Sample questions
Certified Information Security Manager CISM practice questions
An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)
When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?
Which of the following best describes the primary purpose of an information security program?
Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to under…
After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?
Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?
Which THREE of the following are typical roles in an incident response team?
Which TWO of the following are incident categories in an incident management programme?
An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which prior…
During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?
A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control…
Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?
A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Whi…
The security team is designing a security awareness program. Which topic should be prioritized FIRST?
An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the…
Which of the following is the primary purpose of an information security program?
An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?
A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?
Which of the following best describes residual risk?
A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?
An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next criti…
During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals.…