Courseiva

CISM · domain

scenario questions

Practise Certified Information Security Manager CISM scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

924 questions240 easy391 medium293 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (924)

Click any question to see the full explanation, or start a practice session above.

1

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Medium
2

After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?

Medium
3

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

Medium
4

During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?

Medium
5

An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?

Hard
6

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

Easy
7

A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)

Medium
8

A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?

Medium
9

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

Medium
10

A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)

Hard
11

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

Medium
12

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

Medium
13

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

Easy
14

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

Medium
15

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

Easy
16

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

Hard
17

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

Easy
18

A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?

Medium
19

During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?

Hard
20

During an incident, the incident response team is communicating with affected stakeholders. According to best practices, which of the following should be communicated FIRST?

Easy
21

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

Medium
22

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

Medium
23

A CISO is reviewing the information security strategy and needs to ensure that security investments are justified in business terms. The CFO has requested that each security initiative be tied to a financial metric that reflects potential loss from cyber events. Which approach is MOST appropriate for the CISO to use?

Medium
24

During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?

Hard
25

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

Medium
26

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

Easy
27

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

Easy
28

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Hard
29

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

Hard
30

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Medium
31

Which of the following are key components of a mature information security program? (Select 2)

Hard
32

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

Medium
33

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Hard
34

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

Medium
35

Which TWO of the following are key indicators of a potential insider threat incident? (Select exactly 2)

Medium
36

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

Medium
37

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

Easy
38

A healthcare organization is developing its information security strategy. The CISO is considering how to best align the strategy with the organization's overall business strategy. Which of the following approaches would be MOST effective?

Medium
39

Which of the following incident categories would typically require the involvement of the crisis management team?

Easy
40

During a major incident, the incident response manager must decide whether to declare a crisis and activate the crisis management team (CMT). Which factor is MOST important in making that decision?

Hard
41

A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?

Hard
42

A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?

Medium
43

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

Easy
44

An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.

Easy
45

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

Medium
46

A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?

Hard
47

A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?

Medium
48

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

Easy
49

Which of the following best describes the primary purpose of an Information Security Program?

Medium
50

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

Medium
51

A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?

Hard
52

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

Medium
53

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Hard
54

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Hard
55

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

Hard
56

An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?

Hard
57

A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?

Medium
58

An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?

Easy
59

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

Hard
60

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

Medium
61

During an incident investigation, the forensic analyst discovers that a malware sample communicates with an external IP address. The organization's incident response plan requires a decision on whether to block the IP at the firewall. What should the incident response team do FIRST?

Medium
62

A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?

Easy
63

During an incident, the CIRT leader decides to contain a compromised server by disconnecting it from the network. However, this action may result in loss of volatile forensics data. What should the CIRT leader do?

Easy
64

Which of the following is the PRIMARY responsibility of the CISO in an organization?

Easy
65

A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?

Easy
66

What is the primary purpose of a security incident near-miss reporting culture?

Easy
67

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

Easy
68

A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?

Easy
69

An organization's security governance committee has approved a new security policy. What is the NEXT critical step to ensure the policy's effectiveness?

Easy
70

A financial services firm has activated its crisis management team (CMT) for a significant data breach. The CISO, who is a member of the CMT, is asked to present the technical details of the incident. However, the CMT's primary focus should be on which of the following?

Medium
71

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Medium
72

An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?

Hard
73

A newly appointed CISO is establishing an information security governance framework. The organization has a complex structure with multiple business units, each with its own IT function. The CISO wants to ensure that security decisions are made with input from all relevant stakeholders and that security risks are managed consistently across the enterprise. Which of the following should be the CISO's FIRST step in establishing this framework?

Medium
74

Which TWO of the following are components of a typical vulnerability management program?

Easy
75

An organization suspects a data breach. Which two actions should the incident response team take before notifying affected customers? (Choose two.)

Hard
76

A company is restructuring its security governance due to rapid growth. The CISO reports to the CIO. What is the PRIMARY risk of this reporting structure?

Medium
77

A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?

Medium
78

Which THREE of the following are essential components of an information security risk management framework?

Hard
79

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Hard
80

Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?

Medium
81

Which THREE of the following should be included in an incident communication template?

Medium
82

Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?

Medium
83

A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?

Medium
84

Which TWO factors are most important when prioritizing security investments? (Select TWO.)

Medium
85

A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?

Hard
86

An organization is developing its incident response plan and wants to ensure that it has the necessary authority and communication channels in place before an incident occurs. Which TWO of the following should be established to enable effective incident response? (Choose two.)

Medium
87

Which component is essential for building a strong security culture within an organization?

Easy
88

A CISO is defining the scope of the information security program. The organization has multiple locations and uses cloud services extensively. Which factor is MOST important to consider when defining the program's scope?

Easy
89

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

Hard
90

During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?

Hard
91

After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?

Medium
92

Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?

Easy
93

Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?

Medium
94

What is the PRIMARY reason for having an incident response team roster and contact list readily available?

Easy
95

A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)

Medium
96

Given the exhibit, what is the MOST significant governance gap in the described architecture?

Easy
97

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Easy
98

An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Medium
99

Which of the following is the PRIMARY responsibility of a steering committee in an information security program?

Easy
100

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

Medium
101

A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?

Hard
102

An organization has multiple business units with different risk tolerances. How should the security program address this?

Hard
103

A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?

Hard
104

An organization's information security program has a documented risk management process. During a review, the CISO finds that risk assessments are performed annually but do not account for changes in the threat landscape or business environment. Which of the following is the BEST recommendation to improve the program?

Hard
105

A multinational corporation is establishing an information security governance framework. The board has approved a top-down approach where security policies are created at the corporate level and adapted locally. Which of the following is a key benefit of this approach?

Medium
106

A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)

Hard
107

Which TWO of the following are key components of an information security risk assessment? (Choose two.)

Easy
108

A user reports that their computer is behaving oddly, and an IT technician finds a suspicious file in the startup folder. The technician is not sure if this is an incident. What should the technician do FIRST?

Easy
109

During a major incident, the incident response team determines that a compromised server must be rebuilt immediately to restore a critical service. A forensic analyst objects, noting that the server contains evidence relevant to a pending regulatory investigation. How should the incident manager resolve this conflict?

Hard
110

Based on the exhibit, what is the MOST likely issue?

Hard
111

A security manager is building a risk register for a newly deployed customer relationship management platform. Which TWO of the following entries are most appropriate to record as risks rather than as controls or assets? (Choose two.)

Medium
112

An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?

Hard
113

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget, and they report to their respective business unit leaders. The CISO has limited authority over these teams. A recent incident revealed inconsistent security controls across business units, and the board is concerned about the overall risk posture. Which of the following should the CISO recommend to improve the program's effectiveness?

Medium
114

Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)

Medium
115

During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?

Medium
116

A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?

Hard
117

An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?

Hard
118

A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?

Medium
119

An incident response plan (IRP) is being tested. Which metric is MOST indicative of the team's effectiveness during an exercise?

Easy
120

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

Medium
121

Which THREE are key components of an effective post-incident review?

Hard
122

An information security manager is developing a security scorecard for the board. Which of the following should be included to BEST demonstrate governance performance?

Easy
123

A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?

Hard
124

An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?

Medium
125

A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?

Medium
126

Which THREE of the following are key phases of the incident management lifecycle according to NIST or ISO? (Choose three.)

Easy
127

A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)

Hard
128

An organization's security steering committee meets quarterly but lacks decision-making authority. Projects are delayed due to lack of prioritization. What is the most effective improvement?

Medium
129

Which TWO of the following are primary objectives of a security awareness program?

Easy
130

A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?

Medium
131

An incident response team discovers that an employee's workstation is infected with malware. The workstation contains sensitive customer data. Which of the following is the MOST appropriate containment strategy?

Easy
132

Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?

Medium
133

A multinational corporation is designing an information security strategy to support its global operations. Which approach best ensures that the strategy is actionable and measurable?

Medium
134

An organization's security operations center (SOC) confirms that a production database server is actively exfiltrating customer records to an external IP address. The SOC manager must decide whether to immediately isolate the server from the network. Which factor should PRIMARILY guide this decision?

Medium
135

An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?

Medium
136

A multinational corporation is experiencing significant security incidents due to inconsistent security policies across subsidiaries. The CISO proposes implementing a centralized governance model. However, business unit leaders argue that local regulations require autonomy. Which approach best balances governance with local compliance?

Hard
137

An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
138

A security manager is drafting the escalation criteria for the incident response plan. The organisation wants to ensure that incidents are escalated to the crisis management team (CMT) appropriately. Which of the following is the BEST basis for defining when an incident should be escalated to the CMT?

Medium
139

A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?

Hard
140

A security operations center receives an alert from an IDS indicating possible command and control traffic. The analyst is unsure if it's a true positive. Which combination of actions should be taken first?

Hard
141

A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?

Medium
142

A CISO is reviewing the organization's information security program and wants to improve its maturity. Which of the following are characteristics of a mature information security program? (Choose two.)

Medium
143

Which of the following is a key objective of implementing a security champions program?

Easy
144

Which incident severity level requires executive notification and 24/7 response, and has major business impact?

Easy
145

An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?

Hard
146

A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?

Medium
147

Refer to the exhibit. An information security manager reviews the risk register and sees that Risk ID R001 has a residual risk of High with a treatment of Accept. Which of the following best explains why this situation may indicate a governance failure?

Medium
148

An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?

Hard
149

A financial services company has a policy requiring annual risk assessments for all critical vendors. During an internal audit, it is discovered that several vendors have not been reassessed in over two years. The CISO needs to address this governance gap. Which action should be taken FIRST?

Medium
150

An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?

Medium
151

A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)

Hard
152

A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?

Easy
153

An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?

Medium
154

A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?

Medium
155

A security analyst receives an alert from the SIEM indicating that a user account has been added to the domain administrators group outside of the change management window. The analyst confirms the change was not authorized. According to CISM incident management principles, what should the analyst do FIRST?

Easy
156

A CISO is presenting the information security program's value to the board. The board is particularly concerned about the organization's ability to detect and respond to advanced threats. Which of the following metrics would BEST demonstrate the program's effectiveness in this area?

Medium
157

An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?

Easy
158

A security manager learns that a production database containing customer records was copied to an unauthorized external drive by a contractor. The incident response team has contained the contractor's access. According to CISM best practices, which action should the security manager take NEXT?

Medium
159

An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Hard
160

A large enterprise experiences a data breach involving personal identifiable information (PII) of customers. The incident response team has contained the breach and is now in the eradication phase. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is MOST critical?

Hard
161

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

Medium
162

A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?

Medium
163

A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?

Easy
164

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

Medium
165

A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?

Hard
166

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

Medium
167

An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?

Hard
168

An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)

Hard
169

An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?

Easy
170

An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?

Hard
171

Which of the following is the primary reason for conducting a lessons learned meeting after an incident?

Easy
172

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

Easy
173

Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?

Hard
174

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

Medium
175

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

Easy
176

An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?

Medium
177

A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?

Medium
178

A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)

Hard
179

A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?

Hard
180

Which of the following is the best indicator that an organization has effective information security governance?

Easy
181

During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?

Hard
182

Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Easy
183

An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?

Medium
184

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

Medium
185

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Medium
186

A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?

Easy
187

A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?

Medium
188

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

Hard
189

Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?

Easy
190

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

Medium
191

A global financial services firm is establishing an information security governance framework. The board of directors wants assurance that security risks are managed effectively across all business units. Which of the following is the MOST important element for the CISO to implement to provide this assurance?

Medium
192

Based on the risk register entry, what is the primary gap in the current controls?

Easy
193

A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?

Easy
194

A multinational corporation operates in multiple jurisdictions with varying data protection laws. The CISO is establishing a governance structure to manage compliance with these laws while maintaining a consistent security posture. Which of the following is the MOST effective approach for the CISO to take?

Hard
195

A multinational corporation has a decentralized information security program. Each business unit manages its own security budget and controls, leading to inconsistent practices and duplicated efforts. The CISO wants to improve program efficiency and effectiveness while respecting business unit autonomy. Which of the following is the BEST approach?

Medium
196

According to the exhibit, which role is responsible for conducting forensic analysis?

Medium
197

A CISO has implemented a security program based on ISO/IEC 27001. During a management review, the CIO asks how the program contributes to business value. Which of the following metrics would BEST demonstrate the program's contribution to business value?

Hard
198

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that the framework will effectively manage risk and comply with regulations such as GDPR and PCI DSS. Which of the following are essential components of an effective information security governance framework? (Choose two.)

Hard
199

Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?

Easy
200

A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?

Easy
201

An organization's information security governance committee has not met for the past six months. Which of the following is the most significant risk associated with this situation?

Hard
202

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

Hard
203

During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?

Medium
204

During a major incident, the incident response manager is coordinating containment while the crisis management team (CMT) handles business continuity decisions. A responder proposes immediately wiping and rebuilding an affected server to restore service quickly, but the server contains evidence relevant to a potential legal action. Which of the following is the MOST appropriate action for the incident response manager to take?

Hard
205

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Hard
206

A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?

Easy
207

After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?

Medium
208

A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?

Hard
209

Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?

Easy
210

A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?

Hard
211

During a live intrusion, the incident response lead must decide how the team will communicate. The attackers are believed to be monitoring the corporate email and collaboration platform. Which of the following is the MOST appropriate action to maintain confidentiality of incident communications?

Hard
212

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

Medium
213

An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?

Hard
214

An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?

Medium
215

Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?

Easy
216

Given the exhibit, what is the most likely classification of this incident?

Medium
217

Which capability maturity model (CMM) level indicates that security processes are measured and controlled?

Easy
218

An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?

Hard
219

An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?

Easy
220

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

Hard
221

A financial institution is integrating a newly acquired fintech startup. The startup has a very different security culture. What governance approach best ensures integration without stifling innovation?

Hard
222

You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?

Medium
223

A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?

Hard
224

What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
225

Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?

Medium
226

Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?

Easy
227

A security manager is reviewing the organization's information security governance framework. The board has expressed concern that security decisions are not consistently aligned with the organization's risk appetite. Which of the following would BEST address this concern?

Hard
228

Which of the following is a leading indicator for security performance?

Medium
229

During a merger, the acquiring company's board insists on integrating the target company's information security governance into its own within 90 days. However, the target has a significantly different risk culture and lacks documented policies. What is the most critical governance risk in this scenario?

Hard
230

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

Easy
231

An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?

Medium
232

During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?

Medium
233

During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?

Hard
234

A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?

Medium
235

You are the information security manager for a mid-sized e-commerce company. The company operates a web application that handles credit card transactions and stores customer data in a backend database. The incident response team has just been alerted to a potential data breach: an intrusion detection system (IDS) flagged a SQL injection attack pattern on the web application's login page. The attack originated from an external IP address (5.5.5.5) and appears to have been successful, as the IDS also detected a large outbound data transfer from the database server to another external IP (6.6.6.6) shortly after. The database server is not segmented from the web server. The company has a legal obligation to report breaches involving cardholder data within 72 hours. The incident response plan is being activated. The team includes a forensic analyst, a network engineer, and a legal advisor. The web application is currently running and serving customers. The CEO wants to minimize business disruption. Which of the following actions should the incident response team take FIRST?

Medium
236

Which governance structure is characterized by a single security team that serves the entire organization?

Easy
237

Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?

Medium
238

A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?

Easy
239

An organization has just experienced a ransomware attack that encrypted files on several file servers. The incident response team has contained the incident. What is the next critical step?

Easy
240

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

Medium
241

A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?

Medium
242

An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?

Easy
243

A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?

Easy
244

A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?

Hard
245

A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?

Hard
246

An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)

Hard
247

An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?

Medium
248

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Medium
249

A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?

Hard
250

Which TWO actions are appropriate during the containment phase of an incident involving a malware outbreak on multiple workstations?

Medium
251

During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?

Easy
252

An organization's incident response plan has not been updated in two years. Which of the following is the MOST likely consequence?

Easy
253

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Hard
254

A multinational retailer's security operations center (SOC) identifies that an attacker has compromised a point-of-sale (POS) system in a European store and is moving laterally toward the payment card processing environment. The incident response manager needs to decide the FIRST action to limit business impact while preserving the ability to investigate. Which action should be taken FIRST?

Medium
255

During a major incident, the incident response team discovers that the attacker is still active in the environment and is moving laterally. The incident response manager must decide on the immediate course of action. Which of the following should be the PRIMARY consideration when determining whether to isolate affected network segments?

Hard
256

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

Easy
257

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Easy
258

An organization is developing its incident response plan. The CISO wants to ensure that the plan includes provisions for communicating with external parties during and after an incident. Which of the following should be the PRIMARY consideration when defining external communication procedures?

Medium
259

A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?

Medium
260

An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?

Medium
261

A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?

Easy
262

Which TWO of the following are common approaches to information security risk assessment?

Medium
263

A security audit has identified several governance weaknesses. Which TWO of the following are most likely to indicate a lack of effective information security governance? (Choose two.)

Easy
264

A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?

Hard
265

A CISO is reviewing the organization's risk management process. The board has asked how the CISO ensures that security risks are managed within the organization's risk appetite. Which activity BEST demonstrates this?

Hard
266

An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?

Easy
267

An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)

Medium
268

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Medium
269

An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?

Hard
270

A financial institution is restructuring its information security governance to comply with a new regulatory requirement that mandates a formal risk appetite statement. The board has conflicting views on the level of risk to accept. Which of the following should the information security manager do to facilitate the definition of risk appetite?

Hard
271

During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?

Medium
272

Which of the following is the primary purpose of communicating risk assessment results to senior management?

Easy
273

A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?

Hard
274

A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?

Medium
275

A security analyst detects an unusual spike in outbound traffic from a database server. Which of the following is the FIRST step in the incident response process?

Easy
276

A retail company's security operations center receives an alert that a point-of-sale terminal is communicating with a known malicious command-and-control domain. The analyst confirms the connection is active. According to incident response best practices, which action should the analyst take FIRST?

Easy
277

A global retailer is establishing an information security governance framework. The CISO must ensure that the framework addresses both internal and external requirements. Which THREE of the following are essential components of an effective information security governance framework? (Choose three.)

Hard
278

A financial services firm has just contained a breach in which an attacker exfiltrated customer records from a database server. Legal counsel advises the incident manager that the matter will likely result in litigation and regulatory inquiry. Which TWO actions should the incident manager take to preserve the evidentiary value of the affected server? (Choose two.)

Hard
279

A company's incident response plan defines roles for the incident response team, but during a recent tabletop exercise it became clear that no one had authority to make binding decisions about shutting down production systems. Which of the following should be established to resolve this gap?

Easy
280

Which of the following is the PRIMARY benefit of having a formal policy exception management process?

Medium
281

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

Easy
282

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

Medium
283

Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?

Hard
284

Which of the following is the PRIMARY purpose of an incident response plan?

Easy
285

An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?

Hard
286

A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)

Hard
287

A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?

Hard
288

A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?

Medium
289

Which document should be reviewed and updated at least annually?

Easy
290

Which TWO of the following are key components of an information security governance framework? (Choose two.)

Medium
291

A multinational organisation suffers a breach affecting customers in several jurisdictions. The incident response manager must coordinate notification obligations while the investigation is still ongoing and facts are incomplete. Which of the following is the MOST appropriate approach?

Hard
292

A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?

Medium
293

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

Hard
294

A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?

Hard
295

Which THREE of the following are key performance indicators (KPIs) for an information security program?

Medium
296

An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?

Easy
297

An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?

Easy
298

An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?

Medium
299

An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?

Hard
300

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

Medium
301

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?

Medium
302

A security operations centre (SOC) analyst receives an alert that a production database server is transmitting large volumes of customer data to an external IP address. The analyst confirms the traffic is malicious. According to CISM best practices, which of the following should the analyst do FIRST?

Medium
303

A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)

Medium
304

A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?

Hard
305

A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?

Medium
306

An organization has completed its response to a data breach and is conducting a post-incident review. Management wants assurance that lessons learned will actually improve future response capability. Which outcome BEST demonstrates that the post-incident review achieved this objective?

Medium
307

A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?

Hard
308

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

Medium
309

A CISO is designing a security governance framework for a multinational corporation. The framework must address the need for clear accountability, alignment with business strategy, and effective risk management across diverse business units. Which TWO of the following are essential components of such a governance framework? (Choose two.)

Hard
310

A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?

Easy
311

A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?

Easy
312

In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?

Easy
313

Which TWO of the following are essential components of a security program governance structure?

Medium
314

During a forensic investigation, the external forensics firm discovers evidence that may indicate criminal activity. The incident manager wants to ensure attorney-client privilege is maintained. What should be done?

Hard
315

An organization experiences a DDoS attack that overwhelms their internet connection. Which containment strategy would be MOST effective?

Easy
316

An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?

Medium
317

Order the steps for establishing a security incident response team (IRT).

Medium
318

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Hard
319

Which THREE of the following are typical roles in an incident response team?

Easy
320

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

Hard
321

During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?

Medium
322

Match each risk management term to its definition.

Medium
323

After a ransomware attack, the incident response team successfully restores systems from backups. However, the ransomware encrypts files that were modified after the last backup was taken. Which of the following is the BEST way to minimize future data loss?

Hard
324

An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?

Medium
325

Which of the following best describes residual risk?

Easy
326

A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?

Easy
327

Which TWO metrics are considered leading indicators for information security program performance?

Medium
328

A financial institution is designing an incident response plan. They want to ensure that during a ransomware incident, critical transaction systems can be restored within 4 hours. Which metric should be used to measure this requirement?

Medium
329

A retail company suffers a breach involving payment card data. The incident response manager must decide whether to engage external forensic investigators and outside counsel. Which of the following is the PRIMARY reason to bring in external expertise at this point?

Medium
330

A mid-sized manufacturing firm has decided to transfer the risk of a ransomware attack on its production network by purchasing a cyber insurance policy. The policy includes a $1 million coverage limit and a $50,000 deductible. Six months later, a ransomware incident causes $400,000 in recovery costs. The insurer approves the claim. What is the organization's financial responsibility for this incident?

Easy
331

A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?

Hard
332

A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?

Hard
333

In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?

Hard
334

Which THREE of the following are challenges in implementing information security governance in a decentralized organization?

Hard
335

After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?

Medium
336

After a security incident, the incident response team identifies that the root cause was a phishing email that bypassed the email filter. The email contained a malicious macro that executed PowerShell commands. Which control would be MOST effective in preventing similar incidents in the future?

Hard
337

A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?

Medium
338

Arrange the steps for implementing a new firewall rule in an enterprise environment.

Medium
339

An organization's incident response team is notified of a potential denial-of-service (DoS) attack targeting their web application. The team suspects a distributed denial-of-service (DDoS) attack. What is the FIRST step the team should take?

Medium
340

A CISO at a healthcare payer is revising the incident response plan after a tabletop exercise exposed confusion about who may commit the organization to public statements and remediation costs during a major breach. The board wants clarity on governance-level decision rights that must exist before the next incident. Which TWO activities should be assigned to the crisis management team rather than to the tactical incident response team? (Choose two.)

Hard
341

An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?

Hard
342

During an incident, the incident response team needs to preserve evidence for legal proceedings. Which of the following is the MOST important action to take?

Easy
343

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Hard
344

Which THREE steps are essential in the post-incident review process?

Easy
345

A large enterprise is implementing a new governance framework. The board has approved a risk appetite statement. What is the MOST important next step for the information security manager?

Medium
346

A CISO is developing a set of information security policies for a healthcare organization. The organization must comply with HIPAA and internal privacy requirements. Which of the following should be the PRIMARY consideration when drafting the security policy framework?

Easy
347

A security manager is reviewing the incident response plan and notices that the plan does not specify how to handle a situation where the incident response team cannot reach the primary incident response manager. What should be done to address this gap?

Hard
348

A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?

Medium
349

A security manager is developing key performance indicators (KPIs) for the information security program. Which of the following is the MOST important characteristic of an effective KPI?

Easy
350

After a security incident, the incident response team prepares a report detailing the root cause, impact, and lessons learned. Who is the PRIMARY audience for this report?

Easy
351

A small business is developing its first information security program. Which approach is most effective?

Easy
352

Which THREE of the following are common challenges in incident response? (Select exactly 3)

Medium
353

An organisation has just completed containment of a significant data breach. The incident response manager is preparing the post-incident review. Which of the following activities BEST ensures that lessons learned translate into lasting improvement of the incident response capability?

Medium
354

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget. The CISO wants to improve consistency and reduce duplication of efforts. Which of the following is the MOST effective approach?

Hard
355

A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?

Hard
356

A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?

Easy
357

Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?

Hard
358

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Easy
359

An organization is developing its incident response capabilities and wants to ensure that it can effectively detect and respond to security incidents. Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Choose two.)

Medium
360

Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?

Medium
361

Which of the following are key components of an information security program's strategic plan? (Select two.)

Medium
362

Acme Corp, a global manufacturer, has a decentralized security governance model. Each business unit manages its own security, resulting in inconsistent policies and repeated audit findings. The new CISO proposes a federated model where a central team sets minimum standards and each unit can add local controls. However, the European unit's head insists on full autonomy due to GDPR strictness. The board is concerned about compliance costs. What should the CISO do first?

Hard
363

In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?

Easy
364

During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?

Hard
365

Which incident category involves unauthorized access to systems or data by an individual within the organization?

Easy
366

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

Medium
367

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to the business and driving continuous improvement. Which of the following are the MOST appropriate key performance indicators (KPIs) for the information security program? (Choose two.)

Hard
368

During a phishing campaign, several employees clicked a malicious link that downloaded a remote access trojan (RAT). The incident response team has isolated the infected endpoints and is analyzing network traffic. They suspect that data may have been exfiltrated but are unsure. The team needs to determine the extent of data exfiltration as quickly as possible. What action should the team take FIRST?

Medium
369

Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)

Hard
370

Which THREE of the following are essential components of a mature information security governance framework?

Hard
371

An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?

Medium
372

Which incident severity level requires executive notification and a 24/7 response?

Easy
373

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

Hard
374

An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?

Medium
375

You are the CISO of a mid-sized e-commerce company with 500 employees. The company recently suffered a data breach where an attacker exfiltrated customer credit card data from the production database. The investigation revealed that the breach originated from a compromised developer workstation. The developer had been granted direct access to the production database for troubleshooting purposes, a practice that had been in place for years. The security governance framework currently lacks a formal process for managing privileged access. The board has asked for immediate improvements to prevent recurrence. Which course of action BEST addresses the governance gap?

Hard
376

Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?

Hard
377

A financial services firm's incident response team has contained a credential-stuffing attack that compromised several customer accounts. The CISO asks the incident manager to determine what should happen next before the team stands down. Which action BEST aligns with CISM incident management practices?

Medium
378

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

Medium
379

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

Medium
380

During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?

Medium
381

An organization's information security strategy is being developed. The CISO wants to ensure that the strategy supports business objectives while managing risk. Which of the following should be the PRIMARY input to the strategy development process?

Easy
382

Which TWO of the following are primary responsibilities of the board of directors in information security governance?

Easy
383

A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?

Hard
384

A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?

Medium
385

After a merger, the combined organization has two different risk tolerance levels: one entity is risk-averse, the other is risk-taking. What is the best governance action?

Hard
386

A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?

Easy
387

During a security audit, several deviations from policy are found. What should the security manager do first?

Medium
388

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Hard
389

A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?

Medium
390

A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)

Hard
391

Which of the following is the primary purpose of an Information Security Program?

Easy
392

An organization has recently experienced a data breach that resulted in the loss of customer personally identifiable information (PII). The board of directors is concerned about the effectiveness of the information security governance program. Which of the following should the CISO recommend as the MOST important action to improve governance?

Easy
393

A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)

Medium
394

A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?

Medium
395

A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?

Hard
396

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

Medium
397

An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)

Medium
398

A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?

Easy
399

Which TWO of the following are essential components of an information security program charter?

Easy
400

A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?

Hard
401

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

Hard
402

A CISO is establishing a security governance framework for a decentralized organization where each business unit operates independently. The CISO wants to ensure that security policies are consistently applied while respecting business unit autonomy. Which two actions are MOST appropriate to achieve this? (Choose two.)

Hard
403

An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?

Easy
404

A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?

Hard
405

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

Hard
406

Which THREE of the following are components of a security operations center (SOC)?

Easy
407

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

Hard
408

During an incident investigation, the team discovers that a compromised account was used to exfiltrate data. Which of the following should the team do NEXT?

Medium
409

In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?

Easy
410

Which of the following is the primary responsibility of the board of directors in information security governance?

Easy
411

What is the PRIMARY purpose of a security champions program?

Easy
412

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

Medium
413

Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?

Easy
414

An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?

Hard
415

Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?

Easy
416

After containing a security incident, the team conducts a root cause analysis. They find the breach originated from a compromised third-party vendor account. What is the most effective long-term mitigation?

Medium
417

An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?

Medium
418

A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?

Medium
419

A multinational corporation is designing its information security governance framework. The board has requested a single metric that best indicates the effectiveness of the security program. Which metric would BEST satisfy this request?

Hard
420

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

Medium
421

During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?

Medium
422

Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)

Hard
423

Which document should be created FIRST when establishing an information security program?

Easy
424

A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?

Easy
425

A financial services company is updating its information security policies to reflect a new regulation. The CISO must ensure the policies are effectively communicated and enforced. Which action is MOST important to achieve this?

Medium
426

A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?

Medium
427

A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?

Easy
428

Which of the following are key components of an effective information security program? (Select TWO.)

Medium
429

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?

Easy
430

Which TWO of the following are PRIMARY goals of incident management according to industry best practices?

Easy
431

Which role is primarily responsible for designing and reviewing an organization's security architecture?

Easy
432

During a major incident, the incident response team has contained the threat but recovery is taking longer than expected. The business continuity manager reports that the manual workaround in place will fail within four hours due to capacity limits. Which action should the incident manager take FIRST?

Hard
433

An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?

Easy
434

A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?

Hard
435

During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)

Easy
436

In a security awareness program, which training approach is most appropriate for software developers?

Medium
437

An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?

Medium
438

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

Easy
439

An organization is defining the composition of its incident response team. Which role is PRIMARILY responsible for coordinating communication with the media and the public during a high-profile incident?

Easy
440

Which of the following best describes a key benefit of a centralized information security governance model?

Easy
441

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

Medium
442

An information security program must include elements to ensure continuous improvement. Which TWO of the following are MOST essential for continuous improvement?

Medium
443

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

Medium
444

Which of the following is the BEST example of a board-level security metric?

Easy
445

Which THREE of the following are considered key components of an incident response plan?

Medium
446

After a phishing attack, an organization's incident response team identifies that the attacker gained access to an email account and sent internal spear-phishing emails. What is the BEST immediate containment action?

Hard
447

A CISO is developing a set of metrics to report to the board on the effectiveness of the information security governance program. Which of the following metrics would BEST demonstrate that security governance is aligned with business objectives? (Choose two.)

Hard
448

A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)

Hard
449

A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?

Easy
450

Which of the following are key components of an information security program? (Select TWO)

Easy
451

A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?

Medium
452

An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?

Hard
453

Arrange the steps for deploying a security patch to critical servers in a production environment.

Medium
454

During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?

Medium
455

Arrange the steps for performing a vulnerability scan on a network segment.

Medium
456

During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?

Hard
457

An organization's incident response plan includes a call tree. During an incident, the primary contact is unreachable. What should happen?

Medium
458

Which of the following is a leading indicator of security program effectiveness?

Easy
459

Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)

Medium
460

A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?

Easy
461

A healthcare organization's information security program has a risk register with several high-risk items. The CISO is allocating budget for risk treatment. Which of the following is the MOST important factor when deciding whether to mitigate, transfer, or accept a risk?

Hard
462

A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?

Medium
463

Which TWO elements are key components of a security culture measurement program?

Easy
464

A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?

Medium
465

An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?

Hard
466

After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?

Hard
467

An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?

Hard
468

An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?

Easy
469

Which THREE of the following are best practices for handling evidence during an incident investigation?

Hard
470

A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?

Easy
471

An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?

Medium
472

What is the primary function of a Security Operations Center (SOC)?

Easy
473

A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)

Medium
474

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

Hard
475

Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?

Easy
476

Order the steps for a risk assessment process according to ISACA's risk management framework.

Medium
477

In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?

Medium
478

During a security incident, the incident response team discovers that an attacker has exfiltrated data via an encrypted tunnel over HTTPS. Which log source is MOST likely to provide evidence of the exfiltration?

Hard
479

A global financial services firm is aligning its information security program with the COBIT framework. The board wants assurance that IT risks are governed effectively. Which COBIT component is MOST directly responsible for ensuring that IT risk management activities are aligned with enterprise risk management?

Hard
480

An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?

Easy
481

A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)

Hard
482

Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?

Easy
483

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

Hard
484

Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?

Medium
485

A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?

Hard
486

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

Hard
487

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that security risks are managed effectively and that the program aligns with regulatory requirements. Which TWO elements are MOST critical for the CISO to define as part of this governance framework? (Choose two.)

Medium
488

An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?

Medium
489

During an incident investigation, the response team discovers that the attacker exploited a known vulnerability for which a patch was available but not applied. What should be the team's primary focus during the recovery phase?

Medium
490

An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:

Hard
491

BankOne has a mature security governance program but recently failed a regulatory audit because the board had not formally approved the risk appetite statement. The CISO argues that risk appetite is reviewed annually and was verbally approved. To prevent recurrence, what governance change is most effective?

Medium
492

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Hard
493

A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?

Easy
494

A multinational corporation is implementing a risk-based approach to information security governance. The chief information security officer (CISO) has been asked to prioritize security initiatives based on business impact. Which of the following actions should the CISO take FIRST to align security governance with business objectives?

Medium
495

A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?

Hard
496

During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?

Medium
497

An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?

Medium
498

A CISO is developing an information security governance framework for a financial institution. Which of the following is the PRIMARY purpose of such a framework?

Easy
499

You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?

Medium
500

An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)

Hard
501

Which of the following is the most important factor for ensuring the long-term success of an information security program?

Easy
502

In a third-party risk management programme, what is the primary purpose of vendor tiering?

Medium
503

After an incident is contained and eradicated, the incident response team conducts a post-incident review. Which of the following is the PRIMARY objective of this review?

Medium
504

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Hard
505

Which of the following is the PRIMARY purpose of a security awareness program?

Easy
506

An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?

Medium
507

An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)

Medium
508

A security program lacks executive support. What is the best strategy to gain support?

Hard
509

During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?

Hard
510

An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)

Medium
511

Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)

Easy
512

During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?

Medium
513

An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?

Medium
514

Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)

Medium
515

An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?

Easy
516

A multinational corporation has just detected a ransomware attack that encrypted critical files on a file server. The incident response team has been activated. Which of the following should be the FIRST action taken by the team?

Medium
517

Which TWO of the following are key components of an effective incident response plan?

Medium
518

A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?

Hard
519

A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?

Hard
520

A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?

Hard
521

After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?

Hard
522

A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?

Easy
523

A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?

Hard
524

An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?

Hard
525

An organization plans to implement ISO/IEC 27001 to formalize its information security management system. Which step is most critical to ensure successful implementation?

Easy
526

An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?

Hard
527

A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?

Medium
528

A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?

Hard
529

An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?

Medium
530

After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?

Hard
531

A CISO is developing a business case for a new security initiative. The organization's executives are focused on cost reduction and operational efficiency. Which of the following approaches is BEST to gain executive support?

Medium
532

Which TWO of the following are indicators of a potential security incident?

Easy
533

Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?

Medium
534

An organization's security monitoring system detects multiple failed login attempts from an internal IP address to a critical database server. The attempts are occurring every few seconds. What is the FIRST step the incident response team should take?

Easy
535

A security analyst detects unusual outbound network traffic from a database server to an unknown IP address. The traffic uses encrypted connections on port 443. Which type of attack is MOST likely occurring?

Medium
536

A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?

Hard
537

A retail company's security governance includes a policy that all software must be approved by a security committee. This delays critical business applications. The CIO complains. How should the CISO adjust governance?

Easy
538

A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?

Medium
539

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

Easy
540

Match each security control type to its example.

Medium
541

Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?

Easy
542

Which THREE of the following are responsibilities of the board of directors regarding information security governance?

Medium
543

A CISO is establishing an information security governance framework to ensure that security activities are aligned with business strategy. The organization has multiple business units, each with its own IT and security staff. Which of the following is the MOST effective way to ensure ongoing alignment?

Medium
544

Which is a key component of an information security program?

Easy
545

Based on the exhibit, what is the most significant security gap in this configuration?

Medium
546

A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)

Medium
547

During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?

Medium
548

An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?

Medium
549

A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?

Easy
550

TechStart, a cloud-based startup, has rapidly grown from 50 to 500 employees. It lacks a formal security governance structure. The CEO asks the CISO to develop one. The CISO finds that the company's culture values speed over compliance. The board expects a governance framework within three months. What is the most practical approach?

Medium
551

An organization's information security program is being developed. The CISO needs to ensure that the program's objectives are aligned with the organization's strategic goals. Which of the following is the BEST source of input for defining the security program's objectives?

Easy
552

A financial services firm has activated its incident response team for a suspected insider data theft. The legal department advises that the matter may become a criminal case. The security manager must decide how to handle the forensic images and analyst notes. Which action BEST supports both the investigation and potential legal proceedings?

Hard
553

An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?

Easy
554

An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?

Medium
555

Which security team role is primarily responsible for defining and maintaining security architecture standards?

Easy
556

Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?

Easy
557

Which THREE elements are essential for an effective information security governance framework?

Medium
558

A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)

Medium
559

A multinational corporation must comply with both GDPR and CCPA. Which governance approach is most effective?

Medium
560

A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?

Medium
561

A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?

Medium
562

A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?

Hard
563

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

Easy
564

A retail company is building an information security risk register to support its risk management program. The risk manager wants to ensure the register captures the information needed to track and report risks to senior management. Which TWO of the following are essential elements that should be included for each identified risk? (Choose two.)

Medium
565

An organization is implementing a new cloud-based ERP system. Which of the following is the MOST important action for the information security manager to ensure alignment with the organization's risk appetite?

Medium
566

You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?

Hard
567

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Medium
568

An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?

Hard
569

Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?

Medium
570

Which role is primarily responsible for developing and maintaining the organization's security architecture?

Easy
571

A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?

Medium
572

A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?

Medium
573

A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?

Medium
574

A security manager is drafting the incident classification section of the incident response plan. Executives want a documented, repeatable way to rank incidents so that notification and escalation paths are triggered consistently. Which of the following should be the PRIMARY basis for assigning an incident severity level?

Medium
575

Which TWO actions are essential during the detection and analysis phase of incident response?

Medium
576

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

Easy
577

During a suspected insider data theft investigation, the incident response team discovers that the suspect's laptop is still powered on and logged in. Legal counsel advises that evidence must be preserved for potential litigation. Which of the following actions should the team take FIRST?

Hard
578

A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?

Hard
579

A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?

Medium
580

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

Medium
581

A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?

Medium
582

During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?

Hard
583

A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?

Hard
584

After a security incident, which step should be taken first?

Easy
585

An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?

Easy
586

During a major data breach, the incident response manager needs to determine whether the organization must notify regulators and affected individuals. Which factor is MOST important in making this determination?

Hard
587

After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?

Hard
588

A global insurance provider has completed a risk assessment for a new policyholder web portal. The risk treatment plan includes purchasing cyber insurance to transfer a portion of the financial impact. Which of the following is the PRIMARY consideration when evaluating this treatment option?

Medium
589

An organization's information security strategy is being updated to align with the business goal of expanding into new markets. The CISO must ensure that the strategy addresses the varying legal and regulatory requirements of these markets. Which of the following should be the PRIMARY consideration when updating the strategy?

Hard
590

A CISO is updating the organization's information security policy to reflect a new regulatory requirement. The policy must be approved before it can be communicated to employees. Who is MOST appropriate to approve the updated policy?

Easy
591

During an incident investigation, the incident response team needs to collect volatile data from a compromised server. Which of the following data should be collected FIRST?

Easy
592

Which governance model is characterized by a single, centralized security team that serves the entire organization?

Easy
593

Which TWO of the following are primary objectives of information security governance? (Choose two.)

Easy
594

A security architect is selecting controls for an e-commerce platform. Which TWO of the following are examples of compensating controls?

Easy
595

Which of the following best describes the primary purpose of a security program's governance framework?

Medium
596

When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?

Medium
597

Order the steps for implementing a security awareness training program.

Medium
598

A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)

Medium
599

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

Hard
600

A CISO is updating the enterprise information security strategy. The organization's business strategy now emphasizes rapid expansion into cloud-based services and third-party partnerships. Which of the following should be the CISO's FIRST action to ensure the security strategy remains aligned with the business strategy?

Medium
601

A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?

Medium
602

An incident response team is dealing with a persistent threat that uses fileless malware. Which containment strategy is most effective?

Hard
603

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

Hard
604

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

Easy
605

Which TWO of the following are typically considered key components of an information security governance framework?

Easy
606

During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?

Hard
607

Which of the following is the PRIMARY purpose of an information security risk assessment?

Easy
608

After a merger, two companies with different security cultures are being integrated. What is the BEST approach for the information security manager to achieve a unified governance structure?

Medium
609

A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?

Medium
610

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

Hard
611

An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)

Medium
612

Which TWO components are essential for an effective information security governance framework?

Easy
613

Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)

Easy
614

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

Medium
615

What is the primary purpose of a vulnerability management program?

Easy
616

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

Medium
617

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

Easy
618

A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?

Medium
619

A global financial services firm is revising its information security governance framework. The board of directors has expressed concern that the current security strategy is not adequately aligned with the firm's business objectives and regulatory obligations. The CISO is tasked with improving this alignment. Which of the following actions would BEST address the board's concern?

Hard
620

Based on the exhibit, what is the PRIMARY risk of the automated response policy as configured?

Easy
621

Which of the following is the FIRST step in the security policy development lifecycle?

Medium
622

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

Hard
623

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

Medium
624

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

Medium
625

An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?

Medium
626

A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?

Medium
627

A financial institution is designing its information security governance to comply with multiple regulations. The board has limited risk appetite. Which approach BEST ensures effective governance while minimizing conflict?

Hard
628

During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?

Hard
629

Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)

Hard
630

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

Hard
631

A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?

Medium
632

Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?

Easy
633

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

Hard
634

An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?

Medium
635

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Hard
636

Which THREE of the following are essential components of an information security governance framework?

Medium
637

A global retailer is expanding into new markets and must comply with varying data protection laws. The CISO is revising the information security strategy to ensure it remains aligned with the changing business environment. Which approach BEST ensures ongoing alignment between the security strategy and business objectives?

Hard
638

A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?

Hard
639

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

Medium
640

An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?

Medium
641

A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?

Hard
642

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

Medium
643

Which board-level committee typically receives security reports to provide oversight?

Medium
644

A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?

Hard
645

An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?

Hard
646

A CISO is presenting the information security program's annual report to the board. The board is concerned about the rising cost of cyber insurance and wants to understand how the program can help reduce premiums. Which of the following actions would MOST directly influence the cost of cyber insurance?

Hard
647

A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?

Hard
648

An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?

Hard
649

Which of the following is a LEADING indicator of security performance?

Easy
650

An organization has just recovered from a ransomware attack and restored systems from backups. Before returning to normal operations, what is the MOST important step?

Hard
651

A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?

Hard
652

Which THREE of the following are essential components of an incident response plan? (Select exactly 3)

Hard
653

An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?

Medium
654

During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?

Medium
655

An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?

Hard
656

An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?

Easy
657

Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?

Easy
658

A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?

Medium
659

A security analyst detects unusual outbound traffic from a critical server to an unknown external IP address during business hours. Which step should be taken FIRST in the incident response process?

Easy
660

Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
661

A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?

Easy
662

A healthcare organization is developing an information security strategy. The board has mandated that the strategy must support innovation while protecting patient data. Which governance approach BEST balances these priorities?

Hard
663

Based on the exhibit, what is the MOST likely scenario?

Medium
664

Order the steps for implementing a data classification policy in an organization.

Medium
665

During an incident, the response team collects volatile data from a compromised server. Which of the following should be collected FIRST to minimize loss of evidence?

Medium
666

Which of the following is the PRIMARY benefit of a security champions program?

Easy
667

An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?

Easy
668

Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?

Hard
669

An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?

Medium
670

During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?

Medium
671

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

Medium
672

An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?

Medium
673

During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?

Medium
674

A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?

Medium
675

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Medium
676

A company is considering outsourcing its security operations center (SOC). Which governance consideration is MOST critical before finalizing the decision?

Hard
677

A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?

Medium
678

An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)

Hard
679

A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?

Hard
680

A software company is defining the roles and responsibilities within its information security programme. The CISO wants clarity on who is accountable for ensuring that security requirements are integrated into the software development lifecycle. Which role should be assigned this accountability?

Easy
681

A security awareness manager is designing role-based training. Which training is most appropriate for software developers?

Medium
682

An organization experiences a data breach involving customer personally identifiable information (PII). The incident response team has contained the breach. Which of the following should be the PRIMARY consideration when deciding whether to notify affected customers?

Hard
683

An organization is establishing a new information security program. The CISO needs to ensure that the program's structure and processes are aligned with the organization's overall business strategy. Which of the following should be the CISO's FIRST step?

Easy
684

Which of the following is the primary objective of a security champions programme?

Easy
685

An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?

Medium
686

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Medium
687

A CISO is developing a set of key risk indicators (KRIs) to monitor information security governance effectiveness. The CISO wants to ensure that the KRIs are actionable and aligned with business objectives. Which two characteristics are MOST important for effective KRIs? (Choose two.)

Hard
688

An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?

Easy
689

A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?

Easy
690

The security team is designing a security awareness program. Which topic should be prioritized FIRST?

Easy
691

An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?

Medium
692

Which of the following is the PRIMARY purpose of a security champions program?

Easy
693

An analyst receives an alert indicating a potential data exfiltration. The alert shows a host IP address 10.10.50.200 sending large amounts of data to an external IP address 203.0.113.5 over port 443. What should the analyst do FIRST?

Easy
694

An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?

Easy
695

Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?

Hard
696

The following incident response configuration is set: ``` playbook: standard actions: - notify: incident_response_team - auto_containment: true priority_override: false ``` Based on the configuration snippet, what is the expected behavior when an incident is triggered?

Hard
697

Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)

Hard
698

A company discovers a credential compromise affecting multiple user accounts. According to best practices, what is the first step the incident response team should take?

Hard
699

A multinational corporation is implementing an information security governance framework. The board has requested a mechanism to ensure that security investments align with business objectives. Which of the following is the BEST approach to achieve this alignment?

Medium
700

An incident response plan should include which three key components to ensure effective response? (Choose three.)

Medium
701

Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?

Easy
702

Which TWO are key indicators of a data breach? (Choose two.)

Easy
703

Which of the following best describes the role of the chief information security officer (CISO) in a governance context?

Medium
704

An organization has a mature incident management process. After a major incident, they conduct a post-incident review. Which activity is MOST important during this review?

Medium
705

After a ransomware attack, a company discovers that backups are also encrypted. The incident response team has isolated the affected systems. What should be the next step?

Medium
706

A newly appointed CISO is reviewing the organization's information security policy framework. The board asks which document should define the organization's overall security objectives and assign responsibilities at the highest level. Which document is MOST appropriate for this purpose?

Easy
707

Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?

Easy
708

An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?

Medium
709

A global manufacturing company has a decentralized information security program. Each region has its own security team and budget. The CISO is concerned about inconsistent security practices and wants to improve the program's maturity. Which of the following is the MOST effective approach to achieve consistency across regions while respecting local autonomy?

Medium
710

A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?

Medium
711

A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?

Easy
712

An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?

Medium
713

Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?

Easy
714

Which TWO of the following are essential components of an effective information security governance framework? (Select exactly two.)

Medium
715

A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?

Hard
716

An organization's incident response plan (IRP) is being updated. Which stakeholder should be included in the IRP development to ensure legal and regulatory requirements are met?

Easy
717

An organization's incident response plan includes a step to 'contain the incident.' Which of the following actions is an example of containment?

Easy
718

A retail company's risk committee is reviewing the annual risk assessment. The CISO notes that the organization's stated risk appetite for customer data confidentiality is low, but a business unit wants to launch a loyalty program that shares purchase history with a third-party analytics provider. Which of the following should the CISO do FIRST?

Easy
719

During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?

Easy
720

An organization's incident response plan defines containment, eradication, and recovery phases. During a major incident involving a compromised application server, the incident response manager must decide whether to take the server offline immediately or keep it running to observe attacker behavior. Which of the following is the MOST important factor in making this decision?

Medium
721

During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?

Easy
722

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Medium
723

A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)

Hard
724

A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?

Medium
725

An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?

Hard
726

A financial services firm is updating its information security strategy and needs to align it with the organization's overall business goals. The CISO has been asked to ensure that the security strategy directly supports the achievement of business objectives. Which of the following should be the PRIMARY consideration when aligning the security strategy with business goals?

Medium
727

A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?

Easy
728

An organization's IR plan is tested annually. After a test, many gaps are identified. What is the best next step?

Hard
729

During an incident investigation, the security team discovers that an attacker exfiltrated sensitive customer data via encrypted DNS tunneling over a period of three months. The data loss was only noticed after a routine audit. Which of the following weaknesses MOST likely allowed the attacker to remain undetected for so long?

Hard
730

A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?

Hard
731

Which of the following is a key objective of a Security Operations Center (SOC)?

Easy
732

Which metric is most indicative of security program effectiveness?

Easy
733

A healthcare organization's information security program has a policy that requires all ePHI to be encrypted at rest. During a review, the CISO discovers that a legacy application storing ePHI does not support encryption. The application is critical for patient care and cannot be replaced immediately. Which of the following should the CISO do FIRST?

Medium
734

During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?

Hard
735

A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?

Medium
736

A security operations center (SOC) analyst receives an alert indicating that a workstation is communicating with a known command-and-control (C2) server. The analyst confirms the traffic is malicious. According to CISM best practices, which action should the analyst take NEXT?

Medium
737

In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?

Medium
738

Which THREE of the following are typical steps in a qualitative risk assessment?

Medium
739

After successfully containing an incident, the incident response team discovers that the attacker exploited a previously unknown vulnerability in a web application. The vulnerability is not yet patched by the vendor. The organization's management is concerned about the risk of another attack using the same vulnerability. What should the team recommend as the immediate action to reduce this risk?

Easy
740

When designing phishing simulations, which approach best balances user learning and operational disruption?

Hard
741

An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?

Medium
742

A global financial services firm has a mature information security program. The CISO wants to ensure that the program's strategic objectives remain aligned with changing business goals, such as a new push into mobile banking. Which of the following is the MOST effective way to achieve this alignment?

Medium
743

A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?

Medium
744

An organization is developing its information security program and wants to ensure that security roles and responsibilities are clearly defined and communicated across the enterprise. Which of the following should be established FIRST to achieve this?

Easy
745

An information security manager is reviewing the organization's risk register and notices that a risk related to unpatched software has been assigned a risk score of 9 (on a scale of 1-10) with a note that the risk is 'accepted' because patching would disrupt a critical production system. Which of the following should the manager do NEXT?

Hard
746

A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?

Medium
747

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

Medium
748

An organization's intrusion detection system alerts on a potential C2 communication from an internal host. Which phase of the incident response lifecycle should be initiated first?

Easy
749

A financial services firm has a mature information security program. The Chief Information Security Officer (CISO) is asked by the board to demonstrate that the program is aligned with the organization's strategic objectives. Which of the following is the MOST effective way for the CISO to provide this assurance?

Medium
750

During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?

Medium
751

A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?

Hard
752

Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)

Medium
753

When selecting security controls, a company must prioritize which controls first?

Medium
754

You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?

Hard
755

A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?

Medium
756

An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?

Easy
757

Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?

Hard
758

A financial services firm has completed a risk assessment and identified that its customer-facing web application has a high risk of SQL injection. The CISO must ensure the risk is treated appropriately. Which of the following should be the FIRST action?

Medium
759

The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?

Easy
760

A security manager is reviewing the organization's information security strategy and notices that it focuses heavily on technology controls but lacks integration with business processes. Which action should the manager take to improve alignment with business objectives?

Medium
761

An organization's incident response team is reviewing its post-incident activities after resolving a significant security incident. Management wants to ensure lessons learned are captured and that the response capability improves over time. Which TWO of the following activities are MOST important to include in the post-incident phase? (Choose two.)

Medium
762

Which THREE of the following are essential roles in an effective information security governance structure? (Choose three.)

Hard
763

Which TWO of the following are best practices for preserving digital evidence during an incident? (Select exactly 2)

Easy
764

Which TWO of the following are essential components of an incident response programme?

Medium
765

A newly appointed CISO is reviewing the existing information security program. The program has many documented policies and procedures, but the CISO notices that they have not been updated in over three years. What should the CISO do FIRST?

Easy
766

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

Hard
767

During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?

Hard
768

During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
769

A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?

Hard
770

A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?

Hard
771

Which of the following are key components of an Information Security Risk Management program? (Select TWO.)

Medium
772

Match each business continuity term to its definition.

Medium
773

A CISO is updating the organization's information security strategy to address emerging risks from cloud adoption and remote work. Which of the following should be the FIRST step in this process?

Medium
774

An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?

Medium
775

Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?

Medium
776

A global retailer operates point-of-sale systems in 12 countries. The risk register shows a single entry titled 'Payment card data breach' with a likelihood of 4 and an impact of 5. A new CISO argues this entry is too coarse to support treatment decisions. Which action BEST improves the usefulness of the risk register for decision-making?

Hard
777

After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?

Hard
778

A global retailer's CISO is establishing an information security governance framework. The company operates in 20 countries, each with different privacy laws. The board wants assurance that security investments are justified and risks are managed consistently. Which governance mechanism BEST provides this assurance?

Hard
779

A company has recently adopted COBIT 2019 as its governance framework. The board is requesting a concise report on the effectiveness of the security program. Which reporting structure best aligns with COBIT's guidance?

Medium
780

A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?

Easy
781

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

Medium
782

A small e-commerce company with 50 employees and limited IT budget is establishing its first formal information security program. The company processes customer payment data and must comply with PCI DSS. The CEO wants to balance security with operational costs. The IT manager proposes investing in a state-of-the-art security information and event management (SIEM) system costing $100,000 annually. The CISO, however, recommends a more phased approach. Considering the company's size, budget constraints, and compliance requirements, what should be the CISO's primary recommendation?

Easy
783

During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?

Medium
784

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?

Medium
785

A multinational company experiences a ransomware attack that encrypts critical servers in its European and North American data centers. The incident response team has contained the spread, but restoration will take several days. Executive leadership asks the CISO what should be done to manage the business impact while recovery proceeds. Which of the following is the MOST appropriate immediate action?

Easy
786

An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?

Medium
787

A security analyst receives an alert indicating a potential data exfiltration from a server. Which of the following should be the FIRST step in the incident response process?

Easy
788

A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?

Medium
789

An organization is implementing a security champions program. What is the primary purpose of this initiative?

Medium
790

An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?

Medium
791

During containment of a confirmed intrusion, the incident response manager must decide whether to immediately rebuild the compromised server or first acquire volatile data. Legal counsel has signalled that litigation is likely. Which of the following is the BEST course of action?

Medium
792

Refer to the exhibit. An organization uses these firewall rules. After a breach, the IR team finds that the attacker gained access via SSH from an external IP. Which rule is most likely misconfigured?

Hard
793

An organization has just experienced a data breach involving customer personal information. The incident manager is determining the appropriate communication strategy. Which action BEST aligns with CISM incident management practices?

Easy
794

Which of the following is the PRIMARY reason to include legal counsel in the incident response team?

Medium
795

A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?

Medium
796

Which of the following is the primary purpose of having a pre-established forensic retainer agreement?

Easy
797

A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?

Medium
798

Refer to the exhibit. What is most suspicious about this event?

Hard
799

A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?

Medium
800

Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)

Hard
801

A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)

Hard
802

During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?

Medium
803

During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
804

Which TWO are key elements of a security awareness program designed to change employee behavior?

Hard
805

Which TWO of the following are key indicators that an organization's information security governance is inadequate?

Hard
806

A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?

Medium
807

During a post-incident review, the incident response team identifies that the root cause of a data breach was a misconfigured firewall rule that allowed unrestricted inbound access from the internet. Which corrective action BEST addresses this issue?

Easy
808

A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?

Medium
809

An incident responder is handling a phishing attack that resulted in credential theft. Which TWO actions should be taken FIRST in the containment phase?

Medium
810

Which of the following are essential components of an information security program governance framework? (Select TWO.)

Medium
811

An organisation is reviewing its incident response capabilities after a near-miss. The CISO wants to ensure the team can effectively detect and respond to future incidents. Which TWO of the following are the MOST important capabilities to establish before an incident occurs? (Choose two.)

Hard
812

After a major security incident, the incident response team completes the containment, eradication, and recovery phases. The CISO is now planning the post-incident activities. Which activity is MOST critical to ensure that lessons learned are effectively incorporated?

Hard
813

An organization's incident response plan requires that evidence be collected in a forensically sound manner. A responder is about to capture volatile data from a compromised server. Which action BEST preserves the integrity of the evidence?

Medium
814

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

Medium
815

During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?

Hard
816

An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?

Medium
817

Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?

Medium
818

An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?

Medium
819

During a major ransomware incident, the chief information security officer (CISO) must decide whether to pay the ransom to restore encrypted clinical trial data at a pharmaceutical company. The attackers have threatened to publish the data if not paid within 48 hours. Which of the following is the MOST important factor for the CISO to consider when making this business decision?

Hard
820

An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)

Hard
821

Which TWO of the following are risk treatment strategies as defined in ISO 27005?

Easy
822

A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)

Medium
823

Which TWO of the following are recommended practices when conducting a post-incident review? (Select TWO)

Hard
824

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Medium
825

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Medium
826

An organisation has just completed recovery from a significant cybersecurity incident. The CISO wants to ensure the lessons learned are captured and used to improve future response. Which of the following should be performed as part of the post-incident activity?

Easy
827

A healthcare organization is developing an information security governance framework. The CISO needs to ensure that the framework supports regulatory compliance with HIPAA and aligns with the organization's strategic goals. Which of the following should be the FIRST step in this process?

Medium
828

An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?

Medium
829

Which TWO of the following are essential components of an incident response plan? (Select two.)

Medium
830

A financial services firm has just contained a malware outbreak that disabled online banking for six hours. The incident commander confirms systems are restored and monitoring is stable. Executive leadership now wants to know what must happen before the incident can be formally closed. Which activity is MOST important to complete prior to closure?

Hard
831

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

Hard
832

A security analyst notices unusual outbound traffic from a server that is not scheduled for any data transfers. Which step should the analyst take FIRST?

Easy
833

During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?

Hard
834

An organization has recently experienced a data breach that resulted in reputational damage and regulatory fines. The board has asked the CISO to improve the information security governance framework to prevent future incidents. Which of the following should the CISO do FIRST?

Easy
835

An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?

Medium
836

Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?

Medium
837

Which TWO of the following are typical components of a security awareness program?

Easy
838

Which TWO of the following are key indicators that an organization's information security governance is effective?

Medium
839

Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)

Medium
840

A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?

Medium
841

A financial services firm with a federated governance model is revising its information security strategy. The board has mandated that security investments must demonstrably support business objectives. The CISO is asked to define the MOST effective way to align security governance with business strategy. Which of the following should the CISO do FIRST?

Medium
842

An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?

Medium
843

Which THREE elements should be included in an incident response plan to ensure effective communication during a security incident?

Hard
844

An organization is updating its information security policy framework. The CISO wants to ensure that the policies are effectively communicated and understood by all employees. Which of the following is the MOST effective method to achieve this?

Medium
845

Which THREE are essential steps in incident containment? (Choose three.)

Medium
846

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

Medium
847

Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?

Easy
848

A company's information security manager is tasked with ensuring that security initiatives align with business goals. Which of the following best demonstrates this alignment?

Easy
849

An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)

Medium
850

A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?

Hard
851

An organization's incident response plan defines communication procedures, but during a recent incident, customers learned about a data breach from media reports before receiving any notification from the company. The information security manager has been asked to address this gap. Which of the following is the MOST effective improvement?

Medium
852

Which THREE of the following are key components of an incident response plan? (Select THREE)

Medium
853

Which THREE of the following are typical roles in an incident response team? (Select THREE)

Medium
854

An organization has just experienced a malware outbreak that was contained by isolating affected endpoints. Before restoring the isolated systems to normal operation, the incident response team must decide what activity comes next in the response lifecycle. Which of the following should the team perform NEXT?

Easy
855

A security manager is reviewing the organization's incident response capabilities. During a tabletop exercise, participants struggled to determine who has authority to shut down a critical production system during a suspected incident. Which action BEST addresses this gap?

Hard
856

A global financial services firm with 15,000 employees has recently experienced a significant data breach due to inadequate oversight of third-party vendors. The breach originated from a cloud service provider that had been granted elevated access without a formal risk assessment or contract review. The board has directed the CISO to overhaul the information security governance framework to prevent recurrence. Currently, the organization has a decentralized security model where each business unit manages its own vendor relationships. The CISO proposes a centralized governance body. Which of the following is the BEST course of action to establish effective governance over third-party risk?

Hard
857

A manufacturing company has an incident response plan that includes a communication plan. However, during a recent ransomware incident, the team realized that the external legal counsel was not listed in the plan. The incident requires consultation with legal due to potential regulatory implications. The incident response manager needs to address this gap quickly. What should the manager do?

Easy
858

After detecting a ransomware infection on a file server, the incident response team performs containment and eradication. Which step should be prioritized during the recovery phase to minimize business impact?

Medium
859

An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)

Medium
860

A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)

Hard
861

A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?

Hard
862

A CISO is building the programme's risk treatment capability and wants to ensure that identified risks are handled consistently across business units. Which TWO activities are essential components of an effective risk treatment process? (Choose two.)

Hard
863

During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?

Hard
864

An organization's IDS logs show multiple outbound connections to an external IP address from a server that normally communicates only internally. The logs indicate the process is running under the SYSTEM account. Which of the following BEST describes the likely root cause?

Hard
865

Which of the following best describes the role of a security architect in a security program?

Medium
866

A financial services firm has completed containment and eradication of a sophisticated intrusion. The incident response team is now preparing for the post-incident phase. The CISO asks what activity will BEST reduce the likelihood of a similar incident recurring. Which activity should be prioritized?

Hard
867

An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)

Hard
868

A global insurance provider has just completed a quantitative risk assessment for a new claims-processing application. The assessment used the Annualized Loss Expectancy (ALE) formula and produced an ALE of $850,000 for the risk of a data breach. The vendor's proposed control has an Annualized Cost of the Safeguard (ACS) of $300,000 and a projected risk reduction of 60%. The CISO asks the information security manager to determine the cost-benefit of implementing this control. What is the net benefit (or loss) of the control?

Medium
869

During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?

Hard
870

Which of the following best describes the difference between risk appetite and risk tolerance?

Easy
871

A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?

Medium
872

An organization is reviewing its incident response plan after a tabletop exercise revealed confusion about roles during a major incident. The CISO wants to clarify which activities belong to the incident response team versus the crisis management team. Which TWO of the following activities are PRIMARY responsibilities of the crisis management team during a major incident? (Choose two.)

Medium
873

What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?

Easy
874

An organization has just completed its response to a significant security incident. The information security manager is preparing the post-incident review and wants to ensure the effort produces lasting improvement rather than a one-time report. Which of the following activities is MOST important to include in the post-incident review?

Easy
875

A mid-sized financial services firm has a newly appointed CISO. The board has asked for assurance that the information security program aligns with the organization's strategic goals and risk appetite. The CISO needs to establish a governance structure that provides ongoing oversight and ensures security decisions are made at the right level. Which of the following should the CISO implement FIRST?

Medium
876

A CISO is establishing a security metrics program to measure the effectiveness of the information security program. The CISO wants to include both key goal indicators (KGIs) and key performance indicators (KPIs). Which of the following are examples of KGIs? (Choose two.)

Hard
877

A security manager is drafting the incident response plan and needs to define how the organization will classify and escalate incidents. Executive leadership wants assurance that high-impact incidents reach the right decision-makers quickly. Which of the following should the security manager do FIRST to establish effective incident classification and escalation?

Medium
878

During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?

Hard
879

A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?

Hard
880

A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?

Hard
881

A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?

Hard
882

An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?

Medium
883

An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)

Hard
884

An organization's incident response team has completed the initial response to a ransomware incident. During the post-incident review, they identify that the detection was delayed because security logs from different systems were not correlated. The team wants to improve detection capabilities. What should the team recommend as the primary improvement?

Medium
885

An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?

Hard
886

An organization's governance framework requires regular reporting to the board. Which reporting frequency and format is MOST effective for a board with limited security expertise?

Hard
887

A global financial services firm has a mature information security program with policies, standards, and procedures aligned to ISO/IEC 27001. The CISO is preparing for the annual management review of the program. The board has asked for assurance that the program remains effective as the threat landscape and business strategy evolve. Which activity BEST provides this assurance?

Hard
888

A CISO is establishing an information security governance framework. The organization operates in multiple countries with varying data protection laws. Which of the following should be the PRIMARY consideration when developing security policies?

Easy
889

A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?

Hard
890

A CISO at a healthcare insurer is revising the information security strategy after a merger with a smaller regional provider. The board has asked how security will support the combined company's growth targets while protecting patient data. Which action BEST aligns the security strategy with the business objectives?

Medium
891

An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)

Medium
892

When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?

Medium
893

During an incident investigation, the team discovers that an attacker used a valid user's credentials to access a sensitive database. The user's account had multi-factor authentication (MFA) enabled. How is this MOST likely possible?

Hard
894

A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?

Medium
895

Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?

Medium
896

A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?

Hard
897

An organization has just contained a malware outbreak on several servers. The incident response manager must decide which activities belong in the eradication phase before restoration begins. Which TWO of the following activities are part of eradication? (Choose two.)

Hard
898

Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?

Medium
899

A healthcare organization is conducting a risk assessment for a new telehealth platform that will process protected health information. The assessment team proposes using a qualitative approach because of tight deadlines. Which of the following is the MOST significant limitation of relying solely on qualitative risk assessment for this initiative?

Hard
900

A newly appointed CISO is reviewing the organization's information security governance framework. The CISO finds that security responsibilities are not clearly defined across business units, leading to gaps and overlaps. Which of the following should the CISO do FIRST to address this issue?

Easy
901

A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?

Hard
902

A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?

Medium
903

An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?

Hard
904

Which TWO are common challenges in incident management?

Medium
905

An organization has a distributed incident response team across multiple time zones. During a critical incident, communication delays occur due to different work hours. Which strategy BEST improves coordination and response time?

Hard
906

During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?

Hard
907

A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)

Hard
908

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to senior management. Which of the following are characteristics of effective security metrics? (Choose two.)

Hard
909

Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?

Easy
910

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Medium
911

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Hard
912

An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)

Medium
913

An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?

Hard
914

A financial institution is hit by a Distributed Denial of Service (DDoS) attack that is overwhelming their internet-facing services. The incident response team activates the plan, but the attack continues to escalate. The CEO is under pressure and asks the incident response manager whether they should pay the ransom demand (the attackers also sent an extortion note demanding payment to stop the attack). The manager must advise the CEO on the best course of action.

Hard
915

A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?

Hard
916

Which of the following is the PRIMARY goal of incident containment?

Easy
917

An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?

Medium
918

After a security incident, the board holds the CISO accountable. The CISO argues that the incident was caused by a failure in the third-party risk management process. Which of the following governance deficiencies is most likely the root cause?

Medium
919

An information security manager is asked to report on the effectiveness of the security program. Which metric would BEST indicate governance effectiveness?

Easy
920

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Hard
921

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Medium
922

An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?

Hard
923

An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?

Hard
924

Which of the following is the PRIMARY role of the board of directors in information security governance?

Easy

Frequently asked questions

What does the scenario questions domain cover on the CISM exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 924 scenario questions questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.