistakenly thinking that identifying threats (Option C) comes first because threats are the 'active' element, but CISM emphasizes that asset identification is the foundational step that drives all subsequent analysis.

How to eliminate wrong answers

Option A is wrong because selecting security controls is a risk treatment step that occurs after risks have been assessed and prioritized, not at the beginning of the assessment. Option B is wrong because vulnerability scanning is a technical activity that identifies weaknesses in existing systems, but it cannot be effectively scoped or targeted without first knowing which assets are in scope and their classification. Option C is wrong because while identifying threat sources is important, it logically follows asset identification; you must know what assets you are protecting before you can determine which threats are relevant to those specific assets.

602
MCQhard

An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?

A.Isolate affected endpoints from the network while preserving memory
B.Disable user accounts
C.Block known malicious IPs
D.Reimage all endpoints
AnswerA

Fileless malware resides in memory rather than on disk, so powering off destroys the only evidence. Isolating endpoints from the network halts propagation while preserving volatile memory for forensic analysis, satisfying containment without losing the artefacts needed to understand the threat.

Why this answer

Fileless malware resides in memory and often uses legitimate system tools, making traditional disk-based containment ineffective. Isolating affected endpoints from the network while preserving memory is most effective because it prevents lateral movement and exfiltration while allowing forensic analysis of volatile data to understand the attack.

Exam trap

CISM often tests the misconception that reimaging or disabling accounts is sufficient for fileless malware, ignoring the need to preserve volatile memory for analysis.

How to eliminate wrong answers

Option B is wrong because disabling user accounts does not contain the malware itself; the malware may continue running under system contexts or other accounts. Option C is wrong because blocking known malicious IPs is reactive and may not cover all command-and-control channels, especially if the malware uses domain generation algorithms or legitimate services. Option D is wrong because reimaging all endpoints is disruptive and destroys volatile evidence, and it may not be necessary if the threat is contained.

603
MCQhard

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

A.Consolidate all security tools
B.Conduct a comprehensive risk assessment of the target
C.Merge the security teams into one reporting structure
D.Standardize security policies immediately
AnswerB

A comprehensive risk assessment of the target identifies inherited vulnerabilities, control gaps and compliance exposure before integration decisions are made. It satisfies the merger scenario's highest-priority need by informing every subsequent integration choice with the target's actual risk posture.

Why this answer

Conducting a comprehensive risk assessment of the target company is the highest priority because it identifies vulnerabilities, gaps, and threats that must be understood before any integration decisions are made. Without this assessment, consolidating tools, merging teams, or standardizing policies could introduce unacceptable risk or overlook critical exposures. Risk assessment informs all subsequent integration actions and ensures the acquiring company's security posture is not weakened.

Exam trap

CISM often tests the principle that risk assessment must precede any integration action; candidates are tempted to pick visible actions like tool consolidation or policy standardization.

How to eliminate wrong answers

Option A is wrong because consolidating security tools before understanding the target's risk profile may remove controls that are actually mitigating unknown threats. Option C is wrong because merging security teams into one reporting structure is an organizational change that should follow, not precede, a risk assessment; doing it first can disrupt incident response and lose institutional knowledge. Option D is wrong because standardizing security policies immediately may be impossible or harmful if the target's environment has unique regulatory or technical constraints that the assessment would reveal.

604
MCQeasy

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

A.To ensure compliance with regulations
B.To assign accountability to individuals
C.To track the budget for security initiatives
D.To measure the effectiveness of security controls
AnswerD

KPIs quantify how well implemented controls reduce risk, directly satisfying the stem's demand for performance measurement rather than activity tracking. Unlike metrics counting outputs, effectiveness indicators reveal whether controls actually mitigate threats, enabling management to judge programme value and justify resource decisions.

Why this answer

KPIs are designed to provide measurable evidence of how well the security program is achieving its objectives, specifically by quantifying the effectiveness of security controls. For example, a KPI like 'mean time to detect (MTTD)' directly measures the performance of detection controls, enabling data-driven decisions on control improvements. This aligns with the CISM focus on governance and performance management, not just compliance or budgeting.

Exam trap

The trap here is that candidates often confuse KPIs with compliance metrics or operational tasks, mistakenly thinking the primary purpose is to ensure regulatory adherence rather than to measure and improve the effectiveness of security controls.

How to eliminate wrong answers

Option A is wrong because compliance with regulations is a baseline requirement, not the primary purpose of KPIs; KPIs measure performance beyond mere compliance, such as control effectiveness. Option B is wrong because assigning accountability is a function of roles and responsibilities within the governance structure, not a direct purpose of KPIs, which are metrics, not assignment tools. Option C is wrong because tracking the budget for security initiatives is a financial management activity, typically measured by cost-related metrics (e.g., cost per incident), not the primary purpose of KPIs, which focus on operational and strategic effectiveness.

605
Multi-Selecteasy

Which TWO of the following are typically considered key components of an information security governance framework?

Select 2 answers
A.Adoption of a formal risk management process
B.Scheduling of regular penetration tests
C.Establishment of a performance measurement system
D.Development of a detailed incident response plan
E.Implementation of specific technical controls
AnswersA, C

A formal risk management process identifies, assesses and treats information risk in line with the organisation's risk appetite, directing security investment and control selection. It is a core governance component because it links security decisions to business risk.

Why this answer

Option A (adoption of a formal risk management process) is correct because governance frameworks such as ISO/IEC 27001 and COBIT require an ongoing, structured risk management process to identify, assess, treat, and monitor information security risks, providing the decision-making foundation that governance bodies use to align security with business objectives. Option C (establishment of a performance measurement system) is correct because governance depends on metrics, KPIs, and reporting mechanisms (e.g., COBIT's performance management domain) to monitor whether security controls and objectives are effective and to hold management accountable. The unmarked options do not belong because scheduling regular penetration tests (B), developing a detailed incident response plan (D), and implementing specific technical controls (E) are operational, tactical activities executed under the governance framework rather than components of the governance framework itself.

Exam trap

CISM often tests the governance-versus-management distinction, and the trap is selecting operational activities (pen tests, IR plans, technical controls) that feel security-related but are not governance framework components.

606
MCQhard

During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?

A.Establish a policy review committee with business unit representatives to align policy with operational needs.
B.Provide additional security awareness training focused on policy requirements.
C.Escalate non-compliance to senior management for disciplinary action.
D.Increase the frequency of automated policy compliance checks.
AnswerA

Aligning the policy with operational realities addresses the root cause of non-compliance: business units ignore rules that conflict with how they actually work. A review committee with their representatives secures ownership and practicality, satisfying the stem's requirement to improve compliance rather than merely enforce it.

Why this answer

The most effective way to improve compliance is to align the policy with operational realities by involving business unit representatives in a policy review committee. When policies conflict with business processes, users will bypass them; adjusting the policy to be both secure and practical increases voluntary adherence. This addresses the root cause—policy misalignment—rather than treating symptoms like lack of awareness or enforcement.

Exam trap

The trap here is that candidates often choose awareness training (B) as a quick fix, but CISM emphasizes that non-compliance due to policy misalignment requires policy revision, not just more training or enforcement.

How to eliminate wrong answers

Option B is wrong because additional awareness training assumes the non-compliance stems from ignorance, but the audit found the policy is not being followed despite likely existing training; the core issue is policy impracticality, not lack of knowledge. Option C is wrong because escalating non-compliance for disciplinary action treats the symptom (violations) without fixing the underlying policy that may be unworkable, and it can damage trust and reduce reporting of genuine issues. Option D is wrong because increasing automated compliance checks only detects violations more frequently but does not address why business units are not following the policy; it may even increase friction and shadow IT if the policy remains misaligned.

607
MCQeasy

Which of the following is the PRIMARY purpose of an information security risk assessment?

A.To eliminate all identified risks
B.To identify and evaluate risks in terms of likelihood and impact
C.To comply with regulatory requirements
D.To assign blame for security incidents
AnswerB

Identifying and evaluating risks by likelihood and impact is the core mechanism of risk assessment, producing the prioritised risk picture that drives subsequent treatment decisions. This directly satisfies the stem's demand for the primary purpose, since assessment precedes mitigation; auditing, control implementation and monitoring are separate downstream activities.

Why this answer

The primary purpose of an information security risk assessment is to identify and evaluate risks in terms of their likelihood and impact. This process enables an organization to prioritize risks and determine appropriate risk treatment options, such as mitigation, transfer, acceptance, or avoidance, based on a clear understanding of the risk landscape. Without this evaluation, any subsequent risk management decisions would lack a defensible basis.

Exam trap

The trap here is that candidates often confuse the purpose of a risk assessment with the purpose of risk treatment or compliance, leading them to select 'comply with regulatory requirements' as the primary purpose, when in fact compliance is a secondary benefit, not the core objective.

Why the other options are wrong

A

Eliminating all risks is impractical and not the primary purpose; risk assessment informs risk treatment decisions.

C

Compliance may be a driver but is not the primary purpose; the core is informed decision-making.

D

Risk assessment is proactive, not punitive.

608
MCQmedium

After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?

A.Implement a regulatory framework as the baseline
B.Maintain separate frameworks until a natural convergence occurs
C.Adopt the security framework of the acquiring company
D.Develop a new framework incorporating strengths from both companies
AnswerD

Building a new framework that incorporates the strengths of both security cultures creates shared ownership and avoids imposing one company's practices on the other. This satisfies the merger constraint by producing a unified governance structure both parties accept.

Why this answer

Merging two distinct security cultures requires a deliberate, collaborative approach that leverages the best practices from both organizations. Developing a new framework that incorporates strengths from both companies ensures buy-in from stakeholders and creates a unified governance structure that is tailored to the combined entity's risk profile, rather than imposing one side's culture or waiting for an uncertain natural convergence.

Exam trap

The trap here is that candidates often assume the acquiring company's framework should dominate (Option C) due to organizational hierarchy, but CISM emphasizes that effective governance requires cultural integration and stakeholder alignment, not unilateral imposition.

How to eliminate wrong answers

Option A is wrong because implementing a regulatory framework as the baseline (e.g., ISO 27001 or NIST CSF) provides a compliance foundation but does not address the cultural integration or operational differences between the two companies, potentially leading to resistance or gaps in governance. Option B is wrong because maintaining separate frameworks until a natural convergence occurs is passive and risky; it prolongs security inconsistencies, creates blind spots in oversight, and fails to establish a unified governance structure in a timely manner. Option C is wrong because adopting the security framework of the acquiring company ignores the acquired company's existing controls and cultural strengths, which can cause friction, loss of institutional knowledge, and non-compliance with legacy requirements.

609
MCQmedium

A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?

A.Derive the security strategy from the organization's business strategy and refresh it through an annual governance review tied to business planning.
B.Base the strategy on the most recent penetration test findings and reissue it whenever a critical vulnerability is discovered.
C.Let the IT steering committee define the strategy and forward it to the CISO for technical review before board approval.
D.Adopt the security framework used by the largest competitor and implement its controls in the same sequence.
AnswerA

A security strategy must cascade from and support the business strategy, otherwise it becomes a technology wish list disconnected from value creation. Tying the refresh to the annual business planning cycle keeps objectives, risk appetite, and funding aligned as the retailer expands into new markets, and gives governance bodies a predictable point to reassess priorities.

Why this answer

Strategy alignment means the security programme exists to enable business objectives, so the strategy must be derived from the business strategy and revisited on the same planning cadence. Governance review tied to business planning keeps risk appetite, funding, and priorities synchronized. Technical artefacts such as penetration tests or competitor frameworks inform tactics but cannot define strategic direction for the organization.

Exam trap

The trap here is assuming a security strategy is built from technical findings or peer benchmarks rather than from the business strategy it must support.

610
MCQhard

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

A.Slower incident response
B.Inconsistent security levels across business units
C.Higher cost of compliance
D.Duplication of controls
AnswerB

Decentralised governance lets each business unit set its own controls, so enforcement, risk tolerance and reporting diverge across the institution. That inconsistency directly undermines the uniform, auditable control baseline the new regulatory framework demands, creating gaps regulators can cite. Centralised models instead impose one standard, which is why this is the most significant risk.

Why this answer

In a decentralized governance model, each business unit may implement its own security controls, leading to inconsistent security levels across the organization. This is the most significant risk because it creates gaps and vulnerabilities that can be exploited, especially in a regulated financial institution. While other risks exist, inconsistency directly undermines the overall security posture.

Exam trap

CISM often tests governance models, and candidates may choose 'duplication of controls' or 'higher cost' as the most significant risk, overlooking that inconsistent security levels directly increase the likelihood of breaches and regulatory non-compliance.

How to eliminate wrong answers

Option A is wrong because slower incident response is a possible consequence but not the most significant risk; inconsistency can cause incidents in the first place. Option C is wrong because higher cost of compliance is a financial concern, but not as critical as security gaps. Option D is wrong because duplication of controls is inefficient but less severe than inconsistent security levels that can lead to breaches.

611
Multi-Selectmedium

An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)

Select 2 answers
A.Documented roles, responsibilities, and contact details for the response team and key internal stakeholders
B.A complete inventory of every software vulnerability present across the enterprise
C.A defined incident classification and severity scheme agreed with business stakeholders
D.A guarantee that no incident will escalate beyond the technical response team
E.A published list of the organization's security tool vendors for marketing purposes
AnswersA, C

Clear roles and current contact information let the team mobilize quickly and avoid confusion about who decides, who communicates, and who executes. This is foundational to any response capability because incidents rarely occur during business hours with everyone available. Without defined responsibilities, response stalls at the moment speed matters most, increasing impact and cost.

Why this answer

Effective incident response depends on shared severity definitions and clearly assigned roles with current contacts, because these determine how quickly and consistently the organization triages, escalates, and coordinates. A vulnerability inventory supports prevention rather than response, while assuming incidents stay technical and publishing vendor lists for marketing do not strengthen the capability and can even increase exposure.

Exam trap

The trap here is selecting preventive or promotional activities, such as vulnerability inventories or vendor marketing lists, when the question asks specifically about pre-established incident response capability elements.

612
Multi-Selecteasy

Which TWO components are essential for an effective information security governance framework?

Select 2 answers
A.Implementation of an intrusion detection system
B.Detailed technical configuration guides
C.Board-level oversight of security programs
D.Alignment of security program with business objectives
E.Daily threat intelligence feeds
AnswersC, D

Board-level oversight ensures security strategy receives authority, funding and accountability at the highest organisational tier, directing risk decisions rather than delegating them to technical teams. This satisfies governance's requirement for top-down direction and demonstrable executive ownership of the security programme.

Why this answer

Option C is correct because an effective information security governance framework requires board-level oversight, which provides strategic direction, accountability, and authority for the security program at the highest organizational level. Option D is correct because governance must align the security program with business objectives, ensuring that security investments and risk decisions directly support organizational goals and value creation. These two components reflect the core purpose of governance—direction and alignment from leadership—rather than operational or tactical activities.

Option A is incorrect because an intrusion detection system is a technical control used in security operations, not a governance component. Option B is incorrect because detailed technical configuration guides are implementation artifacts, not governance elements. Option E is incorrect because daily threat intelligence feeds are operational inputs that support monitoring and response, not governance structure or oversight.

Exam trap

CISM often tests the governance vs. management distinction — candidates pick technical controls (IDS, config guides) because they sound security-relevant, but governance questions require strategic/oversight answers, not operational ones.

613
Multi-Selecteasy

Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)

Select 2 answers
A.Restore normal business operations
B.Eradicate the root cause of the incident
C.Preserve evidence for legal proceedings
D.Prevent the incident from spreading to other systems
E.Limit the scope and impact of the incident
AnswersD, E

Containment isolates affected systems to halt lateral movement, directly satisfying the goal of preventing spread to other systems. Segmenting networks, disabling accounts, or blocking traffic stops the adversary propagating while evidence is preserved for later eradication and recovery phases.

Why this answer

Option D is correct because the containment phase is specifically designed to stop an active incident from propagating to additional hosts, accounts, or network segments, for example by isolating compromised endpoints, segmenting VLANs, or blocking malicious C2 traffic at the firewall. Option E is correct because containment also aims to limit the scope and impact of the incident, minimizing damage to data, services, and other assets while the incident is still being actively managed. Options A, B, and C do not belong here: restoring normal business operations is the goal of the recovery phase, eradicating the root cause is the goal of the eradication phase, and while evidence preservation is important throughout incident response, it is not one of the two primary goals of containment itself.

Exam trap

CISM often tests phase boundaries, and the trap is selecting eradication or recovery activities (root cause removal, restoring operations) as containment goals.

614
MCQmedium

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

A.Configuration management
B.Intrusion detection system (IDS)
C.Network segmentation
D.Vulnerability scanning
AnswerC

Network segmentation limits lateral movement and constrains exposure of the unpatched application, reducing exploitability while patching is deferred. This satisfies the compensating control requirement because it mitigates residual risk through an alternative mechanism rather than removing the underlying vulnerability.

Why this answer

Network segmentation is a compensating control because it reduces the attack surface and lateral movement potential of an unpatched application by isolating it from other systems, thereby mitigating the risk that the vulnerability could be exploited to reach critical assets. When patching is delayed by operational constraints, segmentation provides an alternative risk-reduction mechanism that addresses the same underlying exposure.

Exam trap

CISM often tests the distinction between preventive, detective, and compensating controls, so candidates pick IDS or vulnerability scanning because they sound security-relevant, missing that only a control that actually reduces exploitability or impact (like segmentation) qualifies as compensating.

How to eliminate wrong answers

Option A is wrong because configuration management is a preventive/hygiene control that ensures systems are built and maintained to a baseline — it does not directly compensate for an unpatched vulnerability's exploitability. Option B is wrong because an IDS is a detective control: it can alert on exploitation attempts but does not prevent or reduce the impact of a successful exploit, so it does not compensate for the missing patch. Option D is wrong because vulnerability scanning is also a detective control that identifies the unpatched state; it does not mitigate the risk, it merely confirms it exists.

615
MCQeasy

What is the primary purpose of a vulnerability management program?

A.To enforce access control policies
B.To detect and respond to security incidents
C.To manage third-party security risks
D.To identify, assess, and remediate security weaknesses in systems
AnswerD

A vulnerability management programme systematically discovers, prioritises and fixes weaknesses across the estate, directly satisfying the stem's demand for its primary purpose. Identification feeds risk-based assessment, which drives remediation decisions. This continuous cycle reduces exploitable exposure, distinguishing it from penetration testing, which offers only a point-in-time snapshot rather than ongoing assurance.

Why this answer

Vulnerability management aims to identify, classify, and remediate vulnerabilities to reduce the attack surface.

616
MCQmedium

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

A.Percentage of budget spent on security
B.Number of security patches applied
C.Number of security policies created
D.Mean time to detect incidents
AnswerD

Mean time to detect incidents quantifies how quickly the security function identifies threats, a capability executives directly link to reduced breach impact and programme effectiveness. It demonstrates operational value more concretely than activity counts or compliance percentages, satisfying the requirement to show programme worth.

Why this answer

Mean time to detect (MTTD) incidents directly measures how quickly the security program identifies threats, which is a core outcome executives care about — reduced exposure window and improved resilience. It demonstrates program effectiveness in a business-relevant way rather than just activity or spend.

Exam trap

The trap is selecting activity or spend metrics (patches, policies, budget) that are easy to count but do not demonstrate value — CISM consistently favors outcome-based metrics tied to risk reduction.

How to eliminate wrong answers

Option A is wrong because percentage of budget spent is an input/resource metric, not an outcome — spending more does not prove the program is effective. Option B is wrong because the number of patches applied is an activity metric that says nothing about risk reduction or whether critical vulnerabilities were addressed in time. Option C is wrong because the number of policies created is a documentation activity metric with no direct link to security outcomes or business value.

617
MCQeasy

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

A.Immediately mandate compliance with a new enterprise-wide security policy.
B.Develop a minimum security standard (MSS) and a phased implementation roadmap based on risk.
C.Centralize all security operations and disband local teams.
D.Adopt the most mature subsidiary's program as the enterprise standard.
AnswerB

A minimum security standard sets non-negotiable controls every subsidiary must meet, while the risk-based phased roadmap sequences remediation according to each unit's maturity and exposure. This balances central control with local flexibility and respects the constrained budget.

Why this answer

Correct answer is B because developing a minimum security standard (MSS) and a phased implementation roadmap based on risk allows each subsidiary to implement controls based on their unique risk profiles while ensuring a common baseline. This approach balances flexibility with control, respects varying maturity levels, and avoids disruption. Option A (immediate enterprise-wide policy) ignores diverse operational processes and may cause resistance.

Option C (centralize all security operations) is costly and impractical given the budget and local teams. Option D (adopt the most mature subsidiary's program) may not fit the context of less mature units.

618
MCQmedium

A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?

A.It documents the risk assessment results in a centralized risk register.
B.It aligns with the organization’s overall enterprise risk management framework.
C.It is reviewed and approved annually by the board of directors.
D.It uses a consistent set of defined likelihood and impact criteria.
AnswerD

Defined likelihood and impact criteria are the foundation of repeatability and comparability. When assessors apply the same scales and definitions across the cloud POS platform and subsequent assessments, results can be meaningfully compared, aggregated and trended. Without this consistency, quantitative or qualitative ratings become subjective and cannot reliably support risk-based decisions or demonstrate changes in risk posture over time.

Why this answer

Repeatability and comparability depend on consistent measurement criteria. By defining what likelihood and impact mean and how they are rated, the organization ensures that different assessors evaluating the cloud POS platform or other systems will produce results that can be compared and trended. Documentation, governance approval and ERM alignment support the process but do not by themselves eliminate subjective variation in risk ratings.

Exam trap

The trap here is confusing the governance and documentation attributes of a risk methodology with the measurement consistency that actually makes assessments repeatable and comparable.

619
MCQhard

A global financial services firm is revising its information security governance framework. The board of directors has expressed concern that the current security strategy is not adequately aligned with the firm's business objectives and regulatory obligations. The CISO is tasked with improving this alignment. Which of the following actions would BEST address the board's concern?

A.Increase the security budget to hire more security staff and purchase advanced security tools.
B.Implement a balanced scorecard for security that tracks technical metrics such as patch compliance and antivirus coverage.
C.Conduct an annual penetration test and present the results to the board to demonstrate security effectiveness.
D.Integrate security risk considerations into the enterprise risk management (ERM) process and report on them alongside other business risks.
AnswerD

Integrating security risk into ERM ensures that security is viewed as a business risk and is managed in alignment with business objectives. It allows the board to see security risks in the context of other risks and make informed decisions. This approach also helps meet regulatory obligations by demonstrating comprehensive risk oversight. It directly addresses the board's concern about alignment by embedding security into the core risk management framework.

Why this answer

Integrating security risk into the enterprise risk management process ensures that security is managed as a business risk, aligning it with business objectives and regulatory requirements. This approach provides the board with a comprehensive view of risk and demonstrates that security is not a standalone function but an integral part of the organization's risk posture.

Exam trap

The trap here is focusing on operational or technical solutions when the board's concern is about strategic alignment and governance integration.

620
MCQeasy

Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?

A.Blocking the IP may be ineffective against dynamic IPs
B.The SOC manager may not receive notifications in time
C.Automatic approval may cause unnecessary disruption on false positives
D.The trigger severity is too low
AnswerC

Automated response acts on detection signals without human validation, so a false positive triggers containment against healthy systems. That causes unnecessary disruption and potential outage, which is the primary risk of the policy as configured in the exhibit.

Why this answer

An automated response policy that approves blocking actions without human validation can trigger unnecessary disruption when false positives occur. Even if the severity threshold is appropriate, the lack of a verification step means legitimate traffic may be blocked, impacting business operations. The primary risk is not the effectiveness of the block but the operational impact of automated decisions on benign events.

Exam trap

The trap here is that candidates focus on the technical effectiveness of the block (dynamic IPs) or the severity threshold, rather than recognizing that the automated approval itself—without human-in-the-loop—is the primary risk, as it can cause business disruption from false positives.

How to eliminate wrong answers

Option A is wrong because dynamic IPs are a secondary concern; the primary risk is false positives causing disruption, not the block's effectiveness against IP rotation. Option B is wrong because the SOC manager's notification timing is a procedural issue, not the primary risk of the automated response policy itself. Option D is wrong because the trigger severity being too low could increase false positives, but the core risk is the automatic approval mechanism, not the severity threshold—adjusting severity does not eliminate the risk of false positives causing disruption.

621
MCQmedium

Which of the following is the FIRST step in the security policy development lifecycle?

A.Gap analysis
B.Legal review
C.Approval
D.Stakeholder consultation
AnswerA

Gap analysis compares current security posture against a chosen framework or standard, revealing deficiencies that the policy must address. This precedes drafting, approval and implementation, so it is genuinely first. Without identifying gaps, subsequent policy content lacks justified scope and direction.

Why this answer

In the security policy development lifecycle, a gap analysis is performed first to compare the organization's current state against the desired state (e.g., regulatory requirements, frameworks like ISO 27001 or NIST). This identifies what policies are missing or inadequate before drafting begins. Only after gaps are understood can legal review, stakeholder consultation, and formal approval meaningfully occur.

Exam trap

CISM often tests lifecycle ordering, and candidates frequently assume 'stakeholder consultation' or 'legal review' comes first because those sound collaborative or risk-averse — but the exam expects gap analysis as the foundational first step that identifies what the policy must address.

How to eliminate wrong answers

Option B is wrong because legal review happens after a draft policy exists, not as the first step. Option C is wrong because approval is one of the final steps, occurring after drafting, review, and consultation. Option D is wrong because stakeholder consultation informs the drafting but presupposes that a gap analysis has already identified what needs to be addressed.

622
MCQhard

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

A.Prioritize initiatives based on security team capacity
B.Align security initiatives with the organization's strategic business objectives
C.Base the roadmap on the latest industry threat intelligence
D.Create the roadmap based on compliance requirements only
AnswerB

Anchoring each security initiative to a named strategic business objective makes the roadmap traceable to business intent, satisfying the alignment requirement. Security priorities then shift as business strategy shifts, rather than being driven by technology or compliance alone, which is what the CISO's multi-year horizon demands.

Why this answer

A multi-year security roadmap must be driven by the organization's strategic business objectives to ensure security investments enable rather than obstruct business goals. Aligning initiatives with business strategy ensures the roadmap is prioritized by business value, secures executive sponsorship, and remains relevant as the business evolves. This is the foundational principle of business-aligned security governance.

Exam trap

CISM often tests whether candidates default to compliance or threat-driven roadmaps, but the exam consistently rewards business-strategy alignment as the primary driver — candidates who pick 'compliance requirements only' or 'latest threat intelligence' fall for the reactive/technical trap.

How to eliminate wrong answers

Option A is wrong because prioritizing by security team capacity is an internal resource constraint, not a strategic alignment driver — it can lead to under-investing in high-business-value initiatives. Option C is wrong because basing the roadmap solely on the latest threat intelligence is reactive and may not reflect the organization's specific risk profile or business priorities. Option D is wrong because compliance-only roadmaps are minimum-bar and do not address business strategy, competitive advantage, or risk appetite.

623
MCQmedium

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

A.Difficulty in achieving economies of scale for security operations
B.Lack of skilled security personnel in some business units
C.Increased cost due to duplication of security tools
D.Inconsistent enforcement of security policies across business units
AnswerD

Decentralised units setting their own security practices produce divergent policy enforcement, leaving gaps and unmanaged enterprise risk. This satisfies the stem's greatest-risk constraint because the CISO, reporting to the CIO, lacks the authority and independence to mandate consistent controls across business units.

Why this answer

In a decentralized governance model where each business unit runs its own security team and the CISO reports to the CIO (rather than the board or CEO), the greatest risk is inconsistent enforcement of security policies across business units. Decentralization without a strong central authority or common control framework leads to divergent interpretations, uneven risk postures, and gaps that attackers can exploit across the enterprise. This is a governance and risk aggregation issue, which outweighs cost or staffing concerns.

Exam trap

CISM often tests whether candidates can distinguish operational inefficiencies (cost, staffing, scale) from governance risks (inconsistent policy enforcement), and candidates frequently pick cost or staffing because those are more tangible — but the exam rewards the systemic governance risk.

How to eliminate wrong answers

Option A is wrong because difficulty achieving economies of scale is an efficiency concern, not the greatest risk — it affects cost, not necessarily security effectiveness. Option B is wrong because lack of skilled personnel in some units is a resourcing issue that can be mitigated through training or shared services, and is less severe than systemic policy inconsistency. Option C is wrong because increased cost from tool duplication is a financial inefficiency, not a security risk — the exam asks for the GREATEST risk, which is about security posture and governance.

624
MCQmedium

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

A.The provider's certifications and SOC 2 reports
B.The provider's data center locations
C.The provider's market share and brand reputation
D.The provider's pricing compared to competitors
AnswerA

Independent certifications and SOC 2 reports provide audited, third-party evidence of the provider's control environment, letting the CISO assess posture without relying on self-attestation. This satisfies the stem's most-important consideration by supplying verifiable assurance about the controls protecting the organisation's data.

Why this answer

Independent third-party attestations such as SOC 2 reports and certifications (ISO 27001, FedRAMP, PCI DSS) provide verifiable evidence of the provider's security controls, making them the most important consideration in a vendor risk assessment. They allow the CISO to evaluate the provider's actual control environment rather than relying on marketing claims, brand reputation, or pricing.

Exam trap

CISM often tests the difference between evidence-based assurance (SOC 2, ISO 27001) and superficial factors (brand, pricing, location), so candidates choose reputation or data center location because they sound like reasonable business considerations rather than auditable security evidence.

How to eliminate wrong answers

Option B is wrong because data center locations matter for data residency and regulatory compliance, but they are a secondary consideration — location alone says nothing about the strength of the provider's security controls. Option C is wrong because market share and brand reputation are not evidence of security posture; a large, well-known provider can still have significant control gaps, and reputation is not auditable. Option D is wrong because pricing is a commercial factor, not a security control indicator — cheaper providers are not inherently less secure, and expensive ones are not inherently more secure.

625
MCQmedium

An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?

A.Notify all employees about the incident and remind them of security policies.
B.Increase the frequency of antivirus signature updates on all endpoints.
C.Perform a root cause analysis to identify and remediate the initial access vector.
D.Close the incident and restore affected systems from backups.
AnswerC

Root cause analysis examines logs, forensic artifacts, and timeline data to determine how the attacker gained entry, such as a phishing email, exposed service, or stolen credential. Identifying and remediating that vector prevents recurrence and informs improvements to controls, monitoring, and the incident response plan. It also supports lessons learned and any regulatory or insurance reporting requirements.

Why this answer

When the initial access vector is unknown, the highest priority is a structured root cause analysis to determine how the attacker entered and to eliminate that pathway. This prevents recurrence and feeds lessons learned into control improvements, monitoring enhancements, and plan updates. Recovery, signature updates, and awareness communications are useful supporting activities, but none of them replaces identifying and closing the actual entry point.

Exam trap

The trap here is treating recovery and closure as the end of the incident, when an unknown access vector means the root cause has not been addressed and the environment remains exposed.

626
MCQmedium

A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?

A.The physical location of the data center hosting each system
B.The number of users who have accounts on each application
C.Whether the system was purchased or developed in-house
D.The criticality of the business processes and information the assets support
AnswerD

Scope should follow business impact. Assets and processes that support critical services, hold sensitive data, or carry regulatory obligations define where governance, controls, and assurance effort must apply. Scoping by technical category or location instead produces coverage gaps precisely where the organization can least tolerate failure, which is the outcome the CISO must avoid.

Why this answer

Governance scope should be anchored to business criticality and information sensitivity, because that is where disruption, regulatory breach, or data loss would cause the greatest harm. Location, user population, and sourcing model are attributes that shape how controls are applied once an asset is in scope, but none of them reliably identifies which assets warrant programme governance in the first place.

Exam trap

The trap here is scoping by an easily counted technical attribute such as location or user count instead of by the business impact the asset supports.

627
MCQhard

A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?

A.Assign different compliance teams for each regulation
B.Implement a harmonized control framework that maps to all regulations
C.Adopt a single regulatory framework and ignore others
D.Create separate governance committees for each regulation
AnswerB

A harmonised framework maps controls once against every regulation, eliminating duplicated and contradictory requirements. This satisfies the limited risk appetite by reducing control gaps and overlap, while removing the conflicting interpretations that fragmented, regulation-by-regulation governance creates.

Why this answer

A harmonized control framework (e.g., ISO 27001, NIST CSF) maps common controls across multiple regulations (e.g., GDPR, PCI DSS, SOX), reducing duplication and conflict. This aligns with the board's limited risk appetite by providing a single, consistent set of controls that satisfy all requirements, avoiding the inefficiency and potential gaps of siloed approaches.

Exam trap

The trap here is that candidates may think separate teams or committees provide deeper specialization, but CISM emphasizes that governance must be integrated and risk-aligned, not fragmented, to avoid control conflicts and inefficiencies.

How to eliminate wrong answers

Option A is wrong because assigning different compliance teams for each regulation creates silos, leading to duplicated effort, inconsistent control application, and increased risk of conflicting interpretations. Option C is wrong because adopting a single regulatory framework and ignoring others violates legal obligations, exposing the institution to fines and audit failures. Option D is wrong because separate governance committees for each regulation fragment oversight, causing coordination overhead and potential policy conflicts that undermine a unified risk posture.

628
MCQhard

During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?

A.Immediately power off the server to stop all malicious activity and prevent further data loss
B.Rebuild the server from a known-good image immediately to restore service and remove any attacker foothold
C.Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection
D.Leave the server online and continue monitoring the command-and-control traffic to gather more intelligence on the attacker
AnswerC

Network isolation stops command-and-control communication and lateral movement while keeping the system running so memory, active connections, and process state can be captured. This preserves volatile evidence and supports scoping the intrusion, satisfying both containment and investigation needs. It is the standard balanced approach when a system must be contained without destroying forensic value.

Why this answer

The best balance is to contain the system without destroying volatile evidence. Network isolation stops malicious communication and lateral movement while leaving memory, running processes, and active connections intact for collection. Powering off, prolonged passive monitoring, or immediate rebuild each sacrifice either containment or investigative capability, so they fail to meet both requirements simultaneously.

Exam trap

The trap here is equating containment with shutting the system down, when isolation actually contains the threat while preserving the volatile evidence needed for investigation.

629
Multi-Selecthard

Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)

Select 3 answers
A.Social media posts from employees
B.Industry information sharing groups
C.Vendor vulnerability databases
D.Open-source intelligence (OSINT)
E.Internal network traffic logs
AnswersB, C, D

Industry information sharing groups, such as ISACs, supply sector-specific indicators and adversary tactics that internal telemetry alone cannot reveal. This satisfies the stem's requirement for valid threat intelligence sources during incident response, because members exchange anonymised, timely data on active campaigns affecting comparable environments, enriching detection and prioritisation beyond Microsoft Entra ID logs.

Why this answer

Option B (Industry information sharing groups) is correct because organizations such as ISACs (Information Sharing and Analysis Centers) and CERTs distribute vetted threat indicators, TTPs, and advisories that directly inform incident response decisions. Option C (Vendor vulnerability databases) is correct because sources like the NVD, CVE, and vendor security advisories provide authoritative vulnerability details, CVSS scores, and patch guidance used to assess and remediate incidents. Option D (Open-source intelligence, OSINT) is correct because publicly available data such as threat feeds, malware analyses, and attacker infrastructure from security blogs, forums, and repositories enriches incident context and attribution.

Option A is not a valid threat intelligence source because employee social media posts are unvetted, potentially unreliable, and not structured intelligence. Option E is not a threat intelligence source but internal telemetry; network traffic logs are evidence collected during incident response, not external intelligence about threats.

Exam trap

ISACA CISM often tests the distinction between operational data (logs) and external threat intelligence, leading candidates to incorrectly select internal logs as a threat intelligence source instead of recognizing them as evidence for detection and analysis.

630
MCQhard

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

A.Revise the policy to accommodate the business need
B.Escalate to the board for approval
C.Increase monitoring of excepted systems
D.Reject all future exceptions for that control
AnswerA

Repeated exceptions for one control signal the policy no longer matches operational reality, so the control itself is misaligned rather than the business being non-compliant. Revising the policy addresses the root cause, eliminating the need for duplicate exceptions and restoring a single, enforceable baseline.

Why this answer

When multiple exceptions are granted for the same control due to recurring business constraints, the control itself is likely misaligned with business reality, so the best action is to revise the policy to accommodate the legitimate business need. This addresses the root cause rather than repeatedly managing exceptions. It also reduces risk by bringing the activity under a formally approved, monitored policy instead of a patchwork of exceptions.

Exam trap

The trap is choosing a control-oriented response (increase monitoring, reject exceptions) when the scenario describes a systemic policy misalignment — CISM expects you to recognize that repeated exceptions signal a need to fix the policy, not to tighten enforcement.

How to eliminate wrong answers

Option B is wrong because escalating to the board for each exception is an escalation of a symptom, not a fix, and boards should not be involved in operational policy exceptions. Option C is wrong because increasing monitoring treats the symptom and leaves the policy misaligned, creating ongoing administrative burden and potential audit findings. Option D is wrong because rejecting all future exceptions ignores legitimate business constraints and may force workarounds that increase risk or halt business operations.

631
MCQmedium

A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?

A.Highlight the technical sophistication of the proposed security controls
B.Emphasize the potential cost savings from preventing security incidents
C.Present industry benchmarks showing the average cost of a data breach
D.Demonstrate how security enables the achievement of business objectives and protects revenue streams
AnswerD

This approach aligns security with the executives' priorities by showing that security is not just a cost center but a business enabler. It highlights how security measures can protect revenue, facilitate market expansion, and build customer trust. By directly linking security to business objectives, the CISO can secure executive support and funding more effectively. This strategic alignment is a core principle of a mature information security program and is essential for gaining buy-in from business leaders.

Why this answer

The most effective approach is to demonstrate how security enables business objectives and protects revenue streams. This aligns security with the executives' strategic priorities, positioning it as a value driver rather than a cost. By showing that security supports growth, innovation, and customer trust, the CISO can build a compelling business case that resonates with executive leadership and secures necessary funding.

Exam trap

The trap here is focusing on technical or fear-based arguments instead of linking security to the business outcomes executives care about.

632
MCQeasy

Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?

A.The policy does not specify quarterly review of access rights.
B.The data owner did not approve the exceptions.
C.Contractors should not have any access to financial systems.
D.Lack of documentation for approved exceptions.
AnswerD

Contractors holding financial system access without documented exceptions means the exception approval process is not being evidenced, so approvals cannot be audited or reviewed. The deficiency is the missing documentation trail, not the access itself.

Why this answer

The policy requires documented exceptions for any access granted outside standard provisioning rules. The security manager observed that contractors had access without such documentation, which directly violates the governance requirement for maintaining an audit trail of approved exceptions. Without this documentation, the organization cannot demonstrate that access was properly authorized, creating a compliance gap.

Exam trap

The trap here is that candidates may focus on who approved the access (Option B) rather than recognizing that the core governance deficiency is the lack of documentation for approved exceptions, which is a distinct control requirement.

How to eliminate wrong answers

Option A is wrong because the policy does not necessarily require quarterly reviews; the deficiency is specifically about undocumented exceptions, not the frequency of access reviews. Option B is wrong because the data owner may have approved the exceptions, but the failure to document them is the governance deficiency; approval without documentation still violates policy. Option C is wrong because contractors can be granted access to financial systems if exceptions are properly documented and approved; the policy does not categorically prohibit contractor access.

633
MCQhard

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

A.Vendor's insurance certificate
B.Annual self-assessment questionnaire only
C.Contractual security requirements and right to audit
D.SOC 2 Type II report without contractual clauses
AnswerC

Contractual security requirements plus right to audit give the organisation enforceable obligations and verification over a vendor holding sensitive customer data. This satisfies the stem's minimum requirement by enabling both control specification and independent assurance, which certifications alone cannot guarantee.

Why this answer

For a vendor storing sensitive customer data, the contract must include explicit security requirements (e.g., encryption, access controls, breach notification) and a right to audit, which gives the organization the legal ability to verify compliance. This is the minimum contractual safeguard recommended by TPRM best practices. Without these clauses, the organization has no enforceable mechanism to ensure the vendor protects data.

Exam trap

CISM often tests the misconception that a SOC 2 report or insurance certificate alone is sufficient due diligence, when the enforceable contract with security requirements and audit rights is the foundational control.

How to eliminate wrong answers

Option A is wrong because an insurance certificate only demonstrates financial protection, not security controls or the right to verify them. Option B is wrong because a self-assessment questionnaire alone is not enforceable and lacks independent verification; it should be part of a broader program, not the minimum contract requirement. Option D is wrong because a SOC 2 Type II report, while valuable, does not replace contractual security requirements and the right to audit; without contractual clauses, the organization cannot compel remediation or access.

634
Multi-Selectmedium

An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?

Select 2 answers
A.Determining acceptable risk levels
B.Analyzing threats and vulnerabilities
C.Monitoring incident response plans
D.Evaluating the effectiveness of existing controls
E.Selecting controls to mitigate risks
AnswersB, D

This is a core activity in risk identification and analysis.

Why this answer

Analyzing threats and vulnerabilities is a core step in the risk assessment process, as defined by the NIST SP 800-30 and ISO 31000 frameworks. This activity identifies potential threat sources and existing vulnerabilities that could be exploited, enabling the calculation of likelihood and impact for risk scenarios.

Exam trap

The trap here is confusing risk assessment (identify/analyze) with risk treatment (select controls) or risk evaluation (set acceptable levels), leading candidates to pick A or E instead of focusing on the core assessment activities B and D.

635
Multi-Selecthard

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Select 3 answers
A.Annual reassessment of the vendor's security controls
B.Contractual requirement for data encryption
C.Periodic review of vendor's security certifications (e.g., SOC 2)
D.One-time onboarding risk assessment
E.Continuous monitoring of vendor's external attack surface
AnswersA, C, E

Critical vendors require scheduled revalidation because their risk profile and controls change over time. An annual reassessment confirms security controls remain effective and aligned with contractual obligations, satisfying the ongoing monitoring requirement rather than relying on point-in-time onboarding evidence.

Why this answer

Option A is correct because an annual reassessment of the vendor's security controls is a core recurring activity in the ongoing monitoring phase, ensuring that the vendor's safeguards remain effective as its environment, personnel, and threats change over time. Option C is correct because periodically reviewing the vendor's security certifications, such as a SOC 2 Type II report, provides independent attestation that controls were tested over a defined period and helps detect any scope changes, exceptions, or qualified opinions. Option E is correct because continuous monitoring of the vendor's external attack surface—for example, tracking exposed services, expired TLS certificates, or newly disclosed CVEs affecting the vendor—gives early warning of emerging risk between formal assessments.

Option B does not belong because a contractual requirement for data encryption is a risk-treatment/contractual control established during due diligence and contracting, not a recurring monitoring activity. Option D does not belong because a one-time onboarding risk assessment is part of the initial due diligence phase, whereas ongoing monitoring requires repeated, continuous, or periodic evaluation rather than a single point-in-time review.

Exam trap

CISM often tests the confusion between onboarding activities (contractual clauses, initial assessments) and ongoing monitoring activities (reassessments, certification reviews, continuous monitoring).

636
Multi-Selectmedium

Which THREE of the following are essential components of an information security governance framework?

Select 3 answers
A.A process for conducting security incident response.
B.Implementation of technical security controls such as firewalls.
C.Strategic alignment of security with business objectives.
D.Defined roles and responsibilities for security management.
E.Performance measurement and reporting mechanisms.
AnswersC, D, E

Governance ensures security supports business goals.

Why this answer

Strategic alignment of security with business objectives (Option C) is essential because an information security governance framework must ensure that security initiatives directly support and enable the organization's mission and goals. Without this alignment, security becomes a siloed cost center rather than a strategic enabler, leading to misallocated resources and reduced executive sponsorship. This principle is foundational to the CISM governance domain, where security is viewed as a business function, not just a technical discipline.

Exam trap

ISACA often tests the distinction between governance (strategic oversight) and management (operational execution), and the trap here is that candidates confuse operational processes like incident response or technical controls with governance framework components, leading them to select A or B instead of the correct strategic elements.

637
MCQhard

A global retailer is expanding into new markets and must comply with varying data protection laws. The CISO is revising the information security strategy to ensure it remains aligned with the changing business environment. Which approach BEST ensures ongoing alignment between the security strategy and business objectives?

A.Delegate strategy updates to the security operations team based on emerging threats.
B.Conduct an annual penetration test and use the results to update the security strategy.
C.Integrate security strategy reviews into the enterprise strategic planning cycle and adjust based on business changes.
D.Adopt a widely recognized security framework and mandate compliance with its controls.
AnswerC

Embedding security strategy reviews into the enterprise strategic planning cycle ensures that security remains aligned with business objectives as markets and regulations evolve. This approach makes alignment a recurring, proactive activity rather than a one-time effort. It allows the CISO to anticipate changes and adjust security initiatives in tandem with business strategy, which is essential for effective governance in a dynamic environment.

Why this answer

Integrating security strategy reviews into the enterprise strategic planning cycle ensures that security is continuously aligned with business objectives, especially as the retailer enters new markets with different regulations. This approach makes alignment a proactive, recurring process rather than a one-off or reactive activity. It enables the CISO to adjust security initiatives in response to business changes, which is critical for effective governance and risk management.

Exam trap

The trap here is equating framework adoption or penetration testing with strategic alignment, when true alignment requires embedding security into the business planning cycle.

638
MCQhard

A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?

A.The risk whose exposure most exceeds the organisation's defined risk appetite and tolerance.
B.The risk with the largest potential financial loss in the register.
C.The risk that the external auditor flagged in the most recent report.
D.The risk with the highest technical severity score from the vulnerability scanner.
AnswerA

Risk appetite and tolerance express how much risk the organisation is willing to accept in pursuit of objectives. When exposure exceeds tolerance, the gap represents a governance-level obligation that demands action, making it the primary driver for prioritisation. This approach ensures remediation aligns with board-approved direction rather than isolated technical severity, which is central to CISM's risk management perspective.

Why this answer

Prioritisation should reflect the gap between current exposure and the board-approved risk appetite and tolerance. That gap defines which risks the organisation has formally committed to treat, and it integrates likelihood, impact, and business context rather than relying on a single dimension such as loss magnitude, audit attention, or technical severity. Aligning remediation with risk appetite keeps security investment defensible to executive stakeholders.

Exam trap

The trap here is equating the highest technical severity or largest loss figure with the highest priority, when governance alignment to risk appetite is what determines treatment order.

639
MCQmedium

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

A.Patch compliance percentage
B.Number of security incidents
C.Phishing simulation click rate
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect directly quantifies how quickly the security programme identifies threats, giving the board a measurable indicator of detection effectiveness. Unlike volume-based metrics, MTTD reflects actual capability against the stem's detection constraint, and its trend over time shows whether monitoring, tuning and staffing investments are improving outcomes.

Why this answer

Mean time to detect (MTTD) directly measures how quickly the security program identifies threats, which is the core of detection effectiveness. It is a quantitative metric that the board can use to assess improvement over time and benchmark against industry standards. Other metrics like patch compliance or phishing click rate are preventive or user-awareness measures, not detection performance indicators.

Exam trap

CISM often tests the difference between preventive, detective, and corrective metrics; candidates may mistakenly choose a preventive metric like patch compliance when asked for a detection effectiveness measure.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures vulnerability management and prevention, not the ability to detect threats. Option B is wrong because the number of security incidents is a lagging indicator of incident volume, not detection speed or effectiveness; it can be high even with poor detection if many incidents occur. Option C is wrong because phishing simulation click rate measures user susceptibility and awareness training effectiveness, not the security program's detection capabilities.

640
MCQmedium

An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?

A.Increase the control strength
B.Re-assess the risk and control effectiveness
C.Report to senior management
D.Accept the risk as residual
AnswerB

Re-assessing the risk and control effectiveness establishes whether the control was implemented as designed and whether residual risk was miscalculated. This diagnostic step must precede any further treatment decision, since the unchanged level may stem from poor implementation or an inaccurate original assessment.

Why this answer

When a control is implemented but the risk level remains unchanged, the risk manager must first re-assess the risk and control effectiveness to determine why the control failed to reduce the risk. This aligns with the CISM risk management process, which mandates that controls be evaluated for proper design and operation before any escalation or acceptance decisions are made. Without this re-assessment, the organization cannot know whether the control is misconfigured, insufficient, or simply not addressing the correct threat vector.

Exam trap

The trap here is that candidates mistakenly jump to 'increase control strength' (Option A) because they assume the control is simply too weak, rather than first verifying whether the control is actually functioning or correctly designed to address the specific risk.

How to eliminate wrong answers

Option A is wrong because increasing control strength without first understanding why the current control is ineffective could waste resources and may not address the root cause, such as a misconfiguration or incorrect threat model. Option C is wrong because reporting to senior management should occur only after the risk manager has performed a re-assessment and has a clear picture of the control failure and its implications. Option D is wrong because accepting the risk as residual is premature; the risk manager must first verify whether the control can be adjusted or replaced before deciding to accept an unchanged risk level.

641
MCQhard

A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?

A.Outsource security governance to a managed security service provider (MSSP).
B.Fully centralized security governance with global standards enforced uniformly.
C.Federated governance: global standards with local implementation and oversight.
D.Fully decentralized security governance, each region independent.
AnswerC

Federated governance balances centralised standards with regional autonomy: global policies set minimum security baselines, while local teams adapt implementation to jurisdictional, regulatory and cultural constraints. This directly satisfies the stem's dual requirement of consistency and regional flexibility, unlike purely centralised or fully devolved models that sacrifice one objective for the other.

Why this answer

Federated governance (Option C) is the correct choice because it establishes a global security framework with mandatory standards (e.g., ISO 27001 controls, encryption baselines like AES-256) while delegating implementation and oversight to regional units. This structure balances consistency with local legal requirements (e.g., GDPR in Europe, PIPL in China) and operational needs, avoiding the rigidity of full centralization or the fragmentation of full decentralization.

Exam trap

The trap here is that candidates often confuse 'federated governance' with 'decentralized governance' (Option D). In the context of ISACA CISM, federated governance enforces a mandatory global baseline (e.g., security standards, risk management framework) while permitting local adaptation to comply with regional laws and operational needs. Decentralized governance lacks any central authority or consistent standards, which is unacceptable for a global program.

How to eliminate wrong answers

Option A is wrong because outsourcing security governance to an MSSP abdicates strategic control and does not inherently provide a structure for consistent global standards with regional flexibility; MSSPs typically execute operational tasks (e.g., SIEM monitoring) rather than define governance frameworks. Option B is wrong because fully centralized governance with uniform enforcement ignores regional legal variations (e.g., data residency laws) and local risk appetites, leading to non-compliance or operational friction. Option D is wrong because fully decentralized governance creates inconsistent security postures, making it impossible to enforce global baselines (e.g., minimum encryption standards or incident response timelines) and increasing overall risk exposure.

642
MCQmedium

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

A.SOC Manager
B.Security Architect
C.Incident Responder
D.Security Analyst
AnswerD

Security analysts perform tier-one triage, correlating alerts from SIEM and other monitoring tools and investigating whether activity constitutes a genuine threat. This alert analysis and escalation decision-making is their primary function, distinct from engineering, monitoring tooling ownership or management oversight.

Why this answer

The Security Analyst (often Tier 1 or Tier 2) is primarily responsible for monitoring alerts, triaging them, and determining whether they represent genuine threats. This role performs the initial analysis and escalates confirmed incidents to incident responders. The SOC Manager oversees operations, the Security Architect designs controls, and the Incident Responder handles confirmed incidents.

Exam trap

CISM often tests the distinction between roles: candidates may confuse the Incident Responder (who handles confirmed incidents) with the Security Analyst (who analyzes alerts to determine if they are genuine threats).

How to eliminate wrong answers

Option A is wrong because the SOC Manager is responsible for managing the SOC's people, processes, and performance, not for analyzing individual alerts. Option B is wrong because the Security Architect designs security systems and controls, not day-to-day alert triage. Option C is wrong because the Incident Responder focuses on containing, eradicating, and recovering from confirmed incidents, which occurs after the analyst determines a genuine threat.

643
MCQmedium

Which board-level committee typically receives security reports to provide oversight?

A.Nominating committee
B.Compensation committee
C.Audit/risk committee
D.Finance committee
AnswerC

The audit/risk committee holds board-level oversight of risk and internal control, making it the natural recipient for security reporting. It provides independent scrutiny of risk posture and remediation, satisfying the governance requirement that security oversight sits with those accountable for enterprise risk.

Why this answer

The audit/risk committee is typically responsible for overseeing risk management, internal controls, and compliance, making it the natural board-level committee to receive security reports. This committee ensures that security risks are aligned with the organization's risk appetite and that mitigation strategies are effective. Other committees like nominating or compensation focus on governance structure and executive pay, not security oversight.

Exam trap

The trap here is confusing the audit committee's financial oversight with broader risk oversight; candidates may overlook that audit committees often have expanded risk responsibilities, including cybersecurity.

How to eliminate wrong answers

Option A is wrong because the nominating committee focuses on board composition, director recruitment, and governance policies, not security oversight. Option B is wrong because the compensation committee deals with executive remuneration and incentives, which is unrelated to security reporting. Option D is wrong because the finance committee primarily oversees financial reporting, budgeting, and financial risks, not the broader security program.

644
MCQhard

A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?

A.Outsourcing all security testing to a third-party vendor.
B.Implementing a secure coding training program for developers and integrating security gates into the CI/CD pipeline.
C.Requiring developers to sign a security policy acknowledging their responsibilities.
D.Conducting a penetration test after each major release.
AnswerB

Training developers on secure coding and embedding security gates into the CI/CD pipeline are proactive measures that integrate security throughout development. Training reduces the introduction of vulnerabilities, while automated gates catch issues early. This shifts security left, making it more efficient and cost-effective. It is the most effective way to embed security into the SDLC and reduce production vulnerabilities.

Why this answer

The correct answer is implementing a secure coding training program for developers and integrating security gates into the CI/CD pipeline. This approach proactively builds security into the development process, reducing vulnerabilities at the source. Training equips developers to write secure code, and automated gates enforce security checks early and consistently.

Together, they embed security into the SDLC effectively.

Exam trap

The trap here is relying on reactive measures like penetration testing or policy acknowledgments instead of proactively integrating security into the development process through training and automated gates.

645
MCQhard

An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?

A.Adopt a comprehensive control catalogue as the baseline, then tailor control selection and implementation using the organisation's risk assessment results.
B.Build a bespoke control set from scratch based on internal incident history, avoiding external frameworks that may not reflect the organisation's environment.
C.Implement every control in the chosen catalogue to the highest specified level so that no gap can ever be identified by an auditor.
D.Allow each business unit to select controls from any framework it prefers, provided the unit documents its choices in its own risk register.
AnswerA

This combines the breadth of a recognised catalogue with risk-based tailoring, which is how control frameworks are intended to be used. The catalogue provides completeness and a common reference, while risk assessment determines which controls are relevant, how strictly they are applied and where compensating measures are acceptable, keeping effort proportionate to actual exposure.

Why this answer

Control frameworks are designed to be adopted as a baseline and then tailored through risk assessment, which gives both completeness and proportionality. Implementing everything at maximum strength wastes resources, letting each unit choose its own framework destroys comparability, and a purely bespoke set risks blind spots that established catalogues are designed to prevent.

Exam trap

The trap here is assuming that maximum implementation of every catalogue control equals the strongest programme, when frameworks are meant to be tailored by risk.

646
MCQhard

A CISO is presenting the information security program's annual report to the board. The board is concerned about the rising cost of cyber insurance and wants to understand how the program can help reduce premiums. Which of the following actions would MOST directly influence the cost of cyber insurance?

A.Implementing and documenting a formal risk management process with regular assessments.
B.Outsourcing security monitoring to a managed security service provider (MSSP).
C.Increasing the number of security awareness training sessions per year.
D.Purchasing additional security tools to enhance the defense-in-depth strategy.
AnswerA

Insurers assess risk based on the maturity of an organization's risk management practices. A formal, documented process with regular assessments demonstrates proactive risk reduction, which can lead to lower premiums. It provides evidence that the organization understands and manages its cyber risk, making it a more attractive insurance candidate.

Why this answer

The correct answer is implementing and documenting a formal risk management process with regular assessments. Insurers evaluate the maturity and effectiveness of an organization's risk management to determine premiums. A documented process with regular assessments provides tangible evidence of risk reduction, which is a key factor in negotiating lower premiums.

Exam trap

The trap here is assuming that adding more tools or training sessions directly lowers premiums, when insurers primarily value a mature, documented risk management process.

647
MCQhard

A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?

A.Implement the strictest regulatory requirements globally to ensure compliance everywhere.
B.Adopt a baseline of controls that meet the lowest common denominator of all regulations.
C.Develop a risk-based framework that allows for tailored controls based on local risk assessments.
D.Allow each business unit to define its own security controls based on local requirements.
AnswerC

A risk-based framework lets the corporation apply controls proportionate to assessed local risk, accommodating differing legal requirements across regulated jurisdictions while preserving business agility. Uniform or purely compliance-driven controls cannot flex to each region's distinct regulatory and risk profile.

Why this answer

A risk-based framework, such as ISO 27001 or NIST SP 800-53, allows the organization to establish a baseline of controls while tailoring them to address specific local legal requirements and risk profiles. This approach balances security and business agility by avoiding unnecessary overhead from overly strict global mandates while ensuring that critical regulatory obligations are met through localized risk assessments.

Exam trap

The trap here is that candidates often confuse 'strictest globally' (Option A) with 'best practice' due to a desire for simplicity, but CISM emphasizes that a risk-based approach is the only method that effectively balances compliance, security, and business agility in a multi-regulatory environment.

How to eliminate wrong answers

Option A is wrong because implementing the strictest regulatory requirements globally (e.g., GDPR's data protection rules applied in jurisdictions with less stringent laws) can introduce excessive operational friction, reduce business agility, and may conflict with local laws that permit different practices. Option B is wrong because adopting a baseline that meets the lowest common denominator of all regulations (e.g., only complying with the weakest privacy law) would leave the organization non-compliant with stricter regulations like GDPR or HIPAA, exposing it to significant legal and financial penalties. Option D is wrong because allowing each business unit to define its own security controls based on local requirements without a centralized governance framework leads to inconsistent security postures, gaps in coverage, and increased risk of regulatory non-compliance across the multinational enterprise.

648
MCQhard

An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?

A.Ensure all external communications are approved through legal counsel and aligned with applicable regulatory notification requirements and deadlines.
B.Release detailed technical findings immediately to all customers so they can assess their own risk without delay.
C.Delay all notifications until the forensic investigation is fully complete to ensure accuracy in every statement.
D.Allow each regional business unit to communicate independently using its own messaging and timing without central coordination.
AnswerA

Breach notification obligations vary by jurisdiction and often carry strict deadlines, content requirements, and prescribed recipients. Legal counsel must review external communications to avoid conflicting statements, waiving privileges, or missing mandatory timelines. Aligning messages with regulatory requirements protects the organization from penalties and ensures affected parties receive accurate, timely information while the investigation continues.

Why this answer

Multi-jurisdiction breaches trigger overlapping notification laws with different deadlines and content rules, so external communications must be reviewed by legal counsel and mapped to each applicable requirement. This ensures deadlines are met, statements are consistent, and privileges or ongoing investigations are not compromised. Timely, accurate, and compliant communication protects the organization legally and preserves stakeholder trust while the technical investigation proceeds in parallel.

Exam trap

The trap here is choosing between speed and completeness of disclosure, when the governing consideration is legal review and alignment with jurisdiction-specific notification requirements and deadlines.

649
MCQeasy

Which of the following is a LEADING indicator of security performance?

A.Cost of a data breach
B.Mean time to detect (MTTD)
C.Number of security incidents
D.Patch compliance percentage
AnswerD

Patch compliance percentage measures control execution before breaches occur, making it predictive rather than retrospective. Unlike incident counts, which record past failures, it signals whether vulnerability exposure is being actively reduced, so it functions as a leading indicator.

Why this answer

Patch compliance percentage is a leading indicator because it measures proactive security hygiene—the proportion of systems with current patches—which predicts future breach likelihood. Leading indicators are forward-looking and actionable, allowing organizations to prevent incidents before they occur. MTTD, incident counts, and breach costs are lagging indicators that measure past performance.

Exam trap

CISM often tests the distinction between leading and lagging indicators; candidates may incorrectly select MTTD or incident counts as leading when they are actually lagging measures of past performance.

How to eliminate wrong answers

Option A is wrong because cost of a data breach is a lagging indicator that measures the financial impact after an incident has occurred. Option B is wrong because Mean Time to Detect (MTTD) is a lagging indicator that measures how long it took to detect past incidents, not a predictor of future security posture. Option C is wrong because the number of security incidents is a lagging indicator that reflects past events rather than proactive control effectiveness.

650
MCQhard

An organization has just recovered from a ransomware attack and restored systems from backups. Before returning to normal operations, what is the MOST important step?

A.Update the incident response plan.
B.Test the restored systems to ensure functionality and security.
C.Notify stakeholders.
D.Conduct a root cause analysis.
AnswerB

Testing restored systems verifies both functionality and security before normal operations resume. Untested restores may harbour dormant malware, missed patches or corrupted data, so validation confirms the environment is genuinely clean and fit for production use.

Why this answer

After recovering from a ransomware attack and restoring systems from backups, the most critical step is to test the restored systems for both functionality and security. This ensures that the backups are clean (free of malware), that system integrity is verified, and that no residual threats remain before returning to normal operations. Without this validation, the organization risks re-infection or operational failures that could undermine the entire recovery effort.

Exam trap

The trap here is that candidates often confuse the urgency of stakeholder notification or root cause analysis with the immediate operational necessity of validating system integrity and security before resuming business operations.

How to eliminate wrong answers

Option A is wrong because updating the incident response plan is a post-incident improvement activity that should occur after the immediate threat is neutralized and systems are verified, not before returning to operations. Option C is wrong because notifying stakeholders is important but secondary to ensuring the restored environment is safe and functional; premature notification could cause confusion if systems fail or are re-infected. Option D is wrong because conducting a root cause analysis is a forensic and process improvement step that follows stabilization and validation, and it does not directly confirm that the restored systems are secure and operational.

651
MCQhard

A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?

A.Maintain a separate security risk register scored on a technical severity scale, and provide the enterprise risk function with a monthly extract of open findings.
B.Report security risk using the same likelihood and impact scales, risk appetite statements and escalation thresholds used by the enterprise risk function.
C.Transfer responsibility for scoring and owning security risks to the enterprise risk management team so that a single team manages all risk registers.
D.Adopt the ISO/IEC 27005 risk assessment methodology and require all business units to complete annual security risk assessments using its process.
AnswerB

Enterprise risk frameworks work because all risk types are expressed in a common language, so they can be aggregated and compared. Adopting the same scales, appetite statements and escalation thresholds lets security risk be consolidated into the corporate risk profile and debated alongside credit, operational and market risk, which is exactly what alignment means in practice.

Why this answer

Aligning security risk with enterprise risk management means the same scales, appetite statements and escalation thresholds are used, so security risk can be aggregated and compared with other risk types. A separate technical register, transferred ownership or a security-only methodology all leave security risk expressed differently from the rest of the enterprise, defeating the purpose of alignment.

Exam trap

The trap here is equating alignment with adopting a recognised security risk methodology rather than with using the enterprise's common risk language and appetite.

652
Multi-Selecthard

Which THREE of the following are essential components of an incident response plan? (Select exactly 3)

Select 3 answers
A.A list of all software licenses in the organization
B.Annual budget for security tools
C.Communication plan for internal and external stakeholders
D.Roles and responsibilities of the incident response team
E.Step-by-step procedures for handling different types of incidents
AnswersC, D, E

Communication is critical during incidents.

Why this answer

A communication plan is essential because it defines how the incident response team will coordinate internally and notify external stakeholders such as regulators, law enforcement, customers, and the media. Without a predefined communication plan, critical updates may be delayed or mishandled, leading to regulatory penalties or reputational damage. This aligns with NIST SP 800-61 and CISM best practices for incident management.

Exam trap

ISACA often tests the distinction between operational incident response components (roles, procedures, communication) and supporting organizational artifacts (licenses, budgets) that are not part of the actual response plan.

653
MCQmedium

An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?

A.Eliminating the need for vulnerability assessments
B.Replacing the role of security architects
C.Improving secure coding adoption and collaboration
D.Reducing the need for a SOC
AnswerC

Embedding advocates within development teams places security expertise directly into daily coding workflows, enabling peer coaching and early vulnerability detection. This raises secure coding adoption and cross-team collaboration, satisfying the stem's primary-benefit requirement without adding separate security gates.

Why this answer

A security champions program embeds security-minded individuals within development teams to promote secure coding practices, provide peer guidance, and improve collaboration between security and engineering. The primary benefit is cultural and practical: security becomes part of the development workflow rather than a gate at the end. This improves secure coding adoption and cross-team collaboration, which is the core outcome of the program.

Exam trap

CISM often tests whether candidates overstate the impact of a control — the trap is choosing an answer that claims a program replaces an existing function (assessments, architects, SOC) rather than augmenting and improving it.

How to eliminate wrong answers

Option A is wrong because security champions do not eliminate the need for vulnerability assessments; assessments remain a required control, and champions complement rather than replace them. Option B is wrong because champions are not replacements for security architects — architects define strategy and design, while champions embed practices at the team level. Option D is wrong because a SOC is still required for monitoring and incident response; champions reduce friction and improve prevention, but they do not replace detection and response operations.

654
MCQmedium

During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?

A.Disable the user account
B.Restore the user's system from a backup
C.Block the sender's IP address at the firewall
D.Change all user passwords
AnswerA

Disabling the account immediately revokes the compromised credentials' ability to authenticate, cutting off the attacker's access path while investigation continues. This contains the breach at its entry point, preventing lateral movement or further data theft using that identity.

Why this answer

Disabling the user account immediately stops any ongoing misuse of the compromised credentials, preventing the attacker from accessing additional resources. Option A is correct.

655
MCQhard

An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?

A.The incident response manager
B.The chief executive officer (CEO) or designated crisis management team
C.The business continuity manager
D.The chief information security officer (CISO)
AnswerB

Declaring a disaster exceeds operational incident authority, requiring executive mandate to commit organisation-wide resources and invoke continuity arrangements. The CEO or designated crisis management team holds that strategic authority, satisfying the stem's MTD-exceeded escalation trigger.

Why this answer

The CEO or designated crisis management team holds the authority to declare a disaster and activate the BCP because this decision has enterprise-wide impact, requiring executive-level accountability and resource allocation. The CEO is ultimately responsible for business survival, and the crisis management team is typically pre-authorized to make this call when MTD is exceeded. This aligns with CISM's governance principle that business continuity is a business decision, not an IT or security decision.

Exam trap

CISM often tests the distinction between tactical incident response roles and strategic business continuity authority, causing candidates to incorrectly assume the CISO or BCP manager can declare a disaster.

How to eliminate wrong answers

Option A is wrong because the incident response manager focuses on tactical containment and recovery of the incident, not on declaring a disaster or activating the BCP—that authority resides at the executive level. Option C is wrong because the business continuity manager coordinates BCP development and maintenance but typically does not have the authority to declare a disaster; that decision requires executive approval. Option D is wrong because the CISO is responsible for information security strategy and may advise on the incident, but declaring a disaster and activating the BCP is a business continuity governance decision, not a security function.

656
MCQeasy

An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?

A.Notify affected customers about the data breach.
B.Eradicate the root cause of the incident.
C.Recover the affected systems to normal operations.
D.Conduct a lessons learned session.
AnswerB

This is correct because after containment, the next phase in the incident response lifecycle is eradication. Eradication involves removing the cause of the incident, such as malware, backdoors, or vulnerabilities, to prevent recurrence. CISM follows the standard incident response phases: preparation, identification, containment, eradication, recovery, and lessons learned. Eradication must be completed before recovery to ensure the environment is clean.

Why this answer

After containment, the incident response team should proceed to eradication to remove the root cause of the incident. This ensures that the threat is eliminated before recovery. Recovery, lessons learned, and customer notification are subsequent steps.

CISM emphasizes a structured incident response process, and eradication is the logical next phase after containment to prevent the incident from recurring.

Exam trap

The trap here is thinking that recovery or notification comes immediately after containment, when actually eradication must occur first to prevent recurrence.

657
MCQeasy

Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?

A.Data breach
B.DDoS
C.Ransomware
D.Insider threat
AnswerD

Insider threats uniquely cover harm caused by employees, whether malicious or accidental, matching the stem's requirement for internal actors. Unlike external categories such as hacktivists or nation-states, this classification hinges on the actor's authorised access and trusted position within the organisation, satisfying the intent and origin constraints.

Why this answer

An insider threat is the correct category because it specifically involves harm caused by individuals within the organization, whether through malicious intent (e.g., data exfiltration, sabotage) or accidental actions (e.g., misconfiguration, phishing click). This aligns with the CISM definition of insider threats as incidents originating from employees, contractors, or trusted partners who have authorized access to information systems.

Exam trap

ISACA CISM often tests the distinction between the incident category (who or what caused it) and the incident type or outcome, leading candidates to confuse 'insider threat' with 'data breach' because a data breach can be caused by an insider, but the question asks for the category that involves the employee's action.

How to eliminate wrong answers

Option A is wrong because a data breach is the outcome or result of an incident (e.g., unauthorized access or disclosure of data), not the category of the actor or cause; it does not specify whether the source is internal or external. Option B is wrong because a DDoS (Distributed Denial of Service) attack is an external, volumetric network attack that overwhelms system resources, typically launched from botnets, not from an employee's intentional or accidental actions. Option C is wrong because ransomware is a type of malware that encrypts files for extortion, usually delivered via external phishing or exploit kits, and does not inherently involve an employee's direct action causing harm to systems.

658
MCQmedium

A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?

A.Reboot the server to clear the potential malware
B.Notify the incident response team and escalate
C.Disconnect the server from the network immediately
D.Perform initial triage to verify the alert and assess severity
AnswerD

Triage validates whether the alert is a true positive and gauges business impact before committing containment resources, preventing wasted effort on false positives and avoiding premature actions that could disrupt a critical server. Verification and severity assessment must precede escalation, containment or eradication.

Why this answer

The first step in any incident response is to verify that an alert represents a real incident and assess its severity. Performing initial triage allows the analyst to gather evidence, determine the scope, and decide on the appropriate response without causing unnecessary disruption. Rebooting, disconnecting, or escalating prematurely can destroy evidence or disrupt critical services.

Exam trap

CISM often tests the order of incident response steps, and candidates frequently jump to containment (disconnecting) or escalation without first verifying the alert, falling for the trap of assuming the alert is always accurate.

How to eliminate wrong answers

Option A is wrong because rebooting a server can destroy volatile evidence (e.g., memory-resident malware) and may not remove the infection, potentially allowing it to persist. Option B is wrong because notifying the incident response team and escalating should occur after initial triage confirms the incident and its severity, not as the very first step. Option C is wrong because immediately disconnecting the server from the network can disrupt critical business operations and may be premature before verifying the alert; containment should follow triage.

659
MCQeasy

A security analyst detects unusual outbound traffic from a critical server to an unknown external IP address during business hours. Which step should be taken FIRST in the incident response process?

A.Notify law enforcement about the potential breach
B.Isolate the server from the network immediately
C.Contact the server owner to verify the traffic
D.Report the incident to senior management
AnswerC

Verifying with the server owner establishes whether the outbound traffic is legitimate business activity before escalating, satisfying the stem's requirement to act first. This validation step prevents wasted containment effort on false positives and confirms whether the detection warrants full incident response.

Why this answer

The first step in incident response is to verify and validate the alert. Contacting the server owner to confirm whether the outbound traffic is authorized prevents unnecessary disruption and false positives. This aligns with the NIST SP 800-61 incident response lifecycle, where identification and initial triage precede containment or escalation.

Exam trap

The trap here is that candidates often choose immediate containment (Option B) due to urgency, but CISM emphasizes that verification must precede containment to avoid false positives and operational impact.

How to eliminate wrong answers

Option A is wrong because notifying law enforcement is a late-stage step that occurs only after the incident is confirmed and evidence is preserved; premature notification can compromise investigation and violate chain-of-custody protocols. Option B is wrong because immediately isolating the server without verification risks disrupting legitimate business operations and may destroy volatile evidence (e.g., active network connections, memory artifacts) needed for forensic analysis. Option D is wrong because reporting to senior management is a notification step that should follow confirmation of a genuine incident, not precede initial triage and validation.

660
MCQeasy

Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

A.To assign blame for the incident.
B.To determine the financial impact of the incident.
C.To document the incident for regulatory reporting.
D.To update the incident response plan and playbooks based on findings.
AnswerD

The meeting's output is corrective: identified gaps, control failures and response weaknesses are translated into revised procedures, playbooks and controls. Without feeding findings back into the plan, the same deficiencies recur, so plan and playbook updates are the primary purpose rather than blame allocation or reporting.

Why this answer

Lessons learned meetings are designed to identify strengths and weaknesses in the incident response process and to implement improvements.

661
MCQeasy

A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?

A.Accept the risk as it is already controlled
B.Evaluate the residual risk and decide on additional controls
C.Transfer the risk to a cyber insurance provider
D.Conduct another round of user awareness training
AnswerB

With spam filtering and awareness training already applied, the next step is evaluating residual risk and deciding whether additional controls are warranted. This satisfies the stem's constraint of determining what to do next to manage the phishing risk.

Why this answer

After implementing initial controls (spam filtering and user awareness training), the organization must evaluate the residual risk—the risk that remains after controls are applied. This step is required by the CISM risk management process to determine whether the residual risk level is acceptable or if additional controls are needed. Option B correctly follows the risk assessment lifecycle: identify risk, apply controls, assess residual risk, then decide on further action.

Exam trap

The trap here is that candidates assume existing controls are sufficient and jump to acceptance (Option A) or repeat training (Option D), without recognizing that the CISM process mandates a formal residual risk evaluation before any risk response decision.

How to eliminate wrong answers

Option A is wrong because accepting risk without evaluating residual risk violates the CISM risk management process; acceptance is only appropriate after confirming that residual risk is within the organization's risk appetite. Option C is wrong because transferring risk to a cyber insurance provider does not reduce the likelihood or impact of phishing attacks; it only provides financial compensation after a loss, and is not a next step before evaluating residual risk. Option D is wrong because conducting another round of user awareness training without first evaluating residual risk is premature; the effectiveness of the existing training must be measured to determine if additional training is necessary.

662
MCQhard

A healthcare organization is developing an information security strategy. The board has mandated that the strategy must support innovation while protecting patient data. Which governance approach BEST balances these priorities?

A.Implement strict access controls and encryption for all data.
B.Establish a risk appetite framework that defines acceptable risk levels for innovation initiatives.
C.Adopt a 'security by design' approach for all new projects.
D.Create a separate innovation sandbox with limited data access.
AnswerB

A risk appetite framework lets the board define how much risk is tolerable, so innovation proceeds within agreed boundaries rather than being blocked. It directly satisfies the mandate to balance innovation against patient-data protection through governed risk tolerance.

Why this answer

A risk appetite framework (Option B) is the correct governance approach because it explicitly defines the level of risk the organization is willing to accept in pursuit of innovation, allowing the board to balance patient data protection with strategic growth. This framework provides a decision-making boundary for security controls, ensuring that innovation initiatives are not stifled by overly restrictive measures while still maintaining compliance with healthcare regulations like HIPAA and HITECH.

Exam trap

The trap here is that candidates often confuse tactical security controls (like encryption or sandboxes) with governance frameworks, failing to recognize that only a risk appetite framework provides the strategic balance between innovation and protection required by the board's mandate.

How to eliminate wrong answers

Option A is wrong because implementing strict access controls and encryption for all data is a tactical control measure, not a governance framework; it fails to address the board's mandate to support innovation, as blanket restrictions can hinder agile development and data sharing required for new healthcare technologies. Option C is wrong because adopting a 'security by design' approach for all new projects is a best practice for secure development, but it does not provide a governance-level mechanism to balance risk and innovation; it focuses on implementation rather than strategic risk acceptance. Option D is wrong because creating a separate innovation sandbox with limited data access is an operational tactic that isolates risk but does not establish a governance framework for the entire organization; it avoids the core issue of defining acceptable risk levels across all initiatives and may lead to shadow IT if not governed properly.

663
MCQmedium

Based on the exhibit, what is the MOST likely scenario?

A.A user is performing a scheduled task that requires authentication.
B.A user forgot their password and successfully logged in after retrying.
C.An attacker brute-forced the password and then used the credentials to access a file server.
D.A system administrator is testing password policies.
AnswerC

Repeated failed authentications followed by a successful logon and subsequent file-server access match credential brute forcing: the attacker guesses the password, then uses the valid account to reach data. The sequence links authentication abuse directly to the file access.

Why this answer

The exhibit shows multiple failed authentication attempts (Event ID 4625) from a single user account within a short time window, followed by a successful logon (Event ID 4624) and then an access event to a file share (Event ID 5140). This pattern of rapid, repeated failures culminating in a single success is characteristic of a brute-force attack, where the attacker guesses the password and then uses the compromised credentials to access a file server.

Exam trap

The trap here is that candidates may misinterpret the failed logons as a user simply forgetting their password (Option B), but the rapid, repeated failures followed by a successful logon and file access clearly indicate a brute-force attack rather than a benign password mistake.

How to eliminate wrong answers

Option A is wrong because scheduled tasks typically use service accounts or stored credentials and do not generate a burst of failed logon events; they would show a single successful logon without preceding failures. Option B is wrong because a user who forgot their password would not generate dozens of failed attempts in rapid succession; they would typically use a password reset workflow or have a few retries, not a sustained brute-force pattern. Option D is wrong because a system administrator testing password policies would likely use a dedicated test account or controlled conditions, not a real user account, and would not follow the failed logons with a file server access event.

664
Drag & Dropmedium

Order the steps for implementing a data classification policy in an organization.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Data classification starts with defining categories, then procedures, training, labeling, and monitoring.

665
MCQmedium

During an incident, the response team collects volatile data from a compromised server. Which of the following should be collected FIRST to minimize loss of evidence?

A.Contents of RAM
B.Contents of hard drive
C.Event logs
D.Network configuration
AnswerA

Contents of RAM must be captured first because memory is volatile and lost on power-off, satisfying the stem's constraint to minimise evidence loss. Order of volatility dictates that CPU registers and cache, then RAM, precede disk and archival media. Capturing RAM preserves running processes, network connections and encryption keys unavailable elsewhere.

Why this answer

Volatile data, such as the contents of RAM, is lost when a system is powered off. The first priority during incident response is to capture this data because it contains running processes, network connections, encryption keys, and malware that exist only in memory. Collecting RAM first ensures that this critical evidence is preserved before any other actions that might alter the system state.

Exam trap

The trap here is that candidates often confuse the order of volatility (OOV) principle, mistakenly prioritizing non-volatile data like event logs or disk contents because they seem more stable, but the exam tests the understanding that volatile data must be captured first to prevent its permanent loss.

How to eliminate wrong answers

Option B is wrong because the contents of the hard drive are non-volatile and persist after power loss; collecting it first would risk overwriting or losing volatile data in RAM during the acquisition process. Option C is wrong because event logs are stored on the hard drive and are non-volatile; they can be collected later without risk of immediate loss, and accessing them first could alter system state. Option D is wrong because network configuration is also non-volatile and stored in the registry or configuration files on disk; it does not require immediate capture and can be gathered after volatile data is secured.

666
MCQeasy

Which of the following is the PRIMARY benefit of a security champions program?

A.Reducing the need for security awareness training
B.Embedding security advocates in business units
C.Automating security testing
D.Eliminating third-party risks
AnswerB

Placing advocates within business units distributes security ownership beyond the central team, so risks are identified and addressed where work actually happens. This satisfies the primary benefit of extending reach and embedding accountability into daily business processes rather than relying solely on periodic centralised training.

Why this answer

A security champions program embeds security-minded individuals within business units to act as liaisons between the security team and the business. This distributes security responsibility and promotes a security culture, enabling early risk identification and faster remediation. The primary benefit is not reducing training, automating testing, or eliminating third-party risks, but rather integrating security advocates into development and operational teams.

Exam trap

CISM often tests the difference between cultural initiatives and technical controls; candidates may confuse the champions program with automation or training reduction, missing its core purpose of embedding advocates in business units.

How to eliminate wrong answers

Option A is wrong because a security champions program supplements, not replaces, formal security awareness training; it enhances the security culture but does not reduce the need for foundational training. Option C is wrong because automating security testing is a technical control, not the primary benefit of a champions program, which focuses on human advocacy and cultural change. Option D is wrong because third-party risks are managed through vendor risk management processes, not by internal security champions; the program does not directly eliminate external risks.

667
MCQeasy

An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?

A.Risk avoidance
B.Risk reduction
C.Risk acceptance
D.Risk transfer
AnswerC

Risk acceptance is appropriate because the mitigation cost exceeds the potential loss, making further controls economically unjustifiable. The organization formally acknowledges the residual risk and retains it, satisfying the stem's cost-benefit constraint. Senior management must approve this decision, and the risk should be monitored and reviewed periodically in case the inherent risk profile changes.

Why this answer

Risk acceptance is the appropriate treatment when the cost of mitigating a risk exceeds the potential loss it represents. In this scenario, since mitigation costs more than the expected loss, accepting the risk is the most economically justified and effective strategy. The organization consciously retains the risk and monitors it, rather than spending more to prevent it than the loss would cost.

Exam trap

CISM often tests the distinction between accepting a risk because it is cost-justified versus avoiding or transferring it, and candidates frequently default to 'mitigate' or 'transfer' without weighing the stated cost-versus-loss economics.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or process entirely to avoid the risk — this is typically more disruptive and costly than the loss itself, and may not be feasible for a critical business process. Option B is wrong because risk reduction (mitigation) involves implementing controls to lower the risk, which is exactly what the scenario says costs more than the potential loss, making it economically unjustified. Option D is wrong because risk transfer (e.g., insurance) shifts financial impact but does not eliminate the risk and may not be available or cost-effective for this specific exposure.

668
Multi-Selecthard

Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?

Select 3 answers
A.Placing a legal hold on relevant data
B.Maintaining a documented chain of custody
C.Performing analysis directly on original systems
D.Using automated tools without validation
E.Creating bit-for-bit forensic copies of affected media
AnswersA, B, E

A legal hold preserves relevant data and prevents routine deletion or alteration once litigation is reasonably anticipated. Issuing it early satisfies the admissibility requirement by ensuring potentially relevant evidence remains intact and available for forensic collection and court presentation.

Why this answer

Option A is correct because a legal hold preserves potentially relevant data and prevents routine deletion or alteration, which is essential for demonstrating that evidence was not spoliated before collection. Option B is correct because a documented chain of custody records every transfer, access, and storage event for the evidence, allowing the court to verify its integrity and authenticity. Option E is correct because creating bit-for-bit forensic copies (forensic images) preserves the original media and allows analysis on a verified duplicate, typically validated with hash values such as MD5 or SHA-256.

Option C is not correct because performing analysis directly on original systems can alter metadata, timestamps, and other artifacts, undermining admissibility. Option D is not correct because using automated tools without validation fails to establish that the tools produce reliable, repeatable results, which is necessary for forensic soundness.

Exam trap

A common misconception is that direct analysis on original systems is acceptable, but in forensic procedures, any direct manipulation of original media is prohibited to avoid altering the evidence and compromising its admissibility.

669
MCQmedium

An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?

A.The percentage of the security budget spent on different projects.
B.Key risk indicators (KRIs) related to the organization's critical assets.
C.A log of all recent security incidents and their root causes.
D.A detailed list of all security tools and their functionalities.
AnswerB

KRIs give the board forward-looking, quantified insight into exposures affecting critical assets, linking security posture to business risk. This supports informed risk-based decisions and oversight, which is the board's governance responsibility rather than operational detail.

Why this answer

Key risk indicators (KRIs) provide a forward-looking, quantifiable measure of risk exposure tied directly to critical assets, which is essential for the board to understand the effectiveness of governance and risk management. Unlike operational or tactical data, KRIs enable informed strategic decisions about risk appetite and resource allocation, aligning with the CISM focus on governance over management.

Exam trap

The trap here is that candidates confuse operational reporting (incident logs, tool lists) with governance reporting, which demands high-level, risk-focused metrics like KRIs that support strategic oversight.

How to eliminate wrong answers

Option A is wrong because budget allocation percentages are a tactical financial detail, not a governance-level indicator; the board needs risk context, not spending breakdowns. Option C is wrong because a log of all incidents is operational data that overwhelms the board with noise; governance reporting requires aggregated trends and risk impact, not raw root-cause details. Option D is wrong because a list of tools and their functionalities is a technical inventory, irrelevant to governance; the board needs assurance that controls are effective, not a catalog of products.

670
MCQmedium

During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?

A.Notify potentially affected customers
B.Perform a root cause analysis
C.Reset passwords for all user accounts
D.Review authentication logs for other anomalies
AnswerB

Root cause analysis identifies how the account was compromised and why exfiltration went undetected, so controls can be strengthened against recurrence. Simply disabling the account only contains this incident; the stem asks for prevention of similar incidents, which requires understanding the underlying weakness.

Why this answer

Performing a root cause analysis (RCA) is the next best action because it systematically identifies the underlying vulnerability or control weakness that allowed the account compromise. Without understanding how the attacker gained access—whether through phishing, credential stuffing, or a software vulnerability—simply disabling the account does not prevent recurrence. The RCA will inform targeted remediation, such as patching, policy changes, or implementing multi-factor authentication (MFA).

Exam trap

The trap here is that candidates confuse 'next best action' with 'immediate containment step'—they choose to reset all passwords or review logs again, when the correct post-containment priority is to analyze the root cause to prevent recurrence, as emphasized in the CISM Incident Management lifecycle.

How to eliminate wrong answers

Option A is wrong because notifying customers prematurely, before the root cause is understood and containment is fully verified, can cause unnecessary panic, violate legal hold requirements, and may not address the actual attack vector. Option C is wrong because resetting passwords for all user accounts is a broad, reactive measure that does not address the specific compromise method (e.g., a keylogger or token theft) and may disrupt operations without fixing the underlying vulnerability. Option D is wrong because reviewing authentication logs for other anomalies is a detection step that should have already occurred during the incident; the next logical step after containment is to analyze the root cause, not continue hunting for other signs without understanding how the first breach happened.

671
MCQmedium

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

A.Ease of implementation
B.Availability of new technology
C.Alignment with business strategy and risk appetite
D.Cost of the initiative
AnswerC

A multi-year roadmap consumes limited budget and resources, so initiatives must map to business strategy and the organisation's risk appetite. That alignment ensures security investment addresses the risks the business actually cares about, rather than technical preference alone.

Why this answer

The primary driver for prioritizing security initiatives in a multi-year roadmap should be alignment with business strategy and risk appetite. This ensures that security investments support business objectives and address the most significant risks to the organization. Other factors like ease of implementation or cost are secondary considerations that should be evaluated within the context of strategic alignment.

Exam trap

CISM often tests the distinction between business alignment and technical factors; candidates may choose cost or ease of implementation as primary drivers, forgetting that security must support business objectives.

How to eliminate wrong answers

Option A is wrong because ease of implementation may lead to prioritizing trivial tasks over critical risk reduction, which does not necessarily align with business needs. Option B is wrong because availability of new technology can be tempting but may not address the organization's specific risks or strategic goals; it can lead to technology-driven rather than risk-driven decisions. Option D is wrong because cost is a constraint, not a driver; while budget matters, prioritizing solely on cost can result in underinvesting in critical areas or missing strategic opportunities.

672
MCQmedium

An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerB

Risk acceptance is appropriate because the mitigation cost exceeds the potential loss, making transfer or avoidance economically unjustifiable. The manager formally acknowledges the residual risk, documents it, and retains it within the organisation's defined risk appetite, satisfying the cost-benefit constraint stated in the stem.

Why this answer

When the cost of mitigating a risk exceeds the potential loss, the most appropriate strategy is risk acceptance. This means the organization acknowledges the risk and decides to bear the potential loss, as the cost of mitigation is not justified. Risk acceptance is a valid treatment when the risk is within the organization's risk appetite.

Exam trap

CISM often tests the confusion between risk acceptance and risk mitigation, leading candidates to choose mitigation because the risk is high, without considering the cost-benefit analysis that makes acceptance the most appropriate strategy.

Why the other options are wrong

A

Mitigation cost exceeds potential loss, making it inefficient.

C

Transfer (e.g., insurance) may still be expensive; acceptance is more direct when cost of transfer also high.

D

Avoidance would mean discontinuing the activity, which may not be feasible or cost-effective.

673
MCQmedium

During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?

A.The impact of losing both primary and backup data is unacceptably high
B.The risk owner does not have authority to accept risks
C.Encryption is not required as the facility is secure
D.The cost of implementing encrypted offsite backups is minimal
AnswerA

Unencrypted onsite backups create correlated loss: a single physical event destroys primary and backup data together. That catastrophic availability and confidentiality impact outweighs the low likelihood the risk owner cites, so acceptance cannot be justified without encryption or offsite copies.

Why this answer

The core principle of risk acceptance requires that the residual risk be within the organization's risk appetite. In this scenario, the backup data is stored onsite without encryption, meaning a single physical breach (e.g., fire, theft, or natural disaster) could destroy both primary and backup data simultaneously. The impact of losing all data—potentially leading to business failure—is unacceptably high, outweighing the low likelihood of a physical breach.

The risk owner's acceptance is invalid because the risk exceeds the organization's risk tolerance, as per CISM's risk management framework.

Exam trap

A common misconception is that risk acceptance is always valid if the risk owner approves it. However, according to ISACA CISM principles, acceptance must align with the organization's risk appetite, and a high-impact risk cannot be accepted solely based on low likelihood.

How to eliminate wrong answers

Option B is wrong because the risk owner, typically a business process owner, generally has the authority to accept risks within their scope, unless explicitly restricted by policy; the question does not indicate such a restriction. Option C is wrong because it incorrectly assumes that a secure facility eliminates the need for encryption, but encryption is a critical control for data at rest to protect against unauthorized access even if physical security is breached (e.g., an insider threat or theft of storage media). Option D is wrong because the cost of implementing encrypted offsite backups is not the primary reason to challenge acceptance; risk acceptance decisions are based on risk appetite and impact, not solely on cost, and minimal cost does not automatically invalidate acceptance.

674
MCQmedium

A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?

A.Create an information security steering committee with business unit representation to prioritize and approve security initiatives.
B.Develop a security metrics dashboard that reports tool utilization and spending to the board of directors.
C.Conduct a gap assessment of all existing security tools against the NIST Cybersecurity Framework to identify redundancies.
D.Implement a centralized security budget and require all business units to submit purchase requests to the CISO for approval.
AnswerA

A steering committee with cross-functional representation establishes formal governance for prioritizing and approving security investments. It directly addresses the lack of central oversight by creating a decision-making body that aligns security spending with enterprise risk appetite. This is a foundational governance step before defining metrics or conducting assessments, as it provides the authority and structure needed for subsequent actions.

Why this answer

Establishing an information security steering committee is the foundational governance action because it creates a formal, cross-functional body responsible for aligning security investments with enterprise risk appetite. This committee provides the authority and structure to prioritize initiatives, resolve conflicts, and ensure ongoing oversight. Other actions, such as centralizing budgets or conducting assessments, are either tactical or lack the collaborative governance needed to sustain alignment.

Exam trap

The trap here is assuming that centralizing budget control or performing a gap assessment constitutes governance, when governance fundamentally requires a decision-making structure with business representation.

675
Multi-Selectmedium

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Select 3 answers
A.The management or governance failure that allowed the process failure.
B.The cost of the breach to the organization.
C.The specific employee who clicked the phishing email.
D.The technical vulnerability that allowed the breach.
E.The process failure that allowed the vulnerability to exist.
AnswersA, D, E

Root cause analysis must extend beyond the immediate technical trigger to the governance layer. Examining the management or governance failure that permitted the process failure to persist identifies systemic accountability gaps, enabling corrective controls that prevent similar PII breaches recurring.

Why this answer

According to CISM best practices, root cause analysis after a data breach should focus on systemic and organizational factors rather than individuals or financial impacts. Option A is correct because governance failures—such as inadequate security policies, missing oversight, or lack of executive accountability—are root causes that enable process and control breakdowns. Option D is correct because identifying the specific technical vulnerability (e.g., an unpatched CVE, misconfigured firewall rule, or weak authentication mechanism) explains how the breach was technically possible.

Option E is correct because the process failure (e.g., absent patch management, ineffective change control, or missing vulnerability scanning) is the underlying reason the vulnerability was allowed to persist. Option B is not a root cause factor; cost is a business impact metric used for post-incident evaluation, not causal analysis. Option C is incorrect because blaming a specific employee who clicked a phishing email addresses a symptom, not the systemic root cause, and CISM emphasizes examining control failures rather than individual blame.

Page 8

Page 9 of 13

Page 10