Courseiva
easyMultiple ChoiceObjective-mapped

CISM Practice Question: Has recently experienced a data breach due to an…

An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?

⚠ Common exam trap

It's easy for candidates to confuse tactical security controls (like MFA or EDR) with governance improvements, failing to recognize that the board's request specifically targets the need for a structured program with defined accountability, not just additional technology layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Developing a formalized insider threat program with clear roles and responsibilities.

A formalized insider threat program with clear roles and responsibilities is the first governance improvement because it establishes a structured framework for detecting, preventing, and responding to insider threats. Unlike tactical controls, this program defines ownership, escalation paths, and policy integration, directly addressing the board's request for governance improvements rather than just technical fixes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Developing a formalized insider threat program with clear roles and responsibilities.

    Why this is correct

    This establishes governance over insider risk, including monitoring and response.

  • Conducting annual security awareness training for all employees.

    Why it's wrong here

    Training supports the program but is not the primary governance improvement.

  • Implementing two-factor authentication for all critical systems.

    Why it's wrong here

    Like option A, this is a technical control, not a governance recommendation.

  • Deploying endpoint detection and response (EDR) software on all systems.

    Why it's wrong here

    Technical controls are necessary but governance requires policies and oversight first.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.