Courseiva

CISM · domain

scenario questions

Practise Certified Information Security Manager CISM scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

871 questions223 easy375 medium273 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (871)

Click any question to see the full explanation, or start a practice session above.

1

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Medium
2

After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?

Medium
3

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

Medium
4

During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?

Medium
5

An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?

Hard
6

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

Easy
7

Which of the following is a leading indicator of security program effectiveness?

Easy
8

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

Medium
9

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

Medium
10

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

Medium
11

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

Easy
12

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

Medium
13

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

Easy
14

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

Hard
15

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

Easy
16

During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?

Hard
17

During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?

Easy
18

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

Medium
19

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

Medium
20

An organization is under a DDoS attack that is saturating their internet link. The incident response team needs to mitigate the attack. Which action should be taken first?

Hard
21

An employee emails a spreadsheet containing employee salaries to all staff by mistake. According to the exhibit, what is the minimum handling requirement that was violated?

Medium
22

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

Medium
23

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

Easy
24

Refer to the exhibit. The exhibit shows network traffic from a server to a database. What does this pattern MOST likely indicate?

Easy
25

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

Easy
26

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Hard
27

Refer to the exhibit. A system administrator reviews the log and notices repeated failed SSH attempts from the same IP address. What is the most appropriate risk response?

Medium
28

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

Hard
29

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Medium
30

A security manager is designing a security awareness program. Which TWO metrics are leading indicators of program effectiveness?

Medium
31

Which of the following are key components of a mature information security program? (Select 2)

Hard
32

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

Medium
33

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Hard
34

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

Medium
35

Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)

Medium
36

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

Medium
37

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

Easy
38

Which of the following incident categories would typically require the involvement of the crisis management team?

Easy
39

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

Easy
40

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

Medium
41

During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?

Medium
42

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

Easy
43

Which of the following best describes the primary purpose of an Information Security Program?

Medium
44

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

Medium
45

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

Medium
46

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Hard
47

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Hard
48

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

Hard
49

A small marketing firm with 50 employees experiences a ransomware attack. The IT administrator quickly isolates the infected workstations by disconnecting them from the network. The company has a backup strategy that performs nightly backups to an on-premises NAS device. The administrator restores the affected systems from the most recent backup, but some files remain encrypted. The users report that the backups from the last two days show corruption as well. The firm does not have a formal incident response plan. The owner is anxious to get back to work and asks the administrator what to do next. What should the administrator do?

Easy
50

Given the exhibit, what is the MOST appropriate action for the information security manager?

Medium
51

An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?

Easy
52

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

Hard
53

Refer to the exhibit. This error log indicates a failure in which component of information security governance?

Hard
54

You are the information security manager for a mid-sized e-commerce company with 500 employees. The company recently experienced a data breach where an attacker exploited a vulnerability in a third-party payment processing API, resulting in the exposure of 10,000 customer credit card numbers. The breach was detected by an external forensics team 90 days after the initial compromise. The board is concerned about the company's ability to detect and respond to incidents. Currently, the company has a part-time security team of three people who focus on firewall management and antivirus updates. There is no formal incident response plan, and security monitoring is limited to basic log review once a week. The CISO has asked you to recommend a course of action to improve the security posture, with a focus on governance and oversight. Which of the following is the BEST course of action?

Hard
55

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

Medium
56

A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?

Hard
57

During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?

Medium
58

An organization is developing an information security program for a new subsidiary. Which approach BEST ensures that the subsidiary's program complements the parent's?

Medium
59

During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?

Easy
60

Which of the following is the PRIMARY responsibility of the CISO in an organization?

Easy
61

What is the primary purpose of a security incident near-miss reporting culture?

Easy
62

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

Easy
63

Refer to the exhibit. Based on the exhibit, what is the security implication of this cloud storage bucket policy?

Hard
64

Which TWO are essential elements of an information security program?

Medium
65

An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?

Easy
66

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Medium
67

An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?

Hard
68

Which TWO of the following are components of a typical vulnerability management program?

Easy
69

An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)

Hard
70

A company is restructuring its security governance due to rapid growth. The CISO reports to the CIO. What is the PRIMARY risk of this reporting structure?

Medium
71

A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?

Medium
72

Which THREE of the following are essential components of an information security risk management framework?

Hard
73

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Hard
74

Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?

Medium
75

Which THREE of the following should be included in an incident communication template?

Medium
76

Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?

Medium
77

Which TWO factors are most important when prioritizing security investments? (Select TWO.)

Medium
78

A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?

Hard
79

Which component is essential for building a strong security culture within an organization?

Easy
80

During a ransomware incident, the incident response team identifies that the encryption process is still ongoing. The CISO decides to isolate affected systems to prevent further spread. Which of the following is the MOST appropriate next step?

Medium
81

A large e-commerce company detects a sophisticated attack that has compromised a web application server. The server contains customer payment card information. The incident response team is activated. During triage, the team discovers that the attacker has gained administrative access and installed a backdoor. The company's public relations department wants to issue a press release as soon as possible to maintain customer trust. Legal counsel advises that the breach must be reported to regulators within 72 hours. The technical team is working on containment. What is the MOST important priority for the incident manager at this point?

Medium
82

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

Hard
83

During a P1 (critical) security incident, which of the following is the MOST appropriate frequency for providing executive status updates?

Medium
84

During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?

Hard
85

After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?

Medium
86

An information security manager is developing a program metric to report to senior management. Which metric best demonstrates the effectiveness of the information security program?

Medium
87

An incident has been declared involving a ransomware attack that encrypted critical servers. The organization has backups, but the backups were also encrypted. Which of the following is the BEST course of action?

Hard
88

Match each security role to its primary responsibility.

Medium
89

Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?

Easy
90

Which of the following is a leading indicator of security program effectiveness?

Easy
91

Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?

Medium
92

What is the PRIMARY reason for having an incident response team roster and contact list readily available?

Easy
93

An organization is implementing a new cloud-based ERP system. As part of the emerging risk assessment, the information security manager needs to identify potential risks associated with the cloud migration. Which THREE of the following should be considered as part of the emerging risk assessment for cloud adoption?

Medium
94

A security program manager is reviewing the results of a recent internal audit that identified several security gaps. The manager must prioritize remediation efforts. Which factor should be given the MOST weight?

Hard
95

Given the exhibit, what is the MOST significant governance gap in the described architecture?

Easy
96

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Easy
97

An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Medium
98

Which of the following is the PRIMARY responsibility of a steering committee in an information security program?

Easy
99

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

Medium
100

An organization has multiple business units with different risk tolerances. How should the security program address this?

Hard
101

A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?

Hard
102

A multinational corporation is establishing an information security governance framework. The board has approved a top-down approach where security policies are created at the corporate level and adapted locally. Which of the following is a key benefit of this approach?

Medium
103

An organization's security budget is 12% of the IT budget. Which of the following best describes the maturity of this security program?

Hard
104

Which TWO of the following are key components of an information security risk assessment? (Choose two.)

Easy
105

A user reports that their computer is behaving oddly, and an IT technician finds a suspicious file in the startup folder. The technician is not sure if this is an incident. What should the technician do FIRST?

Easy
106

Based on the exhibit, what is the MOST likely issue?

Hard
107

When establishing an information security program, which TWO of the following are key components of governance?

Easy
108

An information security manager reviews the suspicious activity log shown in the exhibit. The payroll file is supposed to be encrypted and only accessible internally. What is the MOST likely cause for the failed download?

Hard
109

An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?

Hard
110

During a major security incident classified as P1, which of the following is the MOST appropriate communication frequency to the executive team?

Medium
111

Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)

Medium
112

During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?

Medium
113

A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?

Hard
114

An organization's security team detects an unusual spike in outbound traffic from a database server to an external IP address during a routine security scan. The database server contains sensitive customer data. Which of the following is the MOST appropriate initial response?

Hard
115

An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?

Hard
116

A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?

Medium
117

An incident response plan (IRP) is being tested. Which metric is MOST indicative of the team's effectiveness during an exercise?

Easy
118

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

Medium
119

Which THREE are key components of an effective post-incident review?

Hard
120

An information security manager is developing a security scorecard for the board. Which of the following should be included to BEST demonstrate governance performance?

Easy
121

Given the exhibit output from a web server, which connection is MOST suspicious and likely indicates a command-and-control (C2) channel?

Hard
122

A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?

Hard
123

An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?

Medium
124

Which THREE of the following are key phases of the incident management lifecycle according to NIST or ISO? (Choose three.)

Easy
125

A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)

Hard
126

During a data breach investigation, the team discovers that an attacker exfiltrated data via encrypted HTTPS to a server abroad. Which forensic step is most critical?

Hard
127

An organization's security steering committee meets quarterly but lacks decision-making authority. Projects are delayed due to lack of prioritization. What is the most effective improvement?

Medium
128

Which TWO of the following are primary objectives of a security awareness program?

Easy
129

An incident response team discovers that an employee's workstation is infected with malware. The workstation contains sensitive customer data. Which of the following is the MOST appropriate containment strategy?

Easy
130

Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?

Medium
131

Which TWO of the following are key responsibilities of an information security governance committee?

Hard
132

Based on the SIEM alert exhibit, which immediate action should the incident responder take?

Medium
133

A multinational corporation is designing an information security strategy to support its global operations. Which approach best ensures that the strategy is actionable and measurable?

Medium
134

An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?

Medium
135

A multinational corporation is experiencing significant security incidents due to inconsistent security policies across subsidiaries. The CISO proposes implementing a centralized governance model. However, business unit leaders argue that local regulations require autonomy. Which approach best balances governance with local compliance?

Hard
136

An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
137

Match each data classification level to its handling requirement.

Medium
138

During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?

Medium
139

Based on the exhibit, which risk should be addressed first if the organization has limited resources?

Medium
140

A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?

Hard
141

Which TWO actions are key components of the 'Containment' phase in incident response?

Medium
142

A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?

Medium
143

A security operations center receives an alert from an IDS indicating possible command and control traffic. The analyst is unsure if it's a true positive. Which combination of actions should be taken first?

Hard
144

A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?

Medium
145

Which of the following is a key objective of implementing a security champions program?

Easy
146

Which incident severity level requires executive notification and 24/7 response, and has major business impact?

Easy
147

Refer to the exhibit. An organization is implementing access controls for a new data repository that will store financial reports classified as Category C. Which of the following is the MOST appropriate control to include?

Medium
148

An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?

Hard
149

A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?

Medium
150

Refer to the exhibit. An information security manager reviews the risk register and sees that Risk ID R001 has a residual risk of High with a treatment of Accept. Which of the following best explains why this situation may indicate a governance failure?

Medium
151

An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?

Hard
152

Match each information security program component with its correct description.

Hard
153

An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?

Medium
154

A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?

Easy
155

An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?

Medium
156

A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?

Medium
157

An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?

Easy
158

An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Hard
159

A large enterprise experiences a data breach involving personal identifiable information (PII) of customers. The incident response team has contained the breach and is now in the eradication phase. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is MOST critical?

Hard
160

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

Medium
161

A multinational corporation is establishing a risk appetite framework. The board has defined risk appetite as 'no more than one major security incident per year resulting in financial loss exceeding $1M'. Which of the following best represents the risk tolerance for a specific business unit's annual cybersecurity budget allocation?

Hard
162

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

Medium
163

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

Medium
164

An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?

Hard
165

An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)

Hard
166

Which of the following is the primary reason for conducting a lessons learned meeting after an incident?

Easy
167

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

Easy
168

Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?

Hard
169

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

Medium
170

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

Easy
171

Match each incident management phase to its activity.

Medium
172

An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?

Medium
173

A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)

Hard
174

During incident investigation, which evidence preservation method is most important?

Easy
175

Which of the following is the best indicator that an organization has effective information security governance?

Easy
176

During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?

Hard
177

Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Easy
178

An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?

Medium
179

A small business cannot afford a dedicated security team. Which governance model is most appropriate?

Easy
180

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

Medium
181

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Medium
182

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

Hard
183

An organization is developing a vendor risk management program. Which TWO of the following should be included in the vendor onboarding risk assessment?

Medium
184

Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?

Easy
185

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

Medium
186

Based on the risk register entry, what is the primary gap in the current controls?

Easy
187

Refer to the exhibit. Based on the risk register extract, which risk should the information security manager prioritize for additional treatment?

Hard
188

Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?

Easy
189

According to the exhibit, which role is responsible for conducting forensic analysis?

Medium
190

You are the information security manager for a financial services company that processes credit card transactions. The company uses a mix of on-premises servers and cloud services. During a routine vulnerability scan, you discover that one of the web servers has been compromised with a web shell that allows remote command execution. The server is part of a cluster that handles customer-facing web traffic. The incident response team is activated. The team's immediate actions include isolating the server from the network and taking a forensic image. However, the server is critical for business operations, and management is pressuring you to restore service quickly. The server's logs show that the web shell was uploaded three days ago, and during that time, the server processed approximately 10,000 transactions. The team has not yet fully analyzed the forensic image. You need to decide on the next steps. What should you do FIRST?

Hard
191

Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?

Easy
192

A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?

Easy
193

Refer to the exhibit. A security analyst reviews the firewall configuration and identifies a potential risk. What is the most likely risk?

Hard
194

An organization's information security governance committee has not met for the past six months. Which of the following is the most significant risk associated with this situation?

Hard
195

During a risk assessment, an organization identifies that a legacy system processes credit card data and has a high likelihood of being exploited. The cost to remediate the vulnerability is $500,000, while the potential loss from a breach is $2 million with a 30% annual probability. What is the most appropriate risk treatment decision based on this information?

Hard
196

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

Hard
197

During an incident, the incident response team discovers that the attacker used stolen credentials to access the network. What should the team do during the eradication phase?

Medium
198

During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?

Medium
199

Which of the following is the PRIMARY purpose of an incident response plan?

Easy
200

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is working on containment. Which communication should the incident manager prioritize FIRST?

Hard
201

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Hard
202

A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?

Easy
203

After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?

Medium
204

Which metric is considered a lagging indicator of security program performance?

Medium
205

You are the incident response manager for a mid-sized e-commerce company. At 2:00 PM, the security operations center receives an alert from the intrusion detection system indicating a potential SQL injection attack against the customer database server. The server hosts a critical database containing customer PII and payment card data. The alert shows multiple suspicious queries from an internal IP address 192.168.10.50, which belongs to the development team's jump box. The development team uses this jump box to access production servers for maintenance. The jump box is managed by the IT operations team. The CEO is currently in a meeting with investors and cannot be disturbed. The CISO is on leave. The company has a written incident response plan that designates the IT director as the incident response coordinator in the absence of the CISO. The IT director has limited security knowledge. The database administrator (DBA) reports that the database is experiencing high CPU usage and that some customer records appear to have been modified. You need to take immediate action. What should you do FIRST?

Hard
206

Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?

Easy
207

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

Medium
208

An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?

Medium
209

Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?

Easy
210

Given the exhibit, what is the most likely classification of this incident?

Medium
211

Which capability maturity model (CMM) level indicates that security processes are measured and controlled?

Easy
212

Refer to the exhibit. The audit finding reveals a deficiency in which critical aspect of information security governance?

Hard
213

An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?

Easy
214

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

Hard
215

A financial institution is integrating a newly acquired fintech startup. The startup has a very different security culture. What governance approach best ensures integration without stifling innovation?

Hard
216

You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?

Medium
217

A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?

Hard
218

During a forensic investigation, an incident responder needs to collect memory from a compromised server. What is the BEST method to preserve evidence integrity?

Hard
219

What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
220

Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?

Medium
221

Which of the following is a leading indicator for security performance?

Medium
222

During a merger, the acquiring company's board insists on integrating the target company's information security governance into its own within 90 days. However, the target has a significantly different risk culture and lacks documented policies. What is the most critical governance risk in this scenario?

Hard
223

Match each risk assessment activity with the correct phase of the risk management lifecycle: Activities: 1. Identify assets and threats 2. Determine risk level 3. Select controls to reduce risk 4. Monitor risk over time Phases: A. Risk Assessment B. Risk Treatment C. Risk Monitoring D. Risk Communication (not used)

Medium
224

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

Easy
225

An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?

Medium
226

During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?

Medium
227

During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?

Hard
228

You are the information security manager for a mid-sized e-commerce company. The company operates a web application that handles credit card transactions and stores customer data in a backend database. The incident response team has just been alerted to a potential data breach: an intrusion detection system (IDS) flagged a SQL injection attack pattern on the web application's login page. The attack originated from an external IP address (5.5.5.5) and appears to have been successful, as the IDS also detected a large outbound data transfer from the database server to another external IP (6.6.6.6) shortly after. The database server is not segmented from the web server. The company has a legal obligation to report breaches involving cardholder data within 72 hours. The incident response plan is being activated. The team includes a forensic analyst, a network engineer, and a legal advisor. The web application is currently running and serving customers. The CEO wants to minimize business disruption. Which of the following actions should the incident response team take FIRST?

Medium
229

Which governance structure is characterized by a single security team that serves the entire organization?

Easy
230

Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?

Medium
231

An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next critical step?

Easy
232

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

Medium
233

During a simulated phishing exercise, several employees clicked a link and entered their credentials on a fake login page. The security team needs to determine the impact. Which of the following should be the NEXT step?

Medium
234

An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?

Easy
235

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Medium
236

A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?

Hard
237

Which TWO actions are appropriate during the containment phase of an incident involving a malware outbreak on multiple workstations?

Medium
238

An organization's incident response plan has not been updated in two years. Which of the following is the MOST likely consequence?

Easy
239

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Hard
240

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

Easy
241

Which of the following is the PRIMARY reason for aligning the information security program with business objectives?

Easy
242

An organization has implemented a host-based intrusion prevention system (HIPS) on all endpoints. An internal audit reveals that many incidents go undetected because users often disable HIPS when it interferes with applications. Which of the following is the MOST effective control to address this issue?

Hard
243

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Easy
244

A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?

Easy
245

Which TWO of the following are common approaches to information security risk assessment?

Medium
246

A security audit has identified several governance weaknesses. Which TWO of the following are most likely to indicate a lack of effective information security governance? (Choose two.)

Easy
247

A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?

Hard
248

A security manager is developing metrics for the executive dashboard. Which combination of metrics provides a balanced view of security program performance?

Medium
249

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Medium
250

A financial institution is restructuring its information security governance to comply with a new regulatory requirement that mandates a formal risk appetite statement. The board has conflicting views on the level of risk to accept. Which of the following should the information security manager do to facilitate the definition of risk appetite?

Hard
251

During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?

Medium
252

Which of the following is the primary purpose of communicating risk assessment results to senior management?

Easy
253

A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?

Hard
254

A security analyst detects an unusual spike in outbound traffic from a database server. Which of the following is the FIRST step in the incident response process?

Easy
255

Which of the following is the PRIMARY benefit of having a formal policy exception management process?

Medium
256

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

Easy
257

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

Medium
258

Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?

Hard
259

Which of the following is the PRIMARY purpose of an incident response plan?

Easy
260

An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?

Hard
261

A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?

Hard
262

Which TWO of the following are essential components of an information security governance framework according to ISACA's COBIT?

Medium
263

Which document should be reviewed and updated at least annually?

Easy
264

Which TWO of the following are key components of an information security governance framework? (Choose two.)

Medium
265

A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?

Medium
266

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

Hard
267

A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?

Hard
268

An organization uses ISO 27001 Annex A as its control framework. During a risk assessment, a control weakness is identified that could lead to a high-impact data breach. However, implementing the recommended control is cost-prohibitive. Which approach BEST addresses this situation?

Hard
269

An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?

Easy
270

An information security manager is developing a security program for a multinational organization. Which of the following should be considered when defining the program scope? (Select THREE)

Medium
271

An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?

Hard
272

During a third-party risk assessment, the security team discovers that a critical vendor has subcontracted data processing to another company without notification. This represents which type of risk?

Medium
273

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

Medium
274

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?

Medium
275

A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?

Hard
276

An organization is developing a security policy for remote access. According to the policy hierarchy, where should this policy fit?

Medium
277

A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?

Medium
278

A security analyst suspects a credential compromise involving an executive's account. The analyst has isolated the system. What should be the NEXT step according to best practices?

Hard
279

A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?

Hard
280

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

Medium
281

A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?

Easy
282

A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?

Easy
283

In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?

Easy
284

Which TWO of the following are essential components of a security program governance structure?

Medium
285

An organization experiences a DDoS attack that overwhelms their internet connection. Which containment strategy would be MOST effective?

Easy
286

An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?

Medium
287

A financial institution has a mature incident response program. During a security incident, the incident response team identifies that a business-critical application is affected. The team must decide whether to continue containing the incident or allow limited operations to continue. Which factor should be given the HIGHEST priority?

Hard
288

Order the steps for establishing a security incident response team (IRT).

Medium
289

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Hard
290

Which of the following is the primary purpose of an information security program?

Easy
291

Which THREE of the following are typical roles in an incident response team?

Easy
292

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

Hard
293

During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?

Medium
294

Match each risk management term to its definition.

Medium
295

After a ransomware attack, the incident response team successfully restores systems from backups. However, the ransomware encrypts files that were modified after the last backup was taken. Which of the following is the BEST way to minimize future data loss?

Hard
296

An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?

Medium
297

Which of the following best describes residual risk?

Easy
298

Which TWO metrics are considered leading indicators for information security program performance?

Medium
299

A bank detects unusual activity on a server containing sensitive financial data. The activity appears to be from a compromised vendor account that has legitimate remote access to the server for maintenance. The incident manager must decide on containment while maintaining business operations. The vendor account has elevated privileges and is used for routine updates. Disabling the account would delay critical maintenance. What is the BEST course of action?

Hard
300

A financial institution is designing an incident response plan. They want to ensure that during a ransomware incident, critical transaction systems can be restored within 4 hours. Which metric should be used to measure this requirement?

Medium
301

A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?

Hard
302

A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?

Hard
303

An organization is designing its information security program and needs to ensure it supports business continuity. Which TWO of the following should be integrated into the program?

Hard
304

In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?

Hard
305

Which THREE of the following are challenges in implementing information security governance in a decentralized organization?

Hard
306

After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?

Medium
307

After a security incident, the incident response team identifies that the root cause was a phishing email that bypassed the email filter. The email contained a malicious macro that executed PowerShell commands. Which control would be MOST effective in preventing similar incidents in the future?

Hard
308

A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?

Medium
309

Which TWO budget components are considered 'services' in a typical security budget?

Medium
310

Arrange the steps for implementing a new firewall rule in an enterprise environment.

Medium
311

An organization's incident response team is notified of a potential denial-of-service (DoS) attack targeting their web application. The team suspects a distributed denial-of-service (DDoS) attack. What is the FIRST step the team should take?

Medium
312

During an incident, the incident response team needs to preserve evidence for legal proceedings. Which of the following is the MOST important action to take?

Easy
313

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Hard
314

Refer to the exhibit. The CISO wants to improve the program. Which recommendation BEST addresses the main gap shown in the dashboard?

Medium
315

A company's incident response team uses a SIEM to detect security events. Which SIEM capability is MOST critical for early detection of a potential incident?

Medium
316

Which THREE steps are essential in the post-incident review process?

Easy
317

A large enterprise is implementing a new governance framework. The board has approved a risk appetite statement. What is the MOST important next step for the information security manager?

Medium
318

Arrange the steps for responding to a data breach involving personally identifiable information (PII).

Medium
319

Under the proposed SEC rules for cybersecurity incident disclosure, what is the timeframe for reporting a material cybersecurity incident?

Medium
320

After a security incident, the incident response team prepares a report detailing the root cause, impact, and lessons learned. Who is the PRIMARY audience for this report?

Easy
321

A small business is developing its first information security program. Which approach is most effective?

Easy
322

During an internal audit, it was found that the security policy does not address the use of personal devices for work. Which governance action should be taken first?

Easy
323

Which THREE of the following are common challenges in incident response? (Select exactly 3)

Medium
324

Order the steps for conducting an internal audit of an information security management system (ISMS) based on ISO 27001.

Medium
325

A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?

Hard
326

A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?

Easy
327

Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?

Hard
328

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Easy
329

Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?

Medium
330

Which of the following are key components of an information security program's strategic plan? (Select two.)

Medium
331

Acme Corp, a global manufacturer, has a decentralized security governance model. Each business unit manages its own security, resulting in inconsistent policies and repeated audit findings. The new CISO proposes a federated model where a central team sets minimum standards and each unit can add local controls. However, the European unit's head insists on full autonomy due to GDPR strictness. The board is concerned about compliance costs. What should the CISO do first?

Hard
332

In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?

Easy
333

Refer to the exhibit. The dashboard shows the incident response plan test is overdue. What is the MOST immediate risk?

Easy
334

During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?

Hard
335

Which incident category involves unauthorized access to systems or data by an individual within the organization?

Easy
336

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

Medium
337

During a phishing campaign, several employees clicked a malicious link that downloaded a remote access trojan (RAT). The incident response team has isolated the infected endpoints and is analyzing network traffic. They suspect that data may have been exfiltrated but are unsure. The team needs to determine the extent of data exfiltration as quickly as possible. What action should the team take FIRST?

Medium
338

Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)

Hard
339

Which incident severity level requires executive notification and a 24/7 response?

Easy
340

Based on the exhibit, what is the most likely vulnerability that an attacker could exploit?

Hard
341

An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?

Medium
342

Which incident severity level requires executive notification and a 24/7 response?

Easy
343

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

Hard
344

An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?

Medium
345

You are the CISO of a mid-sized e-commerce company with 500 employees. The company recently suffered a data breach where an attacker exfiltrated customer credit card data from the production database. The investigation revealed that the breach originated from a compromised developer workstation. The developer had been granted direct access to the production database for troubleshooting purposes, a practice that had been in place for years. The security governance framework currently lacks a formal process for managing privileged access. The board has asked for immediate improvements to prevent recurrence. Which course of action BEST addresses the governance gap?

Hard
346

You are the incident response manager for a multinational corporation that processes sensitive financial data. The company has a mature security operations center (SOC) that monitors network traffic, endpoints, and cloud services. At 2:00 AM local time, the SOC alerts you to a critical incident: an internal server (IP 10.10.10.50) is communicating with an external IP address (198.51.100.23) known to be associated with a ransomware group. The server hosts a financial database that is replicated to a secondary site every 6 hours. The last successful replication was at 1:00 AM. The SOC has already isolated the server from the network by blocking its outbound traffic at the firewall. However, the server is still running. The initial investigation suggests that the communication started 30 minutes ago. The database contains customer PII and transactional data. Your incident response plan includes steps for containment, eradication, recovery, and post-incident review. The CEO is being notified and expects a recommendation on the best course of action. The company has a cyber insurance policy that requires timely notification and preservation of evidence. The legal department advises that any action that could destroy evidence must be carefully considered. Which of the following is the BEST course of action?

Hard
347

Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?

Hard
348

An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)

Hard
349

A security analyst reviews the following alert from the SIEM: 'Multiple failed login attempts from IP 10.0.0.5 to the domain controller within 5 minutes.' Which TWO actions should the analyst take as part of initial incident response?

Hard
350

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

Medium
351

Match each security metric to its description.

Medium
352

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

Medium
353

An incident response team discovers that an attacker used stolen credentials to access a database. Which step is MOST critical during the eradication phase?

Medium
354

During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?

Medium
355

Which TWO of the following are primary responsibilities of the board of directors in information security governance?

Easy
356

A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?

Hard
357

An organization has a decentralized security governance model. The CISO is struggling to enforce consistent security policies across business units. What is the BEST approach to improve consistency?

Medium
358

After a merger, the combined organization has two different risk tolerance levels: one entity is risk-averse, the other is risk-taking. What is the best governance action?

Hard
359

A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?

Easy
360

During a security audit, several deviations from policy are found. What should the security manager do first?

Medium
361

An organization is implementing a security culture measurement program. Which THREE metrics would BEST indicate a positive security culture?

Hard
362

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Hard
363

Which of the following is the primary purpose of an Information Security Program?

Easy
364

You are the CISO of a large healthcare organization that has recently experienced a data breach due to an insider who exfiltrated patient data over several months. The breach was discovered by an external partner. The organization's information security program includes data loss prevention (DLP) tools, but they were not configured to monitor outbound data from the compromised system. Additionally, user activity monitoring (UAM) was only applied to privileged users, not to regular staff. The board demands a comprehensive improvement plan that will prevent similar incidents. However, there are concerns about employee privacy and budget constraints. The organization has a strong culture of trust and minimal monitoring. Which of the following should be the first priority in the revised program?

Hard
365

A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?

Hard
366

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

Medium
367

An organization is implementing a security controls framework based on NIST SP 800-53. The CISO wants to prioritize controls that will provide the greatest risk reduction for critical assets. Which approach should be used to select the initial set of controls?

Medium
368

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

Hard
369

Which of the following is the PRIMARY role of the board of directors in information security governance?

Medium
370

A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?

Hard
371

An organization's information security program recently experienced a ransomware attack that encrypted critical data. Which of the following program components should be improved first to prevent recurrence?

Easy
372

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

Hard
373

Which THREE of the following are components of a security operations center (SOC)?

Easy
374

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

Hard
375

During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?

Medium
376

In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?

Easy
377

Which of the following is the primary responsibility of the board of directors in information security governance?

Easy
378

What is the PRIMARY purpose of a security champions program?

Easy
379

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

Medium
380

Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?

Easy
381

A security manager is designing a metrics dashboard for the CISO. Which TWO metrics are leading indicators of security performance? (Select TWO)

Medium
382

Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?

Easy
383

After containing a security incident, the team conducts a root cause analysis. They find the breach originated from a compromised third-party vendor account. What is the most effective long-term mitigation?

Medium
384

An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?

Medium
385

A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?

Medium
386

A multinational corporation is designing its information security governance framework. The board has requested a single metric that best indicates the effectiveness of the security program. Which metric would BEST satisfy this request?

Hard
387

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

Medium
388

During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?

Medium
389

Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)

Hard
390

Which document should be created FIRST when establishing an information security program?

Easy
391

A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?

Medium
392

Which of the following are key components of an effective information security program? (Select TWO.)

Medium
393

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?

Easy
394

Which TWO of the following are PRIMARY goals of incident management according to industry best practices?

Easy
395

Which role is primarily responsible for designing and reviewing an organization's security architecture?

Easy
396

A CISO is developing key risk indicators (KRIs) for the security programme. Which TWO of the following are lagging indicators? (Select TWO.)

Medium
397

A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?

Hard
398

Which of the following BEST describes the role of a security architect in a security program?

Medium
399

During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)

Easy
400

In a security awareness program, which training approach is most appropriate for software developers?

Medium
401

An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?

Medium
402

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

Easy
403

During a P1 incident involving a ransomware attack, the crisis management team has been activated. The communications lead is drafting an all-staff internal communication. Which of the following should be INCLUDED in this communication?

Hard
404

Which of the following best describes a key benefit of a centralized information security governance model?

Easy
405

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

Medium
406

A company's information security manager notices that several business units have implemented shadow IT systems that bypass the central security governance. Which of the following governance strategies would most effectively address this issue in the long term?

Hard
407

During a P1 incident, the incident response manager is preparing an executive sitrep. Which of the following should be included to preserve legal privilege?

Medium
408

Based on the exhibit, which of the following is the MOST likely attack vector?

Medium
409

A security program manager is selecting metrics to report to the board. Which THREE metrics provide the BEST indication of the program's effectiveness?

Hard
410

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

Medium
411

Which of the following is the BEST example of a board-level security metric?

Easy
412

After a phishing attack, an organization's incident response team identifies that the attacker gained access to an email account and sent internal spear-phishing emails. What is the BEST immediate containment action?

Hard
413

Which of the following is the FIRST step in the security policy development lifecycle?

Easy
414

Which of the following are key components of an information security program? (Select TWO)

Easy
415

An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?

Hard
416

Arrange the steps for deploying a security patch to critical servers in a production environment.

Medium
417

During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?

Medium
418

Arrange the steps for performing a vulnerability scan on a network segment.

Medium
419

During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?

Hard
420

An organization's incident response plan includes a call tree. During an incident, the primary contact is unreachable. What should happen?

Medium
421

Which of the following is a leading indicator of security program effectiveness?

Easy
422

Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)

Medium
423

A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?

Easy
424

A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?

Medium
425

Which TWO elements are key components of a security culture measurement program?

Easy
426

A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?

Medium
427

After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?

Hard
428

An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?

Hard
429

An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?

Easy
430

Which THREE of the following are best practices for handling evidence during an incident investigation?

Hard
431

A CISO is evaluating metrics for an executive security report. Which TWO of the following are lagging indicators?

Medium
432

An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?

Medium
433

Which host should be prioritized for risk mitigation based on the vulnerability scan results?

Hard
434

During incident response, a forensic investigator needs to collect evidence from a compromised server. Which action BEST preserves evidence integrity?

Medium
435

What is the primary function of a Security Operations Center (SOC)?

Easy
436

Which THREE are key performance indicators (KPIs) for an information security program?

Hard
437

A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)

Medium
438

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

Hard
439

Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?

Easy
440

Order the steps for a risk assessment process according to ISACA's risk management framework.

Medium
441

In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?

Medium
442

During a security incident, the incident response team discovers that an attacker has exfiltrated data via an encrypted tunnel over HTTPS. Which log source is MOST likely to provide evidence of the exfiltration?

Hard
443

Which THREE of the following are critical success factors for implementing an information security program?

Hard
444

An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?

Easy
445

Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?

Easy
446

A multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?

Medium
447

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

Hard
448

Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?

Medium
449

A security administrator reports that the VPN tunnel to the remote peer (10.1.1.1) intermittently fails. Which of the following is the most likely cause?

Medium
450

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

Hard
451

Which TWO of the following are incident categories in an incident management programme?

Hard
452

In a security operations center (SOC), which function is PRIMARILY responsible for analyzing alerts and determining whether they represent actual security incidents?

Medium
453

An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?

Medium
454

During an incident investigation, the response team discovers that the attacker exploited a known vulnerability for which a patch was available but not applied. What should be the team's primary focus during the recovery phase?

Medium
455

When should an incident response transition to business continuity and disaster recovery (BC/DR) activation?

Medium
456

An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:

Hard
457

Match each CISM domain to its focus area.

Medium
458

After a supply chain attack, the incident response team identifies that a third-party vendor's compromised credentials were used to access the organization's network. Which incident category should this be classified under?

Hard
459

BankOne has a mature security governance program but recently failed a regulatory audit because the board had not formally approved the risk appetite statement. The CISO argues that risk appetite is reviewed annually and was verbally approved. To prevent recurrence, what governance change is most effective?

Medium
460

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Hard
461

A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?

Easy
462

A multinational corporation is implementing a risk-based approach to information security governance. The chief information security officer (CISO) has been asked to prioritize security initiatives based on business impact. Which of the following actions should the CISO take FIRST to align security governance with business objectives?

Medium
463

Which THREE of the following are valid methods to identify information security risks? (Choose three.)

Hard
464

A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?

Hard
465

An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?

Medium
466

A CISO is developing an information security governance framework for a financial institution. Which of the following is the PRIMARY purpose of such a framework?

Easy
467

You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?

Medium
468

An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)

Hard
469

Which of the following is the most important factor for ensuring the long-term success of an information security program?

Easy
470

In a third-party risk management programme, what is the primary purpose of vendor tiering?

Medium
471

After an incident is contained and eradicated, the incident response team conducts a post-incident review. Which of the following is the PRIMARY objective of this review?

Medium
472

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Hard
473

Which of the following is the PRIMARY purpose of a security awareness program?

Easy
474

An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?

Medium
475

A security architect is designing a defense-in-depth strategy. Which combination of controls best exemplifies this approach?

Medium
476

An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)

Medium
477

A security program lacks executive support. What is the best strategy to gain support?

Hard
478

During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?

Hard
479

Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)

Easy
480

An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?

Medium
481

During an audit of the information security program, the auditor identifies that several critical systems are not included in the incident response plan. Which of the following are the MOST appropriate actions for the security manager to take? (Select TWO.)

Medium
482

An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?

Easy
483

A multinational corporation has just detected a ransomware attack that encrypted critical files on a file server. The incident response team has been activated. Which of the following should be the FIRST action taken by the team?

Medium
484

Which TWO of the following are key components of an effective incident response plan?

Medium
485

A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?

Hard
486

A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?

Hard
487

Which TWO of the following are appropriate actions to take during the detection phase of incident management?

Hard
488

A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?

Hard
489

An organization is required to notify regulators of a material cybersecurity incident within 4 business days. Which regulation imposes this requirement?

Hard
490

An organization is redesigning its information security program to better align with business objectives. The CISO reports to the CIO, but business leaders feel security decisions are too IT-centric. Which reporting structure would best address this concern?

Medium
491

After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?

Hard
492

A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?

Easy
493

A healthcare organization is merging with another entity and must integrate their IT systems. During due diligence, it is discovered that the acquired company has a high number of unpatched critical vulnerabilities in its electronic health record (EHR) system. The merger timeline is aggressive and the integration team wants to proceed as planned. As the risk manager, what is the best course of action?

Hard
494

An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?

Hard
495

An organization plans to implement ISO/IEC 27001 to formalize its information security management system. Which step is most critical to ensure successful implementation?

Easy
496

An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?

Hard
497

A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?

Hard
498

An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?

Medium
499

After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?

Hard
500

Which TWO of the following are indicators of a potential security incident?

Easy
501

Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?

Medium
502

An organization's security monitoring system detects multiple failed login attempts from an internal IP address to a critical database server. The attempts are occurring every few seconds. What is the FIRST step the incident response team should take?

Easy
503

A security analyst detects unusual outbound network traffic from a database server to an unknown IP address. The traffic uses encrypted connections on port 443. Which type of attack is MOST likely occurring?

Medium
504

Refer to the exhibit. A company implements this data classification scheme. Which risk is most likely introduced by this scheme?

Easy
505

A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?

Hard
506

A CISO is evaluating security metrics for reporting to the board. Which TWO of the following are leading indicators?

Medium
507

A retail company's security governance includes a policy that all software must be approved by a security committee. This delays critical business applications. The CIO complains. How should the CISO adjust governance?

Easy
508

A CISO wants to present a high-level security status to the board using a one-page dashboard. Which of the following metrics is MOST appropriate for this audience?

Medium
509

A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?

Medium
510

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

Easy
511

Match each security control type to its example.

Medium
512

A security team detects lateral movement within the network using PowerShell scripts. Which TWO actions are MOST effective to contain the threat?

Hard
513

Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?

Easy
514

Which THREE of the following are responsibilities of the board of directors regarding information security governance?

Medium
515

An organization maintains evidence handling procedures for incident response. A forensic investigator needs to collect a hard drive from a compromised server. Which of the following is the MOST critical step to ensure admissibility in court?

Hard
516

The SIEM alerts on this traffic. What should the incident analyst do FIRST?

Hard
517

Which is a key component of an information security program?

Easy
518

Refer to the exhibit. Given the exhibit, which type of incident is MOST likely occurring?

Medium
519

Based on the exhibit, what is the most significant security gap in this configuration?

Medium
520

A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)

Medium
521

An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?

Medium
522

A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?

Easy
523

TechStart, a cloud-based startup, has rapidly grown from 50 to 500 employees. It lacks a formal security governance structure. The CEO asks the CISO to develop one. The CISO finds that the company's culture values speed over compliance. The board expects a governance framework within three months. What is the most practical approach?

Medium
524

Which THREE of the following are incident severity levels defined in a typical incident management program? (Select three.)

Medium
525

An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?

Easy
526

Based on the exhibit, which role is responsible for notifying affected users about the phishing attack?

Easy
527

An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?

Medium
528

Which security team role is primarily responsible for defining and maintaining security architecture standards?

Easy
529

An organization has an incident response plan that designates a primary and alternate incident response team. During a simulated ransomware attack, the primary team is unavailable. What should the alternate team do FIRST?

Easy
530

Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?

Easy
531

A multinational corporation must comply with both GDPR and CCPA. Which governance approach is most effective?

Medium
532

A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?

Medium
533

A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?

Medium
534

An organization is updating its security policies. After drafting the policy, which step should occur NEXT?

Medium
535

A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?

Hard
536

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

Easy
537

An organization is implementing a new cloud-based ERP system. Which of the following is the MOST important action for the information security manager to ensure alignment with the organization's risk appetite?

Medium
538

You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?

Hard
539

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Medium
540

An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?

Hard
541

Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?

Medium
542

Which role is primarily responsible for developing and maintaining the organization's security architecture?

Easy
543

A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?

Medium
544

A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?

Medium
545

Which TWO actions are essential during the detection and analysis phase of incident response?

Medium
546

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

Easy
547

A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?

Hard
548

A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?

Medium
549

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

Medium
550

What is the first step in the security policy development lifecycle?

Easy
551

A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?

Medium
552

During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?

Hard
553

After a security incident, which step should be taken first?

Easy
554

After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?

Hard
555

Based on the incident response policy exhibit, which phase should include notifying external stakeholders such as law enforcement?

Easy
556

During an incident investigation, the incident response team needs to collect volatile data from a compromised server. Which of the following data should be collected FIRST?

Easy
557

Which governance model is characterized by a single, centralized security team that serves the entire organization?

Easy
558

Which TWO of the following are primary objectives of information security governance? (Choose two.)

Easy
559

Which of the following best describes the primary purpose of a security program's governance framework?

Medium
560

A CISO is preparing the security budget for the next fiscal year. The current IT budget is $10 million. For a mature security program, what is the recommended security budget range?

Hard
561

When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?

Medium
562

Order the steps for implementing a security awareness training program.

Medium
563

Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)

Hard
564

Which of the following is the most significant risk in this architecture?

Easy
565

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

Hard
566

After a data breach, the CISO is updating the incident response plan. Which of the following is MOST critical to include?

Hard
567

A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?

Medium
568

An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?

Hard
569

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

Hard
570

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

Easy
571

A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?

Medium
572

Which TWO of the following are typically considered key components of an information security governance framework?

Easy
573

During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?

Hard
574

Which of the following is the PRIMARY purpose of an information security risk assessment?

Easy
575

After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?

Medium
576

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

Hard
577

Which TWO components are essential for an effective information security governance framework?

Easy
578

Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)

Easy
579

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

Medium
580

What is the primary purpose of a vulnerability management program?

Easy
581

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

Medium
582

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

Easy
583

Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?

Easy
584

Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?

Easy
585

Which of the following is the FIRST step in the security policy development lifecycle?

Medium
586

Refer to the exhibit. A security analyst reviews the ACL on the organization's border router. Based on the exhibit, which of the following is the MOST significant governance concern?

Hard
587

During the identification phase of incident response, which of the following is the MOST reliable indicator of a security incident?

Medium
588

A security manager is developing metrics for the C-suite dashboard. Which combination of metrics would provide the best view of security program effectiveness, including both leading and lagging indicators?

Hard
589

A company's incident response team is conducting a tabletop exercise. They are discussing the steps after containment to prevent recurrence. The facilitator asks: 'What is the MOST important next step after containing an incident?' The team considers several options.

Medium
590

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

Hard
591

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

Medium
592

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

Medium
593

Which THREE of the following are typically included in an information security program budget?

Easy
594

A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?

Hard
595

Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)

Hard
596

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

Hard
597

Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?

Easy
598

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

Hard
599

An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?

Medium
600

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Hard
601

Which THREE of the following are essential components of an information security governance framework?

Medium
602

Which of the following is the FIRST step when engaging an external forensics firm for an incident?

Easy
603

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

Medium
604

An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?

Medium
605

A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?

Hard
606

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

Medium
607

Which board-level committee typically receives security reports to provide oversight?

Medium
608

Following a credential compromise incident, the incident response team is conducting root cause analysis using the 5 Whys technique. The first 'why' reveals that the password was weak. The second 'why' reveals that the password policy allowed simple passwords. What should be the focus of the third 'why'?

Hard
609

A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?

Hard
610

A security manager needs to justify an increase in the security budget to the board. The current budget is 0.15% of revenue. Which approach would most effectively demonstrate the need for additional funding?

Hard
611

Which of the following is a LEADING indicator of security performance?

Easy
612

An organization has just recovered from a ransomware attack and restored systems from backups. Before returning to normal operations, what is the MOST important step?

Hard
613

A company is implementing an information security program. Which of the following is the PRIMARY reason to align the program with business objectives?

Medium
614

Which THREE of the following are essential components of an incident response plan? (Select exactly 3)

Hard
615

Which THREE elements are typically included in a security governance charter?

Easy
616

An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?

Medium
617

During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?

Medium
618

An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?

Hard
619

In a Capability Maturity Model (CMM) for information security processes, which level is characterized by processes being measured and controlled?

Medium
620

Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?

Easy
621

During a P1 (critical) incident, the incident response manager is coordinating response activities. Who is primarily responsible for activating the crisis management team (CMT)?

Medium
622

A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?

Medium
623

A security analyst detects unusual outbound traffic from a critical server to an unknown external IP address during business hours. Which step should be taken FIRST in the incident response process?

Easy
624

Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
625

Which THREE of the following are key components of an incident response plan?

Easy
626

A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?

Easy
627

Which TWO of the following are key performance indicators (KPIs) that demonstrate the effectiveness of a security awareness program?

Hard
628

A healthcare organization is developing an information security strategy. The board has mandated that the strategy must support innovation while protecting patient data. Which governance approach BEST balances these priorities?

Hard
629

Your organization is a multinational corporation with a hybrid cloud infrastructure, including on-premises data centers and AWS, Azure, and GCP environments. You have a distributed incident response team and a central SIEM that aggregates logs from all sources. You are the incident manager on duty when an alert fires indicating that a high-privilege user account (a domain admin) has been observed logging in from an IP address in a country where the company has no operations, at 3:00 AM local time. Subsequent investigation reveals that the same account also has a successful logon from the corporate headquarters at the same time, which is geographically impossible. The SIEM shows a single event for the suspicious logon, and no other indicators of compromise are present. The account has not been used for months. What is the BEST course of action?

Medium
630

Based on the exhibit, what is the MOST likely scenario?

Medium
631

Order the steps for implementing a data classification policy in an organization.

Medium
632

You are the director of information security at a multinational corporation that operates in many countries with conflicting data privacy laws. The company's information security program includes a data classification policy and a data retention schedule, but there is no consistent method for handling cross-border data flows. Recently, a regulator in Country A fined the company for transferring personal data to Country B, which does not provide adequate protection. The legal department recommends implementing a binding corporate rules (BCR) approach, but the IT department says it would be too complex to implement across all systems. You must update the program to ensure compliance while minimizing operational impact. The board wants a solution that can be implemented within one year with reasonable cost. What should you do?

Hard
633

During an incident, the response team collects volatile data from a compromised server. Which of the following should be collected FIRST to minimize loss of evidence?

Medium
634

Which of the following is the PRIMARY benefit of a security champions program?

Easy
635

An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?

Easy
636

Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?

Hard
637

An organization's incident response team is handling a P2 incident involving an insider threat. The team has identified the employee responsible. The communications lead is preparing a notification to affected parties. Which of the following should be included in the notification?

Medium
638

An organization is developing an incident response plan. The CISO wants to ensure that the plan aligns with industry best practices. Which framework should the CISO use as a primary reference?

Hard
639

An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?

Medium
640

During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?

Medium
641

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

Medium
642

An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?

Medium
643

During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?

Medium
644

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Medium
645

During a DDoS attack classified as P2, what is the EXPECTED response time and notification level?

Medium
646

An organization has implemented a balanced scorecard to measure the effectiveness of its information security program. Which of the following metrics would be MOST appropriate for the 'internal processes' perspective?

Hard
647

A company is considering outsourcing its security operations center (SOC). Which governance consideration is MOST critical before finalizing the decision?

Hard
648

A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?

Medium
649

An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)

Hard
650

A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?

Hard
651

A security awareness manager is designing role-based training. Which training is most appropriate for software developers?

Medium
652

Which of the following is the primary objective of a security champions programme?

Easy
653

An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?

Medium
654

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Medium
655

An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?

Easy
656

A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?

Easy
657

The security team is designing a security awareness program. Which topic should be prioritized FIRST?

Easy
658

Which TWO of the following are valid risk response options?

Easy
659

An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?

Medium
660

Which of the following is the PRIMARY purpose of a security champions program?

Easy
661

During a DDoS attack, the incident response team is struggling to mitigate the attack. The team decides to engage the organization's ISP and a DDoS mitigation service. Which of the following should be done FIRST?

Medium
662

An analyst receives an alert indicating a potential data exfiltration. The alert shows a host IP address 10.10.50.200 sending large amounts of data to an external IP address 203.0.113.5 over port 443. What should the analyst do FIRST?

Easy
663

Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?

Hard
664

The following incident response configuration is set: ``` playbook: standard actions: - notify: incident_response_team - auto_containment: true priority_override: false ``` Based on the configuration snippet, what is the expected behavior when an incident is triggered?

Hard
665

Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)

Hard
666

A multinational corporation is implementing an information security governance framework. The board has requested a mechanism to ensure that security investments align with business objectives. Which of the following is the BEST approach to achieve this alignment?

Medium
667

An incident response plan should include which three key components to ensure effective response? (Choose three.)

Medium
668

Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?

Easy
669

Based on the log entries, what is the most likely scenario?

Hard
670

Which TWO are key indicators of a data breach? (Choose two.)

Easy
671

Which of the following best describes the role of the chief information security officer (CISO) in a governance context?

Medium
672

An organization has a mature incident management process. After a major incident, they conduct a post-incident review. Which activity is MOST important during this review?

Medium
673

After a ransomware attack, a company discovers that backups are also encrypted. The incident response team has isolated the affected systems. What should be the next step?

Medium
674

Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?

Easy
675

An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?

Medium
676

A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?

Medium
677

A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?

Easy
678

A financial institution is implementing a risk management program and needs to select a methodology that balances quantitative and qualitative factors, complies with regulatory requirements, and provides a consistent framework for risk assessment across business units. Which methodology would best meet these requirements?

Medium
679

An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?

Medium
680

Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?

Easy
681

Which TWO of the following are essential components of an effective information security governance framework? (Select exactly two.)

Medium
682

A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?

Hard
683

An organization is conducting a root cause analysis after a data breach. Which of the following sequences BEST aligns with the 5 Whys approach from a CISM perspective?

Medium
684

An organization's incident response plan (IRP) is being updated. Which stakeholder should be included in the IRP development to ensure legal and regulatory requirements are met?

Easy
685

An organization's incident response plan includes a step to 'contain the incident.' Which of the following actions is an example of containment?

Easy
686

Based on the exhibit, what is the first action the incident response team should take?

Easy
687

During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?

Easy
688

Which of the following are key components of an information security risk management program? (Select TWO)

Medium
689

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Medium
690

A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)

Hard
691

An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?

Hard
692

A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?

Easy
693

An organization's IR plan is tested annually. After a test, many gaps are identified. What is the best next step?

Hard
694

During an incident investigation, the security team discovers that an attacker exfiltrated sensitive customer data via encrypted DNS tunneling over a period of three months. The data loss was only noticed after a routine audit. Which of the following weaknesses MOST likely allowed the attacker to remain undetected for so long?

Hard
695

After a ransomware incident, the incident response team contains the spread and begins eradication. The team discovers that the ransomware encrypted files on a file server and also deleted shadow copies. Which of the following should the team do NEXT to support recovery?

Medium
696

A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?

Hard
697

Which of the following is a key objective of a Security Operations Center (SOC)?

Easy
698

Which metric is most indicative of security program effectiveness?

Easy
699

During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?

Hard
700

In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?

Medium
701

Which THREE of the following are typical steps in a qualitative risk assessment?

Medium
702

After successfully containing an incident, the incident response team discovers that the attacker exploited a previously unknown vulnerability in a web application. The vulnerability is not yet patched by the vendor. The organization's management is concerned about the risk of another attack using the same vulnerability. What should the team recommend as the immediate action to reduce this risk?

Easy
703

When designing phishing simulations, which approach best balances user learning and operational disruption?

Hard
704

An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?

Medium
705

A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?

Medium
706

Arrange the steps in order for conducting a business impact analysis (BIA) in business continuity management.

Medium
707

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

Medium
708

An organization's intrusion detection system alerts on a potential C2 communication from an internal host. Which phase of the incident response lifecycle should be initiated first?

Easy
709

During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?

Medium
710

A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?

Hard
711

Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)

Medium
712

When selecting security controls, a company must prioritize which controls first?

Medium
713

You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?

Hard
714

An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?

Easy
715

Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?

Hard
716

Based on the exhibit, an incident involves unauthorized access to a file server containing corporate training videos. No sensitive data is stored there. Which priority should the incident be assigned?

Medium
717

The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?

Easy
718

Which THREE of the following are essential roles in an effective information security governance structure? (Choose three.)

Hard
719

Which TWO of the following are best practices for preserving digital evidence during an incident? (Select exactly 2)

Easy
720

Which TWO of the following are essential components of an incident response programme?

Medium
721

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

Hard
722

During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?

Hard
723

During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
724

After a major incident, the lessons learned meeting is scheduled. According to best practices, when should this meeting typically be held after incident resolution?

Hard
725

A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?

Hard
726

Which of the following are key components of an Information Security Risk Management program? (Select TWO.)

Medium
727

Match each business continuity term to its definition.

Medium
728

A company's security program includes a policy that prohibits the use of personal devices for work. However, the CISO discovers that several executives are using personal tablets to access corporate email. What is the most appropriate action for the CISO to take?

Hard
729

An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?

Medium
730

Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?

Medium
731

An organization has a high residual risk after implementing all feasible controls. According to CISM best practices, which of the following should the information security manager do? (Select TWO.)

Hard
732

After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?

Hard
733

A company has recently adopted COBIT 2019 as its governance framework. The board is requesting a concise report on the effectiveness of the security program. Which reporting structure best aligns with COBIT's guidance?

Medium
734

A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?

Easy
735

Match each security framework to its primary purpose.

Medium
736

A security analyst detects a potential data exfiltration from a critical server. According to incident response best practices, what is the first action the analyst should take?

Easy
737

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

Medium
738

During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?

Medium
739

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?

Medium
740

An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?

Medium
741

A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?

Medium
742

An organization is implementing a security champions program. What is the primary purpose of this initiative?

Medium
743

An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?

Medium
744

Refer to the exhibit. An organization uses these firewall rules. After a breach, the IR team finds that the attacker gained access via SSH from an external IP. Which rule is most likely misconfigured?

Hard
745

Match each cryptographic term to its description.

Medium
746

Which of the following is the PRIMARY reason to include legal counsel in the incident response team?

Medium
747

A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?

Medium
748

Which of the following is the primary purpose of having a pre-established forensic retainer agreement?

Easy
749

A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?

Medium
750

Refer to the exhibit. What is most suspicious about this event?

Hard
751

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Easy
752

Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)

Hard
753

A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)

Hard
754

During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?

Medium
755

During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
756

Which TWO are key elements of a security awareness program designed to change employee behavior?

Hard
757

Which TWO of the following are key indicators that an organization's information security governance is inadequate?

Hard
758

A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?

Medium
759

During a post-incident review, the incident response team identifies that the root cause of a data breach was a misconfigured firewall rule that allowed unrestricted inbound access from the internet. Which corrective action BEST addresses this issue?

Easy
760

Based on the exhibit, what is the MOST appropriate next step for the information security manager?

Easy
761

An organization's incident response team is handling a P2 insider threat incident involving unauthorized access to customer data. According to the incident classification, which of the following is the MOST appropriate notification and response timeframe?

Medium
762

A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?

Medium
763

Which of the following are essential components of an information security program governance framework? (Select TWO.)

Medium
764

After a major security incident, the incident response team completes the containment, eradication, and recovery phases. The CISO is now planning the post-incident activities. Which activity is MOST critical to ensure that lessons learned are effectively incorporated?

Hard
765

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

Medium
766

During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?

Hard
767

An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?

Medium
768

Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?

Medium
769

An organization uses a SIEM to correlate security events. The SIEM generates an alert for a possible brute-force attack against an admin account. The incident response team reviews the alert and finds that the account is a service account with a known password. What should the team do NEXT?

Hard
770

An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?

Medium
771

An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)

Hard
772

Which TWO of the following are key performance indicators (KPIs) commonly used to measure the effectiveness of incident management processes?

Easy
773

An organization is implementing a defense-in-depth strategy. Which of the following is the BEST example of a compensating control?

Medium
774

Which TWO of the following are risk treatment strategies as defined in ISO 27005?

Easy
775

Which TWO of the following are recommended practices when conducting a post-incident review? (Select TWO)

Hard
776

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Medium
777

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Medium
778

An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?

Medium
779

Which TWO of the following are essential components of an incident response plan? (Select two.)

Medium
780

An incident response team is handling a P2 (high) incident. According to the incident severity classification, which of the following is the expected response timeframe?

Hard
781

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

Hard
782

A security analyst notices unusual outbound traffic from a server that is not scheduled for any data transfers. Which step should the analyst take FIRST?

Easy
783

During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?

Hard
784

An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?

Medium
785

An organization is designing a security awareness program. Which TWO of the following should be included for developers?

Medium
786

Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?

Medium
787

Which TWO of the following are typical components of a security awareness program?

Easy
788

Which TWO of the following are key indicators that an organization's information security governance is effective?

Medium
789

Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)

Medium
790

A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?

Medium
791

An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?

Medium
792

Which THREE elements should be included in an incident response plan to ensure effective communication during a security incident?

Hard
793

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

Medium
794

Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?

Easy
795

A small business without a dedicated incident response team experiences a suspected breach. Who should be primarily responsible for leading the incident response efforts?

Easy
796

A company's information security manager is tasked with ensuring that security initiatives align with business goals. Which of the following best demonstrates this alignment?

Easy
797

An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)

Medium
798

During a P1 incident, the crisis management team (CMT) has been activated. The CEO asks for an hourly sitrep. Which of the following is the MOST appropriate content for the sitrep?

Medium
799

A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?

Hard
800

Which of the following is a LEADING indicator of security performance?

Easy
801

Which incident severity level requires executive notification and a 24/7 response?

Medium
802

Which THREE of the following are key components of an incident response plan? (Select THREE)

Medium
803

Which THREE of the following are typical roles in an incident response team? (Select THREE)

Medium
804

A global financial services firm with 15,000 employees has recently experienced a significant data breach due to inadequate oversight of third-party vendors. The breach originated from a cloud service provider that had been granted elevated access without a formal risk assessment or contract review. The board has directed the CISO to overhaul the information security governance framework to prevent recurrence. Currently, the organization has a decentralized security model where each business unit manages its own vendor relationships. The CISO proposes a centralized governance body. Which of the following is the BEST course of action to establish effective governance over third-party risk?

Hard
805

A manufacturing company has an incident response plan that includes a communication plan. However, during a recent ransomware incident, the team realized that the external legal counsel was not listed in the plan. The incident requires consultation with legal due to potential regulatory implications. The incident response manager needs to address this gap quickly. What should the manager do?

Easy
806

After detecting a ransomware infection on a file server, the incident response team performs containment and eradication. Which step should be prioritized during the recovery phase to minimize business impact?

Medium
807

A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)

Hard
808

A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?

Hard
809

During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?

Hard
810

An organization's IDS logs show multiple outbound connections to an external IP address from a server that normally communicates only internally. The logs indicate the process is running under the SYSTEM account. Which of the following BEST describes the likely root cause?

Hard
811

Which of the following best describes the role of a security architect in a security program?

Medium
812

An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)

Hard
813

During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?

Hard
814

Which TWO of the following are components of an incident response programme?

Medium
815

Which of the following best describes the difference between risk appetite and risk tolerance?

Easy
816

A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?

Medium
817

An incident has been declared as P2 (high severity). According to the incident classification, what is the expected response timeframe and notification requirement?

Medium
818

What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?

Easy
819

A security awareness program includes phishing simulations. After six months, the click rate has decreased from 15% to 8%, but the number of reported phishing emails has also dropped. The CISO wants to measure the effectiveness of the program. Which metric would best indicate sustained improvement in security behavior?

Medium
820

During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?

Hard
821

A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?

Hard
822

A financial services company is updating its risk treatment plan for a high-risk legacy system that processes customer data. The risk owner has recommended acceptance of the risk. Which TWO conditions must be met for the risk acceptance to be valid according to ISACA CISM (Certified Information Security Manager) best practices?

Medium
823

A CISO is planning the security programme budget and wants to justify the investment to the CFO. The organization has a moderate risk appetite and an IT budget of $10 million. What is the most appropriate budget range for the security programme based on industry benchmarks?

Hard
824

A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?

Hard
825

An information security manager is developing a security scorecard for the board. Which combination of metrics BEST provides a balanced view of security program effectiveness?

Hard
826

An organization has decided to adopt a risk-based approach to information security. What is the FIRST step the information security manager should take to implement this approach?

Medium
827

A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?

Hard
828

An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?

Medium
829

An organization's incident response team has completed the initial response to a ransomware incident. During the post-incident review, they identify that the detection was delayed because security logs from different systems were not correlated. The team wants to improve detection capabilities. What should the team recommend as the primary improvement?

Medium
830

Which of the following best describes the primary purpose of an information security program?

Easy
831

An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?

Hard
832

An organization's governance framework requires regular reporting to the board. Which reporting frequency and format is MOST effective for a board with limited security expertise?

Hard
833

A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?

Hard
834

An organization wants to implement a defense-in-depth strategy for its web application. Which set of controls best exemplifies this approach?

Medium
835

During a risk assessment, an organization identifies a critical vulnerability in a legacy system that cannot be patched. The system's availability is crucial for business operations. Which of the following risk treatment strategies is MOST appropriate?

Hard
836

A small business owner wants to establish an information security program but has limited budget and staff. Which of the following frameworks would be most appropriate to guide the program?

Easy
837

An organization has experienced a P2 incident. According to standard incident severity definitions, which response timeframe is typically expected?

Medium
838

An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)

Medium
839

When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?

Medium
840

During an incident investigation, the team discovers that an attacker used a valid user's credentials to access a sensitive database. The user's account had multi-factor authentication (MFA) enabled. How is this MOST likely possible?

Hard
841

An information security manager is designing a risk dashboard for the board of directors. Which of the following key risk indicators (KRIs) would be MOST effective for monitoring changes in the organization's security posture related to third-party risk?

Easy
842

A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?

Medium
843

Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?

Medium
844

A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?

Hard
845

Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?

Medium
846

A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?

Hard
847

A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?

Medium
848

An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?

Hard
849

Which of the following metrics would be MOST useful for measuring the effectiveness of a phishing simulation program?

Medium
850

An organization has a distributed incident response team across multiple time zones. During a critical incident, communication delays occur due to different work hours. Which strategy BEST improves coordination and response time?

Hard
851

During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?

Hard
852

Refer to the exhibit. An analyst sees this alert on the network. What is the most appropriate immediate action?

Medium
853

A multinational financial institution uses a third-party Managed Security Service Provider (MSSP) for 24/7 monitoring of its security infrastructure. During a targeted attack, the MSSP’s analysts detected anomalous activity on a critical server at 2:00 AM. However, due to the service level agreement (SLA) which allows up to 12 hours for notification of lower-priority incidents, the MSSP classified the incident as medium severity and did not notify the internal incident response team until 2:00 PM. By then, the attacker had exfiltrated sensitive customer data. The internal team is conducting a post-incident review. What is the PRIMARY issue that led to the delay?

Hard
854

Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?

Easy
855

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Medium
856

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Hard
857

An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)

Medium
858

An organization's incident response team is conducting a lessons learned meeting after a major incident. Which outcome is MOST critical to document?

Medium
859

An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?

Hard
860

A financial institution is hit by a Distributed Denial of Service (DDoS) attack that is overwhelming their internet-facing services. The incident response team activates the plan, but the attack continues to escalate. The CEO is under pressure and asks the incident response manager whether they should pay the ransom demand (the attackers also sent an extortion note demanding payment to stop the attack). The manager must advise the CEO on the best course of action.

Hard
861

Which of the following is the PRIMARY goal of incident containment?

Easy
862

An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?

Medium
863

In the context of incident severity classification, which of the following best describes a P3 (medium) incident?

Easy
864

After a security incident, the board holds the CISO accountable. The CISO argues that the incident was caused by a failure in the third-party risk management process. Which of the following governance deficiencies is most likely the root cause?

Medium
865

An organization has a policy to share indicators of compromise (IoCs) with an Information Sharing and Analysis Center (ISAC). This activity is most closely associated with which phase of incident management?

Medium
866

An information security manager is asked to report on the effectiveness of the security program. Which metric would BEST indicate governance effectiveness?

Easy
867

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Hard
868

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Medium
869

An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?

Hard
870

An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?

Hard
871

Which of the following is the PRIMARY role of the board of directors in information security governance?

Easy

Frequently asked questions

What does the scenario questions domain cover on the CISM exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 871 scenario questions questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.