Courseiva

CISM · domain

Information Security Programme

Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the CISM exam.

162 questions35 easy83 medium44 hard

Focused practice

Practice Information Security Programme questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Security Programme

RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.

Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences

Matching RAM speed (MHz) to motherboard and CPU support

Calculating total memory capacity from module size and slots

Troubleshooting common RAM errors like beep codes and blue screens

Why learners struggle

Why Information Security Programme questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Information Security Programme exam traps

  • Confusing DDR3 and DDR4 notch positions and voltage requirements
  • Assuming dual-channel requires identical size modules only
  • Mixing ECC and non-ECC RAM in a single system
  • Forgetting that 32-bit OS limits usable RAM to 4 GB

Question index

All Information Security Programme questions (162)

Click any question to see the full explanation, or start a practice session above.

1

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Medium
2

Which of the following is a leading indicator of security program effectiveness?

Easy
3

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

Medium
4

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

Easy
5

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

Medium
6

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Medium
7

A security manager is designing a security awareness program. Which TWO metrics are leading indicators of program effectiveness?

Medium
8

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

Medium
9

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

Medium
10

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

Hard
11

Which TWO of the following are components of a typical vulnerability management program?

Easy
12

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Hard
13

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

Hard
14

Which of the following is a leading indicator of security program effectiveness?

Easy
15

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Easy
16

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

Medium
17

A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?

Hard
18

An organization's security budget is 12% of the IT budget. Which of the following best describes the maturity of this security program?

Hard
19

An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?

Hard
20

A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?

Medium
21

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

Medium
22

A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)

Hard
23

A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?

Medium
24

Which of the following is a key objective of implementing a security champions program?

Easy
25

An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?

Hard
26

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

Medium
27

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

Medium
28

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

Medium
29

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Medium
30

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

Hard
31

An organization is developing a vendor risk management program. Which TWO of the following should be included in the vendor onboarding risk assessment?

Medium
32

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

Hard
33

Which metric is considered a lagging indicator of security program performance?

Medium
34

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

Medium
35

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

Hard
36

Which of the following is a leading indicator for security performance?

Medium
37

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

Medium
38

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Medium
39

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Hard
40

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

Easy
41

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Easy
42

A security manager is developing metrics for the executive dashboard. Which combination of metrics provides a balanced view of security program performance?

Medium
43

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Medium
44

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

Easy
45

An organization uses ISO 27001 Annex A as its control framework. During a risk assessment, a control weakness is identified that could lead to a high-impact data breach. However, implementing the recommended control is cost-prohibitive. Which approach BEST addresses this situation?

Hard
46

During a third-party risk assessment, the security team discovers that a critical vendor has subcontracted data processing to another company without notification. This represents which type of risk?

Medium
47

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

Medium
48

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?

Medium
49

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

Medium
50

In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?

Easy
51

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Hard
52

Which TWO metrics are considered leading indicators for information security program performance?

Medium
53

Which TWO budget components are considered 'services' in a typical security budget?

Medium
54

A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?

Easy
55

In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?

Easy
56

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

Medium
57

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

Hard
58

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

Medium
59

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

Medium
60

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Hard
61

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

Medium
62

An organization is implementing a security controls framework based on NIST SP 800-53. The CISO wants to prioritize controls that will provide the greatest risk reduction for critical assets. Which approach should be used to select the initial set of controls?

Medium
63

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

Hard
64

Which THREE of the following are components of a security operations center (SOC)?

Easy
65

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

Hard
66

What is the PRIMARY purpose of a security champions program?

Easy
67

A security manager is designing a metrics dashboard for the CISO. Which TWO metrics are leading indicators of security performance? (Select TWO)

Medium
68

A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?

Medium
69

Which role is primarily responsible for designing and reviewing an organization's security architecture?

Easy
70

A CISO is developing key risk indicators (KRIs) for the security programme. Which TWO of the following are lagging indicators? (Select TWO.)

Medium
71

Which of the following BEST describes the role of a security architect in a security program?

Medium
72

In a security awareness program, which training approach is most appropriate for software developers?

Medium
73

Which of the following is a leading indicator of security program effectiveness?

Easy
74

A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?

Medium
75

A CISO is evaluating metrics for an executive security report. Which TWO of the following are lagging indicators?

Medium
76

What is the primary function of a Security Operations Center (SOC)?

Easy
77

A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)

Medium
78

Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?

Easy
79

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

Hard
80

Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?

Medium
81

In a security operations center (SOC), which function is PRIMARILY responsible for analyzing alerts and determining whether they represent actual security incidents?

Medium
82

In a third-party risk management programme, what is the primary purpose of vendor tiering?

Medium
83

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Hard
84

Which of the following is the PRIMARY purpose of a security awareness program?

Easy
85

A security architect is designing a defense-in-depth strategy. Which combination of controls best exemplifies this approach?

Medium
86

An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)

Medium
87

A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?

Hard
88

An organization is redesigning its information security program to better align with business objectives. The CISO reports to the CIO, but business leaders feel security decisions are too IT-centric. Which reporting structure would best address this concern?

Medium
89

An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?

Hard
90

Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?

Medium
91

A CISO is evaluating security metrics for reporting to the board. Which TWO of the following are leading indicators?

Medium
92

A CISO wants to present a high-level security status to the board using a one-page dashboard. Which of the following metrics is MOST appropriate for this audience?

Medium
93

Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?

Easy
94

Which security team role is primarily responsible for defining and maintaining security architecture standards?

Easy
95

Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?

Easy
96

A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?

Medium
97

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

Easy
98

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Medium
99

Which role is primarily responsible for developing and maintaining the organization's security architecture?

Easy
100

A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?

Hard
101

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

Medium
102

A CISO is preparing the security budget for the next fiscal year. The current IT budget is $10 million. For a mature security program, what is the recommended security budget range?

Hard
103

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

Medium
104

What is the primary purpose of a vulnerability management program?

Easy
105

A security manager is developing metrics for the C-suite dashboard. Which combination of metrics would provide the best view of security program effectiveness, including both leading and lagging indicators?

Hard
106

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

Medium
107

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

Hard
108

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Hard
109

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

Medium
110

A security manager needs to justify an increase in the security budget to the board. The current budget is 0.15% of revenue. Which approach would most effectively demonstrate the need for additional funding?

Hard
111

Which of the following is a LEADING indicator of security performance?

Easy
112

An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?

Medium
113

A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?

Medium
114

Which of the following is the PRIMARY benefit of a security champions program?

Easy
115

A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?

Medium
116

A security awareness manager is designing role-based training. Which training is most appropriate for software developers?

Medium
117

Which of the following is the primary objective of a security champions programme?

Easy
118

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Medium
119

An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?

Medium
120

Which of the following is the PRIMARY purpose of a security champions program?

Easy
121

Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?

Easy
122

An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?

Medium
123

A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?

Medium
124

A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)

Hard
125

An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?

Hard
126

Which of the following is a key objective of a Security Operations Center (SOC)?

Easy
127

In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?

Medium
128

When designing phishing simulations, which approach best balances user learning and operational disruption?

Hard
129

A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?

Hard
130

When selecting security controls, a company must prioritize which controls first?

Medium
131

During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?

Hard
132

A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?

Hard
133

A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?

Easy
134

An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?

Medium
135

An organization is implementing a security champions program. What is the primary purpose of this initiative?

Medium
136

An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?

Medium
137

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Easy
138

A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)

Hard
139

Which TWO are key elements of a security awareness program designed to change employee behavior?

Hard
140

A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?

Medium
141

An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?

Medium
142

An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)

Hard
143

An organization is implementing a defense-in-depth strategy. Which of the following is the BEST example of a compensating control?

Medium
144

An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?

Medium
145

An organization is designing a security awareness program. Which TWO of the following should be included for developers?

Medium
146

Which TWO of the following are typical components of a security awareness program?

Easy
147

Which of the following is a LEADING indicator of security performance?

Easy
148

Which of the following best describes the role of a security architect in a security program?

Medium
149

A security awareness program includes phishing simulations. After six months, the click rate has decreased from 15% to 8%, but the number of reported phishing emails has also dropped. The CISO wants to measure the effectiveness of the program. Which metric would best indicate sustained improvement in security behavior?

Medium
150

A CISO is planning the security programme budget and wants to justify the investment to the CFO. The organization has a moderate risk appetite and an IT budget of $10 million. What is the most appropriate budget range for the security programme based on industry benchmarks?

Hard
151

A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?

Hard
152

An information security manager is developing a security scorecard for the board. Which combination of metrics BEST provides a balanced view of security program effectiveness?

Hard
153

A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?

Hard
154

An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?

Medium
155

An organization wants to implement a defense-in-depth strategy for its web application. Which set of controls best exemplifies this approach?

Medium
156

When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?

Medium
157

Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?

Medium
158

A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?

Hard
159

Which of the following metrics would be MOST useful for measuring the effectiveness of a phishing simulation program?

Medium
160

An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?

Hard
161

An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?

Medium
162

An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?

Hard

Frequently asked questions

What does the Information Security Programme domain cover on the CISM exam?
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
How many questions are in this domain?
This page lists all 162 Information Security Programme questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Security Programme questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism security programme Practice Questions