CISM · domain
scenario questions
Practise Certified Information Security Manager CISM scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (871)
Click any question to see the full explanation, or start a practice session above.
A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)
Medium2After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?
Medium3Which of the following is a key reason to have a forensic retainer in place before an incident occurs?
Medium4During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?
Medium5An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?
Hard6You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?
Easy7Which of the following is a leading indicator of security program effectiveness?
Easy8During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?
Medium9A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?
Medium10A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?
Medium11Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?
Easy12You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?
Medium13Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?
Easy14A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?
Hard15An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?
Easy16During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?
Hard17During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?
Easy18An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?
Medium19Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?
Medium20An organization is under a DDoS attack that is saturating their internet link. The incident response team needs to mitigate the attack. Which action should be taken first?
Hard21An employee emails a spreadsheet containing employee salaries to all staff by mistake. According to the exhibit, what is the minimum handling requirement that was violated?
Medium22An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?
Medium23An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
Easy24Refer to the exhibit. The exhibit shows network traffic from a server to a database. What does this pattern MOST likely indicate?
Easy25What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?
Easy26During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)
Hard27Refer to the exhibit. A system administrator reviews the log and notices repeated failed SSH attempts from the same IP address. What is the most appropriate risk response?
Medium28A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?
Hard29Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)
Medium30A security manager is designing a security awareness program. Which TWO metrics are leading indicators of program effectiveness?
Medium31Which of the following are key components of a mature information security program? (Select 2)
Hard32An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Medium33An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?
Hard34As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?
Medium35Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)
Medium36Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?
Medium37An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?
Easy38Which of the following incident categories would typically require the involvement of the crisis management team?
Easy39Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?
Easy40A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?
Medium41During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?
Medium42An organization's security program includes a risk assessment process. Which step should be performed FIRST?
Easy43Which of the following best describes the primary purpose of an Information Security Program?
Medium44An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?
Medium45An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?
Medium46Which THREE characteristics indicate a higher maturity level in a security program maturity model?
Hard47Which THREE of the following are common challenges in implementing an information security program across a large enterprise?
Hard48During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?
Hard49A small marketing firm with 50 employees experiences a ransomware attack. The IT administrator quickly isolates the infected workstations by disconnecting them from the network. The company has a backup strategy that performs nightly backups to an on-premises NAS device. The administrator restores the affected systems from the most recent backup, but some files remain encrypted. The users report that the backups from the last two days show corruption as well. The firm does not have a formal incident response plan. The owner is anxious to get back to work and asks the administrator what to do next. What should the administrator do?
Easy50Given the exhibit, what is the MOST appropriate action for the information security manager?
Medium51An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?
Easy52An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?
Hard53Refer to the exhibit. This error log indicates a failure in which component of information security governance?
Hard54You are the information security manager for a mid-sized e-commerce company with 500 employees. The company recently experienced a data breach where an attacker exploited a vulnerability in a third-party payment processing API, resulting in the exposure of 10,000 customer credit card numbers. The breach was detected by an external forensics team 90 days after the initial compromise. The board is concerned about the company's ability to detect and respond to incidents. Currently, the company has a part-time security team of three people who focus on firewall management and antivirus updates. There is no formal incident response plan, and security monitoring is limited to basic log review once a week. The CISO has asked you to recommend a course of action to improve the security posture, with a focus on governance and oversight. Which of the following is the BEST course of action?
Hard55A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?
Medium56A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?
Hard57During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?
Medium58An organization is developing an information security program for a new subsidiary. Which approach BEST ensures that the subsidiary's program complements the parent's?
Medium59During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?
Easy60Which of the following is the PRIMARY responsibility of the CISO in an organization?
Easy61What is the primary purpose of a security incident near-miss reporting culture?
Easy62A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?
Easy63Refer to the exhibit. Based on the exhibit, what is the security implication of this cloud storage bucket policy?
Hard64Which TWO are essential elements of an information security program?
Medium65An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?
Easy66Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)
Medium67An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?
Hard68Which TWO of the following are components of a typical vulnerability management program?
Easy69An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)
Hard70A company is restructuring its security governance due to rapid growth. The CISO reports to the CIO. What is the PRIMARY risk of this reporting structure?
Medium71A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?
Medium72Which THREE of the following are essential components of an information security risk management framework?
Hard73A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?
Hard74Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?
Medium75Which THREE of the following should be included in an incident communication template?
Medium76Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?
Medium77Which TWO factors are most important when prioritizing security investments? (Select TWO.)
Medium78A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?
Hard79Which component is essential for building a strong security culture within an organization?
Easy80During a ransomware incident, the incident response team identifies that the encryption process is still ongoing. The CISO decides to isolate affected systems to prevent further spread. Which of the following is the MOST appropriate next step?
Medium81A large e-commerce company detects a sophisticated attack that has compromised a web application server. The server contains customer payment card information. The incident response team is activated. During triage, the team discovers that the attacker has gained administrative access and installed a backdoor. The company's public relations department wants to issue a press release as soon as possible to maintain customer trust. Legal counsel advises that the breach must be reported to regulators within 72 hours. The technical team is working on containment. What is the MOST important priority for the incident manager at this point?
Medium82An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?
Hard83During a P1 (critical) security incident, which of the following is the MOST appropriate frequency for providing executive status updates?
Medium84During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?
Hard85After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?
Medium86An information security manager is developing a program metric to report to senior management. Which metric best demonstrates the effectiveness of the information security program?
Medium87An incident has been declared involving a ransomware attack that encrypted critical servers. The organization has backups, but the backups were also encrypted. Which of the following is the BEST course of action?
Hard88Match each security role to its primary responsibility.
Medium89Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?
Easy90Which of the following is a leading indicator of security program effectiveness?
Easy91Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?
Medium92What is the PRIMARY reason for having an incident response team roster and contact list readily available?
Easy93An organization is implementing a new cloud-based ERP system. As part of the emerging risk assessment, the information security manager needs to identify potential risks associated with the cloud migration. Which THREE of the following should be considered as part of the emerging risk assessment for cloud adoption?
Medium94A security program manager is reviewing the results of a recent internal audit that identified several security gaps. The manager must prioritize remediation efforts. Which factor should be given the MOST weight?
Hard95Given the exhibit, what is the MOST significant governance gap in the described architecture?
Easy96In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)
Easy97An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Medium98Which of the following is the PRIMARY responsibility of a steering committee in an information security program?
Easy99A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?
Medium100An organization has multiple business units with different risk tolerances. How should the security program address this?
Hard101A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?
Hard102A multinational corporation is establishing an information security governance framework. The board has approved a top-down approach where security policies are created at the corporate level and adapted locally. Which of the following is a key benefit of this approach?
Medium103An organization's security budget is 12% of the IT budget. Which of the following best describes the maturity of this security program?
Hard104Which TWO of the following are key components of an information security risk assessment? (Choose two.)
Easy105A user reports that their computer is behaving oddly, and an IT technician finds a suspicious file in the startup folder. The technician is not sure if this is an incident. What should the technician do FIRST?
Easy106Based on the exhibit, what is the MOST likely issue?
Hard107When establishing an information security program, which TWO of the following are key components of governance?
Easy108An information security manager reviews the suspicious activity log shown in the exhibit. The payroll file is supposed to be encrypted and only accessible internally. What is the MOST likely cause for the failed download?
Hard109An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?
Hard110During a major security incident classified as P1, which of the following is the MOST appropriate communication frequency to the executive team?
Medium111Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)
Medium112During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?
Medium113A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?
Hard114An organization's security team detects an unusual spike in outbound traffic from a database server to an external IP address during a routine security scan. The database server contains sensitive customer data. Which of the following is the MOST appropriate initial response?
Hard115An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?
Hard116A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?
Medium117An incident response plan (IRP) is being tested. Which metric is MOST indicative of the team's effectiveness during an exercise?
Easy118A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?
Medium119Which THREE are key components of an effective post-incident review?
Hard120An information security manager is developing a security scorecard for the board. Which of the following should be included to BEST demonstrate governance performance?
Easy121Given the exhibit output from a web server, which connection is MOST suspicious and likely indicates a command-and-control (C2) channel?
Hard122A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?
Hard123An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?
Medium124Which THREE of the following are key phases of the incident management lifecycle according to NIST or ISO? (Choose three.)
Easy125A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)
Hard126During a data breach investigation, the team discovers that an attacker exfiltrated data via encrypted HTTPS to a server abroad. Which forensic step is most critical?
Hard127An organization's security steering committee meets quarterly but lacks decision-making authority. Projects are delayed due to lack of prioritization. What is the most effective improvement?
Medium128Which TWO of the following are primary objectives of a security awareness program?
Easy129An incident response team discovers that an employee's workstation is infected with malware. The workstation contains sensitive customer data. Which of the following is the MOST appropriate containment strategy?
Easy130Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?
Medium131Which TWO of the following are key responsibilities of an information security governance committee?
Hard132Based on the SIEM alert exhibit, which immediate action should the incident responder take?
Medium133A multinational corporation is designing an information security strategy to support its global operations. Which approach best ensures that the strategy is actionable and measurable?
Medium134An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?
Medium135A multinational corporation is experiencing significant security incidents due to inconsistent security policies across subsidiaries. The CISO proposes implementing a centralized governance model. However, business unit leaders argue that local regulations require autonomy. Which approach best balances governance with local compliance?
Hard136An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard137Match each data classification level to its handling requirement.
Medium138During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?
Medium139Based on the exhibit, which risk should be addressed first if the organization has limited resources?
Medium140A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?
Hard141Which TWO actions are key components of the 'Containment' phase in incident response?
Medium142A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?
Medium143A security operations center receives an alert from an IDS indicating possible command and control traffic. The analyst is unsure if it's a true positive. Which combination of actions should be taken first?
Hard144A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?
Medium145Which of the following is a key objective of implementing a security champions program?
Easy146Which incident severity level requires executive notification and 24/7 response, and has major business impact?
Easy147Refer to the exhibit. An organization is implementing access controls for a new data repository that will store financial reports classified as Category C. Which of the following is the MOST appropriate control to include?
Medium148An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
Hard149A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?
Medium150Refer to the exhibit. An information security manager reviews the risk register and sees that Risk ID R001 has a residual risk of High with a treatment of Accept. Which of the following best explains why this situation may indicate a governance failure?
Medium151An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?
Hard152Match each information security program component with its correct description.
Hard153An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?
Medium154A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?
Easy155An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?
Medium156A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?
Medium157An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?
Easy158An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Hard159A large enterprise experiences a data breach involving personal identifiable information (PII) of customers. The incident response team has contained the breach and is now in the eradication phase. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is MOST critical?
Hard160Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?
Medium161A multinational corporation is establishing a risk appetite framework. The board has defined risk appetite as 'no more than one major security incident per year resulting in financial loss exceeding $1M'. Which of the following best represents the risk tolerance for a specific business unit's annual cybersecurity budget allocation?
Hard162In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?
Medium163A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?
Medium164An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?
Hard165An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)
Hard166Which of the following is the primary reason for conducting a lessons learned meeting after an incident?
Easy167An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?
Easy168Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?
Hard169During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?
Medium170Which of the following is the PRIMARY reason for including communication templates in the incident response plan?
Easy171Match each incident management phase to its activity.
Medium172An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?
Medium173A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)
Hard174During incident investigation, which evidence preservation method is most important?
Easy175Which of the following is the best indicator that an organization has effective information security governance?
Easy176During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?
Hard177Which TWO of the following are examples of risk mitigation controls? (Choose two.)
Easy178An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?
Medium179A small business cannot afford a dedicated security team. Which governance model is most appropriate?
Easy180An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?
Medium181A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?
Medium182A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
Hard183An organization is developing a vendor risk management program. Which TWO of the following should be included in the vendor onboarding risk assessment?
Medium184Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?
Easy185After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?
Medium186Based on the risk register entry, what is the primary gap in the current controls?
Easy187Refer to the exhibit. Based on the risk register extract, which risk should the information security manager prioritize for additional treatment?
Hard188Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?
Easy189According to the exhibit, which role is responsible for conducting forensic analysis?
Medium190You are the information security manager for a financial services company that processes credit card transactions. The company uses a mix of on-premises servers and cloud services. During a routine vulnerability scan, you discover that one of the web servers has been compromised with a web shell that allows remote command execution. The server is part of a cluster that handles customer-facing web traffic. The incident response team is activated. The team's immediate actions include isolating the server from the network and taking a forensic image. However, the server is critical for business operations, and management is pressuring you to restore service quickly. The server's logs show that the web shell was uploaded three days ago, and during that time, the server processed approximately 10,000 transactions. The team has not yet fully analyzed the forensic image. You need to decide on the next steps. What should you do FIRST?
Hard191Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?
Easy192A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?
Easy193Refer to the exhibit. A security analyst reviews the firewall configuration and identifies a potential risk. What is the most likely risk?
Hard194An organization's information security governance committee has not met for the past six months. Which of the following is the most significant risk associated with this situation?
Hard195During a risk assessment, an organization identifies that a legacy system processes credit card data and has a high likelihood of being exploited. The cost to remediate the vulnerability is $500,000, while the potential loss from a breach is $2 million with a 30% annual probability. What is the most appropriate risk treatment decision based on this information?
Hard196A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?
Hard197During an incident, the incident response team discovers that the attacker used stolen credentials to access the network. What should the team do during the eradication phase?
Medium198During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?
Medium199Which of the following is the PRIMARY purpose of an incident response plan?
Easy200An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is working on containment. Which communication should the incident manager prioritize FIRST?
Hard201Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)
Hard202A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?
Easy203After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?
Medium204Which metric is considered a lagging indicator of security program performance?
Medium205You are the incident response manager for a mid-sized e-commerce company. At 2:00 PM, the security operations center receives an alert from the intrusion detection system indicating a potential SQL injection attack against the customer database server. The server hosts a critical database containing customer PII and payment card data. The alert shows multiple suspicious queries from an internal IP address 192.168.10.50, which belongs to the development team's jump box. The development team uses this jump box to access production servers for maintenance. The jump box is managed by the IT operations team. The CEO is currently in a meeting with investors and cannot be disturbed. The CISO is on leave. The company has a written incident response plan that designates the IT director as the incident response coordinator in the absence of the CISO. The IT director has limited security knowledge. The database administrator (DBA) reports that the database is experiencing high CPU usage and that some customer records appear to have been modified. You need to take immediate action. What should you do FIRST?
Hard206Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?
Easy207An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?
Medium208An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?
Medium209Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
Easy210Given the exhibit, what is the most likely classification of this incident?
Medium211Which capability maturity model (CMM) level indicates that security processes are measured and controlled?
Easy212Refer to the exhibit. The audit finding reveals a deficiency in which critical aspect of information security governance?
Hard213An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?
Easy214During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
Hard215A financial institution is integrating a newly acquired fintech startup. The startup has a very different security culture. What governance approach best ensures integration without stifling innovation?
Hard216You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?
Medium217A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?
Hard218During a forensic investigation, an incident responder needs to collect memory from a compromised server. What is the BEST method to preserve evidence integrity?
Hard219What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy220Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?
Medium221Which of the following is a leading indicator for security performance?
Medium222During a merger, the acquiring company's board insists on integrating the target company's information security governance into its own within 90 days. However, the target has a significantly different risk culture and lacks documented policies. What is the most critical governance risk in this scenario?
Hard223Match each risk assessment activity with the correct phase of the risk management lifecycle: Activities: 1. Identify assets and threats 2. Determine risk level 3. Select controls to reduce risk 4. Monitor risk over time Phases: A. Risk Assessment B. Risk Treatment C. Risk Monitoring D. Risk Communication (not used)
Medium224A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?
Easy225An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?
Medium226During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?
Medium227During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?
Hard228You are the information security manager for a mid-sized e-commerce company. The company operates a web application that handles credit card transactions and stores customer data in a backend database. The incident response team has just been alerted to a potential data breach: an intrusion detection system (IDS) flagged a SQL injection attack pattern on the web application's login page. The attack originated from an external IP address (5.5.5.5) and appears to have been successful, as the IDS also detected a large outbound data transfer from the database server to another external IP (6.6.6.6) shortly after. The database server is not segmented from the web server. The company has a legal obligation to report breaches involving cardholder data within 72 hours. The incident response plan is being activated. The team includes a forensic analyst, a network engineer, and a legal advisor. The web application is currently running and serving customers. The CEO wants to minimize business disruption. Which of the following actions should the incident response team take FIRST?
Medium229Which governance structure is characterized by a single security team that serves the entire organization?
Easy230Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?
Medium231An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next critical step?
Easy232An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?
Medium233During a simulated phishing exercise, several employees clicked a link and entered their credentials on a fake login page. The security team needs to determine the impact. Which of the following should be the NEXT step?
Medium234An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?
Easy235Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)
Medium236A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?
Hard237Which TWO actions are appropriate during the containment phase of an incident involving a malware outbreak on multiple workstations?
Medium238An organization's incident response plan has not been updated in two years. Which of the following is the MOST likely consequence?
Easy239Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?
Hard240Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?
Easy241Which of the following is the PRIMARY reason for aligning the information security program with business objectives?
Easy242An organization has implemented a host-based intrusion prevention system (HIPS) on all endpoints. An internal audit reveals that many incidents go undetected because users often disable HIPS when it interferes with applications. Which of the following is the MOST effective control to address this issue?
Hard243A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?
Easy244A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?
Easy245Which TWO of the following are common approaches to information security risk assessment?
Medium246A security audit has identified several governance weaknesses. Which TWO of the following are most likely to indicate a lack of effective information security governance? (Choose two.)
Easy247A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?
Hard248A security manager is developing metrics for the executive dashboard. Which combination of metrics provides a balanced view of security program performance?
Medium249An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?
Medium250A financial institution is restructuring its information security governance to comply with a new regulatory requirement that mandates a formal risk appetite statement. The board has conflicting views on the level of risk to accept. Which of the following should the information security manager do to facilitate the definition of risk appetite?
Hard251During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?
Medium252Which of the following is the primary purpose of communicating risk assessment results to senior management?
Easy253A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?
Hard254A security analyst detects an unusual spike in outbound traffic from a database server. Which of the following is the FIRST step in the incident response process?
Easy255Which of the following is the PRIMARY benefit of having a formal policy exception management process?
Medium256Which control family in NIST SP 800-53 addresses the identification and authentication of users?
Easy257A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)
Medium258Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?
Hard259Which of the following is the PRIMARY purpose of an incident response plan?
Easy260An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?
Hard261A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?
Hard262Which TWO of the following are essential components of an information security governance framework according to ISACA's COBIT?
Medium263Which document should be reviewed and updated at least annually?
Easy264Which TWO of the following are key components of an information security governance framework? (Choose two.)
Medium265A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?
Medium266An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?
Hard267A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?
Hard268An organization uses ISO 27001 Annex A as its control framework. During a risk assessment, a control weakness is identified that could lead to a high-impact data breach. However, implementing the recommended control is cost-prohibitive. Which approach BEST addresses this situation?
Hard269An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?
Easy270An information security manager is developing a security program for a multinational organization. Which of the following should be considered when defining the program scope? (Select THREE)
Medium271An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?
Hard272During a third-party risk assessment, the security team discovers that a critical vendor has subcontracted data processing to another company without notification. This represents which type of risk?
Medium273A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?
Medium274An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?
Medium275A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?
Hard276An organization is developing a security policy for remote access. According to the policy hierarchy, where should this policy fit?
Medium277A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?
Medium278A security analyst suspects a credential compromise involving an executive's account. The analyst has isolated the system. What should be the NEXT step according to best practices?
Hard279A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?
Hard280A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?
Medium281A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?
Easy282A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?
Easy283In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?
Easy284Which TWO of the following are essential components of a security program governance structure?
Medium285An organization experiences a DDoS attack that overwhelms their internet connection. Which containment strategy would be MOST effective?
Easy286An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?
Medium287A financial institution has a mature incident response program. During a security incident, the incident response team identifies that a business-critical application is affected. The team must decide whether to continue containing the incident or allow limited operations to continue. Which factor should be given the HIGHEST priority?
Hard288Order the steps for establishing a security incident response team (IRT).
Medium289An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
Hard290Which of the following is the primary purpose of an information security program?
Easy291Which THREE of the following are typical roles in an incident response team?
Easy292An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?
Hard293During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?
Medium294Match each risk management term to its definition.
Medium295After a ransomware attack, the incident response team successfully restores systems from backups. However, the ransomware encrypts files that were modified after the last backup was taken. Which of the following is the BEST way to minimize future data loss?
Hard296An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?
Medium297Which of the following best describes residual risk?
Easy298Which TWO metrics are considered leading indicators for information security program performance?
Medium299A bank detects unusual activity on a server containing sensitive financial data. The activity appears to be from a compromised vendor account that has legitimate remote access to the server for maintenance. The incident manager must decide on containment while maintaining business operations. The vendor account has elevated privileges and is used for routine updates. Disabling the account would delay critical maintenance. What is the BEST course of action?
Hard300A financial institution is designing an incident response plan. They want to ensure that during a ransomware incident, critical transaction systems can be restored within 4 hours. Which metric should be used to measure this requirement?
Medium301A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?
Hard302A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?
Hard303An organization is designing its information security program and needs to ensure it supports business continuity. Which TWO of the following should be integrated into the program?
Hard304In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
Hard305Which THREE of the following are challenges in implementing information security governance in a decentralized organization?
Hard306After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?
Medium307After a security incident, the incident response team identifies that the root cause was a phishing email that bypassed the email filter. The email contained a malicious macro that executed PowerShell commands. Which control would be MOST effective in preventing similar incidents in the future?
Hard308A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?
Medium309Which TWO budget components are considered 'services' in a typical security budget?
Medium310Arrange the steps for implementing a new firewall rule in an enterprise environment.
Medium311An organization's incident response team is notified of a potential denial-of-service (DoS) attack targeting their web application. The team suspects a distributed denial-of-service (DDoS) attack. What is the FIRST step the team should take?
Medium312During an incident, the incident response team needs to preserve evidence for legal proceedings. Which of the following is the MOST important action to take?
Easy313A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)
Hard314Refer to the exhibit. The CISO wants to improve the program. Which recommendation BEST addresses the main gap shown in the dashboard?
Medium315A company's incident response team uses a SIEM to detect security events. Which SIEM capability is MOST critical for early detection of a potential incident?
Medium316Which THREE steps are essential in the post-incident review process?
Easy317A large enterprise is implementing a new governance framework. The board has approved a risk appetite statement. What is the MOST important next step for the information security manager?
Medium318Arrange the steps for responding to a data breach involving personally identifiable information (PII).
Medium319Under the proposed SEC rules for cybersecurity incident disclosure, what is the timeframe for reporting a material cybersecurity incident?
Medium320After a security incident, the incident response team prepares a report detailing the root cause, impact, and lessons learned. Who is the PRIMARY audience for this report?
Easy321A small business is developing its first information security program. Which approach is most effective?
Easy322During an internal audit, it was found that the security policy does not address the use of personal devices for work. Which governance action should be taken first?
Easy323Which THREE of the following are common challenges in incident response? (Select exactly 3)
Medium324Order the steps for conducting an internal audit of an information security management system (ISMS) based on ISO 27001.
Medium325A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?
Hard326A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?
Easy327Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?
Hard328An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)
Easy329Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?
Medium330Which of the following are key components of an information security program's strategic plan? (Select two.)
Medium331Acme Corp, a global manufacturer, has a decentralized security governance model. Each business unit manages its own security, resulting in inconsistent policies and repeated audit findings. The new CISO proposes a federated model where a central team sets minimum standards and each unit can add local controls. However, the European unit's head insists on full autonomy due to GDPR strictness. The board is concerned about compliance costs. What should the CISO do first?
Hard332In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?
Easy333Refer to the exhibit. The dashboard shows the incident response plan test is overdue. What is the MOST immediate risk?
Easy334During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?
Hard335Which incident category involves unauthorized access to systems or data by an individual within the organization?
Easy336Which THREE of the following are key activities in a third-party risk management (TPRM) program?
Medium337During a phishing campaign, several employees clicked a malicious link that downloaded a remote access trojan (RAT). The incident response team has isolated the infected endpoints and is analyzing network traffic. They suspect that data may have been exfiltrated but are unsure. The team needs to determine the extent of data exfiltration as quickly as possible. What action should the team take FIRST?
Medium338Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)
Hard339Which incident severity level requires executive notification and a 24/7 response?
Easy340Based on the exhibit, what is the most likely vulnerability that an attacker could exploit?
Hard341An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?
Medium342Which incident severity level requires executive notification and a 24/7 response?
Easy343A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?
Hard344An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?
Medium345You are the CISO of a mid-sized e-commerce company with 500 employees. The company recently suffered a data breach where an attacker exfiltrated customer credit card data from the production database. The investigation revealed that the breach originated from a compromised developer workstation. The developer had been granted direct access to the production database for troubleshooting purposes, a practice that had been in place for years. The security governance framework currently lacks a formal process for managing privileged access. The board has asked for immediate improvements to prevent recurrence. Which course of action BEST addresses the governance gap?
Hard346You are the incident response manager for a multinational corporation that processes sensitive financial data. The company has a mature security operations center (SOC) that monitors network traffic, endpoints, and cloud services. At 2:00 AM local time, the SOC alerts you to a critical incident: an internal server (IP 10.10.10.50) is communicating with an external IP address (198.51.100.23) known to be associated with a ransomware group. The server hosts a financial database that is replicated to a secondary site every 6 hours. The last successful replication was at 1:00 AM. The SOC has already isolated the server from the network by blocking its outbound traffic at the firewall. However, the server is still running. The initial investigation suggests that the communication started 30 minutes ago. The database contains customer PII and transactional data. Your incident response plan includes steps for containment, eradication, recovery, and post-incident review. The CEO is being notified and expects a recommendation on the best course of action. The company has a cyber insurance policy that requires timely notification and preservation of evidence. The legal department advises that any action that could destroy evidence must be carefully considered. Which of the following is the BEST course of action?
Hard347Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?
Hard348An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)
Hard349A security analyst reviews the following alert from the SIEM: 'Multiple failed login attempts from IP 10.0.0.5 to the domain controller within 5 minutes.' Which TWO actions should the analyst take as part of initial incident response?
Hard350A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?
Medium351Match each security metric to its description.
Medium352A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
Medium353An incident response team discovers that an attacker used stolen credentials to access a database. Which step is MOST critical during the eradication phase?
Medium354During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?
Medium355Which TWO of the following are primary responsibilities of the board of directors in information security governance?
Easy356A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?
Hard357An organization has a decentralized security governance model. The CISO is struggling to enforce consistent security policies across business units. What is the BEST approach to improve consistency?
Medium358After a merger, the combined organization has two different risk tolerance levels: one entity is risk-averse, the other is risk-taking. What is the best governance action?
Hard359A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?
Easy360During a security audit, several deviations from policy are found. What should the security manager do first?
Medium361An organization is implementing a security culture measurement program. Which THREE metrics would BEST indicate a positive security culture?
Hard362A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?
Hard363Which of the following is the primary purpose of an Information Security Program?
Easy364You are the CISO of a large healthcare organization that has recently experienced a data breach due to an insider who exfiltrated patient data over several months. The breach was discovered by an external partner. The organization's information security program includes data loss prevention (DLP) tools, but they were not configured to monitor outbound data from the compromised system. Additionally, user activity monitoring (UAM) was only applied to privileged users, not to regular staff. The board demands a comprehensive improvement plan that will prevent similar incidents. However, there are concerns about employee privacy and budget constraints. The organization has a strong culture of trust and minimal monitoring. Which of the following should be the first priority in the revised program?
Hard365A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?
Hard366An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?
Medium367An organization is implementing a security controls framework based on NIST SP 800-53. The CISO wants to prioritize controls that will provide the greatest risk reduction for critical assets. Which approach should be used to select the initial set of controls?
Medium368An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?
Hard369Which of the following is the PRIMARY role of the board of directors in information security governance?
Medium370A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?
Hard371An organization's information security program recently experienced a ransomware attack that encrypted critical data. Which of the following program components should be improved first to prevent recurrence?
Easy372The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?
Hard373Which THREE of the following are components of a security operations center (SOC)?
Easy374A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?
Hard375During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?
Medium376In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?
Easy377Which of the following is the primary responsibility of the board of directors in information security governance?
Easy378What is the PRIMARY purpose of a security champions program?
Easy379An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?
Medium380Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?
Easy381A security manager is designing a metrics dashboard for the CISO. Which TWO metrics are leading indicators of security performance? (Select TWO)
Medium382Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?
Easy383After containing a security incident, the team conducts a root cause analysis. They find the breach originated from a compromised third-party vendor account. What is the most effective long-term mitigation?
Medium384An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?
Medium385A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?
Medium386A multinational corporation is designing its information security governance framework. The board has requested a single metric that best indicates the effectiveness of the security program. Which metric would BEST satisfy this request?
Hard387An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?
Medium388During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?
Medium389Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
Hard390Which document should be created FIRST when establishing an information security program?
Easy391A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?
Medium392Which of the following are key components of an effective information security program? (Select TWO.)
Medium393Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?
Easy394Which TWO of the following are PRIMARY goals of incident management according to industry best practices?
Easy395Which role is primarily responsible for designing and reviewing an organization's security architecture?
Easy396A CISO is developing key risk indicators (KRIs) for the security programme. Which TWO of the following are lagging indicators? (Select TWO.)
Medium397A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?
Hard398Which of the following BEST describes the role of a security architect in a security program?
Medium399During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)
Easy400In a security awareness program, which training approach is most appropriate for software developers?
Medium401An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?
Medium402Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?
Easy403During a P1 incident involving a ransomware attack, the crisis management team has been activated. The communications lead is drafting an all-staff internal communication. Which of the following should be INCLUDED in this communication?
Hard404Which of the following best describes a key benefit of a centralized information security governance model?
Easy405A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?
Medium406A company's information security manager notices that several business units have implemented shadow IT systems that bypass the central security governance. Which of the following governance strategies would most effectively address this issue in the long term?
Hard407During a P1 incident, the incident response manager is preparing an executive sitrep. Which of the following should be included to preserve legal privilege?
Medium408Based on the exhibit, which of the following is the MOST likely attack vector?
Medium409A security program manager is selecting metrics to report to the board. Which THREE metrics provide the BEST indication of the program's effectiveness?
Hard410An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?
Medium411Which of the following is the BEST example of a board-level security metric?
Easy412After a phishing attack, an organization's incident response team identifies that the attacker gained access to an email account and sent internal spear-phishing emails. What is the BEST immediate containment action?
Hard413Which of the following is the FIRST step in the security policy development lifecycle?
Easy414Which of the following are key components of an information security program? (Select TWO)
Easy415An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?
Hard416Arrange the steps for deploying a security patch to critical servers in a production environment.
Medium417During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?
Medium418Arrange the steps for performing a vulnerability scan on a network segment.
Medium419During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?
Hard420An organization's incident response plan includes a call tree. During an incident, the primary contact is unreachable. What should happen?
Medium421Which of the following is a leading indicator of security program effectiveness?
Easy422Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)
Medium423A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?
Easy424A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
Medium425Which TWO elements are key components of a security culture measurement program?
Easy426A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?
Medium427After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?
Hard428An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?
Hard429An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?
Easy430Which THREE of the following are best practices for handling evidence during an incident investigation?
Hard431A CISO is evaluating metrics for an executive security report. Which TWO of the following are lagging indicators?
Medium432An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?
Medium433Which host should be prioritized for risk mitigation based on the vulnerability scan results?
Hard434During incident response, a forensic investigator needs to collect evidence from a compromised server. Which action BEST preserves evidence integrity?
Medium435What is the primary function of a Security Operations Center (SOC)?
Easy436Which THREE are key performance indicators (KPIs) for an information security program?
Hard437A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)
Medium438A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?
Hard439Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?
Easy440Order the steps for a risk assessment process according to ISACA's risk management framework.
Medium441In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?
Medium442During a security incident, the incident response team discovers that an attacker has exfiltrated data via an encrypted tunnel over HTTPS. Which log source is MOST likely to provide evidence of the exfiltration?
Hard443Which THREE of the following are critical success factors for implementing an information security program?
Hard444An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?
Easy445Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?
Easy446A multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?
Medium447An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?
Hard448Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?
Medium449A security administrator reports that the VPN tunnel to the remote peer (10.1.1.1) intermittently fails. Which of the following is the most likely cause?
Medium450A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?
Hard451Which TWO of the following are incident categories in an incident management programme?
Hard452In a security operations center (SOC), which function is PRIMARILY responsible for analyzing alerts and determining whether they represent actual security incidents?
Medium453An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?
Medium454During an incident investigation, the response team discovers that the attacker exploited a known vulnerability for which a patch was available but not applied. What should be the team's primary focus during the recovery phase?
Medium455When should an incident response transition to business continuity and disaster recovery (BC/DR) activation?
Medium456An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:
Hard457Match each CISM domain to its focus area.
Medium458After a supply chain attack, the incident response team identifies that a third-party vendor's compromised credentials were used to access the organization's network. Which incident category should this be classified under?
Hard459BankOne has a mature security governance program but recently failed a regulatory audit because the board had not formally approved the risk appetite statement. The CISO argues that risk appetite is reviewed annually and was verbally approved. To prevent recurrence, what governance change is most effective?
Medium460Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)
Hard461A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
Easy462A multinational corporation is implementing a risk-based approach to information security governance. The chief information security officer (CISO) has been asked to prioritize security initiatives based on business impact. Which of the following actions should the CISO take FIRST to align security governance with business objectives?
Medium463Which THREE of the following are valid methods to identify information security risks? (Choose three.)
Hard464A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?
Hard465An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?
Medium466A CISO is developing an information security governance framework for a financial institution. Which of the following is the PRIMARY purpose of such a framework?
Easy467You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?
Medium468An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)
Hard469Which of the following is the most important factor for ensuring the long-term success of an information security program?
Easy470In a third-party risk management programme, what is the primary purpose of vendor tiering?
Medium471After an incident is contained and eradicated, the incident response team conducts a post-incident review. Which of the following is the PRIMARY objective of this review?
Medium472A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?
Hard473Which of the following is the PRIMARY purpose of a security awareness program?
Easy474An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Medium475A security architect is designing a defense-in-depth strategy. Which combination of controls best exemplifies this approach?
Medium476An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)
Medium477A security program lacks executive support. What is the best strategy to gain support?
Hard478During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?
Hard479Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)
Easy480An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?
Medium481During an audit of the information security program, the auditor identifies that several critical systems are not included in the incident response plan. Which of the following are the MOST appropriate actions for the security manager to take? (Select TWO.)
Medium482An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?
Easy483A multinational corporation has just detected a ransomware attack that encrypted critical files on a file server. The incident response team has been activated. Which of the following should be the FIRST action taken by the team?
Medium484Which TWO of the following are key components of an effective incident response plan?
Medium485A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?
Hard486A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?
Hard487Which TWO of the following are appropriate actions to take during the detection phase of incident management?
Hard488A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?
Hard489An organization is required to notify regulators of a material cybersecurity incident within 4 business days. Which regulation imposes this requirement?
Hard490An organization is redesigning its information security program to better align with business objectives. The CISO reports to the CIO, but business leaders feel security decisions are too IT-centric. Which reporting structure would best address this concern?
Medium491After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?
Hard492A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?
Easy493A healthcare organization is merging with another entity and must integrate their IT systems. During due diligence, it is discovered that the acquired company has a high number of unpatched critical vulnerabilities in its electronic health record (EHR) system. The merger timeline is aggressive and the integration team wants to proceed as planned. As the risk manager, what is the best course of action?
Hard494An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?
Hard495An organization plans to implement ISO/IEC 27001 to formalize its information security management system. Which step is most critical to ensure successful implementation?
Easy496An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?
Hard497A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?
Hard498An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?
Medium499After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?
Hard500Which TWO of the following are indicators of a potential security incident?
Easy501Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?
Medium502An organization's security monitoring system detects multiple failed login attempts from an internal IP address to a critical database server. The attempts are occurring every few seconds. What is the FIRST step the incident response team should take?
Easy503A security analyst detects unusual outbound network traffic from a database server to an unknown IP address. The traffic uses encrypted connections on port 443. Which type of attack is MOST likely occurring?
Medium504Refer to the exhibit. A company implements this data classification scheme. Which risk is most likely introduced by this scheme?
Easy505A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?
Hard506A CISO is evaluating security metrics for reporting to the board. Which TWO of the following are leading indicators?
Medium507A retail company's security governance includes a policy that all software must be approved by a security committee. This delays critical business applications. The CIO complains. How should the CISO adjust governance?
Easy508A CISO wants to present a high-level security status to the board using a one-page dashboard. Which of the following metrics is MOST appropriate for this audience?
Medium509A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?
Medium510Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Easy511Match each security control type to its example.
Medium512A security team detects lateral movement within the network using PowerShell scripts. Which TWO actions are MOST effective to contain the threat?
Hard513Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?
Easy514Which THREE of the following are responsibilities of the board of directors regarding information security governance?
Medium515An organization maintains evidence handling procedures for incident response. A forensic investigator needs to collect a hard drive from a compromised server. Which of the following is the MOST critical step to ensure admissibility in court?
Hard516The SIEM alerts on this traffic. What should the incident analyst do FIRST?
Hard517Which is a key component of an information security program?
Easy518Refer to the exhibit. Given the exhibit, which type of incident is MOST likely occurring?
Medium519Based on the exhibit, what is the most significant security gap in this configuration?
Medium520A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)
Medium521An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?
Medium522A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?
Easy523TechStart, a cloud-based startup, has rapidly grown from 50 to 500 employees. It lacks a formal security governance structure. The CEO asks the CISO to develop one. The CISO finds that the company's culture values speed over compliance. The board expects a governance framework within three months. What is the most practical approach?
Medium524Which THREE of the following are incident severity levels defined in a typical incident management program? (Select three.)
Medium525An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?
Easy526Based on the exhibit, which role is responsible for notifying affected users about the phishing attack?
Easy527An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?
Medium528Which security team role is primarily responsible for defining and maintaining security architecture standards?
Easy529An organization has an incident response plan that designates a primary and alternate incident response team. During a simulated ransomware attack, the primary team is unavailable. What should the alternate team do FIRST?
Easy530Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?
Easy531A multinational corporation must comply with both GDPR and CCPA. Which governance approach is most effective?
Medium532A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?
Medium533A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?
Medium534An organization is updating its security policies. After drafting the policy, which step should occur NEXT?
Medium535A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?
Hard536When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?
Easy537An organization is implementing a new cloud-based ERP system. Which of the following is the MOST important action for the information security manager to ensure alignment with the organization's risk appetite?
Medium538You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?
Hard539A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?
Medium540An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?
Hard541Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?
Medium542Which role is primarily responsible for developing and maintaining the organization's security architecture?
Easy543A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?
Medium544A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?
Medium545Which TWO actions are essential during the detection and analysis phase of incident response?
Medium546Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?
Easy547A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?
Hard548A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?
Medium549An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?
Medium550What is the first step in the security policy development lifecycle?
Easy551A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?
Medium552During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?
Hard553After a security incident, which step should be taken first?
Easy554After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?
Hard555Based on the incident response policy exhibit, which phase should include notifying external stakeholders such as law enforcement?
Easy556During an incident investigation, the incident response team needs to collect volatile data from a compromised server. Which of the following data should be collected FIRST?
Easy557Which governance model is characterized by a single, centralized security team that serves the entire organization?
Easy558Which TWO of the following are primary objectives of information security governance? (Choose two.)
Easy559Which of the following best describes the primary purpose of a security program's governance framework?
Medium560A CISO is preparing the security budget for the next fiscal year. The current IT budget is $10 million. For a mature security program, what is the recommended security budget range?
Hard561When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?
Medium562Order the steps for implementing a security awareness training program.
Medium563Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)
Hard564Which of the following is the most significant risk in this architecture?
Easy565A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?
Hard566After a data breach, the CISO is updating the incident response plan. Which of the following is MOST critical to include?
Hard567A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?
Medium568An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?
Hard569During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?
Hard570Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?
Easy571A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?
Medium572Which TWO of the following are typically considered key components of an information security governance framework?
Easy573During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?
Hard574Which of the following is the PRIMARY purpose of an information security risk assessment?
Easy575After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?
Medium576A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?
Hard577Which TWO components are essential for an effective information security governance framework?
Easy578Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)
Easy579In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?
Medium580What is the primary purpose of a vulnerability management program?
Easy581A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?
Medium582You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?
Easy583Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?
Easy584Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?
Easy585Which of the following is the FIRST step in the security policy development lifecycle?
Medium586Refer to the exhibit. A security analyst reviews the ACL on the organization's border router. Based on the exhibit, which of the following is the MOST significant governance concern?
Hard587During the identification phase of incident response, which of the following is the MOST reliable indicator of a security incident?
Medium588A security manager is developing metrics for the C-suite dashboard. Which combination of metrics would provide the best view of security program effectiveness, including both leading and lagging indicators?
Hard589A company's incident response team is conducting a tabletop exercise. They are discussing the steps after containment to prevent recurrence. The facilitator asks: 'What is the MOST important next step after containing an incident?' The team considers several options.
Medium590A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?
Hard591An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?
Medium592A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?
Medium593Which THREE of the following are typically included in an information security program budget?
Easy594A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?
Hard595Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)
Hard596During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?
Hard597Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?
Easy598An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?
Hard599An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?
Medium600A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?
Hard601Which THREE of the following are essential components of an information security governance framework?
Medium602Which of the following is the FIRST step when engaging an external forensics firm for an incident?
Easy603Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?
Medium604An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?
Medium605A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?
Hard606An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?
Medium607Which board-level committee typically receives security reports to provide oversight?
Medium608Following a credential compromise incident, the incident response team is conducting root cause analysis using the 5 Whys technique. The first 'why' reveals that the password was weak. The second 'why' reveals that the password policy allowed simple passwords. What should be the focus of the third 'why'?
Hard609A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?
Hard610A security manager needs to justify an increase in the security budget to the board. The current budget is 0.15% of revenue. Which approach would most effectively demonstrate the need for additional funding?
Hard611Which of the following is a LEADING indicator of security performance?
Easy612An organization has just recovered from a ransomware attack and restored systems from backups. Before returning to normal operations, what is the MOST important step?
Hard613A company is implementing an information security program. Which of the following is the PRIMARY reason to align the program with business objectives?
Medium614Which THREE of the following are essential components of an incident response plan? (Select exactly 3)
Hard615Which THREE elements are typically included in a security governance charter?
Easy616An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?
Medium617During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?
Medium618An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?
Hard619In a Capability Maturity Model (CMM) for information security processes, which level is characterized by processes being measured and controlled?
Medium620Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?
Easy621During a P1 (critical) incident, the incident response manager is coordinating response activities. Who is primarily responsible for activating the crisis management team (CMT)?
Medium622A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?
Medium623A security analyst detects unusual outbound traffic from a critical server to an unknown external IP address during business hours. Which step should be taken FIRST in the incident response process?
Easy624Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy625Which THREE of the following are key components of an incident response plan?
Easy626A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?
Easy627Which TWO of the following are key performance indicators (KPIs) that demonstrate the effectiveness of a security awareness program?
Hard628A healthcare organization is developing an information security strategy. The board has mandated that the strategy must support innovation while protecting patient data. Which governance approach BEST balances these priorities?
Hard629Your organization is a multinational corporation with a hybrid cloud infrastructure, including on-premises data centers and AWS, Azure, and GCP environments. You have a distributed incident response team and a central SIEM that aggregates logs from all sources. You are the incident manager on duty when an alert fires indicating that a high-privilege user account (a domain admin) has been observed logging in from an IP address in a country where the company has no operations, at 3:00 AM local time. Subsequent investigation reveals that the same account also has a successful logon from the corporate headquarters at the same time, which is geographically impossible. The SIEM shows a single event for the suspicious logon, and no other indicators of compromise are present. The account has not been used for months. What is the BEST course of action?
Medium630Based on the exhibit, what is the MOST likely scenario?
Medium631Order the steps for implementing a data classification policy in an organization.
Medium632You are the director of information security at a multinational corporation that operates in many countries with conflicting data privacy laws. The company's information security program includes a data classification policy and a data retention schedule, but there is no consistent method for handling cross-border data flows. Recently, a regulator in Country A fined the company for transferring personal data to Country B, which does not provide adequate protection. The legal department recommends implementing a binding corporate rules (BCR) approach, but the IT department says it would be too complex to implement across all systems. You must update the program to ensure compliance while minimizing operational impact. The board wants a solution that can be implemented within one year with reasonable cost. What should you do?
Hard633During an incident, the response team collects volatile data from a compromised server. Which of the following should be collected FIRST to minimize loss of evidence?
Medium634Which of the following is the PRIMARY benefit of a security champions program?
Easy635An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?
Easy636Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?
Hard637An organization's incident response team is handling a P2 incident involving an insider threat. The team has identified the employee responsible. The communications lead is preparing a notification to affected parties. Which of the following should be included in the notification?
Medium638An organization is developing an incident response plan. The CISO wants to ensure that the plan aligns with industry best practices. Which framework should the CISO use as a primary reference?
Hard639An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?
Medium640During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?
Medium641A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
Medium642An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?
Medium643During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?
Medium644After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)
Medium645During a DDoS attack classified as P2, what is the EXPECTED response time and notification level?
Medium646An organization has implemented a balanced scorecard to measure the effectiveness of its information security program. Which of the following metrics would be MOST appropriate for the 'internal processes' perspective?
Hard647A company is considering outsourcing its security operations center (SOC). Which governance consideration is MOST critical before finalizing the decision?
Hard648A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?
Medium649An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)
Hard650A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?
Hard651A security awareness manager is designing role-based training. Which training is most appropriate for software developers?
Medium652Which of the following is the primary objective of a security champions programme?
Easy653An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?
Medium654Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?
Medium655An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?
Easy656A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?
Easy657The security team is designing a security awareness program. Which topic should be prioritized FIRST?
Easy658Which TWO of the following are valid risk response options?
Easy659An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
Medium660Which of the following is the PRIMARY purpose of a security champions program?
Easy661During a DDoS attack, the incident response team is struggling to mitigate the attack. The team decides to engage the organization's ISP and a DDoS mitigation service. Which of the following should be done FIRST?
Medium662An analyst receives an alert indicating a potential data exfiltration. The alert shows a host IP address 10.10.50.200 sending large amounts of data to an external IP address 203.0.113.5 over port 443. What should the analyst do FIRST?
Easy663Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?
Hard664The following incident response configuration is set: ``` playbook: standard actions: - notify: incident_response_team - auto_containment: true priority_override: false ``` Based on the configuration snippet, what is the expected behavior when an incident is triggered?
Hard665Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)
Hard666A multinational corporation is implementing an information security governance framework. The board has requested a mechanism to ensure that security investments align with business objectives. Which of the following is the BEST approach to achieve this alignment?
Medium667An incident response plan should include which three key components to ensure effective response? (Choose three.)
Medium668Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?
Easy669Based on the log entries, what is the most likely scenario?
Hard670Which TWO are key indicators of a data breach? (Choose two.)
Easy671Which of the following best describes the role of the chief information security officer (CISO) in a governance context?
Medium672An organization has a mature incident management process. After a major incident, they conduct a post-incident review. Which activity is MOST important during this review?
Medium673After a ransomware attack, a company discovers that backups are also encrypted. The incident response team has isolated the affected systems. What should be the next step?
Medium674Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?
Easy675An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?
Medium676A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
Medium677A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
Easy678A financial institution is implementing a risk management program and needs to select a methodology that balances quantitative and qualitative factors, complies with regulatory requirements, and provides a consistent framework for risk assessment across business units. Which methodology would best meet these requirements?
Medium679An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?
Medium680Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?
Easy681Which TWO of the following are essential components of an effective information security governance framework? (Select exactly two.)
Medium682A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?
Hard683An organization is conducting a root cause analysis after a data breach. Which of the following sequences BEST aligns with the 5 Whys approach from a CISM perspective?
Medium684An organization's incident response plan (IRP) is being updated. Which stakeholder should be included in the IRP development to ensure legal and regulatory requirements are met?
Easy685An organization's incident response plan includes a step to 'contain the incident.' Which of the following actions is an example of containment?
Easy686Based on the exhibit, what is the first action the incident response team should take?
Easy687During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
Easy688Which of the following are key components of an information security risk management program? (Select TWO)
Medium689A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?
Medium690A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)
Hard691An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?
Hard692A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?
Easy693An organization's IR plan is tested annually. After a test, many gaps are identified. What is the best next step?
Hard694During an incident investigation, the security team discovers that an attacker exfiltrated sensitive customer data via encrypted DNS tunneling over a period of three months. The data loss was only noticed after a routine audit. Which of the following weaknesses MOST likely allowed the attacker to remain undetected for so long?
Hard695After a ransomware incident, the incident response team contains the spread and begins eradication. The team discovers that the ransomware encrypted files on a file server and also deleted shadow copies. Which of the following should the team do NEXT to support recovery?
Medium696A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?
Hard697Which of the following is a key objective of a Security Operations Center (SOC)?
Easy698Which metric is most indicative of security program effectiveness?
Easy699During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?
Hard700In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?
Medium701Which THREE of the following are typical steps in a qualitative risk assessment?
Medium702After successfully containing an incident, the incident response team discovers that the attacker exploited a previously unknown vulnerability in a web application. The vulnerability is not yet patched by the vendor. The organization's management is concerned about the risk of another attack using the same vulnerability. What should the team recommend as the immediate action to reduce this risk?
Easy703When designing phishing simulations, which approach best balances user learning and operational disruption?
Hard704An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?
Medium705A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?
Medium706Arrange the steps in order for conducting a business impact analysis (BIA) in business continuity management.
Medium707An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?
Medium708An organization's intrusion detection system alerts on a potential C2 communication from an internal host. Which phase of the incident response lifecycle should be initiated first?
Easy709During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?
Medium710A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?
Hard711Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
Medium712When selecting security controls, a company must prioritize which controls first?
Medium713You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?
Hard714An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?
Easy715Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Hard716Based on the exhibit, an incident involves unauthorized access to a file server containing corporate training videos. No sensitive data is stored there. Which priority should the incident be assigned?
Medium717The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?
Easy718Which THREE of the following are essential roles in an effective information security governance structure? (Choose three.)
Hard719Which TWO of the following are best practices for preserving digital evidence during an incident? (Select exactly 2)
Easy720Which TWO of the following are essential components of an incident response programme?
Medium721Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?
Hard722During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?
Hard723During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium724After a major incident, the lessons learned meeting is scheduled. According to best practices, when should this meeting typically be held after incident resolution?
Hard725A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?
Hard726Which of the following are key components of an Information Security Risk Management program? (Select TWO.)
Medium727Match each business continuity term to its definition.
Medium728A company's security program includes a policy that prohibits the use of personal devices for work. However, the CISO discovers that several executives are using personal tablets to access corporate email. What is the most appropriate action for the CISO to take?
Hard729An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?
Medium730Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?
Medium731An organization has a high residual risk after implementing all feasible controls. According to CISM best practices, which of the following should the information security manager do? (Select TWO.)
Hard732After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?
Hard733A company has recently adopted COBIT 2019 as its governance framework. The board is requesting a concise report on the effectiveness of the security program. Which reporting structure best aligns with COBIT's guidance?
Medium734A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?
Easy735Match each security framework to its primary purpose.
Medium736A security analyst detects a potential data exfiltration from a critical server. According to incident response best practices, what is the first action the analyst should take?
Easy737In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?
Medium738During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?
Medium739An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?
Medium740An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Medium741A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?
Medium742An organization is implementing a security champions program. What is the primary purpose of this initiative?
Medium743An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?
Medium744Refer to the exhibit. An organization uses these firewall rules. After a breach, the IR team finds that the attacker gained access via SSH from an external IP. Which rule is most likely misconfigured?
Hard745Match each cryptographic term to its description.
Medium746Which of the following is the PRIMARY reason to include legal counsel in the incident response team?
Medium747A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?
Medium748Which of the following is the primary purpose of having a pre-established forensic retainer agreement?
Easy749A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?
Medium750Refer to the exhibit. What is most suspicious about this event?
Hard751Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?
Easy752Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)
Hard753A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)
Hard754During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?
Medium755During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium756Which TWO are key elements of a security awareness program designed to change employee behavior?
Hard757Which TWO of the following are key indicators that an organization's information security governance is inadequate?
Hard758A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?
Medium759During a post-incident review, the incident response team identifies that the root cause of a data breach was a misconfigured firewall rule that allowed unrestricted inbound access from the internet. Which corrective action BEST addresses this issue?
Easy760Based on the exhibit, what is the MOST appropriate next step for the information security manager?
Easy761An organization's incident response team is handling a P2 insider threat incident involving unauthorized access to customer data. According to the incident classification, which of the following is the MOST appropriate notification and response timeframe?
Medium762A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?
Medium763Which of the following are essential components of an information security program governance framework? (Select TWO.)
Medium764After a major security incident, the incident response team completes the containment, eradication, and recovery phases. The CISO is now planning the post-incident activities. Which activity is MOST critical to ensure that lessons learned are effectively incorporated?
Hard765An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
Medium766During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?
Hard767An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?
Medium768Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?
Medium769An organization uses a SIEM to correlate security events. The SIEM generates an alert for a possible brute-force attack against an admin account. The incident response team reviews the alert and finds that the account is a service account with a known password. What should the team do NEXT?
Hard770An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?
Medium771An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)
Hard772Which TWO of the following are key performance indicators (KPIs) commonly used to measure the effectiveness of incident management processes?
Easy773An organization is implementing a defense-in-depth strategy. Which of the following is the BEST example of a compensating control?
Medium774Which TWO of the following are risk treatment strategies as defined in ISO 27005?
Easy775Which TWO of the following are recommended practices when conducting a post-incident review? (Select TWO)
Hard776An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)
Medium777Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)
Medium778An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?
Medium779Which TWO of the following are essential components of an incident response plan? (Select two.)
Medium780An incident response team is handling a P2 (high) incident. According to the incident severity classification, which of the following is the expected response timeframe?
Hard781An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?
Hard782A security analyst notices unusual outbound traffic from a server that is not scheduled for any data transfers. Which step should the analyst take FIRST?
Easy783During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?
Hard784An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?
Medium785An organization is designing a security awareness program. Which TWO of the following should be included for developers?
Medium786Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
Medium787Which TWO of the following are typical components of a security awareness program?
Easy788Which TWO of the following are key indicators that an organization's information security governance is effective?
Medium789Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
Medium790A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?
Medium791An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?
Medium792Which THREE elements should be included in an incident response plan to ensure effective communication during a security incident?
Hard793Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?
Medium794Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?
Easy795A small business without a dedicated incident response team experiences a suspected breach. Who should be primarily responsible for leading the incident response efforts?
Easy796A company's information security manager is tasked with ensuring that security initiatives align with business goals. Which of the following best demonstrates this alignment?
Easy797An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)
Medium798During a P1 incident, the crisis management team (CMT) has been activated. The CEO asks for an hourly sitrep. Which of the following is the MOST appropriate content for the sitrep?
Medium799A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?
Hard800Which of the following is a LEADING indicator of security performance?
Easy801Which incident severity level requires executive notification and a 24/7 response?
Medium802Which THREE of the following are key components of an incident response plan? (Select THREE)
Medium803Which THREE of the following are typical roles in an incident response team? (Select THREE)
Medium804A global financial services firm with 15,000 employees has recently experienced a significant data breach due to inadequate oversight of third-party vendors. The breach originated from a cloud service provider that had been granted elevated access without a formal risk assessment or contract review. The board has directed the CISO to overhaul the information security governance framework to prevent recurrence. Currently, the organization has a decentralized security model where each business unit manages its own vendor relationships. The CISO proposes a centralized governance body. Which of the following is the BEST course of action to establish effective governance over third-party risk?
Hard805A manufacturing company has an incident response plan that includes a communication plan. However, during a recent ransomware incident, the team realized that the external legal counsel was not listed in the plan. The incident requires consultation with legal due to potential regulatory implications. The incident response manager needs to address this gap quickly. What should the manager do?
Easy806After detecting a ransomware infection on a file server, the incident response team performs containment and eradication. Which step should be prioritized during the recovery phase to minimize business impact?
Medium807A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)
Hard808A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?
Hard809During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?
Hard810An organization's IDS logs show multiple outbound connections to an external IP address from a server that normally communicates only internally. The logs indicate the process is running under the SYSTEM account. Which of the following BEST describes the likely root cause?
Hard811Which of the following best describes the role of a security architect in a security program?
Medium812An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)
Hard813During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?
Hard814Which TWO of the following are components of an incident response programme?
Medium815Which of the following best describes the difference between risk appetite and risk tolerance?
Easy816A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?
Medium817An incident has been declared as P2 (high severity). According to the incident classification, what is the expected response timeframe and notification requirement?
Medium818What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?
Easy819A security awareness program includes phishing simulations. After six months, the click rate has decreased from 15% to 8%, but the number of reported phishing emails has also dropped. The CISO wants to measure the effectiveness of the program. Which metric would best indicate sustained improvement in security behavior?
Medium820During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?
Hard821A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?
Hard822A financial services company is updating its risk treatment plan for a high-risk legacy system that processes customer data. The risk owner has recommended acceptance of the risk. Which TWO conditions must be met for the risk acceptance to be valid according to ISACA CISM (Certified Information Security Manager) best practices?
Medium823A CISO is planning the security programme budget and wants to justify the investment to the CFO. The organization has a moderate risk appetite and an IT budget of $10 million. What is the most appropriate budget range for the security programme based on industry benchmarks?
Hard824A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?
Hard825An information security manager is developing a security scorecard for the board. Which combination of metrics BEST provides a balanced view of security program effectiveness?
Hard826An organization has decided to adopt a risk-based approach to information security. What is the FIRST step the information security manager should take to implement this approach?
Medium827A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?
Hard828An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?
Medium829An organization's incident response team has completed the initial response to a ransomware incident. During the post-incident review, they identify that the detection was delayed because security logs from different systems were not correlated. The team wants to improve detection capabilities. What should the team recommend as the primary improvement?
Medium830Which of the following best describes the primary purpose of an information security program?
Easy831An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?
Hard832An organization's governance framework requires regular reporting to the board. Which reporting frequency and format is MOST effective for a board with limited security expertise?
Hard833A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
Hard834An organization wants to implement a defense-in-depth strategy for its web application. Which set of controls best exemplifies this approach?
Medium835During a risk assessment, an organization identifies a critical vulnerability in a legacy system that cannot be patched. The system's availability is crucial for business operations. Which of the following risk treatment strategies is MOST appropriate?
Hard836A small business owner wants to establish an information security program but has limited budget and staff. Which of the following frameworks would be most appropriate to guide the program?
Easy837An organization has experienced a P2 incident. According to standard incident severity definitions, which response timeframe is typically expected?
Medium838An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)
Medium839When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?
Medium840During an incident investigation, the team discovers that an attacker used a valid user's credentials to access a sensitive database. The user's account had multi-factor authentication (MFA) enabled. How is this MOST likely possible?
Hard841An information security manager is designing a risk dashboard for the board of directors. Which of the following key risk indicators (KRIs) would be MOST effective for monitoring changes in the organization's security posture related to third-party risk?
Easy842A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?
Medium843Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?
Medium844A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?
Hard845Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?
Medium846A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?
Hard847A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?
Medium848An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?
Hard849Which of the following metrics would be MOST useful for measuring the effectiveness of a phishing simulation program?
Medium850An organization has a distributed incident response team across multiple time zones. During a critical incident, communication delays occur due to different work hours. Which strategy BEST improves coordination and response time?
Hard851During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?
Hard852Refer to the exhibit. An analyst sees this alert on the network. What is the most appropriate immediate action?
Medium853A multinational financial institution uses a third-party Managed Security Service Provider (MSSP) for 24/7 monitoring of its security infrastructure. During a targeted attack, the MSSP’s analysts detected anomalous activity on a critical server at 2:00 AM. However, due to the service level agreement (SLA) which allows up to 12 hours for notification of lower-priority incidents, the MSSP classified the incident as medium severity and did not notify the internal incident response team until 2:00 PM. By then, the attacker had exfiltrated sensitive customer data. The internal team is conducting a post-incident review. What is the PRIMARY issue that led to the delay?
Hard854Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?
Easy855Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)
Medium856An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?
Hard857An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)
Medium858An organization's incident response team is conducting a lessons learned meeting after a major incident. Which outcome is MOST critical to document?
Medium859An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?
Hard860A financial institution is hit by a Distributed Denial of Service (DDoS) attack that is overwhelming their internet-facing services. The incident response team activates the plan, but the attack continues to escalate. The CEO is under pressure and asks the incident response manager whether they should pay the ransom demand (the attackers also sent an extortion note demanding payment to stop the attack). The manager must advise the CEO on the best course of action.
Hard861Which of the following is the PRIMARY goal of incident containment?
Easy862An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?
Medium863In the context of incident severity classification, which of the following best describes a P3 (medium) incident?
Easy864After a security incident, the board holds the CISO accountable. The CISO argues that the incident was caused by a failure in the third-party risk management process. Which of the following governance deficiencies is most likely the root cause?
Medium865An organization has a policy to share indicators of compromise (IoCs) with an Information Sharing and Analysis Center (ISAC). This activity is most closely associated with which phase of incident management?
Medium866An information security manager is asked to report on the effectiveness of the security program. Which metric would BEST indicate governance effectiveness?
Easy867Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)
Hard868Which TWO of the following are key components of an information security program governance structure? (Select TWO.)
Medium869An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?
Hard870An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?
Hard871Which of the following is the PRIMARY role of the board of directors in information security governance?
EasyOther domains
All CISM exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CISM exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 871 scenario questions questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.