CISM · domain
scenario questions
Practise Certified Information Security Manager CISM scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (924)
Click any question to see the full explanation, or start a practice session above.
A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)
Medium2After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?
Medium3Which of the following is a key reason to have a forensic retainer in place before an incident occurs?
Medium4During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?
Medium5An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?
Hard6You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?
Easy7A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)
Medium8A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?
Medium9During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?
Medium10A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)
Hard11A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?
Medium12A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?
Medium13Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?
Easy14You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?
Medium15Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?
Easy16A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?
Hard17An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?
Easy18A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?
Medium19During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?
Hard20During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?
Easy21An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?
Medium22Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?
Medium23A CISO is reviewing the information security strategy and needs to ensure that security investments are justified in business terms. The CFO has requested that each security initiative be tied to a financial metric that reflects potential loss from cyber events. Which approach is MOST appropriate for the CISO to use?
Medium24During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?
Hard25An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?
Medium26An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
Easy27What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?
Easy28During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)
Hard29A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?
Hard30Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)
Medium31Which of the following are key components of a mature information security program? (Select 2)
Hard32An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Medium33An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?
Hard34As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?
Medium35Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)
Medium36Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?
Medium37An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?
Easy38A healthcare organization is developing its information security strategy. The CISO is considering how to best align the strategy with the organization's overall business strategy. Which of the following approaches would be MOST effective?
Medium39Which of the following incident categories would typically require the involvement of the crisis management team?
Easy40During a major incident, the incident response manager must decide whether to declare a crisis and activate the crisis management team (CMT). Which factor is MOST important in making that decision?
Hard41A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?
Hard42A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?
Medium43Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?
Easy44An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.
Easy45A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?
Medium46A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?
Hard47A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?
Medium48An organization's security program includes a risk assessment process. Which step should be performed FIRST?
Easy49Which of the following best describes the primary purpose of an Information Security Program?
Medium50An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?
Medium51A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?
Hard52An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?
Medium53Which THREE characteristics indicate a higher maturity level in a security program maturity model?
Hard54Which THREE of the following are common challenges in implementing an information security program across a large enterprise?
Hard55During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?
Hard56An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?
Hard57A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?
Medium58An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?
Easy59An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?
Hard60A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?
Medium61During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?
Medium62A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?
Easy63During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?
Easy64Which of the following is the PRIMARY responsibility of the CISO in an organization?
Easy65A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?
Easy66What is the primary purpose of a security incident near-miss reporting culture?
Easy67A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?
Easy68A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?
Easy69An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?
Easy70A financial services firm has activated its crisis management team (CMT) for a significant data breach. The CISO, who is a member of the CMT, is asked to present the technical details of the incident. However, the CMT's primary focus should be on which of the following?
Medium71Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)
Medium72An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?
Hard73A newly appointed CISO is establishing an information security governance framework. The organization has a complex structure with multiple business units, each with its own IT function. The CISO wants to ensure that security decisions are made with input from all relevant stakeholders and that security risks are managed consistently across the enterprise. Which of the following should be the CISO's FIRST step in establishing this framework?
Medium74Which TWO of the following are components of a typical vulnerability management program?
Easy75An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)
Hard76A company is restructuring its security governance due to rapid growth. The CISO reports to the CIO. What is the PRIMARY risk of this reporting structure?
Medium77A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?
Medium78Which THREE of the following are essential components of an information security risk management framework?
Hard79A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?
Hard80Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?
Medium81Which THREE of the following should be included in an incident communication template?
Medium82Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?
Medium83A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?
Medium84Which TWO factors are most important when prioritizing security investments? (Select TWO.)
Medium85A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?
Hard86An organization is developing its incident response plan and wants to ensure that it has the necessary authority and communication channels in place before an incident occurs. Which TWO of the following should be established to enable effective incident response? (Choose two.)
Medium87Which component is essential for building a strong security culture within an organization?
Easy88A CISO is defining the scope of the information security program. The organization has multiple locations and uses cloud services extensively. Which factor is MOST important to consider when defining the program's scope?
Easy89An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?
Hard90During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?
Hard91After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?
Medium92Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?
Easy93Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?
Medium94What is the PRIMARY reason for having an incident response team roster and contact list readily available?
Easy95A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)
Medium96Given the exhibit, what is the MOST significant governance gap in the described architecture?
Easy97In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)
Easy98An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Medium99Which of the following is the PRIMARY responsibility of a steering committee in an information security program?
Easy100A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?
Medium101A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?
Hard102An organization has multiple business units with different risk tolerances. How should the security program address this?
Hard103A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?
Hard104An organization's information security program has a documented risk management process. During a review, the CISO finds that risk assessments are performed annually but do not account for changes in the threat landscape or business environment. Which of the following is the BEST recommendation to improve the program?
Hard105A multinational corporation is establishing an information security governance framework. The board has approved a top-down approach where security policies are created at the corporate level and adapted locally. Which of the following is a key benefit of this approach?
Medium106A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)
Hard107Which TWO of the following are key components of an information security risk assessment? (Choose two.)
Easy108A user reports that their computer is behaving oddly, and an IT technician finds a suspicious file in the startup folder. The technician is not sure if this is an incident. What should the technician do FIRST?
Easy109During a major incident, the incident response team determines that a compromised server must be rebuilt immediately to restore a critical service. A forensic analyst objects, noting that the server contains evidence relevant to a pending regulatory investigation. How should the incident manager resolve this conflict?
Hard110Based on the exhibit, what is the MOST likely issue?
Hard111A security manager is building a risk register for a newly deployed customer relationship management platform. Which TWO of the following entries are most appropriate to record as risks rather than as controls or assets? (Choose two.)
Medium112An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?
Hard113A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget, and they report to their respective business unit leaders. The CISO has limited authority over these teams. A recent incident revealed inconsistent security controls across business units, and the board is concerned about the overall risk posture. Which of the following should the CISO recommend to improve the program's effectiveness?
Medium114Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)
Medium115During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?
Medium116A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?
Hard117An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?
Hard118A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?
Medium119An incident response plan (IRP) is being tested. Which metric is MOST indicative of the team's effectiveness during an exercise?
Easy120A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?
Medium121Which THREE are key components of an effective post-incident review?
Hard122An information security manager is developing a security scorecard for the board. Which of the following should be included to BEST demonstrate governance performance?
Easy123A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?
Hard124An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?
Medium125A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?
Medium126Which THREE of the following are key phases of the incident management lifecycle according to NIST or ISO? (Choose three.)
Easy127A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)
Hard128An organization's security steering committee meets quarterly but lacks decision-making authority. Projects are delayed due to lack of prioritization. What is the most effective improvement?
Medium129Which TWO of the following are primary objectives of a security awareness program?
Easy130A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?
Medium131An incident response team discovers that an employee's workstation is infected with malware. The workstation contains sensitive customer data. Which of the following is the MOST appropriate containment strategy?
Easy132Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?
Medium133A multinational corporation is designing an information security strategy to support its global operations. Which approach best ensures that the strategy is actionable and measurable?
Medium134An organization's security operations center (SOC) confirms that a production database server is actively exfiltrating customer records to an external IP address. The SOC manager must decide whether to immediately isolate the server from the network. Which factor should PRIMARILY guide this decision?
Medium135An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?
Medium136A multinational corporation is experiencing significant security incidents due to inconsistent security policies across subsidiaries. The CISO proposes implementing a centralized governance model. However, business unit leaders argue that local regulations require autonomy. Which approach best balances governance with local compliance?
Hard137An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard138A security manager is drafting the escalation criteria for the incident response plan. The organisation wants to ensure that incidents are escalated to the crisis management team (CMT) appropriately. Which of the following is the BEST basis for defining when an incident should be escalated to the CMT?
Medium139A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?
Hard140A security operations center receives an alert from an IDS indicating possible command and control traffic. The analyst is unsure if it's a true positive. Which combination of actions should be taken first?
Hard141A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?
Medium142A CISO is reviewing the organization's information security program and wants to improve its maturity. Which of the following are characteristics of a mature information security program? (Choose two.)
Medium143Which of the following is a key objective of implementing a security champions program?
Easy144Which incident severity level requires executive notification and 24/7 response, and has major business impact?
Easy145An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
Hard146A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?
Medium147Refer to the exhibit. An information security manager reviews the risk register and sees that Risk ID R001 has a residual risk of High with a treatment of Accept. Which of the following best explains why this situation may indicate a governance failure?
Medium148An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?
Hard149A financial services company has a policy requiring annual risk assessments for all critical vendors. During an internal audit, it is discovered that several vendors have not been reassessed in over two years. The CISO needs to address this governance gap. Which action should be taken FIRST?
Medium150An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?
Medium151A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)
Hard152A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?
Easy153An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?
Medium154A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?
Medium155A security analyst receives an alert from the SIEM indicating that a user account has been added to the domain administrators group outside of the change management window. The analyst confirms the change was not authorized. According to CISM incident management principles, what should the analyst do FIRST?
Easy156A CISO is presenting the information security program's value to the board. The board is particularly concerned about the organization's ability to detect and respond to advanced threats. Which of the following metrics would BEST demonstrate the program's effectiveness in this area?
Medium157An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?
Easy158A security manager learns that a production database containing customer records was copied to an unauthorized external drive by a contractor. The incident response team has contained the contractor's access. According to CISM best practices, which action should the security manager take NEXT?
Medium159An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Hard160A large enterprise experiences a data breach involving personal identifiable information (PII) of customers. The incident response team has contained the breach and is now in the eradication phase. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is MOST critical?
Hard161Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?
Medium162A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?
Medium163A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?
Easy164In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?
Medium165A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?
Hard166A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?
Medium167An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?
Hard168An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)
Hard169An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?
Easy170An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?
Hard171Which of the following is the primary reason for conducting a lessons learned meeting after an incident?
Easy172An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?
Easy173Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?
Hard174During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?
Medium175Which of the following is the PRIMARY reason for including communication templates in the incident response plan?
Easy176An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?
Medium177A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?
Medium178A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)
Hard179A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?
Hard180Which of the following is the best indicator that an organization has effective information security governance?
Easy181During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?
Hard182Which TWO of the following are examples of risk mitigation controls? (Choose two.)
Easy183An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?
Medium184An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?
Medium185A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?
Medium186A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?
Easy187A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?
Medium188A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
Hard189Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?
Easy190After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?
Medium191A global financial services firm is establishing an information security governance framework. The board of directors wants assurance that security risks are managed effectively across all business units. Which of the following is the MOST important element for the CISO to implement to provide this assurance?
Medium192Based on the risk register entry, what is the primary gap in the current controls?
Easy193A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?
Easy194A multinational corporation operates in multiple jurisdictions with varying data protection laws. The CISO is establishing a governance structure to manage compliance with these laws while maintaining a consistent security posture. Which of the following is the MOST effective approach for the CISO to take?
Hard195A multinational corporation has a decentralized information security program. Each business unit manages its own security budget and controls, leading to inconsistent practices and duplicated efforts. The CISO wants to improve program efficiency and effectiveness while respecting business unit autonomy. Which of the following is the BEST approach?
Medium196According to the exhibit, which role is responsible for conducting forensic analysis?
Medium197A CISO has implemented a security program based on ISO/IEC 27001. During a management review, the CIO asks how the program contributes to business value. Which of the following metrics would BEST demonstrate the program's contribution to business value?
Hard198A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that the framework will effectively manage risk and comply with regulations such as GDPR and PCI DSS. Which of the following are essential components of an effective information security governance framework? (Choose two.)
Hard199Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?
Easy200A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?
Easy201An organization's information security governance committee has not met for the past six months. Which of the following is the most significant risk associated with this situation?
Hard202A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?
Hard203During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?
Medium204During a major incident, the incident response manager is coordinating containment while the crisis management team (CMT) handles business continuity decisions. A responder proposes immediately wiping and rebuilding an affected server to restore service quickly, but the server contains evidence relevant to a potential legal action. Which of the following is the MOST appropriate action for the incident response manager to take?
Hard205Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)
Hard206A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?
Easy207After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?
Medium208A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?
Hard209Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?
Easy210A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?
Hard211During a live intrusion, the incident response lead must decide how the team will communicate. The attackers are believed to be monitoring the corporate email and collaboration platform. Which of the following is the MOST appropriate action to maintain confidentiality of incident communications?
Hard212An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?
Medium213An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?
Hard214An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?
Medium215Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
Easy216Given the exhibit, what is the most likely classification of this incident?
Medium217Which capability maturity model (CMM) level indicates that security processes are measured and controlled?
Easy218An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?
Hard219An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?
Easy220During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
Hard221A financial institution is integrating a newly acquired fintech startup. The startup has a very different security culture. What governance approach best ensures integration without stifling innovation?
Hard222You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?
Medium223A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?
Hard224What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy225Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?
Medium226Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?
Easy227A security manager is reviewing the organization's information security governance framework. The board has expressed concern that security decisions are not consistently aligned with the organization's risk appetite. Which of the following would BEST address this concern?
Hard228Which of the following is a leading indicator for security performance?
Medium229During a merger, the acquiring company's board insists on integrating the target company's information security governance into its own within 90 days. However, the target has a significantly different risk culture and lacks documented policies. What is the most critical governance risk in this scenario?
Hard230A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?
Easy231An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?
Medium232During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?
Medium233During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?
Hard234A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?
Medium235You are the information security manager for a mid-sized e-commerce company. The company operates a web application that handles credit card transactions and stores customer data in a backend database. The incident response team has just been alerted to a potential data breach: an intrusion detection system (IDS) flagged a SQL injection attack pattern on the web application's login page. The attack originated from an external IP address (5.5.5.5) and appears to have been successful, as the IDS also detected a large outbound data transfer from the database server to another external IP (6.6.6.6) shortly after. The database server is not segmented from the web server. The company has a legal obligation to report breaches involving cardholder data within 72 hours. The incident response plan is being activated. The team includes a forensic analyst, a network engineer, and a legal advisor. The web application is currently running and serving customers. The CEO wants to minimize business disruption. Which of the following actions should the incident response team take FIRST?
Medium236Which governance structure is characterized by a single security team that serves the entire organization?
Easy237Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?
Medium238A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?
Easy239An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next critical step?
Easy240An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?
Medium241A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?
Medium242An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?
Easy243A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?
Easy244A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?
Hard245A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?
Hard246An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)
Hard247An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?
Medium248Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)
Medium249A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?
Hard250Which TWO actions are appropriate during the containment phase of an incident involving a malware outbreak on multiple workstations?
Medium251During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?
Easy252An organization's incident response plan has not been updated in two years. Which of the following is the MOST likely consequence?
Easy253Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?
Hard254A multinational retailer's security operations center (SOC) identifies that an attacker has compromised a point-of-sale (POS) system in a European store and is moving laterally toward the payment card processing environment. The incident response manager needs to decide the FIRST action to limit business impact while preserving the ability to investigate. Which action should be taken FIRST?
Medium255During a major incident, the incident response team discovers that the attacker is still active in the environment and is moving laterally. The incident response manager must decide on the immediate course of action. Which of the following should be the PRIMARY consideration when determining whether to isolate affected network segments?
Hard256Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?
Easy257A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?
Easy258An organization is developing its incident response plan. The CISO wants to ensure that the plan includes provisions for communicating with external parties during and after an incident. Which of the following should be the PRIMARY consideration when defining external communication procedures?
Medium259A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?
Medium260An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?
Medium261A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?
Easy262Which TWO of the following are common approaches to information security risk assessment?
Medium263A security audit has identified several governance weaknesses. Which TWO of the following are most likely to indicate a lack of effective information security governance? (Choose two.)
Easy264A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?
Hard265A CISO is reviewing the organization's risk management process. The board has asked how the CISO ensures that security risks are managed within the organization's risk appetite. Which activity BEST demonstrates this?
Hard266An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?
Easy267An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)
Medium268An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?
Medium269An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?
Hard270A financial institution is restructuring its information security governance to comply with a new regulatory requirement that mandates a formal risk appetite statement. The board has conflicting views on the level of risk to accept. Which of the following should the information security manager do to facilitate the definition of risk appetite?
Hard271During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?
Medium272Which of the following is the primary purpose of communicating risk assessment results to senior management?
Easy273A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?
Hard274A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?
Medium275A security analyst detects an unusual spike in outbound traffic from a database server. Which of the following is the FIRST step in the incident response process?
Easy276A retail company's security operations center receives an alert that a point-of-sale terminal is communicating with a known malicious command-and-control domain. The analyst confirms the connection is active. According to incident response best practices, which action should the analyst take FIRST?
Easy277A global retailer is establishing an information security governance framework. The CISO must ensure that the framework addresses both internal and external requirements. Which THREE of the following are essential components of an effective information security governance framework? (Choose three.)
Hard278A financial services firm has just contained a breach in which an attacker exfiltrated customer records from a database server. Legal counsel advises the incident manager that the matter will likely result in litigation and regulatory inquiry. Which TWO actions should the incident manager take to preserve the evidentiary value of the affected server? (Choose two.)
Hard279A company's incident response plan defines roles for the incident response team, but during a recent tabletop exercise it became clear that no one had authority to make binding decisions about shutting down production systems. Which of the following should be established to resolve this gap?
Easy280Which of the following is the PRIMARY benefit of having a formal policy exception management process?
Medium281Which control family in NIST SP 800-53 addresses the identification and authentication of users?
Easy282A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)
Medium283Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?
Hard284Which of the following is the PRIMARY purpose of an incident response plan?
Easy285An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?
Hard286A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)
Hard287A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?
Hard288A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?
Medium289Which document should be reviewed and updated at least annually?
Easy290Which TWO of the following are key components of an information security governance framework? (Choose two.)
Medium291A multinational organisation suffers a breach affecting customers in several jurisdictions. The incident response manager must coordinate notification obligations while the investigation is still ongoing and facts are incomplete. Which of the following is the MOST appropriate approach?
Hard292A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?
Medium293An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?
Hard294A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?
Hard295Which THREE of the following are key performance indicators (KPIs) for an information security program?
Medium296An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?
Easy297An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?
Easy298An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?
Medium299An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?
Hard300A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?
Medium301An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?
Medium302A security operations centre (SOC) analyst receives an alert that a production database server is transmitting large volumes of customer data to an external IP address. The analyst confirms the traffic is malicious. According to CISM best practices, which of the following should the analyst do FIRST?
Medium303A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)
Medium304A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?
Hard305A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?
Medium306An organization has completed its response to a data breach and is conducting a post-incident review. Management wants assurance that lessons learned will actually improve future response capability. Which outcome BEST demonstrates that the post-incident review achieved this objective?
Medium307A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?
Hard308A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?
Medium309A CISO is designing a security governance framework for a multinational corporation. The framework must address the need for clear accountability, alignment with business strategy, and effective risk management across diverse business units. Which TWO of the following are essential components of such a governance framework? (Choose two.)
Hard310A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?
Easy311A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?
Easy312In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?
Easy313Which TWO of the following are essential components of a security program governance structure?
Medium314During a forensic investigation, the external forensics firm discovers evidence that may indicate criminal activity. The incident manager wants to ensure attorney-client privilege is maintained. What should be done?
Hard315An organization experiences a DDoS attack that overwhelms their internet connection. Which containment strategy would be MOST effective?
Easy316An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?
Medium317Order the steps for establishing a security incident response team (IRT).
Medium318An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
Hard319Which THREE of the following are typical roles in an incident response team?
Easy320An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?
Hard321During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?
Medium322Match each risk management term to its definition.
Medium323After a ransomware attack, the incident response team successfully restores systems from backups. However, the ransomware encrypts files that were modified after the last backup was taken. Which of the following is the BEST way to minimize future data loss?
Hard324An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?
Medium325Which of the following best describes residual risk?
Easy326A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?
Easy327Which TWO metrics are considered leading indicators for information security program performance?
Medium328A financial institution is designing an incident response plan. They want to ensure that during a ransomware incident, critical transaction systems can be restored within 4 hours. Which metric should be used to measure this requirement?
Medium329A retail company suffers a breach involving payment card data. The incident response manager must decide whether to engage external forensic investigators and outside counsel. Which of the following is the PRIMARY reason to bring in external expertise at this point?
Medium330A mid-sized manufacturing firm has decided to transfer the risk of a ransomware attack on its production network by purchasing a cyber insurance policy. The policy includes a $1 million coverage limit and a $50,000 deductible. Six months later, a ransomware incident causes $400,000 in recovery costs. The insurer approves the claim. What is the organization's financial responsibility for this incident?
Easy331A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?
Hard332A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?
Hard333In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
Hard334Which THREE of the following are challenges in implementing information security governance in a decentralized organization?
Hard335After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?
Medium336After a security incident, the incident response team identifies that the root cause was a phishing email that bypassed the email filter. The email contained a malicious macro that executed PowerShell commands. Which control would be MOST effective in preventing similar incidents in the future?
Hard337A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?
Medium338Arrange the steps for implementing a new firewall rule in an enterprise environment.
Medium339An organization's incident response team is notified of a potential denial-of-service (DoS) attack targeting their web application. The team suspects a distributed denial-of-service (DDoS) attack. What is the FIRST step the team should take?
Medium340A CISO at a healthcare payer is revising the incident response plan after a tabletop exercise exposed confusion about who may commit the organization to public statements and remediation costs during a major breach. The board wants clarity on governance-level decision rights that must exist before the next incident. Which TWO activities should be assigned to the crisis management team rather than to the tactical incident response team? (Choose two.)
Hard341An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?
Hard342During an incident, the incident response team needs to preserve evidence for legal proceedings. Which of the following is the MOST important action to take?
Easy343A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)
Hard344Which THREE steps are essential in the post-incident review process?
Easy345A large enterprise is implementing a new governance framework. The board has approved a risk appetite statement. What is the MOST important next step for the information security manager?
Medium346A CISO is developing a set of information security policies for a healthcare organization. The organization must comply with HIPAA and internal privacy requirements. Which of the following should be the PRIMARY consideration when drafting the security policy framework?
Easy347A security manager is reviewing the incident response plan and notices that the plan does not specify how to handle a situation where the incident response team cannot reach the primary incident response manager. What should be done to address this gap?
Hard348A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?
Medium349A security manager is developing key performance indicators (KPIs) for the information security program. Which of the following is the MOST important characteristic of an effective KPI?
Easy350After a security incident, the incident response team prepares a report detailing the root cause, impact, and lessons learned. Who is the PRIMARY audience for this report?
Easy351A small business is developing its first information security program. Which approach is most effective?
Easy352Which THREE of the following are common challenges in incident response? (Select exactly 3)
Medium353An organisation has just completed containment of a significant data breach. The incident response manager is preparing the post-incident review. Which of the following activities BEST ensures that lessons learned translate into lasting improvement of the incident response capability?
Medium354A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget. The CISO wants to improve consistency and reduce duplication of efforts. Which of the following is the MOST effective approach?
Hard355A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?
Hard356A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?
Easy357Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?
Hard358An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)
Easy359An organization is developing its incident response capabilities and wants to ensure that it can effectively detect and respond to security incidents. Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Choose two.)
Medium360Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?
Medium361Which of the following are key components of an information security program's strategic plan? (Select two.)
Medium362Acme Corp, a global manufacturer, has a decentralized security governance model. Each business unit manages its own security, resulting in inconsistent policies and repeated audit findings. The new CISO proposes a federated model where a central team sets minimum standards and each unit can add local controls. However, the European unit's head insists on full autonomy due to GDPR strictness. The board is concerned about compliance costs. What should the CISO do first?
Hard363In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?
Easy364During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?
Hard365Which incident category involves unauthorized access to systems or data by an individual within the organization?
Easy366Which THREE of the following are key activities in a third-party risk management (TPRM) program?
Medium367A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to the business and driving continuous improvement. Which of the following are the MOST appropriate key performance indicators (KPIs) for the information security program? (Choose two.)
Hard368During a phishing campaign, several employees clicked a malicious link that downloaded a remote access trojan (RAT). The incident response team has isolated the infected endpoints and is analyzing network traffic. They suspect that data may have been exfiltrated but are unsure. The team needs to determine the extent of data exfiltration as quickly as possible. What action should the team take FIRST?
Medium369Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)
Hard370Which THREE of the following are essential components of a mature information security governance framework?
Hard371An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?
Medium372Which incident severity level requires executive notification and a 24/7 response?
Easy373A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?
Hard374An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?
Medium375You are the CISO of a mid-sized e-commerce company with 500 employees. The company recently suffered a data breach where an attacker exfiltrated customer credit card data from the production database. The investigation revealed that the breach originated from a compromised developer workstation. The developer had been granted direct access to the production database for troubleshooting purposes, a practice that had been in place for years. The security governance framework currently lacks a formal process for managing privileged access. The board has asked for immediate improvements to prevent recurrence. Which course of action BEST addresses the governance gap?
Hard376Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?
Hard377A financial services firm's incident response team has contained a credential-stuffing attack that compromised several customer accounts. The CISO asks the incident manager to determine what should happen next before the team stands down. Which action BEST aligns with CISM incident management practices?
Medium378A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?
Medium379A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
Medium380During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?
Medium381An organization's information security strategy is being developed. The CISO wants to ensure that the strategy supports business objectives while managing risk. Which of the following should be the PRIMARY input to the strategy development process?
Easy382Which TWO of the following are primary responsibilities of the board of directors in information security governance?
Easy383A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?
Hard384A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?
Medium385After a merger, the combined organization has two different risk tolerance levels: one entity is risk-averse, the other is risk-taking. What is the best governance action?
Hard386A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?
Easy387During a security audit, several deviations from policy are found. What should the security manager do first?
Medium388A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?
Hard389A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?
Medium390A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)
Hard391Which of the following is the primary purpose of an Information Security Program?
Easy392An organization has recently experienced a data breach that resulted in the loss of customer personally identifiable information (PII). The board of directors is concerned about the effectiveness of the information security governance program. Which of the following should the CISO recommend as the MOST important action to improve governance?
Easy393A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)
Medium394A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?
Medium395A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?
Hard396An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?
Medium397An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)
Medium398A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?
Easy399Which TWO of the following are essential components of an information security program charter?
Easy400A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?
Hard401An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?
Hard402A CISO is establishing a security governance framework for a decentralized organization where each business unit operates independently. The CISO wants to ensure that security policies are consistently applied while respecting business unit autonomy. Which two actions are MOST appropriate to achieve this? (Choose two.)
Hard403An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?
Easy404A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?
Hard405The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?
Hard406Which THREE of the following are components of a security operations center (SOC)?
Easy407A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?
Hard408During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?
Medium409In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?
Easy410Which of the following is the primary responsibility of the board of directors in information security governance?
Easy411What is the PRIMARY purpose of a security champions program?
Easy412An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?
Medium413Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?
Easy414An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?
Hard415Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?
Easy416After containing a security incident, the team conducts a root cause analysis. They find the breach originated from a compromised third-party vendor account. What is the most effective long-term mitigation?
Medium417An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?
Medium418A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?
Medium419A multinational corporation is designing its information security governance framework. The board has requested a single metric that best indicates the effectiveness of the security program. Which metric would BEST satisfy this request?
Hard420An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?
Medium421During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?
Medium422Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
Hard423Which document should be created FIRST when establishing an information security program?
Easy424A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?
Easy425A financial services company is updating its information security policies to reflect a new regulation. The CISO must ensure the policies are effectively communicated and enforced. Which action is MOST important to achieve this?
Medium426A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?
Medium427A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?
Easy428Which of the following are key components of an effective information security program? (Select TWO.)
Medium429Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?
Easy430Which TWO of the following are PRIMARY goals of incident management according to industry best practices?
Easy431Which role is primarily responsible for designing and reviewing an organization's security architecture?
Easy432During a major incident, the incident response team has contained the threat but recovery is taking longer than expected. The business continuity manager reports that the manual workaround in place will fail within four hours due to capacity limits. Which action should the incident manager take FIRST?
Hard433An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?
Easy434A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?
Hard435During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)
Easy436In a security awareness program, which training approach is most appropriate for software developers?
Medium437An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?
Medium438Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?
Easy439An organization is defining the composition of its incident response team. Which role is PRIMARILY responsible for coordinating communication with the media and the public during a high-profile incident?
Easy440Which of the following best describes a key benefit of a centralized information security governance model?
Easy441A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?
Medium442An information security program must include elements to ensure continuous improvement. Which TWO of the following are MOST essential for continuous improvement?
Medium443An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?
Medium444Which of the following is the BEST example of a board-level security metric?
Easy445Which THREE of the following are considered key components of an incident response plan?
Medium446After a phishing attack, an organization's incident response team identifies that the attacker gained access to an email account and sent internal spear-phishing emails. What is the BEST immediate containment action?
Hard447A CISO is developing a set of metrics to report to the board on the effectiveness of the information security governance program. Which of the following metrics would BEST demonstrate that security governance is aligned with business objectives? (Choose two.)
Hard448A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)
Hard449A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?
Easy450Which of the following are key components of an information security program? (Select TWO)
Easy451A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?
Medium452An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?
Hard453Arrange the steps for deploying a security patch to critical servers in a production environment.
Medium454During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?
Medium455Arrange the steps for performing a vulnerability scan on a network segment.
Medium456During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?
Hard457An organization's incident response plan includes a call tree. During an incident, the primary contact is unreachable. What should happen?
Medium458Which of the following is a leading indicator of security program effectiveness?
Easy459Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)
Medium460A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?
Easy461A healthcare organization's information security program has a risk register with several high-risk items. The CISO is allocating budget for risk treatment. Which of the following is the MOST important factor when deciding whether to mitigate, transfer, or accept a risk?
Hard462A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
Medium463Which TWO elements are key components of a security culture measurement program?
Easy464A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?
Medium465An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?
Hard466After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?
Hard467An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?
Hard468An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?
Easy469Which THREE of the following are best practices for handling evidence during an incident investigation?
Hard470A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?
Easy471An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?
Medium472What is the primary function of a Security Operations Center (SOC)?
Easy473A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)
Medium474A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?
Hard475Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?
Easy476Order the steps for a risk assessment process according to ISACA's risk management framework.
Medium477In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?
Medium478During a security incident, the incident response team discovers that an attacker has exfiltrated data via an encrypted tunnel over HTTPS. Which log source is MOST likely to provide evidence of the exfiltration?
Hard479A global financial services firm is aligning its information security program with the COBIT framework. The board wants assurance that IT risks are governed effectively. Which COBIT component is MOST directly responsible for ensuring that IT risk management activities are aligned with enterprise risk management?
Hard480An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?
Easy481A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)
Hard482Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?
Easy483An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?
Hard484Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?
Medium485A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?
Hard486A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?
Hard487A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that security risks are managed effectively and that the program aligns with regulatory requirements. Which TWO elements are MOST critical for the CISO to define as part of this governance framework? (Choose two.)
Medium488An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?
Medium489During an incident investigation, the response team discovers that the attacker exploited a known vulnerability for which a patch was available but not applied. What should be the team's primary focus during the recovery phase?
Medium490An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:
Hard491BankOne has a mature security governance program but recently failed a regulatory audit because the board had not formally approved the risk appetite statement. The CISO argues that risk appetite is reviewed annually and was verbally approved. To prevent recurrence, what governance change is most effective?
Medium492Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)
Hard493A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
Easy494A multinational corporation is implementing a risk-based approach to information security governance. The chief information security officer (CISO) has been asked to prioritize security initiatives based on business impact. Which of the following actions should the CISO take FIRST to align security governance with business objectives?
Medium495A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?
Hard496During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?
Medium497An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?
Medium498A CISO is developing an information security governance framework for a financial institution. Which of the following is the PRIMARY purpose of such a framework?
Easy499You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?
Medium500An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)
Hard501Which of the following is the most important factor for ensuring the long-term success of an information security program?
Easy502In a third-party risk management programme, what is the primary purpose of vendor tiering?
Medium503After an incident is contained and eradicated, the incident response team conducts a post-incident review. Which of the following is the PRIMARY objective of this review?
Medium504A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?
Hard505Which of the following is the PRIMARY purpose of a security awareness program?
Easy506An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Medium507An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)
Medium508A security program lacks executive support. What is the best strategy to gain support?
Hard509During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?
Hard510An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)
Medium511Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)
Easy512During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?
Medium513An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?
Medium514Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)
Medium515An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?
Easy516A multinational corporation has just detected a ransomware attack that encrypted critical files on a file server. The incident response team has been activated. Which of the following should be the FIRST action taken by the team?
Medium517Which TWO of the following are key components of an effective incident response plan?
Medium518A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?
Hard519A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?
Hard520A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?
Hard521After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?
Hard522A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?
Easy523A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?
Hard524An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?
Hard525An organization plans to implement ISO/IEC 27001 to formalize its information security management system. Which step is most critical to ensure successful implementation?
Easy526An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?
Hard527A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?
Medium528A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?
Hard529An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?
Medium530After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?
Hard531A CISO is developing a business case for a new security initiative. The organization's executives are focused on cost reduction and operational efficiency. Which of the following approaches is BEST to gain executive support?
Medium532Which TWO of the following are indicators of a potential security incident?
Easy533Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?
Medium534An organization's security monitoring system detects multiple failed login attempts from an internal IP address to a critical database server. The attempts are occurring every few seconds. What is the FIRST step the incident response team should take?
Easy535A security analyst detects unusual outbound network traffic from a database server to an unknown IP address. The traffic uses encrypted connections on port 443. Which type of attack is MOST likely occurring?
Medium536A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?
Hard537A retail company's security governance includes a policy that all software must be approved by a security committee. This delays critical business applications. The CIO complains. How should the CISO adjust governance?
Easy538A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?
Medium539Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Easy540Match each security control type to its example.
Medium541Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?
Easy542Which THREE of the following are responsibilities of the board of directors regarding information security governance?
Medium543A CISO is establishing an information security governance framework to ensure that security activities are aligned with business strategy. The organization has multiple business units, each with its own IT and security staff. Which of the following is the MOST effective way to ensure ongoing alignment?
Medium544Which is a key component of an information security program?
Easy545Based on the exhibit, what is the most significant security gap in this configuration?
Medium546A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)
Medium547During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?
Medium548An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?
Medium549A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?
Easy550TechStart, a cloud-based startup, has rapidly grown from 50 to 500 employees. It lacks a formal security governance structure. The CEO asks the CISO to develop one. The CISO finds that the company's culture values speed over compliance. The board expects a governance framework within three months. What is the most practical approach?
Medium551An organization's information security program is being developed. The CISO needs to ensure that the program's objectives are aligned with the organization's strategic goals. Which of the following is the BEST source of input for defining the security program's objectives?
Easy552A financial services firm has activated its incident response team for a suspected insider data theft. The legal department advises that the matter may become a criminal case. The security manager must decide how to handle the forensic images and analyst notes. Which action BEST supports both the investigation and potential legal proceedings?
Hard553An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?
Easy554An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?
Medium555Which security team role is primarily responsible for defining and maintaining security architecture standards?
Easy556Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?
Easy557Which THREE elements are essential for an effective information security governance framework?
Medium558A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)
Medium559A multinational corporation must comply with both GDPR and CCPA. Which governance approach is most effective?
Medium560A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?
Medium561A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?
Medium562A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?
Hard563When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?
Easy564A retail company is building an information security risk register to support its risk management program. The risk manager wants to ensure the register captures the information needed to track and report risks to senior management. Which TWO of the following are essential elements that should be included for each identified risk? (Choose two.)
Medium565An organization is implementing a new cloud-based ERP system. Which of the following is the MOST important action for the information security manager to ensure alignment with the organization's risk appetite?
Medium566You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?
Hard567A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?
Medium568An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?
Hard569Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?
Medium570Which role is primarily responsible for developing and maintaining the organization's security architecture?
Easy571A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?
Medium572A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?
Medium573A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?
Medium574A security manager is drafting the incident classification section of the incident response plan. Executives want a documented, repeatable way to rank incidents so that notification and escalation paths are triggered consistently. Which of the following should be the PRIMARY basis for assigning an incident severity level?
Medium575Which TWO actions are essential during the detection and analysis phase of incident response?
Medium576Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?
Easy577During a suspected insider data theft investigation, the incident response team discovers that the suspect's laptop is still powered on and logged in. Legal counsel advises that evidence must be preserved for potential litigation. Which of the following actions should the team take FIRST?
Hard578A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?
Hard579A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?
Medium580An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?
Medium581A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?
Medium582During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?
Hard583A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?
Hard584After a security incident, which step should be taken first?
Easy585An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?
Easy586During a major data breach, the incident response manager needs to determine whether the organization must notify regulators and affected individuals. Which factor is MOST important in making this determination?
Hard587After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?
Hard588A global insurance provider has completed a risk assessment for a new policyholder web portal. The risk treatment plan includes purchasing cyber insurance to transfer a portion of the financial impact. Which of the following is the PRIMARY consideration when evaluating this treatment option?
Medium589An organization's information security strategy is being updated to align with the business goal of expanding into new markets. The CISO must ensure that the strategy addresses the varying legal and regulatory requirements of these markets. Which of the following should be the PRIMARY consideration when updating the strategy?
Hard590A CISO is updating the organization's information security policy to reflect a new regulatory requirement. The policy must be approved before it can be communicated to employees. Who is MOST appropriate to approve the updated policy?
Easy591During an incident investigation, the incident response team needs to collect volatile data from a compromised server. Which of the following data should be collected FIRST?
Easy592Which governance model is characterized by a single, centralized security team that serves the entire organization?
Easy593Which TWO of the following are primary objectives of information security governance? (Choose two.)
Easy594A security architect is selecting controls for an e-commerce platform. Which TWO of the following are examples of compensating controls?
Easy595Which of the following best describes the primary purpose of a security program's governance framework?
Medium596When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?
Medium597Order the steps for implementing a security awareness training program.
Medium598A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)
Medium599A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?
Hard600A CISO is updating the enterprise information security strategy. The organization's business strategy now emphasizes rapid expansion into cloud-based services and third-party partnerships. Which of the following should be the CISO's FIRST action to ensure the security strategy remains aligned with the business strategy?
Medium601A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?
Medium602An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?
Hard603During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?
Hard604Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?
Easy605Which TWO of the following are typically considered key components of an information security governance framework?
Easy606During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?
Hard607Which of the following is the PRIMARY purpose of an information security risk assessment?
Easy608After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?
Medium609A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?
Medium610A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?
Hard611An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)
Medium612Which TWO components are essential for an effective information security governance framework?
Easy613Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)
Easy614In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?
Medium615What is the primary purpose of a vulnerability management program?
Easy616A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?
Medium617You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?
Easy618A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?
Medium619A global financial services firm is revising its information security governance framework. The board of directors has expressed concern that the current security strategy is not adequately aligned with the firm's business objectives and regulatory obligations. The CISO is tasked with improving this alignment. Which of the following actions would BEST address the board's concern?
Hard620Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?
Easy621Which of the following is the FIRST step in the security policy development lifecycle?
Medium622A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?
Hard623An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?
Medium624A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?
Medium625An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?
Medium626A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?
Medium627A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?
Hard628During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?
Hard629Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)
Hard630During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?
Hard631A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?
Medium632Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?
Easy633An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?
Hard634An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?
Medium635A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?
Hard636Which THREE of the following are essential components of an information security governance framework?
Medium637A global retailer is expanding into new markets and must comply with varying data protection laws. The CISO is revising the information security strategy to ensure it remains aligned with the changing business environment. Which approach BEST ensures ongoing alignment between the security strategy and business objectives?
Hard638A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?
Hard639Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?
Medium640An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?
Medium641A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?
Hard642An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?
Medium643Which board-level committee typically receives security reports to provide oversight?
Medium644A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?
Hard645An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?
Hard646A CISO is presenting the information security program's annual report to the board. The board is concerned about the rising cost of cyber insurance and wants to understand how the program can help reduce premiums. Which of the following actions would MOST directly influence the cost of cyber insurance?
Hard647A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?
Hard648An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?
Hard649Which of the following is a LEADING indicator of security performance?
Easy650An organization has just recovered from a ransomware attack and restored systems from backups. Before returning to normal operations, what is the MOST important step?
Hard651A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?
Hard652Which THREE of the following are essential components of an incident response plan? (Select exactly 3)
Hard653An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?
Medium654During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?
Medium655An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?
Hard656An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?
Easy657Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?
Easy658A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?
Medium659A security analyst detects unusual outbound traffic from a critical server to an unknown external IP address during business hours. Which step should be taken FIRST in the incident response process?
Easy660Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy661A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?
Easy662A healthcare organization is developing an information security strategy. The board has mandated that the strategy must support innovation while protecting patient data. Which governance approach BEST balances these priorities?
Hard663Based on the exhibit, what is the MOST likely scenario?
Medium664Order the steps for implementing a data classification policy in an organization.
Medium665During an incident, the response team collects volatile data from a compromised server. Which of the following should be collected FIRST to minimize loss of evidence?
Medium666Which of the following is the PRIMARY benefit of a security champions program?
Easy667An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?
Easy668Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?
Hard669An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?
Medium670During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?
Medium671A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
Medium672An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?
Medium673During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?
Medium674A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?
Medium675After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)
Medium676A company is considering outsourcing its security operations center (SOC). Which governance consideration is MOST critical before finalizing the decision?
Hard677A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?
Medium678An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)
Hard679A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?
Hard680A software company is defining the roles and responsibilities within its information security programme. The CISO wants clarity on who is accountable for ensuring that security requirements are integrated into the software development lifecycle. Which role should be assigned this accountability?
Easy681A security awareness manager is designing role-based training. Which training is most appropriate for software developers?
Medium682An organization experiences a data breach involving customer personally identifiable information (PII). The incident response team has contained the breach. Which of the following should be the PRIMARY consideration when deciding whether to notify affected customers?
Hard683An organization is establishing a new information security program. The CISO needs to ensure that the program's structure and processes are aligned with the organization's overall business strategy. Which of the following should be the CISO's FIRST step?
Easy684Which of the following is the primary objective of a security champions programme?
Easy685An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?
Medium686Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?
Medium687A CISO is developing a set of key risk indicators (KRIs) to monitor information security governance effectiveness. The CISO wants to ensure that the KRIs are actionable and aligned with business objectives. Which two characteristics are MOST important for effective KRIs? (Choose two.)
Hard688An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?
Easy689A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?
Easy690The security team is designing a security awareness program. Which topic should be prioritized FIRST?
Easy691An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
Medium692Which of the following is the PRIMARY purpose of a security champions program?
Easy693An analyst receives an alert indicating a potential data exfiltration. The alert shows a host IP address 10.10.50.200 sending large amounts of data to an external IP address 203.0.113.5 over port 443. What should the analyst do FIRST?
Easy694An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?
Easy695Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?
Hard696The following incident response configuration is set: ``` playbook: standard actions: - notify: incident_response_team - auto_containment: true priority_override: false ``` Based on the configuration snippet, what is the expected behavior when an incident is triggered?
Hard697Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)
Hard698A company discovers a credential compromise affecting multiple user accounts. According to best practices, what is the first step the incident response team should take?
Hard699A multinational corporation is implementing an information security governance framework. The board has requested a mechanism to ensure that security investments align with business objectives. Which of the following is the BEST approach to achieve this alignment?
Medium700An incident response plan should include which three key components to ensure effective response? (Choose three.)
Medium701Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?
Easy702Which TWO are key indicators of a data breach? (Choose two.)
Easy703Which of the following best describes the role of the chief information security officer (CISO) in a governance context?
Medium704An organization has a mature incident management process. After a major incident, they conduct a post-incident review. Which activity is MOST important during this review?
Medium705After a ransomware attack, a company discovers that backups are also encrypted. The incident response team has isolated the affected systems. What should be the next step?
Medium706A newly appointed CISO is reviewing the organization's information security policy framework. The board asks which document should define the organization's overall security objectives and assign responsibilities at the highest level. Which document is MOST appropriate for this purpose?
Easy707Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?
Easy708An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?
Medium709A global manufacturing company has a decentralized information security program. Each region has its own security team and budget. The CISO is concerned about inconsistent security practices and wants to improve the program's maturity. Which of the following is the MOST effective approach to achieve consistency across regions while respecting local autonomy?
Medium710A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
Medium711A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
Easy712An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?
Medium713Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?
Easy714Which TWO of the following are essential components of an effective information security governance framework? (Select exactly two.)
Medium715A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?
Hard716An organization's incident response plan (IRP) is being updated. Which stakeholder should be included in the IRP development to ensure legal and regulatory requirements are met?
Easy717An organization's incident response plan includes a step to 'contain the incident.' Which of the following actions is an example of containment?
Easy718A retail company's risk committee is reviewing the annual risk assessment. The CISO notes that the organization's stated risk appetite for customer data confidentiality is low, but a business unit wants to launch a loyalty program that shares purchase history with a third-party analytics provider. Which of the following should the CISO do FIRST?
Easy719During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
Easy720An organization's incident response plan defines containment, eradication, and recovery phases. During a major incident involving a compromised application server, the incident response manager must decide whether to take the server offline immediately or keep it running to observe attacker behavior. Which of the following is the MOST important factor in making this decision?
Medium721During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?
Easy722A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?
Medium723A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)
Hard724A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?
Medium725An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?
Hard726A financial services firm is updating its information security strategy and needs to align it with the organization's overall business goals. The CISO has been asked to ensure that the security strategy directly supports the achievement of business objectives. Which of the following should be the PRIMARY consideration when aligning the security strategy with business goals?
Medium727A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?
Easy728An organization's IR plan is tested annually. After a test, many gaps are identified. What is the best next step?
Hard729During an incident investigation, the security team discovers that an attacker exfiltrated sensitive customer data via encrypted DNS tunneling over a period of three months. The data loss was only noticed after a routine audit. Which of the following weaknesses MOST likely allowed the attacker to remain undetected for so long?
Hard730A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?
Hard731Which of the following is a key objective of a Security Operations Center (SOC)?
Easy732Which metric is most indicative of security program effectiveness?
Easy733A healthcare organization's information security program has a policy that requires all ePHI to be encrypted at rest. During a review, the CISO discovers that a legacy application storing ePHI does not support encryption. The application is critical for patient care and cannot be replaced immediately. Which of the following should the CISO do FIRST?
Medium734During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?
Hard735A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?
Medium736A security operations center (SOC) analyst receives an alert indicating that a workstation is communicating with a known command-and-control (C2) server. The analyst confirms the traffic is malicious. According to CISM best practices, which action should the analyst take NEXT?
Medium737In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?
Medium738Which THREE of the following are typical steps in a qualitative risk assessment?
Medium739After successfully containing an incident, the incident response team discovers that the attacker exploited a previously unknown vulnerability in a web application. The vulnerability is not yet patched by the vendor. The organization's management is concerned about the risk of another attack using the same vulnerability. What should the team recommend as the immediate action to reduce this risk?
Easy740When designing phishing simulations, which approach best balances user learning and operational disruption?
Hard741An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?
Medium742A global financial services firm has a mature information security program. The CISO wants to ensure that the program's strategic objectives remain aligned with changing business goals, such as a new push into mobile banking. Which of the following is the MOST effective way to achieve this alignment?
Medium743A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?
Medium744An organization is developing its information security program and wants to ensure that security roles and responsibilities are clearly defined and communicated across the enterprise. Which of the following should be established FIRST to achieve this?
Easy745An information security manager is reviewing the organization's risk register and notices that a risk related to unpatched software has been assigned a risk score of 9 (on a scale of 1-10) with a note that the risk is 'accepted' because patching would disrupt a critical production system. Which of the following should the manager do NEXT?
Hard746A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?
Medium747An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?
Medium748An organization's intrusion detection system alerts on a potential C2 communication from an internal host. Which phase of the incident response lifecycle should be initiated first?
Easy749A financial services firm has a mature information security program. The Chief Information Security Officer (CISO) is asked by the board to demonstrate that the program is aligned with the organization's strategic objectives. Which of the following is the MOST effective way for the CISO to provide this assurance?
Medium750During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?
Medium751A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?
Hard752Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
Medium753When selecting security controls, a company must prioritize which controls first?
Medium754You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?
Hard755A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?
Medium756An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?
Easy757Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Hard758A financial services firm has completed a risk assessment and identified that its customer-facing web application has a high risk of SQL injection. The CISO must ensure the risk is treated appropriately. Which of the following should be the FIRST action?
Medium759The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?
Easy760A security manager is reviewing the organization's information security strategy and notices that it focuses heavily on technology controls but lacks integration with business processes. Which action should the manager take to improve alignment with business objectives?
Medium761An organization's incident response team is reviewing its post-incident activities after resolving a significant security incident. Management wants to ensure lessons learned are captured and that the response capability improves over time. Which TWO of the following activities are MOST important to include in the post-incident phase? (Choose two.)
Medium762Which THREE of the following are essential roles in an effective information security governance structure? (Choose three.)
Hard763Which TWO of the following are best practices for preserving digital evidence during an incident? (Select exactly 2)
Easy764Which TWO of the following are essential components of an incident response programme?
Medium765A newly appointed CISO is reviewing the existing information security program. The program has many documented policies and procedures, but the CISO notices that they have not been updated in over three years. What should the CISO do FIRST?
Easy766Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?
Hard767During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?
Hard768During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium769A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?
Hard770A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?
Hard771Which of the following are key components of an Information Security Risk Management program? (Select TWO.)
Medium772Match each business continuity term to its definition.
Medium773A CISO is updating the organization's information security strategy to address emerging risks from cloud adoption and remote work. Which of the following should be the FIRST step in this process?
Medium774An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?
Medium775Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?
Medium776A global retailer operates point-of-sale systems in 12 countries. The risk register shows a single entry titled 'Payment card data breach' with a likelihood of 4 and an impact of 5. A new CISO argues this entry is too coarse to support treatment decisions. Which action BEST improves the usefulness of the risk register for decision-making?
Hard777After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?
Hard778A global retailer's CISO is establishing an information security governance framework. The company operates in 20 countries, each with different privacy laws. The board wants assurance that security investments are justified and risks are managed consistently. Which governance mechanism BEST provides this assurance?
Hard779A company has recently adopted COBIT 2019 as its governance framework. The board is requesting a concise report on the effectiveness of the security program. Which reporting structure best aligns with COBIT's guidance?
Medium780A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?
Easy781In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?
Medium782A small e-commerce company with 50 employees and limited IT budget is establishing its first formal information security program. The company processes customer payment data and must comply with PCI DSS. The CEO wants to balance security with operational costs. The IT manager proposes investing in a state-of-the-art security information and event management (SIEM) system costing $100,000 annually. The CISO, however, recommends a more phased approach. Considering the company's size, budget constraints, and compliance requirements, what should be the CISO's primary recommendation?
Easy783During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?
Medium784An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?
Medium785A multinational company experiences a ransomware attack that encrypts critical servers in its European and North American data centers. The incident response team has contained the spread, but restoration will take several days. Executive leadership asks the CISO what should be done to manage the business impact while recovery proceeds. Which of the following is the MOST appropriate immediate action?
Easy786An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Medium787A security analyst receives an alert indicating a potential data exfiltration from a server. Which of the following should be the FIRST step in the incident response process?
Easy788A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?
Medium789An organization is implementing a security champions program. What is the primary purpose of this initiative?
Medium790An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?
Medium791During containment of a confirmed intrusion, the incident response manager must decide whether to immediately rebuild the compromised server or first acquire volatile data. Legal counsel has signalled that litigation is likely. Which of the following is the BEST course of action?
Medium792Refer to the exhibit. An organization uses these firewall rules. After a breach, the IR team finds that the attacker gained access via SSH from an external IP. Which rule is most likely misconfigured?
Hard793An organization has just experienced a data breach involving customer personal information. The incident manager is determining the appropriate communication strategy. Which action BEST aligns with CISM incident management practices?
Easy794Which of the following is the PRIMARY reason to include legal counsel in the incident response team?
Medium795A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?
Medium796Which of the following is the primary purpose of having a pre-established forensic retainer agreement?
Easy797A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?
Medium798Refer to the exhibit. What is most suspicious about this event?
Hard799A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?
Medium800Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)
Hard801A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)
Hard802During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?
Medium803During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium804Which TWO are key elements of a security awareness program designed to change employee behavior?
Hard805Which TWO of the following are key indicators that an organization's information security governance is inadequate?
Hard806A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?
Medium807During a post-incident review, the incident response team identifies that the root cause of a data breach was a misconfigured firewall rule that allowed unrestricted inbound access from the internet. Which corrective action BEST addresses this issue?
Easy808A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?
Medium809An incident responder is handling a phishing attack that resulted in credential theft. Which TWO actions should be taken FIRST in the containment phase?
Medium810Which of the following are essential components of an information security program governance framework? (Select TWO.)
Medium811An organisation is reviewing its incident response capabilities after a near-miss. The CISO wants to ensure the team can effectively detect and respond to future incidents. Which TWO of the following are the MOST important capabilities to establish before an incident occurs? (Choose two.)
Hard812After a major security incident, the incident response team completes the containment, eradication, and recovery phases. The CISO is now planning the post-incident activities. Which activity is MOST critical to ensure that lessons learned are effectively incorporated?
Hard813An organization's incident response plan requires that evidence be collected in a forensically sound manner. A responder is about to capture volatile data from a compromised server. Which action BEST preserves the integrity of the evidence?
Medium814An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
Medium815During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?
Hard816An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?
Medium817Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?
Medium818An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?
Medium819During a major ransomware incident, the chief information security officer (CISO) must decide whether to pay the ransom to restore encrypted clinical trial data at a pharmaceutical company. The attackers have threatened to publish the data if not paid within 48 hours. Which of the following is the MOST important factor for the CISO to consider when making this business decision?
Hard820An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)
Hard821Which TWO of the following are risk treatment strategies as defined in ISO 27005?
Easy822A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)
Medium823Which TWO of the following are recommended practices when conducting a post-incident review? (Select TWO)
Hard824An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)
Medium825Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)
Medium826An organisation has just completed recovery from a significant cybersecurity incident. The CISO wants to ensure the lessons learned are captured and used to improve future response. Which of the following should be performed as part of the post-incident activity?
Easy827A healthcare organization is developing an information security governance framework. The CISO needs to ensure that the framework supports regulatory compliance with HIPAA and aligns with the organization's strategic goals. Which of the following should be the FIRST step in this process?
Medium828An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?
Medium829Which TWO of the following are essential components of an incident response plan? (Select two.)
Medium830A financial services firm has just contained a malware outbreak that disabled online banking for six hours. The incident commander confirms systems are restored and monitoring is stable. Executive leadership now wants to know what must happen before the incident can be formally closed. Which activity is MOST important to complete prior to closure?
Hard831An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?
Hard832A security analyst notices unusual outbound traffic from a server that is not scheduled for any data transfers. Which step should the analyst take FIRST?
Easy833During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?
Hard834An organization has recently experienced a data breach that resulted in reputational damage and regulatory fines. The board has asked the CISO to improve the information security governance framework to prevent future incidents. Which of the following should the CISO do FIRST?
Easy835An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?
Medium836Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
Medium837Which TWO of the following are typical components of a security awareness program?
Easy838Which TWO of the following are key indicators that an organization's information security governance is effective?
Medium839Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
Medium840A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?
Medium841A financial services firm with a federated governance model is revising its information security strategy. The board has mandated that security investments must demonstrably support business objectives. The CISO is asked to define the MOST effective way to align security governance with business strategy. Which of the following should the CISO do FIRST?
Medium842An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?
Medium843Which THREE elements should be included in an incident response plan to ensure effective communication during a security incident?
Hard844An organization is updating its information security policy framework. The CISO wants to ensure that the policies are effectively communicated and understood by all employees. Which of the following is the MOST effective method to achieve this?
Medium845Which THREE are essential steps in incident containment? (Choose three.)
Medium846Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?
Medium847Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?
Easy848A company's information security manager is tasked with ensuring that security initiatives align with business goals. Which of the following best demonstrates this alignment?
Easy849An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)
Medium850A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?
Hard851An organization's incident response plan defines communication procedures, but during a recent incident, customers learned about a data breach from media reports before receiving any notification from the company. The information security manager has been asked to address this gap. Which of the following is the MOST effective improvement?
Medium852Which THREE of the following are key components of an incident response plan? (Select THREE)
Medium853Which THREE of the following are typical roles in an incident response team? (Select THREE)
Medium854An organization has just experienced a malware outbreak that was contained by isolating affected endpoints. Before restoring the isolated systems to normal operation, the incident response team must decide what activity comes next in the response lifecycle. Which of the following should the team perform NEXT?
Easy855A security manager is reviewing the organization's incident response capabilities. During a tabletop exercise, participants struggled to determine who has authority to shut down a critical production system during a suspected incident. Which action BEST addresses this gap?
Hard856A global financial services firm with 15,000 employees has recently experienced a significant data breach due to inadequate oversight of third-party vendors. The breach originated from a cloud service provider that had been granted elevated access without a formal risk assessment or contract review. The board has directed the CISO to overhaul the information security governance framework to prevent recurrence. Currently, the organization has a decentralized security model where each business unit manages its own vendor relationships. The CISO proposes a centralized governance body. Which of the following is the BEST course of action to establish effective governance over third-party risk?
Hard857A manufacturing company has an incident response plan that includes a communication plan. However, during a recent ransomware incident, the team realized that the external legal counsel was not listed in the plan. The incident requires consultation with legal due to potential regulatory implications. The incident response manager needs to address this gap quickly. What should the manager do?
Easy858After detecting a ransomware infection on a file server, the incident response team performs containment and eradication. Which step should be prioritized during the recovery phase to minimize business impact?
Medium859An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)
Medium860A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)
Hard861A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?
Hard862A CISO is building the programme's risk treatment capability and wants to ensure that identified risks are handled consistently across business units. Which TWO activities are essential components of an effective risk treatment process? (Choose two.)
Hard863During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?
Hard864An organization's IDS logs show multiple outbound connections to an external IP address from a server that normally communicates only internally. The logs indicate the process is running under the SYSTEM account. Which of the following BEST describes the likely root cause?
Hard865Which of the following best describes the role of a security architect in a security program?
Medium866A financial services firm has completed containment and eradication of a sophisticated intrusion. The incident response team is now preparing for the post-incident phase. The CISO asks what activity will BEST reduce the likelihood of a similar incident recurring. Which activity should be prioritized?
Hard867An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)
Hard868A global insurance provider has just completed a quantitative risk assessment for a new claims-processing application. The assessment used the Annualized Loss Expectancy (ALE) formula and produced an ALE of $850,000 for the risk of a data breach. The vendor's proposed control has an Annualized Cost of the Safeguard (ACS) of $300,000 and a projected risk reduction of 60%. The CISO asks the information security manager to determine the cost-benefit of implementing this control. What is the net benefit (or loss) of the control?
Medium869During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?
Hard870Which of the following best describes the difference between risk appetite and risk tolerance?
Easy871A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?
Medium872An organization is reviewing its incident response plan after a tabletop exercise revealed confusion about roles during a major incident. The CISO wants to clarify which activities belong to the incident response team versus the crisis management team. Which TWO of the following activities are PRIMARY responsibilities of the crisis management team during a major incident? (Choose two.)
Medium873What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?
Easy874An organization has just completed its response to a significant security incident. The information security manager is preparing the post-incident review and wants to ensure the effort produces lasting improvement rather than a one-time report. Which of the following activities is MOST important to include in the post-incident review?
Easy875A mid-sized financial services firm has a newly appointed CISO. The board has asked for assurance that the information security program aligns with the organization's strategic goals and risk appetite. The CISO needs to establish a governance structure that provides ongoing oversight and ensures security decisions are made at the right level. Which of the following should the CISO implement FIRST?
Medium876A CISO is establishing a security metrics program to measure the effectiveness of the information security program. The CISO wants to include both key goal indicators (KGIs) and key performance indicators (KPIs). Which of the following are examples of KGIs? (Choose two.)
Hard877A security manager is drafting the incident response plan and needs to define how the organization will classify and escalate incidents. Executive leadership wants assurance that high-impact incidents reach the right decision-makers quickly. Which of the following should the security manager do FIRST to establish effective incident classification and escalation?
Medium878During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?
Hard879A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?
Hard880A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?
Hard881A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?
Hard882An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?
Medium883An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)
Hard884An organization's incident response team has completed the initial response to a ransomware incident. During the post-incident review, they identify that the detection was delayed because security logs from different systems were not correlated. The team wants to improve detection capabilities. What should the team recommend as the primary improvement?
Medium885An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?
Hard886An organization's governance framework requires regular reporting to the board. Which reporting frequency and format is MOST effective for a board with limited security expertise?
Hard887A global financial services firm has a mature information security program with policies, standards, and procedures aligned to ISO/IEC 27001. The CISO is preparing for the annual management review of the program. The board has asked for assurance that the program remains effective as the threat landscape and business strategy evolve. Which activity BEST provides this assurance?
Hard888A CISO is establishing an information security governance framework. The organization operates in multiple countries with varying data protection laws. Which of the following should be the PRIMARY consideration when developing security policies?
Easy889A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
Hard890A CISO at a healthcare insurer is revising the information security strategy after a merger with a smaller regional provider. The board has asked how security will support the combined company's growth targets while protecting patient data. Which action BEST aligns the security strategy with the business objectives?
Medium891An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)
Medium892When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?
Medium893During an incident investigation, the team discovers that an attacker used a valid user's credentials to access a sensitive database. The user's account had multi-factor authentication (MFA) enabled. How is this MOST likely possible?
Hard894A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?
Medium895Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?
Medium896A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?
Hard897An organization has just contained a malware outbreak on several servers. The incident response manager must decide which activities belong in the eradication phase before restoration begins. Which TWO of the following activities are part of eradication? (Choose two.)
Hard898Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?
Medium899A healthcare organization is conducting a risk assessment for a new telehealth platform that will process protected health information. The assessment team proposes using a qualitative approach because of tight deadlines. Which of the following is the MOST significant limitation of relying solely on qualitative risk assessment for this initiative?
Hard900A newly appointed CISO is reviewing the organization's information security governance framework. The CISO finds that security responsibilities are not clearly defined across business units, leading to gaps and overlaps. Which of the following should the CISO do FIRST to address this issue?
Easy901A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?
Hard902A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?
Medium903An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?
Hard904Which TWO are common challenges in incident management?
Medium905An organization has a distributed incident response team across multiple time zones. During a critical incident, communication delays occur due to different work hours. Which strategy BEST improves coordination and response time?
Hard906During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?
Hard907A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)
Hard908A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to senior management. Which of the following are characteristics of effective security metrics? (Choose two.)
Hard909Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?
Easy910Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)
Medium911An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?
Hard912An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)
Medium913An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?
Hard914A financial institution is hit by a Distributed Denial of Service (DDoS) attack that is overwhelming their internet-facing services. The incident response team activates the plan, but the attack continues to escalate. The CEO is under pressure and asks the incident response manager whether they should pay the ransom demand (the attackers also sent an extortion note demanding payment to stop the attack). The manager must advise the CEO on the best course of action.
Hard915A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?
Hard916Which of the following is the PRIMARY goal of incident containment?
Easy917An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?
Medium918After a security incident, the board holds the CISO accountable. The CISO argues that the incident was caused by a failure in the third-party risk management process. Which of the following governance deficiencies is most likely the root cause?
Medium919An information security manager is asked to report on the effectiveness of the security program. Which metric would BEST indicate governance effectiveness?
Easy920Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)
Hard921Which TWO of the following are key components of an information security program governance structure? (Select TWO.)
Medium922An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?
Hard923An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?
Hard924Which of the following is the PRIMARY role of the board of directors in information security governance?
EasyOther domains
All CISM exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CISM exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 924 scenario questions questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.