Courseiva

CCNA Information Security Programme Questions

75 of 176 questions · Page 1/3 · Information Security Programme · Answers revealed

1
Multi-Selectmedium

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Select 3 answers
A.Employee's years of service
B.Employee role and job function
C.Past phishing click rate trends
D.Number of security incidents in the past year
E.Current threat landscape and prevalent attack types
AnswersB, C, E

Role and job function determine exposure to targeted attacks, such as finance staff facing invoice fraud or executives facing spear phishing. Tailoring simulation difficulty by function ensures relevance and avoids over-testing low-risk roles, satisfying the stem's design factor requirement.

Why this answer

Option B (Employee role and job function) is correct because employees in finance, HR, or executive roles face different phishing lures and risk levels, so simulations should be tailored to the specific threats and responsibilities of each role. Option C (Past phishing click rate trends) is correct because historical click-rate data reveals which users or departments are most susceptible, allowing frequency and difficulty to be adjusted upward or downward based on demonstrated performance. Option E (Current threat landscape and prevalent attack types) is correct because simulations must reflect real-world tactics such as credential harvesting, QR-code phishing, or business email compromise that are actively trending, ensuring training stays relevant.

Option A (Employee's years of service) is not a reliable indicator of phishing susceptibility, since tenure does not correlate consistently with security awareness or behavior. Option D (Number of security incidents in the past year) is too broad and lagging an indicator; it does not directly inform the design of phishing simulation frequency or difficulty the way role, click trends, and threat landscape do.

2
MCQhard

An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?

A.A KRI is always a lagging indicator of past incidents.
B.A KRI is reported only to the board, while a KPI is reported to management.
C.A KRI measures how well security processes are performing against targets.
D.A KRI provides early warning of increasing risk exposure.
AnswerD

A key risk indicator is a forward-looking metric that signals rising risk before it materializes into incidents. It helps the organization anticipate and mitigate threats. Unlike a KPI, which measures performance against objectives, a KRI tracks conditions that could lead to loss, such as increasing vulnerability counts or growing third-party exposure.

Why this answer

A key risk indicator is forward-looking, providing early warning of increasing risk exposure so leadership can act before incidents occur. A key performance indicator measures how well processes meet targets. The CISO should use KRIs to anticipate risk and KPIs to assess operational effectiveness, ensuring the metrics program supports proactive risk management.

Exam trap

The trap here is equating KRIs with performance measurement, when their defining purpose is predictive risk warning rather than process efficiency.

3
Multi-Selectmedium

A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)

Select 2 answers
A.Defined roles, responsibilities, and accountability for information security across business and technology functions.
B.A complete inventory of every software licence held by the engineering department.
C.A consolidated list of the personal mobile devices used by the sales team.
D.A marketing plan describing how security certifications will be promoted to prospective customers.
E.A risk management process that identifies, evaluates, and treats information security risk in line with the organization's risk appetite.
AnswersA, E

Clear ownership and accountability are essential because security obligations span business units, engineering, legal, and operations. Assigning responsibility ensures controls are implemented and maintained rather than assumed, enables escalation, and supports the segregation of duties that auditors and regulators expect from a growing fintech.

Why this answer

Programme scope must cover both governance and risk disciplines. A risk management process translates business context into prioritized protection decisions, while defined roles and accountability ensure those decisions are executed and sustained across functions. Licence lists, marketing plans, and device inventories are useful operational details but are not defining components of programme scope.

Exam trap

The trap here is selecting tangible operational inventories as programme components instead of the governance and risk elements that actually define programme scope.

4
Multi-Selecthard

A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)

Select 2 answers
A.They remain static over time.
B.They are aligned with business objectives.
C.They are actionable and lead to decisions.
D.They are based on data that is easy to collect.
E.They are expressed in technical jargon.
AnswersB, C

Metrics aligned with business objectives ensure that security efforts support organizational goals and are relevant to executive management. They provide meaningful insights into how security contributes to business success, enabling informed decision-making. This alignment is a key characteristic of effective metrics.

Why this answer

Effective security metrics are aligned with business objectives and are actionable, leading to decisions. These characteristics ensure that metrics are relevant to executive management and support strategic oversight. Other traits, such as ease of collection or technical jargon, do not guarantee effectiveness.

Exam trap

The trap here is equating ease of data collection or technical detail with metric effectiveness, but alignment and actionability are what make metrics valuable.

5
MCQmedium

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

A.Vendor's annual revenue
B.Length of business relationship
C.Contract value
D.Type of data accessed and service criticality
AnswerD

Tiering by data type and service criticality reflects actual risk exposure: sensitive data or business-critical services warrant deeper due diligence, contractual controls and monitoring. This risk-based axis directs limited TPRM effort proportionately, rather than treating all vendors identically.

Why this answer

The tier of a vendor in a TPRM program should be primarily determined by the type of data the vendor accesses and the criticality of the service they provide. These factors directly impact the organization's risk exposure and regulatory compliance obligations. Revenue, relationship length, and contract value do not necessarily correlate with risk.

Exam trap

CISM often tests the misconception that financial metrics (revenue, contract value) determine vendor risk; candidates must focus on data sensitivity and service criticality as the primary drivers.

How to eliminate wrong answers

Option A is wrong because a vendor's annual revenue does not indicate the risk they pose to the organization; a small vendor with access to sensitive data can be high risk. Option B is wrong because a long relationship does not reduce risk; it may even increase complacency. Option C is wrong because contract value is a financial metric, not a risk indicator; a low-value contract for a critical service can still be high risk.

6
MCQeasy

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

A.CISO reports to the CFO
B.CISO reports to the CEO or board of directors
C.CISO reports to the CIO
D.CISO reports to the head of internal audit
AnswerB

Reporting directly to the CEO or board removes intermediate IT management from the chain, preventing conflicts where the security function audits the same operations it reports through. This satisfies the independence and authority constraint, giving the CISO unfiltered escalation and budget influence.

Why this answer

Reporting to the board or a senior executive not directly responsible for IT operations ensures independence and reduces conflicts of interest.

7
MCQmedium

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

A.Providing 24/7 security monitoring
B.Eliminating the need for security awareness training
C.Reducing the need for a dedicated security team
D.Embedding security expertise within development teams
AnswerD

Security champions are developers who receive security training and act as the first point of contact within their own teams, embedding expertise where code is written. This satisfies the stem's primary benefit by scaling security knowledge without adding dedicated security headcount to every team.

Why this answer

A security champions program embeds security expertise within development teams by designating individuals who act as liaisons between the security team and developers. This fosters a security culture, enables early identification of security issues, and reduces the bottleneck of a centralized security team. The primary benefit is scaling security knowledge across the organization.

Exam trap

CISM often tests the misconception that security champions can replace security teams or awareness training; the correct answer emphasizes embedding expertise, not reducing headcount.

How to eliminate wrong answers

Option A is wrong because security champions do not provide 24/7 monitoring; that is the role of a SOC. Option B is wrong because the program complements, not eliminates, security awareness training. Option C is wrong because while it may reduce the burden on the security team, it does not eliminate the need for a dedicated security team; it enhances collaboration.

8
Multi-Selectmedium

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Select 2 answers
A.Vulnerability scanning
B.Identity and access management
C.Incident response
D.Security monitoring and detection
E.Application security testing
AnswersC, D

Incident response supplies the SOC's reactive capability: triage, containment, eradication and recovery once detection confirms an event. Without it, monitoring generates alerts with no structured path to resolution, so it is a core operational component alongside detection.

Why this answer

Incident response (C) is a core SOC component because the SOC's mission includes detecting, containing, eradicating, and recovering from security incidents, typically following a defined IR lifecycle and using tools like SIEM alerts, ticketing, and forensic analysis. Security monitoring and detection (D) is also fundamental, as the SOC continuously collects and correlates telemetry (for example, logs and network flows via a SIEM) to identify suspicious activity and generate alerts that drive response. Vulnerability scanning (A) is a vulnerability management activity often performed by a separate team, even if its output may inform SOC prioritization.

Identity and access management (B) is an access-control discipline typically owned by IAM/identity teams, not a defining SOC component. Application security testing (E) belongs to secure development/AppSec functions such as SAST, DAST, and SCA, rather than the SOC's monitoring-and-response core.

Exam trap

CISM often tests the distinction between preventive controls (vulnerability scanning, IAM) and detective/response controls (monitoring, incident response); candidates may incorrectly include preventive functions as core SOC components.

9
MCQhard

A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?

A.Conduct a penetration test of the disaster recovery site to validate its security posture.
B.Update the disaster recovery plan to reflect the recovery time objectives (RTOs) and recovery point objectives (RPOs) identified in the BIA.
C.Launch a security awareness programme focused on business continuity responsibilities.
D.Increase the cybersecurity insurance coverage to transfer residual risk identified in the BIA.
AnswerB

The BIA establishes critical business processes and their maximum tolerable downtime and data loss, expressed as RTOs and RPOs. The next logical step is to ensure the disaster recovery plan for information systems is updated to meet these targets. This directly links security and resilience priorities to business impact, ensuring recovery capabilities are aligned with what the business actually needs.

Why this answer

The BIA defines critical processes and their RTOs and RPOs. To make the security programme consistent with these findings, the CISO must ensure disaster recovery and related plans are updated so that systems and data can be restored within the required timeframes. This is a direct, necessary step before validating or transferring risk.

Exam trap

The trap here is treating the BIA as a document to be filed rather than a driver for updating recovery plans; testing or insurance does not substitute for aligning RTOs and RPOs with business needs.

10
MCQeasy

An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.

A.Perform daily monitoring of security alerts and coordinate the response to detected incidents.
B.Conduct technical vulnerability assessments of critical systems and track remediation activities.
C.Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.
D.Independently audit the security programme's controls and report findings directly to external regulators.
AnswerC

A security steering committee with cross-functional representation exists to provide governance: setting strategic direction, aligning security investment with business priorities, and resolving conflicts between security and operational needs. This matches its composition, since business, legal, and risk perspectives are needed for strategic trade-off decisions. Operational tasks such as patching or incident response belong to the security team, not this governance body.

Why this answer

A security steering committee is a governance body whose purpose is to align the security programme with business strategy, approve direction, and prioritize initiatives using cross-functional input. Its membership of business, IT, legal, and risk leaders fits strategic decision-making. Operational execution and independent audit are deliberately separated from this body to preserve both efficiency and objectivity.

Exam trap

The trap here is confusing governance oversight with operational execution, assuming a cross-functional committee should perform hands-on security work.

11
MCQmedium

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

A.COBIT 2019
B.NIST SP 800-53
C.ISO 27001 Annex A
D.CIS Controls v8
AnswerD

CIS Controls v8 maps its prioritised safeguards into Implementation Groups IG1, IG2 and IG3, letting organisations sequence controls by maturity and risk. It also targets the most common cyber threats, satisfying both the IG-based and common-threat requirements named in the stem.

Why this answer

CIS Controls v8 provides a prioritized set of actions that collectively form a defense-in-depth set of best practices to mitigate the most common cyber attacks. It is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk and resources, making it the framework that best meets the requirement for prioritized, implementation group-based controls addressing common threats.

Exam trap

The trap is selecting a well-known framework like NIST or ISO without noting the specific requirement for 'implementation group-based' prioritization, which is unique to CIS Controls v8.

How to eliminate wrong answers

Option A is wrong because COBIT 2019 is an IT governance and management framework focused on aligning IT with business objectives, not a prioritized control set for cyber threats. Option B is wrong because NIST SP 800-53 is a comprehensive catalog of security and privacy controls for federal information systems, not organized by implementation groups for prioritization. Option C is wrong because ISO 27001 Annex A provides a list of controls but does not prioritize them into implementation groups based on organizational size or risk.

12
MCQmedium

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

A.IG2
B.IG1
C.IG3
D.IG0
AnswerB

IG1 defines essential cyber hygiene safeguards implementable with limited expertise and budget, making it the foundational implementation group. Addressing it first satisfies the small business's resource constraint, as IG2 and IG3 demand greater maturity and staffing.

Why this answer

CIS Controls v8 defines Implementation Group 1 (IG1) as the foundational set of safeguards for small businesses with limited resources and low-risk data. IG1 represents basic cyber hygiene and should be implemented first to establish a minimum level of security. Therefore, a small business with limited resources should address IG1 first.

Exam trap

The trap is assuming a higher implementation group is better or that IG0 exists; candidates must know that IG1 is the starting point for resource-constrained organizations.

How to eliminate wrong answers

Option A is wrong because IG2 is for organizations with moderate resources and risk, and builds upon IG1; it is not the first group to address. Option C is wrong because IG3 is for large enterprises with sensitive data and high risk, requiring significant resources. Option D is wrong because IG0 does not exist in CIS Controls v8; implementation groups start at IG1.

13
MCQhard

A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?

A.Mandate that all regions immediately adopt the headquarters policy set unchanged
B.Perform a gap assessment of current regional practices against the chosen framework
C.Procure an integrated GRC platform to consolidate all regional risk registers
D.Commission an external audit of every regional security control simultaneously
AnswerB

Before harmonizing anything, the CISO must know where each region stands relative to the target framework. A structured gap assessment produces the factual baseline that prioritization, sequencing, and board reporting all depend on. Jumping to remediation without that baseline risks funding the wrong regions and leaves no defensible measure of progress for the board's comparison objective.

Why this answer

Comparability across regions requires a common reference framework plus a factual baseline of where each region stands against it. A gap assessment delivers both, giving the CISO evidence to prioritize remediation, allocate budget, and report progress to the board. Mandating uniform policy, buying tooling, or auditing everything at once all presume knowledge the CISO does not yet have and skip the diagnostic step that makes the board's comparison meaningful.

Exam trap

The trap here is choosing a decisive-sounding action such as a global policy mandate or tool purchase when the programme first needs an evidence-based baseline against the chosen framework.

14
MCQhard

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

A.Ignore the fourth party as it is outside the organization's scope
B.Conduct a direct assessment of the fourth party
C.Terminate the contract with the vendor
D.Request the vendor to assess and pass through security requirements to its suppliers
AnswerD

Fourth-party risk cannot be assessed directly by the organisation, so contractual flow-down is the practical control. Requiring the vendor to assess its own suppliers and pass through equivalent security requirements extends governance across the supply chain, satisfying the nth-party visibility constraint the stem describes.

Why this answer

The correct answer is D because the organization cannot directly assess every fourth party in its vendor's supply chain, but it can contractually require the vendor to flow down security requirements and assess its own suppliers. This is the standard nth-party risk management approach recommended by frameworks like NIST SP 800-161 and ISO 28000. It maintains accountability through the vendor while extending controls to the fourth party.

Exam trap

CISM often tests the misconception that an organization must directly assess all parties in its supply chain, when in fact the best practice is to require the vendor to manage and assess its own suppliers through contractual flow-down.

How to eliminate wrong answers

Option A is wrong because ignoring the fourth party leaves a critical blind spot in the risk assessment, especially since the fourth party has access to sensitive customer data. Option B is wrong because conducting a direct assessment of the fourth party is often impractical and may not be permitted by the vendor's contract; the organization typically has no direct relationship with the fourth party. Option C is wrong because terminating the contract is a drastic overreaction that may not be necessary if the risk can be mitigated through contractual flow-down requirements.

15
MCQeasy

A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?

A.Commission a penetration test of the electronic health record system.
B.Purchase cyber insurance to transfer residual risk to a third party.
C.Deploy an endpoint detection and response tool across all clinical workstations.
D.Define the security strategy and obtain executive approval for the governance framework and charter.
AnswerD

Governance begins with an approved strategy, charter, and clear accountability, which give the security programme authority and direction. Establishing these first ensures subsequent risk assessments, policies, and control investments are sanctioned by leadership and aligned with the provider's obligations, rather than emerging piecemeal from technical teams.

Why this answer

Governance is about direction, accountability, and decision rights. A newly appointed security leader must first secure executive approval of a strategy and governance charter so the programme has authority and alignment. Technical assessments, tools, and insurance are treatments applied once governance establishes priorities, risk appetite, and responsibilities, and performing them first inverts the correct sequence.

Exam trap

The trap here is equating governance with buying security technology or insurance instead of establishing strategy, charter, and accountability first.

16
MCQeasy

A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?

A.Implementing security controls to mitigate identified risks.
B.Purchasing cyber insurance to transfer risk.
C.Conducting a risk assessment to identify and prioritize risks.
D.Developing a disaster recovery plan for the e-commerce platform.
AnswerC

The first step in risk management is to identify and assess risks. This involves understanding the assets, threats, vulnerabilities, and potential impacts. For an e-commerce platform, this includes risks to customer data, payment processing, and availability. A risk assessment provides the foundation for all subsequent risk management activities, ensuring that controls are applied where they are most needed and that resources are allocated effectively.

Why this answer

The correct answer is conducting a risk assessment to identify and prioritize risks. Risk management begins with understanding the risks to the organization's assets and objectives. This assessment informs all subsequent decisions, including which controls to implement, what risks to transfer, and how to plan for recovery.

It ensures that efforts are targeted and effective.

Exam trap

The trap here is jumping to risk treatment options like controls, insurance, or disaster recovery without first conducting a risk assessment to understand what needs to be treated.

17
Multi-Selecteasy

Which TWO of the following are components of a typical vulnerability management program?

Select 2 answers
A.Conducting security awareness training
B.Remediating identified vulnerabilities through patching
C.Monitoring network traffic for anomalies
D.Performing penetration tests
E.Conducting regular vulnerability scans
AnswersB, E

Patching directly satisfies the remediation phase of the vulnerability management lifecycle, converting identified weaknesses into resolved risk. A typical programme requires this corrective action alongside discovery and assessment; without remediation, scanning yields no risk reduction. It therefore constitutes a core component, matching the stem's requirement for programme elements.

Why this answer

A vulnerability management program is built around a continuous cycle of discovering, prioritizing, and fixing weaknesses, so option E (conducting regular vulnerability scans) is correct because recurring authenticated and unauthenticated scans are the primary discovery mechanism that populates the vulnerability inventory. Option B (remediating identified vulnerabilities through patching) is correct because remediation—applying vendor patches, configuration changes, or compensating controls—closes the loop and is the ultimate goal of the program; scanning without remediation provides no risk reduction. Option A (security awareness training) belongs to a security education/awareness program, not vulnerability management, since it targets human behavior rather than technical weaknesses.

Option C (monitoring network traffic for anomalies) is a detection/incident-monitoring activity typically handled by IDS/IPS, SIEM, or SOC operations, not vulnerability management. Option D (performing penetration tests) is an offensive security assessment that can validate and supplement a vulnerability management program, but it is a point-in-time testing exercise rather than a core component of the ongoing scan-and-remediate process.

Exam trap

CISM often tests the distinction between vulnerability management (proactive identification and remediation of weaknesses) and other security functions like awareness training, monitoring, or penetration testing, causing candidates to select adjacent activities that are not core components.

18
Multi-Selecthard

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Select 2 answers
A.Vendor's marketing budget
B.Criticality of the service provided by the vendor
C.Vendor's stock price
D.Type of data accessed by the vendor
E.Vendor's annual revenue
AnswersB, D

Tiering hinges on how critical the vendor's service is to business operations, since an outage or compromise of a core function causes disproportionate impact. This satisfies the stem by ranking vendors according to operational dependency, driving proportionate due diligence depth.

Why this answer

Option B is correct because the criticality of the service provided by the vendor directly determines how much operational impact a failure or disruption would have on the organization, which is a primary driver of vendor tiering in third-party risk management. Option D is correct because the type of data accessed by the vendor (for example, PII, PHI, PCI, or intellectual property) determines the regulatory, privacy, and security risk exposure, and vendors handling sensitive or regulated data warrant a higher tier. Options A, C, and E are not appropriate tiering factors: marketing budget, stock price, and annual revenue reflect the vendor's financial or promotional posture rather than the risk the vendor poses to the organization's operations, data, or compliance obligations.

Exam trap

The trap is selecting financial or size metrics (revenue, stock price) as tiering factors; candidates must focus on risk-based factors like data sensitivity and business criticality.

19
MCQmedium

A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?

A.Purchase a security information and event management (SIEM) platform to centralize monitoring.
B.Define a security governance framework that links security objectives to business goals and assigns accountability.
C.Deploy a next-generation firewall across all retail locations to protect point-of-sale systems.
D.Conduct a penetration test of the e-commerce platform to identify vulnerabilities.
AnswerB

A governance framework is the foundation that connects security activities to business strategy, defines roles, and establishes accountability. Establishing this first ensures subsequent decisions on risk appetite, controls, and metrics flow from business objectives rather than being retrofitted. The other actions, while valuable, are tactical or dependent on governance being in place, so they cannot reliably deliver sustained alignment on their own.

Why this answer

Governance is the mechanism that ties information security to business strategy by defining objectives, roles, accountability, and decision rights. Without it, security investments and activities lack a consistent rationale and may not support expansion into new markets. The other choices are technical or assessment activities that should be prioritized and scoped by the governance framework, not used to create alignment in the first place.

Exam trap

The trap here is assuming that implementing a technical control or assessment demonstrates strategic alignment, when alignment must first be established through governance and business-linked objectives.

20
MCQhard

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

A.Benchmarking against industry peers showing that the proposed budget is below average.
B.Breach avoidance value, estimating the cost of incidents that were prevented.
C.Operational efficiency gains from automation of security processes.
D.Compliance with all regulatory requirements to avoid fines.
AnswerB

Breach avoidance value quantifies incidents prevented, directly translating security spend into avoided financial loss. This satisfies the board's demand for justification by expressing the increase in monetary terms the board already uses for investment decisions, rather than technical or compliance language.

Why this answer

Breach avoidance value quantifies the cost of incidents that were prevented, directly linking security spending to avoided financial loss and risk reduction. This is the strongest justification because it speaks the board's language — return on security investment — and demonstrates measurable value rather than relative positioning or compliance minimums.

Exam trap

The trap is that candidates choose compliance or benchmarking because they sound authoritative, but CISM favors business-aligned, value-based justifications like breach avoidance over comparative or minimum-requirement arguments.

How to eliminate wrong answers

Option A is wrong because benchmarking against peers is a comparative argument, not a value-based one, and being below average does not prove the increase is justified. Option C is wrong because operational efficiency gains are secondary and do not address risk reduction, which is the core purpose of security spending. Option D is wrong because compliance is a baseline requirement, not a strategic justification — avoiding fines is a cost of doing business, not a demonstration of value.

21
Multi-Selecteasy

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Select 2 answers
A.Vulnerability management
B.Security monitoring and detection
C.Security awareness training
D.Security architecture design
E.Incident response
AnswersB, E

Security monitoring and detection is a core SOC function because it continuously collects and analyses telemetry to identify threats against organisational assets. This satisfies the stem's requirement for core responsibilities, distinguishing day-to-day detection operations from governance, architecture or compliance activities owned elsewhere in the security organisation.

Why this answer

Option B, security monitoring and detection, is a core SOC responsibility because the SOC's primary mission is continuous 24x7 visibility over logs, network traffic, and endpoint telemetry using SIEM, IDS/IPS, and EDR to identify malicious activity. Option E, incident response, is also core because once detection occurs, the SOC triages, contains, eradicates, and recovers from incidents, coordinating escalation and forensic evidence handling. Together, monitoring/detection and incident response form the detect-and-respond loop that defines SOC operations.

Vulnerability management (A) is typically owned by a vulnerability management or risk team, though the SOC may consume its output. Security awareness training (C) belongs to the security awareness/HR function, and security architecture design (D) is an engineering/architecture responsibility rather than a SOC operational function.

22
MCQmedium

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

A.CIS Controls v8
B.ISO 27001 Annex A
C.NIST SP 800-53
D.COBIT 2019
AnswerC

NIST SP 800-53 provides granular control families and is mandated for US federal agencies, satisfying the stem's federal and granularity constraints. Its catalogue spans 20 control families with detailed enhancements, exceeding ISO 27002's breadth and CIS Controls' prioritised subset.

Why this answer

NIST SP 800-53 is the correct answer because it provides the most granular control families (20 families, over 1,000 controls) and is mandated for US federal agencies under FISMA. Its control catalog is organized into detailed families such as AC (Access Control), AU (Audit and Accountability), and CM (Configuration Management), each with specific control enhancements. This level of granularity and its federal adoption make it the best fit for the scenario.

Exam trap

CISM often tests the distinction between frameworks based on granularity and intended audience; candidates may incorrectly choose ISO 27001 because it is widely known, but the key differentiator is that NIST SP 800-53 is specifically required for US federal agencies and offers more detailed control families.

How to eliminate wrong answers

Option A is wrong because CIS Controls v8, while highly prescriptive and prioritized, consists of 18 top-level controls with sub-controls (totaling 153 safeguards) and is not specifically designed for US federal agencies; it is more commonly used by private sector organizations for cyber hygiene. Option B is wrong because ISO 27001 Annex A provides a list of 93 controls (in the 2022 version) grouped into four themes, but it is less granular than NIST SP 800-53 and is an international standard, not a US federal requirement. Option D is wrong because COBIT 2019 is a governance framework for enterprise IT, focusing on processes and maturity models, not a granular control catalog for security controls, and it is not used as the primary control framework for US federal agencies.

23
MCQhard

A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?

A.Phishing click rate
B.Average cost per incident
C.Number of data breaches in the past year
D.Number of security tools deployed
AnswerA

Phishing click rate is a leading indicator: it measures employee susceptibility before an actual breach occurs, giving the executive team actionable insight into human-risk trends. Unlike lagging metrics such as incident counts, it satisfies the dashboard constraint of predicting future risk on a single page.

Why this answer

A phishing click rate is a leading indicator because it measures a current user behavior that predicts future compromise risk, allowing the executive team to act before incidents occur. It is actionable, quantifiable, and directly tied to the effectiveness of security awareness controls. The other options are lagging indicators that report outcomes after the fact.

Exam trap

CISM often tests the distinction between leading and lagging indicators, and candidates frequently pick breach counts or incident costs because they sound like important security metrics, missing that they are historical outcomes rather than predictive measures.

How to eliminate wrong answers

Option B is wrong because average cost per incident is a lagging financial metric that only reflects incidents that already occurred and does not predict future security performance. Option C is wrong because the number of data breaches in the past year is a historical, lagging indicator that cannot be influenced going forward. Option D is wrong because the number of security tools deployed is a vanity metric that measures activity, not effectiveness or risk reduction.

24
Multi-Selecthard

A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)

Select 2 answers
A.A documented information security strategy and supporting policies.
B.An annual penetration test conducted by an external vendor.
C.A disaster recovery plan that is tested annually.
D.A real-time security operations center (SOC) with 24/7 monitoring.
E.A security steering committee that includes business unit leaders.
AnswersA, E

A documented information security strategy and policies are foundational governance components. They provide direction, establish expectations, and define roles and responsibilities. Policies are the basis for enforcing security requirements and demonstrating compliance to regulators. Without them, the program lacks formal authority and consistency. They also enable measurement and accountability, which are critical for governance.

Why this answer

The correct answers are a security steering committee with business unit leaders and a documented information security strategy and supporting policies. These elements provide direction, oversight, and alignment with business goals, which are core to governance. They ensure that security is managed strategically and that accountability is established.

Operational capabilities like a SOC or pen testing are important but do not constitute governance.

Exam trap

The trap here is confusing operational security capabilities, such as a SOC or penetration testing, with governance components, which are about direction, oversight, and policy.

25
MCQhard

An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?

A.Accept the risk without any control
B.Remove the asset from scope
C.Document the risk and obtain management approval for the compensating control
D.Implement the compensating control immediately
AnswerC

Documenting the risk and securing management approval satisfies ISO 27001's requirement that compensating controls be formally accepted, since residual risk must be owned at an appropriate level. Without this authorisation, the alternative control lacks legitimacy and the risk remains unaccounted for in the ISMS, breaching Clause 6.1.3 risk treatment obligations.

Why this answer

Compensating controls require formal acceptance of the residual risk and approval by management to ensure accountability.

26
Multi-Selectmedium

A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?

Select 2 answers
A.Continuous monitoring of security events and alerts.
B.Conducting penetration tests of critical applications.
C.Performing vulnerability scans and patch management.
D.Incident detection and response.
E.Developing secure coding standards for developers.
AnswersA, D

Continuous monitoring of security events and alerts is a primary SOC function because it provides the real-time visibility needed to detect threats as they emerge. This satisfies the stem's requirement for core SOC responsibilities, distinguishing ongoing detection activity from reactive or governance tasks performed elsewhere.

Why this answer

A SOC's core mission is around-the-clock visibility and reaction, so option A (continuous monitoring of security events and alerts) is correct because SOC analysts use SIEM platforms and correlated log/alert feeds to watch for anomalous activity across the environment in real time. Option D (incident detection and response) is also correct because once monitoring surfaces a potential threat, the SOC triages, investigates, contains, eradicates, and recovers from incidents, often following frameworks like NIST SP 800-61. The other options are not primary SOC functions: penetration testing (B) is typically performed by a dedicated offensive security or red team, vulnerability scanning and patch management (C) usually belong to vulnerability management and IT operations, and secure coding standards (E) are the responsibility of application security and development teams.

27
MCQmedium

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

A.Detailed list of known vulnerabilities
B.Number of phishing simulations conducted
C.Names of vendors with critical findings
D.Percentage of systems patched within SLA
AnswerD

Patch compliance within SLA is a quantifiable, outcome-based operational metric that translates technical risk into business terms the board can act on. It shows whether vulnerability exposure is being managed within agreed timeframes, fitting a one-page dashboard.

Why this answer

The board needs high-level, strategic metrics. Percentage of systems patched within SLA provides a clear, concise view of vulnerability management status, which is critical for risk reduction.

28
MCQmedium

A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?

A.Purchase and deploy a next-generation firewall.
B.Conduct a comprehensive risk assessment to identify and prioritize risks.
C.Develop a business continuity plan (BCP).
D.Implement a security awareness training program for all employees.
AnswerB

A risk assessment is foundational to aligning security strategy with business objectives; it identifies threats, vulnerabilities, and impacts, enabling prioritization of controls and resources. In a regulated industry, understanding compliance risks is critical before defining strategy. This step ensures that subsequent decisions are risk-based and support business goals, which is a core CISM principle.

Why this answer

The first step in developing an information security strategy is to understand the organization's risk profile through a comprehensive risk assessment. This ensures that the strategy is aligned with business objectives and regulatory requirements. Other activities, such as training and technology deployment, should be based on identified risks and strategic priorities.

Exam trap

The trap here is assuming that implementing a specific control or program, such as awareness training or a firewall, is the first step, when strategy must begin with risk assessment.

29
Multi-Selecthard

A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)

Select 3 answers
A.Number of security tools deployed
B.Compliance cost avoidance
C.Breach avoidance value
D.Operational efficiency improvements
E.Industry peer comparison
AnswersB, C, D

Compliance cost avoidance quantifies fines, remediation and audit expenses avoided by funding controls, translating security spend into financial terms executives already track. This satisfies the stem's need for justifications that secure approval by demonstrating measurable regulatory cost reduction.

Why this answer

Option B (Compliance cost avoidance) is correct because executives respond to quantifiable financial impact, and demonstrating how security spending prevents regulatory fines, penalties, and audit remediation costs under frameworks like PCI DSS, HIPAA, or GDPR directly ties budget to avoided losses. Option C (Breach avoidance value) is correct because it expresses security investment in business terms—expected loss from data breaches, ransomware, and downtime—using metrics such as ALE (Annualized Loss Expectancy) to show the cost-benefit of prevention versus the cost of a incident. Option D (Operational efficiency improvements) is correct because security controls that streamline processes, reduce manual effort, and lower incident response overhead deliver measurable productivity gains that justify spend beyond pure risk reduction.

Option A (Number of security tools deployed) is not a strong justification because tool count is a vanity metric that does not demonstrate value or risk reduction and may even suggest inefficiency. Option E (Industry peer comparison) is not compelling on its own because peer spending benchmarks do not prove that the investment will protect this specific organization's assets or deliver a positive return.

30
MCQmedium

A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?

A.Deploy an automated compliance scanning tool across all business units to identify policy deviations.
B.Develop a comprehensive set of security policies and distribute them to all department heads for immediate adoption.
C.Conduct a full risk assessment of all critical business systems to quantify the current risk exposure.
D.Obtain executive and board approval for a formal information security charter that defines scope, authority, and accountability.
AnswerD

A formally approved charter establishes the programme's mandate, scope, and authority, giving the CISO the organizational backing needed to enforce policy and require security review. Without this governance foundation, enforcement attempts lack legitimacy. It is the logical first step because every subsequent activity, including policy development and control implementation, depends on an authorized mandate from executive leadership.

Why this answer

Establishing a formal, executive-approved charter gives the information security programme its mandate, scope, and enforcement authority. In this scenario, business units ignore the security team because it lacks organizational legitimacy, not because controls or policies are missing. A charter is the foundational governance artifact from which policy, risk assessment, and control deployment derive their authority.

Exam trap

The trap here is assuming that technical tools or policy documents can substitute for executive-backed governance authority when a programme lacks a formal mandate.

31
MCQmedium

A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?

A.Select controls based on vendor recommendations
B.Implement controls in the order of ease of deployment
C.Prioritize critical controls that address the highest risks
D.Implement all controls simultaneously
AnswerC

Prioritising controls by highest risk ensures limited effort targets exposures with the greatest potential impact, aligning control selection with the application's threat profile. This satisfies the need for a defensible, risk-based prioritisation method rather than technology-driven choices.

Why this answer

The correct answer is C because risk-based prioritization ensures that security resources are focused on the threats and vulnerabilities that could cause the most harm to the organization. By identifying and addressing the highest risks first, the security manager aligns controls with business objectives and maximizes risk reduction per unit of effort. This approach is a core principle of CISM and is consistent with frameworks like NIST RMF and ISO 27005.

Exam trap

CISM often tests the misconception that vendor best practices or ease of implementation should drive control selection, but the exam consistently emphasizes risk-based decision-making as the primary driver.

How to eliminate wrong answers

Option A is wrong because vendor recommendations are generic and not tailored to the organization's specific risk profile, so they may lead to over- or under-investment in controls. Option B is wrong because ease of deployment is an operational convenience, not a risk-based criterion; it can result in critical high-risk areas being ignored. Option D is wrong because implementing all controls simultaneously is often infeasible due to resource constraints and can cause project delays, scope creep, and lack of focus on the most significant risks.

32
MCQeasy

Which of the following is a key objective of implementing a security champions program?

A.To replace the need for a formal security awareness program
B.To reduce the number of security tools needed
C.To embed security advocates in development teams
D.To conduct phishing simulations for all employees
AnswerC

Embedding advocates within development teams satisfies the stem's objective by distributing security ownership to staff who remain in their delivery roles. Champions translate central policy into team-specific practise, raising threat awareness and early risk identification without adding headcount. This scales security culture across squads faster than periodic training or centralised review alone.

Why this answer

Security champions are volunteers within development teams who promote security best practices and facilitate communication between security and development.

33
MCQhard

An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?

A.List all planned technology purchases
B.Describe the latest cyber threats
C.Present ROI analysis showing breach avoidance savings
D.Show industry benchmarks for security spending
AnswerC

Quantifying avoided breach costs in monetary terms translates security spend into the financial language executives use for capital allocation. Demonstrating return on investment directly addresses the approval criterion of business value, making the case more persuasive than technical or compliance-based arguments alone.

Why this answer

Executives respond to financial justification. ROI based on breach avoidance demonstrates value in monetary terms.

34
MCQmedium

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

A.Encryption of data at rest
B.Antivirus software
C.Firewalls
D.Security awareness training
AnswerC

Firewalls inspect and filter traffic at network boundaries, enforcing rules that block unauthorised access at the network layer. Host-based or application controls operate at different layers, so firewalls uniquely satisfy the stem's network-layer protection requirement.

Why this answer

Firewalls operate at the network layer (Layer 3) and transport layer (Layer 4) to filter traffic based on IP addresses, ports, and protocols, preventing unauthorized network access. They are a core component of defense-in-depth at the network perimeter and internal segments. This directly matches the requirement for network-layer protection.

Exam trap

CISM often tests the layer at which a control operates, and candidates may pick encryption or antivirus because they sound security-related, missing that the question specifically asks for network-layer protection against unauthorized access.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest protects data confidentiality on storage media, not network access. Option B is wrong because antivirus software operates at the endpoint layer, scanning files and processes, not network traffic. Option D is wrong because security awareness training addresses the human layer, educating users, not enforcing network access controls.

35
MCQmedium

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

A.Percentage of user access reviews completed on time
B.Mean time to detect (MTTD) security incidents
C.Total cost of security incidents
D.Number of data breaches in the past quarter
AnswerA

Access reviews completed on time measure preventive effort before incidents occur, making them a leading indicator. Unlike breach counts or patch latency, which report past outcomes, this metric signals the health of access governance controls and predicts future exposure from stale entitlements.

Why this answer

Percentage of user access reviews completed on time is a leading indicator because it measures a proactive governance activity that reduces the risk of excessive or inappropriate access before it can be exploited. Completing reviews on time predicts better access control hygiene and lower future incident likelihood. The other options are lagging indicators that report past incidents or their costs.

Exam trap

CISM often tests leading vs. lagging indicators, and candidates may choose MTTD because it sounds proactive, but MTTD is still a lagging measure because it is calculated after incidents occur.

How to eliminate wrong answers

Option B is wrong because mean time to detect (MTTD) is a lagging indicator; it measures how long it took to detect incidents that already occurred. Option C is wrong because total cost of security incidents is a lagging financial outcome of past events. Option D is wrong because number of data breaches in the past quarter is a historical count of incidents that already happened.

36
MCQmedium

A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?

A.Measure the reduction in total security incidents across the organisation year over year.
B.Survey employees annually on their satisfaction with security training content and delivery.
C.Use simulated phishing campaigns with click and report rates, combined with role-based training completion and knowledge assessments.
D.Track the total number of phishing emails reported by staff each month and report the trend.
AnswerC

Combining simulated phishing click and report rates with training completion and knowledge assessment results provides behavioural, participation, and comprehension data. This triangulation shows whether awareness activities change behaviour and where gaps persist, enabling targeted improvement. It gives the board evidence of reduced susceptibility over time, which is the outcome the programme is intended to deliver.

Why this answer

A credible awareness measurement approach combines behavioural evidence from phishing simulations with participation data from training completion and comprehension checks from knowledge assessments. Together these show whether staff can recognise threats and act correctly, and they reveal where reinforcement is needed. This mix produces the trend evidence boards need to judge whether the programme is reducing human risk over time.

Exam trap

The trap here is treating a single metric, such as click rate or incident count, as proof of awareness effectiveness when attribution requires multiple complementary measures.

37
MCQhard

A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?

A.During the testing phase.
B.During the requirements gathering phase.
C.During the post-implementation review.
D.During the deployment phase.
AnswerB

Involving security during requirements gathering ensures that security controls and compliance needs are built into the system from the start. This is the most cost-effective and proactive approach, aligning with the principle of 'security by design.' It allows for risk assessment and identification of security requirements before design and development.

Why this answer

Security should be involved from the requirements gathering phase to ensure that security requirements are identified and incorporated early. This proactive approach reduces costs and risks. Later phases are for validation and verification, but they cannot compensate for missing requirements.

Exam trap

The trap here is thinking that security can be effectively added later in the project lifecycle, but early involvement is critical to avoid costly rework and vulnerabilities.

38
MCQmedium

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

A.Reporting to the CEO
B.Reporting to the COO
C.Reporting to the board or risk committee
D.Reporting to the CFO
AnswerC

Reporting to the board or risk committee removes the CIO's operational bias toward delivery timelines and cost, giving security initiatives independent escalation. This directly resolves the stem's conflict-of-interest constraint that causes deprioritisation under CIO reporting.

Why this answer

Reporting to the board or risk committee provides the CISO with an independent reporting line that is not subordinate to the CIO or other executives whose priorities may conflict with security. This structure ensures security concerns are elevated to a governance body with fiduciary oversight, reducing the likelihood that security initiatives are deprioritized due to operational or budgetary conflicts. It also aligns with governance best practices that separate security oversight from IT delivery.

Exam trap

CISM often tests the difference between administrative reporting (to CIO/CEO) and governance reporting (to board/risk committee); candidates may pick CEO because it sounds senior, but the board provides the independence needed to resolve conflicts of interest.

How to eliminate wrong answers

Option A is wrong because reporting to the CEO still places the CISO within the executive team where competing priorities (e.g., revenue, product deadlines) can overshadow security, and the CEO may not have the specialized oversight of a board committee. Option B is wrong because the COO is focused on operations and may prioritize uptime and efficiency over security controls, creating similar conflicts. Option D is wrong because the CFO is primarily concerned with financial performance and may view security as a cost center, making it harder to justify security investments.

39
Multi-Selectmedium

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Select 3 answers
A.Exit procedures to ensure data is returned or destroyed.
B.Performing a single annual assessment for all vendors.
C.Onboarding risk assessment based on vendor criticality and data access.
D.Requiring all vendors to have ISO 27001 certification.
E.Ongoing monitoring of vendor security posture.
AnswersA, C, E

Exit procedures guarantee that vendor-held data is returned or securely destroyed when the relationship ends, closing the offboarding gap where residual data exposure persists. This satisfies the stem's requirement for a key TPRM component by addressing the full vendor lifecycle, not just onboarding.

Why this answer

Option A is correct because an effective TPRM program must define exit procedures that ensure vendor-held data is returned or securely destroyed when the relationship ends, addressing data retention and offboarding risk. Option C is correct because onboarding risk assessments should be risk-tiered, scoped to the vendor's criticality and level of access to systems and data, rather than applying uniform treatment. Option E is correct because vendor risk is continuous, so ongoing monitoring of the vendor's security posture (for example, via security ratings, questionnaires, or attestation tracking) is needed to detect changes after onboarding.

Option B is not appropriate because a single annual assessment for all vendors ignores differing risk levels and fails to provide continuous oversight. Option D is not required because ISO 27001 certification is only one possible assurance mechanism; mandating it for all vendors is overly prescriptive and does not fit a risk-based program.

Exam trap

CISM often tests the principle of risk-based vendor management; candidates may pick 'all vendors must be ISO 27001 certified' because it sounds rigorous, but the exam expects recognition that a one-size-fits-all requirement is not effective TPRM.

40
MCQhard

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

A.Number of phishing simulations conducted
B.Percentage of IT budget allocated to security
C.Return on investment (ROI) from avoided breach costs
D.Number of security tools deployed
AnswerC

ROI from avoided breach costs translates security spending into financial terms the board already uses for capital decisions. This satisfies the stem by expressing value as quantifiable monetary return, making the budget request directly comparable to other investment proposals.

Why this answer

Return on investment (ROI) from avoided breach costs translates security spending into financial terms that the board understands, showing how investments prevent losses. This metric directly ties security to business value by quantifying the cost avoidance from prevented incidents, which is more compelling than activity-based metrics. Boards are accountable for financial performance and risk, so ROI resonates with their fiduciary responsibilities.

Exam trap

CISM often tests the difference between activity metrics (phishing simulations, tools deployed) and outcome/value metrics (ROI from avoided breach costs); candidates may pick activity metrics because they are easy to measure, but the board cares about financial impact.

How to eliminate wrong answers

Option A is wrong because the number of phishing simulations conducted is an activity metric that shows effort but not effectiveness or financial impact; it does not demonstrate value to the board. Option B is wrong because the percentage of IT budget allocated to security is a cost metric, not a value metric; it shows how much is spent, not what is gained. Option D is wrong because the number of security tools deployed is a vanity metric that does not indicate whether those tools reduce risk or cost.

41
MCQhard

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

A.Data access level and service criticality
B.Contract value
C.Duration of the relationship
D.Vendor size
AnswerA

Data access level and service criticality determine potential impact if a vendor is breached, so they drive assessment priority. This satisfies the stem's prioritisation constraint by ranking vendors on inherent risk exposure rather than contract value or relationship length.

Why this answer

The highest-weighted factor in third-party risk prioritization is the combination of data access level and service criticality. This is because risk exposure is directly proportional to the sensitivity of data the vendor can access and how essential the vendor's service is to business operations. A vendor with access to regulated data (e.g., PII, PHI) or that supports a critical business function poses a significantly higher risk if compromised, regardless of contract value or vendor size.

Thus, these two dimensions determine the potential impact of a vendor-related incident, making them the primary drivers for assessment prioritization.

Exam trap

CISM often tests the misconception that financial or relationship factors (contract value, duration, vendor size) are primary risk indicators, when in fact data access and service criticality are the core determinants of third-party risk exposure.

How to eliminate wrong answers

Option B is wrong because contract value is a financial metric, not a risk indicator; a low-value contract could still involve access to highly sensitive data or critical services, while a high-value contract might be for non-critical goods with no data access. Option C is wrong because the duration of the relationship does not inherently increase risk; a long-standing vendor may have mature controls, while a new vendor might introduce unknown risks, but duration alone does not determine risk exposure. Option D is wrong because vendor size is not a reliable proxy for risk; small vendors can be highly secure, and large vendors can have significant vulnerabilities or poor security practices, so size should not be the primary factor.

42
MCQmedium

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

A.A single firewall with access control lists
B.Antivirus software on all endpoints
C.Physical locks on server room doors and CCTV
D.Network segmentation, intrusion detection systems, and full-disk encryption
AnswerD

These controls operate at distinct layers: segmentation limits lateral movement, intrusion detection monitors network activity, and full-disk encryption protects data at rest. Layered, independent controls across network and endpoint satisfy defence in depth, so one failure does not expose the asset.

Why this answer

Defense in depth requires multiple, layered controls across different domains so that if one fails, others still protect the asset. Network segmentation, intrusion detection systems, and full-disk encryption represent layers across network, monitoring, and data-at-rest controls, covering different attack vectors. This combination exemplifies the principle by providing preventive, detective, and protective controls that complement each other.

Exam trap

CISM often tests the definition of defense in depth; candidates may pick a single strong control (e.g., firewall) or multiple controls of the same type (e.g., locks and CCTV) instead of recognizing the need for diverse, layered controls across different domains.

How to eliminate wrong answers

Option A is wrong because a single firewall with ACLs is a single layer of defense; if the firewall is misconfigured or bypassed, there is no additional protection. Option B is wrong because antivirus on all endpoints is a single control type (endpoint protection) and does not address network or data-at-rest threats. Option C is wrong because physical locks and CCTV are both physical security controls, representing only one layer (physical) and not a multi-layered defense across domains.

43
MCQhard

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

A.Accept the risk because the vendor is contractually responsible
B.Revise the contract to require the vendor to flow down security requirements to sub-suppliers
C.Perform an on-site assessment of the sub-supplier
D.Request that the vendor terminate the sub-supplier relationship
AnswerB

Contractual flow-down clauses extend security requirements to sub-suppliers, closing the nth-party gap the existing agreement leaves open. This addresses the root cause — absent contractual control — rather than merely monitoring a vendor that has no obligation to enforce sub-supplier security.

Why this answer

The core issue is that the vendor contract does not address nth-party (sub-supplier) risk, so the organization has no contractual leverage to require the vendor to manage its sub-suppliers. The best course of action is to revise the contract to include flow-down clauses that require the vendor to impose security requirements on its sub-suppliers, thereby extending the organization's security posture through the supply chain. This addresses the root cause—lack of contractual control—and is a preventive, governance-level action.

Exam trap

CISM often tests the distinction between risk acceptance, risk transfer, and risk mitigation; candidates may incorrectly choose to accept the risk because the vendor is contractually responsible, but the contract's silence on nth-party risk means the risk is not effectively transferred.

How to eliminate wrong answers

Option A is wrong because accepting the risk based on the vendor's contractual responsibility is insufficient when the contract itself does not address nth-party risk; the vendor may not be liable for sub-supplier breaches. Option C is wrong because performing an on-site assessment of the sub-supplier is a point-in-time detective control that does not provide ongoing assurance or contractual enforcement, and the organization may not have the right to assess a sub-supplier directly. Option D is wrong because requesting termination of the sub-supplier relationship is a drastic, potentially disruptive action that may not be feasible or necessary; it does not address the underlying contractual gap and could harm the business relationship.

44
MCQmedium

Which of the following is a leading indicator for security performance?

A.Patch compliance percentage
B.Mean time to recover (MTTR)
C.Number of data breaches
D.Mean time to detect (MTTD)
AnswerA

Patch compliance percentage measures activity performed before incidents occur, revealing whether vulnerability remediation is keeping pace. Unlike breach counts or incident volumes, which are lagging, it predicts future exposure, making it a leading indicator of security performance.

Why this answer

Leading indicators are proactive measures that predict future performance. Patch compliance is a leading indicator because it shows current security posture that influences future incidents.

45
MCQmedium

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

A.Mean time to respond (MTTR) to incidents
B.Number of security incidents in the past quarter
C.Total cost of security incidents
D.Percentage of systems compliant with patch SLAs
AnswerD

Patch SLA compliance measures current remediation performance, so low compliance predicts unpatched exploitable systems and therefore future incidents. It is a leading indicator because it reflects exposure accumulating now, unlike lagging counts of incidents already suffered.

Why this answer

A leading indicator predicts future outcomes, whereas lagging indicators measure past events. The percentage of systems compliant with patch SLAs is a leading indicator because it reflects the current state of vulnerability management, which directly influences the likelihood of future security incidents. High compliance with patching reduces the attack surface and is a proactive measure.

Exam trap

CISM often tests the difference between leading and lagging indicators; candidates may mistakenly select MTTR or incident counts as leading because they are commonly used metrics, but they are lagging.

How to eliminate wrong answers

Option A is wrong because mean time to respond (MTTR) is a lagging indicator; it measures how quickly incidents were handled after they occurred, not future incident likelihood. Option B is wrong because the number of security incidents in the past quarter is a lagging indicator that reports historical events. Option C is wrong because total cost of security incidents is also a lagging indicator, reflecting financial impact after incidents have happened.

46
Multi-Selectmedium

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Select 3 answers
A.Automated patching of vendor systems
B.Contractual security requirements
C.Shared SOC services
D.Vendor tiering based on data access and criticality
E.Onboarding risk assessment
AnswersB, D, E

Contracts embed enforceable security obligations, breach notification duties, audit rights and liability into the vendor relationship. This gives the organisation legal leverage when a third party's controls fail, satisfying the governance requirement that risk be formally transferred and managed.

Why this answer

Contractual security requirements (B) are essential because TPRM must codify security, privacy, breach-notification, and audit obligations in vendor agreements so that controls are legally enforceable. Vendor tiering based on data access and criticality (D) is essential because it lets the organization apply proportionate due diligence, monitoring, and reassessment to vendors according to the sensitivity of data and operational dependency. Onboarding risk assessment (E) is essential because risk must be evaluated before a vendor is engaged or given access, establishing a baseline for approval, remediation, and ongoing oversight.

The unmarked options do not belong: automated patching of vendor systems (A) is an operational control the vendor itself normally performs and is not a core TPRM program element, and shared SOC services (C) are one possible assurance mechanism rather than a required component of every TPRM program.

Exam trap

The trap here is that candidates often confuse operational security controls (like patching or shared SOC) with the governance and risk management components that define a TPRM program, leading them to select options that describe how an organization secures its own environment rather than how it manages vendor risk.

47
Multi-Selecthard

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Select 2 answers
A.Champions report directly to the CISO
B.Champions are rotated every six months
C.Champions act as liaisons between security and their teams
D.Champions have authority to enforce security policies
E.Champions are volunteers from development teams with additional security training
AnswersC, E

Champions functioning as liaisons create a bidirectional channel, translating security requirements into team language and surfacing development constraints to security. This embedded communication satisfies the programme's effectiveness criterion by removing the bottleneck of a central security team.

Why this answer

Option C is correct because the core value of a security champions program is that champions serve as the liaison or bridge between the central security team and their own development/product teams, translating security requirements into the team's language and feeding practical concerns back to security. Option E is correct because effective champions are typically volunteers drawn from development (or engineering) teams who receive additional security training, which gives them credibility with peers and the embedded knowledge to influence secure practices organically. Option A is incorrect because champions normally remain within their existing team and reporting line, not reporting directly to the CISO, which would undermine their embedded liaison role.

Option B is incorrect because rotating champions every six months destroys the continuity, relationship-building, and accumulated security expertise that make the program effective. Option D is incorrect because champions are influencers and advocates, not enforcers; they generally lack the authority to enforce security policies, which remains with security leadership and management.

Exam trap

CISM often tests the characteristics of effective security champions programs; candidates may incorrectly assume champions need authority to enforce policies or should report to the CISO, but the key is their embedded, voluntary, and liaison role.

48
MCQeasy

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

A.NIST SP 800-53
B.COBIT 2019
C.ISO 27001 Annex A
D.CIS Controls v8
AnswerD

CIS Controls v8 uniquely structures its safeguards into Implementation Groups IG1, IG2 and IG3, mapped to organisational risk profile and available resources. No other framework uses this tiered grouping, directly satisfying the stem's stated constraint.

Why this answer

The CIS Controls v8 (Center for Internet Security Critical Security Controls) are organized into Implementation Groups (IG1, IG2, IG3) that are tailored to organizations based on their risk profile and resources. IG1 is for small organizations with limited resources, IG2 for medium, and IG3 for large organizations with mature security programs. This structure is unique to CIS Controls.

Exam trap

CISM often tests familiarity with various frameworks; candidates may confuse CIS Controls with NIST or ISO, but the key differentiator is the Implementation Groups (IG1-IG3) unique to CIS.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-53 is a catalog of security and privacy controls for federal information systems, organized by control families, not implementation groups. Option B is wrong because COBIT 2019 is a governance framework for enterprise IT, focusing on processes and maturity levels, not implementation groups. Option C is wrong because ISO 27001 Annex A provides a list of security controls but does not define implementation groups; it is a certifiable standard.

49
Multi-Selecteasy

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Select 2 answers
A.A single, strong firewall at the network perimeter.
B.A single sign-on (SSO) solution for all applications.
C.Network segmentation to isolate critical systems.
D.Annual penetration testing as the primary security control.
E.Endpoint detection and response (EDR) on all workstations and servers.
AnswersC, E

Segmenting the network into zones with controlled inter-zone traffic limits lateral movement, so compromise of one system cannot reach critical financial systems directly. This enforces least-privilege connectivity, a core defense-in-depth layer satisfying the stem's requirement to isolate critical systems.

Why this answer

Option C is correct because network segmentation isolates critical systems (e.g., cardholder data environments) into separate VLANs or subnets with strict ACLs and firewall rules, so a breach in one zone cannot easily pivot to high-value assets, which is a core defense-in-depth layer. Option E is correct because EDR provides continuous endpoint telemetry, behavioral detection, and automated response (e.g., process isolation, host quarantine) on workstations and servers, adding a host-level detection and response layer that complements perimeter and network controls. Option A is not correct because a single perimeter firewall represents a single point of failure and a flat-trust model, contradicting defense-in-depth's requirement for multiple overlapping controls.

Option B is not correct because SSO centralizes authentication and, if compromised, can grant broad access; it is an identity convenience/control, not a layered defensive component by itself. Option D is not correct because annual penetration testing is a point-in-time assessment, not a primary preventive or detective control, and cannot substitute for continuous layered defenses.

50
Multi-Selectmedium

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Select 2 answers
A.Type and sensitivity of data the vendor accesses
B.Vendor's geographic location
C.Number of employees at the vendor
D.Vendor's annual revenue
E.Criticality of the vendor's service to business operations
AnswersA, E

The type and sensitivity of data a vendor accesses directly determines the potential impact of a breach, making it a primary tiering factor. This satisfies the stem's requirement by tying risk tier to data criticality rather than contract value or vendor size.

Why this answer

Option A is correct because the type and sensitivity of the data a vendor accesses directly drives the inherent risk of a data breach or regulatory violation, making it a primary factor in tiering (e.g., PII, PHI, or PCI data raises the tier). Option E is correct because the criticality of the vendor's service to business operations determines the impact of a vendor failure or outage on the organization's ability to function, which is a core dimension of vendor risk tiering. In contrast, Option B (geographic location) can influence risk but is not a primary tiering factor by itself and is often a sub-factor under data and operational considerations.

Option C (number of employees) and Option D (annual revenue) are vendor size metrics that do not directly reflect the risk the vendor poses to the organization's data or operations, so they are not the most appropriate determinants.

Exam trap

CISM often tests vendor risk tiering factors; candidates may be tempted to select easily quantifiable factors like revenue or employee count, but the exam expects focus on data sensitivity and business criticality.

51
MCQmedium

A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?

A.Conduct a full penetration test of the external attack surface and report findings to the board.
B.Immediately update all security policies to reflect ISO/IEC 27001 requirements and distribute them to staff.
C.Define and obtain board approval for an information security charter that articulates the mandate, authority, and scope of the security function.
D.Deploy an enterprise SIEM and begin centralising log collection from critical systems.
AnswerC

A formally approved charter establishes the security programme's mandate, authority, and scope, and is the foundational governance artifact that ties security activity to board-level oversight and business objectives. Without an approved charter, subsequent policies, metrics, and reporting lack legitimacy and authority. This aligns with CISM's emphasis on establishing governance before executing controls or measurement.

Why this answer

Effective information security governance begins with a board-approved charter that defines the security function's mandate, authority, and scope. This artifact legitimises subsequent strategy, policy, metrics, and control investment, and ensures alignment with business objectives and regulatory obligations. Technical deployments, testing, and policy updates are downstream activities that should reflect the governance framework rather than precede it.

Exam trap

The trap here is assuming that acquiring technology or performing assessments demonstrates governance, when governance actually begins with a formally approved mandate and scope.

52
MCQeasy

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

A.Personnel Security (PS)
B.Identification and Authentication (IA)
C.System and Communications Protection (SC)
D.Access Control (AC)
AnswerB

NIST SP 800-53's Identification and Authentication (IA) family directly governs user identity verification and credential management, satisfying the stem's requirement for the control family addressing user identification and authentication. IA controls cover authenticator management, identity proofing and session authentication, making it the precise match rather than access control or audit families.

Why this answer

The Identification and Authentication (IA) family in NIST SP 800-53 covers user identification, authentication, and credential management.

53
MCQmedium

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

A.Number of phishing simulation campaigns per year
B.Click rate trend over multiple simulation cycles
C.Pass rate on phishing simulation knowledge test
D.Number of employees who report phishing emails
AnswerB

Click rate trend across successive simulation cycles reveals whether user behaviour genuinely improves over time, rather than reflecting a single campaign's snapshot. A sustained downward trend evidences durable learning, whereas one-off completion or report counts can be inflated by transient awareness or repeat reporting.

Why this answer

The click rate trend over multiple simulation cycles best measures long-term effectiveness because it shows whether employee behavior is improving over time. A declining trend indicates that the awareness program is successfully reducing susceptibility to phishing. Other metrics like number of campaigns or test pass rates do not directly reflect real-world behavior change.

Exam trap

CISM often tests the confusion between activity metrics (e.g., number of campaigns) and outcome metrics (e.g., click rate trend), where the former measures effort and the latter measures effectiveness.

How to eliminate wrong answers

Option A is wrong because the number of campaigns per year measures activity, not effectiveness. Option C is wrong because a knowledge test pass rate measures theoretical understanding, not actual behavior in real phishing scenarios. Option D is wrong because the number of employees who report phishing emails is a positive indicator but does not directly measure the reduction in successful phishing attempts; it could be high even if click rates remain high.

54
MCQmedium

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?

A.Access control lists, data loss prevention, and encryption
B.Firewall, antivirus, and encryption
C.Network segmentation, intrusion detection system, and incident response plan
D.Security awareness training, vulnerability scanning, and patching
AnswerC

This combination layers preventive, detective and corrective controls across distinct planes: segmentation limits lateral movement, intrusion detection identifies compromise, and the incident response plan contains and recovers from it. Together they satisfy defence in depth's requirement for independent, complementary layers.

Why this answer

Network segmentation, intrusion detection system, and incident response plan represent a layered defense-in-depth approach because they combine preventive (segmentation), detective (IDS), and corrective (incident response) controls across different layers. This triad addresses network, monitoring, and process domains, which is the essence of defense in depth. The other options either focus on a single control type or lack the breadth of preventive, detective, and corrective measures.

Exam trap

CISM often tests the misconception that defense in depth is simply using multiple preventive tools, when it actually requires a mix of preventive, detective, and corrective controls across different layers.

How to eliminate wrong answers

Option A is wrong because access control lists, data loss prevention, and encryption are all primarily preventive controls, lacking detective and corrective layers. Option B is wrong because firewall, antivirus, and encryption are also all preventive, with no detection or response capability. Option D is wrong because security awareness training, vulnerability scanning, and patching are mostly preventive and administrative, missing the network and response dimensions.

55
Multi-Selectmedium

A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)

Select 2 answers
A.Defined risk response options mapped to each identified risk
B.Technical vulnerability scan results for all systems
C.Approval of the IT budget for security tools
D.Documented risk acceptance by the appropriate business owner
E.A list of all security controls implemented across the enterprise
AnswersA, D

A risk treatment plan must specify the chosen response—mitigate, transfer, avoid, or accept—for each risk. Mapping responses ensures consistency and clarity. This element transforms assessment findings into actionable decisions, providing direction for control implementation and establishing the basis for measuring treatment effectiveness over time.

Why this answer

An effective risk treatment plan documents the chosen response for each risk and records formal acceptance of residual risk by the accountable business owner. These elements ensure decisions are consistent, traceable, and aligned with risk appetite, enabling the organization to demonstrate due care and manage risk deliberately rather than incidentally.

Exam trap

The trap here is treating assessment inputs or funding activities as treatment plan elements, when the plan must capture risk response decisions and accountability.

56
MCQmedium

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

A.Annual computer-based training for all employees covering general security topics
B.Role-based training: developers receive secure coding training, executives receive social engineering awareness
C.Monthly phishing simulations without any accompanying training
D.A one-time security awareness seminar conducted by an external consultant
AnswerB

Tailoring content to each role's actual tasks ensures relevance, so developers learn secure coding for the code they write and executives recognise social engineering targeting them. This role-specific alignment drives daily application of security principles better than generic awareness content.

Why this answer

Role-based training is most effective because it tailors security education to the specific risks and responsibilities of different job functions. Developers need secure coding practices, while executives are prime targets for social engineering. This relevance increases engagement and application of security principles in daily work.

Other approaches are either too generic or lack the necessary depth.

Exam trap

CISM often tests the misconception that a one-size-fits-all annual training is sufficient, when in fact role-based, continuous training is more effective for behavior change.

How to eliminate wrong answers

Option A is wrong because annual computer-based training is often generic and not tailored to specific roles, leading to low engagement and retention. Option C is wrong because phishing simulations without training do not teach employees how to respond correctly; they only test. Option D is wrong because a one-time seminar lacks reinforcement and does not address ongoing or role-specific needs.

57
MCQeasy

In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?

A.CIS Controls v8
B.ISO 27001 Annex A
C.NIST SP 800-53
D.COBIT 2019
AnswerA

CIS Controls v8 uniquely organises its 18 controls into IG1, IG2 and IG3, letting organisations select safeguards matching their risk profile and maturity. No other listed framework uses implementation groups as its prioritisation structure, satisfying the stem's specific requirement.

Why this answer

CIS Controls v8 is specifically structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity. IG1 is for small organizations with limited resources, IG2 for mid-sized with more risk, and IG3 for mature organizations facing advanced threats. This makes it uniquely suited for the scenario described.

Exam trap

CISM often tests the confusion between frameworks that provide control catalogs (ISO 27001, NIST 800-53) and those that offer implementation groups for prioritization (CIS Controls v8).

How to eliminate wrong answers

Option B is wrong because ISO 27001 Annex A provides a catalog of controls but does not define implementation groups; it requires organizations to select controls based on risk assessment. Option C is wrong because NIST SP 800-53 provides a comprehensive control catalog but does not have implementation groups; it uses baselines (low, moderate, high) but not IG1-3. Option D is wrong because COBIT 2019 is a governance framework for IT management, not specifically structured around implementation groups for control prioritization.

58
Multi-Selecthard

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Select 3 answers
A.Biometric authentication for all users.
B.Role-based access control (RBAC) aligned with job functions.
C.Quarterly access reviews for critical systems.
D.Single sign-on (SSO) for all cloud applications.
E.Automated provisioning and de-provisioning of user accounts.
AnswersB, C, E

RBAC ties entitlements to job functions, enforcing least privilege through structured role definitions rather than ad hoc grants. This satisfies the maturity requirement by making access decisions repeatable, auditable and aligned with organisational responsibilities, reducing entitlement drift.

Why this answer

Option B is correct because RBAC maps permissions to job functions rather than individuals, which enforces least privilege and makes entitlements manageable and auditable as roles change. Option C is correct because periodic access reviews (recertification) of critical systems ensure stale or excessive entitlements are detected and revoked, a core governance control in any mature IAM program. Option E is correct because automated provisioning and de-provisioning via lifecycle workflows (often driven by an identity governance platform or SCIM) ensures users receive and lose access promptly, especially at joiner/mover/leaver events.

Option A does not belong because biometrics is only one authentication factor and is not required for all users in a mature IAM program. Option D does not belong because SSO is a valuable convenience and security enhancement, but it is not mandatory for every cloud application and is not itself a defining component of IAM maturity.

Exam trap

CISM often tests the distinction between IAM components and authentication mechanisms, causing candidates to select biometrics or SSO as key components when they are merely supporting technologies.

59
MCQeasy

A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?

A.A list of all security tools deployed in the environment.
B.A detailed technical security architecture diagram.
C.A clear definition of security roles and responsibilities.
D.A schedule for penetration testing.
AnswerC

Clear roles and responsibilities ensure accountability and are fundamental to effective governance. They define who is responsible for what, enabling oversight and decision-making. This is essential for the board to have assurance that security risks are managed, as it establishes ownership and reporting lines.

Why this answer

Effective security governance requires clear definition of roles and responsibilities to establish accountability and oversight. This enables the board to have assurance that security risks are managed. Other elements like tools, diagrams, and testing schedules are operational and do not fulfill governance needs.

Exam trap

The trap here is confusing operational artifacts, such as tool lists or testing schedules, with governance elements that provide strategic oversight and accountability.

60
Multi-Selectmedium

Which TWO metrics are considered leading indicators for information security program performance?

Select 2 answers
A.Patch compliance percentage
B.Phishing click rate
C.Number of data breaches
D.Mean time to detect (MTTD)
AnswersA, B

Patch compliance percentage measures the proportion of systems currently patched, predicting future compromise likelihood rather than reporting past incidents. It satisfies the leading-indicator constraint because it forecasts exposure before exploitation occurs, unlike lagging metrics such as breach counts.

Why this answer

Patch compliance percentage (A) is a leading indicator because it measures preventive control coverage before an incident occurs, showing how well vulnerabilities are being remediated ahead of exploitation. Phishing click rate (B) is also a leading indicator, as it quantifies user susceptibility to social engineering and predicts the likelihood of future credential compromise or malware infection. By contrast, the number of data breaches (C) is a lagging indicator, since it counts security failures only after they have already happened.

Mean time to detect (D) is likewise a lagging indicator, because it measures response performance after an incident has already occurred rather than predicting future risk.

Exam trap

CISM often tests the distinction between leading and lagging indicators, where candidates may incorrectly select breach count or MTTD as leading because they are commonly reported metrics.

61
MCQmedium

A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?

A.Chief Information Officer (CIO)
B.Board of Directors
C.Chief Information Security Officer (CISO)
D.IT Steering Committee
AnswerB

The board of directors holds fiduciary responsibility to shareholders and is ultimately accountable for enterprise risk, including information security. They set risk appetite, approve strategy, and oversee management. While the CISO executes and the steering committee coordinates, the board owns the accountability for ensuring security aligns with and supports business objectives.

Why this answer

Ultimate accountability for the information security program resides with the board of directors, which holds fiduciary duty to stakeholders. The board defines risk appetite and ensures security strategy supports business goals, while the CISO, CIO, and steering committees execute, advise, or coordinate. Distinguishing accountability from responsibility is central to effective governance.

Exam trap

The trap here is assuming the CISO is accountable because they lead security, when accountability for enterprise risk actually sits with the board.

62
MCQeasy

A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?

A.Deliver the same annual training to all employees to ensure consistency.
B.Provide role-based training that addresses specific risks for each job function.
C.Focus only on senior executives since they are the primary targets of social engineering.
D.Conduct quarterly phishing simulations without any formal training.
AnswerB

Role-based training maps controls and threats to each function's actual workflows, so relevance is achieved by addressing the specific risks that job holders face. This satisfies the requirement for differentiated relevance across employee roles rather than generic, one-size-fits-all content.

Why this answer

Role-based training is the most effective approach because it tailors content to the specific risks, tools, and data each job function handles, increasing relevance and retention. For example, finance staff need payment fraud and invoice manipulation training, while developers need secure coding and secrets management. This targeted approach addresses the actual threat surface of each role rather than delivering generic content.

Exam trap

CISM often tests the misconception that consistency (same training for everyone) equals effectiveness, or that simulations alone constitute a training program, when role relevance and formal instruction are the key differentiators.

How to eliminate wrong answers

Option A is wrong because identical annual training for all employees ignores differing risk profiles and often leads to low engagement and poor retention. Option C is wrong because focusing only on executives leaves the majority of the workforce—who are frequent social engineering targets—untrained. Option D is wrong because phishing simulations without formal training test employees without teaching them, which is punitive rather than educational and does not build lasting awareness.

63
MCQeasy

In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?

A.Vendor's data access and service criticality
B.Vendor's annual revenue
C.Vendor's geographic location
D.Vendor's number of employees
AnswerA

Tiering hinges on the inherent risk a vendor introduces, which is driven by the sensitivity of data it accesses and how critical its service is to operations. These two factors determine the depth of due diligence and contractual controls applied, making them the primary tiering criteria.

Why this answer

The vendor's access to sensitive data and the criticality of the service to business operations are the primary factors for tiering, as they directly impact risk exposure.

64
Multi-Selectmedium

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

Select 3 answers
A.Ongoing monitoring of vendor security posture
B.Providing vendor with access to internal network
C.Negotiating contract security requirements
D.Onboarding risk assessment for new vendors
E.Performing background checks on vendor employees
AnswersA, C, D

Ongoing monitoring tracks vendor security posture after onboarding, catching new breaches, expired certifications or degraded controls that initial due diligence missed. This satisfies TPRM's requirement for continuous oversight across the vendor relationship lifecycle, not just at selection.

Why this answer

Option A (Ongoing monitoring of vendor security posture) is correct because TPRM requires continuous oversight of a vendor's security controls, compliance status, and threat exposure after onboarding, using methods such as periodic reassessments, security ratings services, and audit reviews. Option C (Negotiating contract security requirements) is correct because TPRM includes embedding security, privacy, data-handling, breach-notification, and right-to-audit clauses into vendor contracts to establish enforceable obligations and risk allocation. Option D (Onboarding risk assessment for new vendors) is correct because TPRM begins with due diligence before engagement, evaluating the vendor's security posture, data access, criticality, and compliance against organizational risk tolerance.

Option B (Providing vendor with access to internal network) is not a TPRM activity; it is an operational access decision that should be minimized and controlled, not a core program function. Option E (Performing background checks on vendor employees) is not a TPRM program activity; personnel screening is typically the vendor's responsibility under contract, and TPRM focuses on organizational vendor risk rather than individual employee vetting.

Exam trap

CISM often tests whether candidates confuse vendor management with granting access or performing HR-style checks, when the core activities are assessment, contractual controls, and ongoing monitoring.

65
Multi-Selecthard

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

Select 3 answers
A.Objective: Implement a new SIEM. Key Result: Deploy SIEM by Q3.
B.Objective: Enhance incident response. Key Result: Achieve 100% of incidents logged within 1 hour of detection.
C.Objective: Improve vulnerability management. Key Result: Reduce mean time to remediate critical vulnerabilities from 30 to 7 days.
D.Objective: Increase security awareness. Key Result: Conduct quarterly phishing simulations.
E.Objective: Reduce risk from third parties. Key Result: Complete risk assessments for 100% of high-tier vendors by year-end.
AnswersB, C, E

The key result is measurable, time-bound and outcome-focused: logging every incident within one hour of detection is verifiable and directly supports faster containment. It avoids vague activity statements, satisfying the OKR requirement for quantifiable progress tied to a clear objective.

Why this answer

Effective security OKRs pair a qualitative Objective with measurable, outcome-focused Key Results that have a baseline, target, and timeframe. Option B is correct because 'Achieve 100% of incidents logged within 1 hour of detection' is a quantifiable, time-bound metric that directly measures improved incident response performance. Option C is correct because reducing mean time to remediate critical vulnerabilities from 30 to 7 days specifies a clear baseline (30 days), target (7 days), and metric (MTTR), making it a measurable risk-reduction outcome.

Option E is correct because completing risk assessments for 100% of high-tier vendors by year-end is a specific, measurable, and time-bound result tied to reducing third-party risk. Option A is not correct because 'Deploy SIEM by Q3' is a project deliverable/milestone, not an outcome-based key result measuring security improvement. Option D is not correct because 'Conduct quarterly phishing simulations' is an activity/output rather than a measurable outcome such as reduced click rate or reporting rate.

Exam trap

CISM often tests the difference between output/deliverable metrics and outcome-based key results — candidates select activity-based statements (deploy, conduct) as OKRs when true KRs must measure results or impact.

66
MCQmedium

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

A.Breach count and associated financial impact
B.Mean time to detect (MTTD) for incidents
C.Number of firewall rule changes per month
D.Percentage of employees who completed training
AnswerA

Breach count and financial impact express security posture in business terms the board governs, satisfying the dashboard's need for concise, decision-relevant data. Operational metrics such as patch latency lack the strategic framing a one-page executive view requires.

Why this answer

For a one-page executive dashboard, the board needs metrics that communicate business risk and financial impact in a language they understand. Breach count and associated financial impact (A) directly translates security performance into business terms — number of breaches and their monetary cost — which is what boards care about for fiduciary oversight. This metric ties security directly to organizational risk and financial exposure, making it the most relevant for executive-level reporting.

Exam trap

CISM often tests audience-appropriate metrics — candidates pick operational/technical metrics (MTTD, firewall changes) for executive dashboards when boards require business-risk and financial-impact metrics.

How to eliminate wrong answers

Option B is wrong because MTTD is an operational metric that, while important, is too technical and granular for a board-level one-page dashboard — it belongs in security operations reporting. Option C is wrong because firewall rule changes per month is a low-level operational activity metric with no direct business risk or financial context, irrelevant to the board. Option D is wrong because training completion percentage is a compliance/awareness metric that, while useful, does not convey business risk or financial impact at the executive level.

67
MCQmedium

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

A.Report to the Chief Financial Officer (CFO)
B.Report to the Chief Information Officer (CIO)
C.Report to the board of directors or audit committee
D.Report to the Chief Operating Officer (COO)
AnswerC

Reporting to the board or audit committee gives security direct access to governing authority, free from operational conflicts inherent in reporting through IT or finance. This structural independence enables escalation, budget influence and objective oversight of management's risk decisions.

Why this answer

For information security to be independent and influential, the CISO should report to the board of directors or audit committee (C). This reporting line ensures the security function is not subordinate to IT operations (which it must oversee) and gives it direct access to the highest governance body, enabling objective oversight and adequate resourcing. Independence is critical because the CISO must be able to raise risk concerns without conflicts of interest from IT management.

Exam trap

CISM often tests reporting-line independence — candidates choose CIO reporting as 'IT-savvy' when the correct answer is board/audit committee reporting to ensure objectivity and governance influence.

How to eliminate wrong answers

Option A is wrong because reporting to the CFO places security under financial management, which may prioritize cost control over risk mitigation and lacks the governance authority of the board. Option B is wrong because reporting to the CIO creates a conflict of interest — the CISO would be overseeing the same IT organization it must independently assess, compromising objectivity. Option D is wrong because reporting to the COO embeds security in operations, reducing independence and potentially subordinating security to operational efficiency goals.

68
Multi-Selecthard

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Select 2 answers
A.Technology costs for security tools and infrastructure.
B.Legal fees for contract reviews.
C.Marketing budget for security awareness campaigns.
D.Office renovation for security operations center.
E.Personnel costs for security staff salaries and benefits.
AnswersA, E

Security tools and infrastructure are capital and operating outlays that directly enable detective, preventive and corrective capabilities. Without them, no control can be operated, making technology spend a core, recurring line item alongside staffing and services in any mid-sized security budget.

Why this answer

Option A is correct because a security budget must include technology costs for security tools and infrastructure such as firewalls, IDS/IPS, SIEM, endpoint protection, and related hardware/software licensing and maintenance. Option E is correct because personnel costs for security staff salaries and benefits are a core, recurring component of any security budget, covering roles like security analysts, engineers, and managers. Legal fees for contract reviews (B) are typically part of general legal or procurement budgets, not the security budget, unless tied to a specific security incident or compliance matter.

A marketing budget for security awareness campaigns (C) is usually categorized under marketing or HR/training, though awareness is security-related, it is not a standard security budget line. Office renovation for a security operations center (D) is a capital facilities expense, not a typical recurring security budget component.

69
Multi-Selecthard

A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)

Select 2 answers
A.Permit each acquired business unit to retain its existing policies until the next scheduled audit cycle.
B.Delegate policy ownership entirely to each regional CISO and require only annual attestation of compliance.
C.Map the global policy framework to applicable external standards and regulations, and maintain a traceability matrix showing coverage per jurisdiction.
D.Publish a single global security policy set with mandatory controls and allow documented local exceptions approved through a formal risk acceptance process.
E.Adopt the strictest regulation from any jurisdiction as the single global standard for all business units.
AnswersC, D

A traceability matrix demonstrates how each policy requirement satisfies applicable laws and standards in every jurisdiction, providing evidence for auditors and regulators. It also reveals overlaps and conflicts early, so the framework can be adjusted before local assessments. This makes consistency and compliance verifiable rather than assumed, which is essential across diverse regulatory environments.

Why this answer

Consistency and compliance are achieved by pairing a mandatory global policy baseline with a governed exception path, and by mapping that baseline to applicable laws and standards through a traceability matrix. The exception process keeps local regulatory constraints visible and formally accepted, while the matrix provides audit evidence of coverage. Together they let the CISO standardise controls without ignoring jurisdictional differences.

Exam trap

The trap here is believing that either full centralisation or full delegation solves multi-jurisdiction compliance, when the workable model is a common baseline with documented, traceable local exceptions.

70
Multi-Selectmedium

A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)

Select 2 answers
A.Reviewing and approving the enterprise risk register and accepting residual risks.
B.Approving the information security policy and risk appetite statement.
C.Performing vulnerability scans on internal network segments.
D.Monitoring security dashboards and triaging alerts on a daily basis.
E.Configuring and tuning intrusion detection system (IDS) signatures.
AnswersA, B

Reviewing and approving the risk register and formally accepting residual risk are governance responsibilities. They require authority to decide what level of risk the organization will tolerate and to hold risk owners accountable. This oversight ensures that risk decisions are made consistently and at the appropriate level, rather than being delegated to operational teams who implement controls.

Why this answer

Governance involves setting direction, defining risk tolerance, and providing oversight, which includes approving policy and risk appetite and reviewing and accepting residual risks. Operational tasks such as configuring IDS signatures, monitoring dashboards, and running vulnerability scans execute the strategy and controls defined by governance, and are therefore not governance responsibilities.

Exam trap

The trap here is equating any security-related activity with governance; governance is about direction, approval, and oversight, not the hands-on execution of controls.

71
MCQmedium

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

A.Include security requirements in the contract
B.Perform a risk assessment of the vendor
C.Request the vendor's SOC 2 report
D.Conduct an onsite audit of the vendor
AnswerB

Assessing the vendor's risk before engagement establishes whether its controls, data handling and PII exposure are acceptable, and determines the due diligence depth required. Contracting or onboarding first would commit the organisation before understanding residual risk, violating vendor lifecycle best practice.

Why this answer

The first step in the vendor lifecycle is to perform a risk assessment of the vendor (B). Before any contractual, audit, or documentation requests, the organization must understand the risk the vendor poses based on the data it will access (employee PII) and the criticality of the service. This risk assessment determines the appropriate level of due diligence, contractual controls, and ongoing monitoring — it drives all subsequent steps.

Exam trap

CISM often tests the sequence of vendor lifecycle steps — candidates jump to due diligence artifacts (SOC 2, contracts) when the risk assessment must come first to determine what diligence is appropriate.

How to eliminate wrong answers

Option A is wrong because including security requirements in the contract comes after the risk assessment determines what requirements are needed — you cannot draft appropriate controls without first knowing the risk. Option C is wrong because requesting a SOC 2 report is a due diligence activity that follows the risk assessment, which determines whether a SOC 2 is sufficient or additional evidence is needed. Option D is wrong because an onsite audit is a deep-dive due diligence step reserved for high-risk vendors, and it should only be conducted after the risk assessment identifies the need.

72
MCQhard

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

A.The organization is in a highly regulated industry with strict compliance mandates
B.The organization's IT budget is very large
C.The organization has a low number of security incidents historically
D.The organization has a high risk tolerance
AnswerA

Regulatory mandates such as PCI DSS, HIPAA or GDPR compel demonstrable controls, audits and evidence, forcing sustained security spend regardless of appetite. This external obligation, rather than general maturity alone, most plausibly justifies allocating 12% of the IT budget.

Why this answer

A 12% security budget allocation is most likely supported by a highly regulated industry with strict compliance mandates (A). Regulatory requirements (e.g., HIPAA, PCI DSS, GDPR, SOX) mandate specific security controls, audits, and reporting, forcing organizations to invest significantly in security to avoid penalties and maintain compliance. This external pressure justifies and sustains higher security spending compared to discretionary investment.

Exam trap

CISM often tests drivers of security investment — candidates may choose 'large IT budget' or 'low incidents' when the correct driver is regulatory/compliance pressure that mandates spending.

How to eliminate wrong answers

Option B is wrong because a large IT budget does not inherently justify a high security percentage — budget size alone does not drive security investment; risk and compliance requirements do. Option C is wrong because a low number of historical incidents would typically reduce perceived risk and could lead to lower security investment, not support a high allocation. Option D is wrong because high risk tolerance generally leads to lower security investment, as the organization is willing to accept more risk — it does not support a 12% allocation.

73
Multi-Selecteasy

Which THREE of the following are components of a security operations center (SOC)?

Select 3 answers
A.Vulnerability scanning
B.Response
C.Security monitoring
D.Security awareness training
E.Detection
AnswersB, C, E

Response is one of the three SOC components, covering the actions taken once an event is confirmed as an incident, such as containment, eradication and recovery. It complements detection and monitoring within the SOC's operating model.

Why this answer

A SOC is built around the core functions of detection, response, and continuous security monitoring, so options B, C, and E are correct. Detection (E) covers identifying malicious activity through tools such as SIEM correlation rules, IDS/IPS alerts, and endpoint telemetry, which is a primary SOC responsibility. Response (B) covers incident handling activities like triage, containment, eradication, and recovery, which SOC analysts perform once an incident is detected.

Security monitoring (C) is the ongoing 24x7 collection and analysis of logs and alerts from firewalls, endpoints, and network devices that feeds detection and response. Vulnerability scanning (A) is typically a vulnerability management function, and security awareness training (D) is a human-risk/GRC program, so neither is a core SOC component.

74
MCQhard

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

A.Eliminating the requirement for a dedicated security team
B.Reducing the need for automated security testing tools
C.Reducing the frequency of penetration testing
D.Ensuring security is considered during the design and development phases
AnswerD

Champions sit within development teams, so they embed threat modelling, secure coding and abuse-case thinking into design and sprint work before code is written. This satisfies the stem's design-and-development constraint, shifting security left rather than relying on post-hoc testing or central gate reviews.

Why this answer

Security champions act as liaisons, promoting secure coding practices and facilitating communication between security and development, thereby integrating security earlier.

75
MCQeasy

What is the PRIMARY purpose of a security champions program?

A.To embed security advocates in non-security teams to promote security best practices
B.To enforce security policies through peer pressure
C.To conduct security audits of other teams
D.To replace the security team in development projects
AnswerA

Security champions are staff embedded within development, operations, and other non-security teams who advocate secure practises locally. This satisfies the stem's primary purpose by scaling security influence through existing team members rather than centralised security staff alone.

Why this answer

The primary purpose of a security champions program is to embed security advocates within non-security teams (e.g., development, operations) to promote security best practices (A). Champions are team members with an interest in security who receive additional training and act as liaisons between the security team and their functional teams, scaling security awareness and enabling earlier risk identification without adding headcount.

Exam trap

CISM often tests the collaborative nature of security champions — candidates may select enforcement or audit roles when the correct purpose is advocacy, education, and embedding security into non-security teams.

How to eliminate wrong answers

Option B is wrong because enforcing policies through peer pressure is not the purpose — champions promote best practices through collaboration and education, not coercion, which would undermine trust and adoption. Option C is wrong because conducting security audits is the role of the security team or internal audit, not champions — champions are advocates, not auditors, and auditing their own teams would create conflicts. Option D is wrong because replacing the security team in development projects is not the goal — champions augment and support the security team, not replace it; the security team retains accountability for security outcomes.

Page 1 of 3 · 176 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Security Programme questions.