Courseiva

CCNA Cism Governance Questions

33 of 108 questions · Page 2/2 · Cism Governance topic · Answers revealed

76
MCQhard

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

A.Prioritize initiatives based on security team capacity
B.Align security initiatives with the organization's strategic business objectives
C.Base the roadmap on the latest industry threat intelligence
D.Create the roadmap based on compliance requirements only
AnswerB

Anchoring each security initiative to a named strategic business objective makes the roadmap traceable to business intent, satisfying the alignment requirement. Security priorities then shift as business strategy shifts, rather than being driven by technology or compliance alone, which is what the CISO's multi-year horizon demands.

Why this answer

A multi-year security roadmap must be driven by the organization's strategic business objectives to ensure security investments enable rather than obstruct business goals. Aligning initiatives with business strategy ensures the roadmap is prioritized by business value, secures executive sponsorship, and remains relevant as the business evolves. This is the foundational principle of business-aligned security governance.

Exam trap

CISM often tests whether candidates default to compliance or threat-driven roadmaps, but the exam consistently rewards business-strategy alignment as the primary driver — candidates who pick 'compliance requirements only' or 'latest threat intelligence' fall for the reactive/technical trap.

How to eliminate wrong answers

Option A is wrong because prioritizing by security team capacity is an internal resource constraint, not a strategic alignment driver — it can lead to under-investing in high-business-value initiatives. Option C is wrong because basing the roadmap solely on the latest threat intelligence is reactive and may not reflect the organization's specific risk profile or business priorities. Option D is wrong because compliance-only roadmaps are minimum-bar and do not address business strategy, competitive advantage, or risk appetite.

77
MCQmedium

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

A.Difficulty in achieving economies of scale for security operations
B.Lack of skilled security personnel in some business units
C.Increased cost due to duplication of security tools
D.Inconsistent enforcement of security policies across business units
AnswerD

Decentralised units setting their own security practices produce divergent policy enforcement, leaving gaps and unmanaged enterprise risk. This satisfies the stem's greatest-risk constraint because the CISO, reporting to the CIO, lacks the authority and independence to mandate consistent controls across business units.

Why this answer

In a decentralized governance model where each business unit runs its own security team and the CISO reports to the CIO (rather than the board or CEO), the greatest risk is inconsistent enforcement of security policies across business units. Decentralization without a strong central authority or common control framework leads to divergent interpretations, uneven risk postures, and gaps that attackers can exploit across the enterprise. This is a governance and risk aggregation issue, which outweighs cost or staffing concerns.

Exam trap

CISM often tests whether candidates can distinguish operational inefficiencies (cost, staffing, scale) from governance risks (inconsistent policy enforcement), and candidates frequently pick cost or staffing because those are more tangible — but the exam rewards the systemic governance risk.

How to eliminate wrong answers

Option A is wrong because difficulty achieving economies of scale is an efficiency concern, not the greatest risk — it affects cost, not necessarily security effectiveness. Option B is wrong because lack of skilled personnel in some units is a resourcing issue that can be mitigated through training or shared services, and is less severe than systemic policy inconsistency. Option C is wrong because increased cost from tool duplication is a financial inefficiency, not a security risk — the exam asks for the GREATEST risk, which is about security posture and governance.

78
MCQhard

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

A.Revise the policy to accommodate the business need
B.Escalate to the board for approval
C.Increase monitoring of excepted systems
D.Reject all future exceptions for that control
AnswerA

Repeated exceptions for one control signal the policy no longer matches operational reality, so the control itself is misaligned rather than the business being non-compliant. Revising the policy addresses the root cause, eliminating the need for duplicate exceptions and restoring a single, enforceable baseline.

Why this answer

When multiple exceptions are granted for the same control due to recurring business constraints, the control itself is likely misaligned with business reality, so the best action is to revise the policy to accommodate the legitimate business need. This addresses the root cause rather than repeatedly managing exceptions. It also reduces risk by bringing the activity under a formally approved, monitored policy instead of a patchwork of exceptions.

Exam trap

The trap is choosing a control-oriented response (increase monitoring, reject exceptions) when the scenario describes a systemic policy misalignment — CISM expects you to recognize that repeated exceptions signal a need to fix the policy, not to tighten enforcement.

How to eliminate wrong answers

Option B is wrong because escalating to the board for each exception is an escalation of a symptom, not a fix, and boards should not be involved in operational policy exceptions. Option C is wrong because increasing monitoring treats the symptom and leaves the policy misaligned, creating ongoing administrative burden and potential audit findings. Option D is wrong because rejecting all future exceptions ignores legitimate business constraints and may force workarounds that increase risk or halt business operations.

79
MCQhard

A global retailer is expanding into new markets and must comply with varying data protection laws. The CISO is revising the information security strategy to ensure it remains aligned with the changing business environment. Which approach BEST ensures ongoing alignment between the security strategy and business objectives?

A.Delegate strategy updates to the security operations team based on emerging threats.
B.Conduct an annual penetration test and use the results to update the security strategy.
C.Integrate security strategy reviews into the enterprise strategic planning cycle and adjust based on business changes.
D.Adopt a widely recognized security framework and mandate compliance with its controls.
AnswerC

Embedding security strategy reviews into the enterprise strategic planning cycle ensures that security remains aligned with business objectives as markets and regulations evolve. This approach makes alignment a recurring, proactive activity rather than a one-time effort. It allows the CISO to anticipate changes and adjust security initiatives in tandem with business strategy, which is essential for effective governance in a dynamic environment.

Why this answer

Integrating security strategy reviews into the enterprise strategic planning cycle ensures that security is continuously aligned with business objectives, especially as the retailer enters new markets with different regulations. This approach makes alignment a proactive, recurring process rather than a one-off or reactive activity. It enables the CISO to adjust security initiatives in response to business changes, which is critical for effective governance and risk management.

Exam trap

The trap here is equating framework adoption or penetration testing with strategic alignment, when true alignment requires embedding security into the business planning cycle.

80
MCQmedium

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

A.Patch compliance percentage
B.Number of security incidents
C.Phishing simulation click rate
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect directly quantifies how quickly the security programme identifies threats, giving the board a measurable indicator of detection effectiveness. Unlike volume-based metrics, MTTD reflects actual capability against the stem's detection constraint, and its trend over time shows whether monitoring, tuning and staffing investments are improving outcomes.

Why this answer

Mean time to detect (MTTD) directly measures how quickly the security program identifies threats, which is the core of detection effectiveness. It is a quantitative metric that the board can use to assess improvement over time and benchmark against industry standards. Other metrics like patch compliance or phishing click rate are preventive or user-awareness measures, not detection performance indicators.

Exam trap

CISM often tests the difference between preventive, detective, and corrective metrics; candidates may mistakenly choose a preventive metric like patch compliance when asked for a detection effectiveness measure.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures vulnerability management and prevention, not the ability to detect threats. Option B is wrong because the number of security incidents is a lagging indicator of incident volume, not detection speed or effectiveness; it can be high even with poor detection if many incidents occur. Option C is wrong because phishing simulation click rate measures user susceptibility and awareness training effectiveness, not the security program's detection capabilities.

81
MCQmedium

Which board-level committee typically receives security reports to provide oversight?

A.Nominating committee
B.Compensation committee
C.Audit/risk committee
D.Finance committee
AnswerC

The audit/risk committee holds board-level oversight of risk and internal control, making it the natural recipient for security reporting. It provides independent scrutiny of risk posture and remediation, satisfying the governance requirement that security oversight sits with those accountable for enterprise risk.

Why this answer

The audit/risk committee is typically responsible for overseeing risk management, internal controls, and compliance, making it the natural board-level committee to receive security reports. This committee ensures that security risks are aligned with the organization's risk appetite and that mitigation strategies are effective. Other committees like nominating or compensation focus on governance structure and executive pay, not security oversight.

Exam trap

The trap here is confusing the audit committee's financial oversight with broader risk oversight; candidates may overlook that audit committees often have expanded risk responsibilities, including cybersecurity.

How to eliminate wrong answers

Option A is wrong because the nominating committee focuses on board composition, director recruitment, and governance policies, not security oversight. Option B is wrong because the compensation committee deals with executive remuneration and incentives, which is unrelated to security reporting. Option D is wrong because the finance committee primarily oversees financial reporting, budgeting, and financial risks, not the broader security program.

82
MCQmedium

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

A.Ease of implementation
B.Availability of new technology
C.Alignment with business strategy and risk appetite
D.Cost of the initiative
AnswerC

A multi-year roadmap consumes limited budget and resources, so initiatives must map to business strategy and the organisation's risk appetite. That alignment ensures security investment addresses the risks the business actually cares about, rather than technical preference alone.

Why this answer

The primary driver for prioritizing security initiatives in a multi-year roadmap should be alignment with business strategy and risk appetite. This ensures that security investments support business objectives and address the most significant risks to the organization. Other factors like ease of implementation or cost are secondary considerations that should be evaluated within the context of strategic alignment.

Exam trap

CISM often tests the distinction between business alignment and technical factors; candidates may choose cost or ease of implementation as primary drivers, forgetting that security must support business objectives.

How to eliminate wrong answers

Option A is wrong because ease of implementation may lead to prioritizing trivial tasks over critical risk reduction, which does not necessarily align with business needs. Option B is wrong because availability of new technology can be tempting but may not address the organization's specific risks or strategic goals; it can lead to technology-driven rather than risk-driven decisions. Option D is wrong because cost is a constraint, not a driver; while budget matters, prioritizing solely on cost can result in underinvesting in critical areas or missing strategic opportunities.

83
MCQmedium

A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?

A.Create an information security steering committee with business unit representation to prioritize and approve security initiatives.
B.Develop a security metrics dashboard that reports tool utilization and spending to the board of directors.
C.Conduct a gap assessment of all existing security tools against the NIST Cybersecurity Framework to identify redundancies.
D.Implement a centralized security budget and require all business units to submit purchase requests to the CISO for approval.
AnswerA

A steering committee with cross-functional representation establishes formal governance for prioritizing and approving security investments. It directly addresses the lack of central oversight by creating a decision-making body that aligns security spending with enterprise risk appetite. This is a foundational governance step before defining metrics or conducting assessments, as it provides the authority and structure needed for subsequent actions.

Why this answer

Establishing an information security steering committee is the foundational governance action because it creates a formal, cross-functional body responsible for aligning security investments with enterprise risk appetite. This committee provides the authority and structure to prioritize initiatives, resolve conflicts, and ensure ongoing oversight. Other actions, such as centralizing budgets or conducting assessments, are either tactical or lack the collaborative governance needed to sustain alignment.

Exam trap

The trap here is assuming that centralizing budget control or performing a gap assessment constitutes governance, when governance fundamentally requires a decision-making structure with business representation.

84
Multi-Selecthard

A CISO is developing a set of key risk indicators (KRIs) to monitor information security governance effectiveness. The CISO wants to ensure that the KRIs are actionable and aligned with business objectives. Which two characteristics are MOST important for effective KRIs? (Choose two.)

Select 2 answers
A.They are updated on an annual basis to reduce reporting overhead.
B.They are based solely on industry benchmarks.
C.They are measurable and quantifiable.
D.They are directly tied to business objectives and risk appetite.
E.They are kept confidential and shared only with the security team.
AnswersC, D

Effective KRIs must be measurable and quantifiable to allow objective tracking and trend analysis. Without a numerical basis, it is impossible to determine whether risk is increasing or decreasing, making it difficult to take timely action and demonstrate governance effectiveness to stakeholders.

Why this answer

Effective KRIs are measurable and quantifiable, enabling objective tracking, and are directly tied to business objectives and risk appetite, ensuring relevance to strategic goals. These characteristics allow the CISO to monitor governance effectiveness and make informed decisions that align security with business needs.

Exam trap

The trap here is selecting characteristics that seem efficient or common, such as annual updates or sole reliance on benchmarks, which actually undermine the actionability and relevance of KRIs.

85
MCQmedium

Which of the following best describes the role of the chief information security officer (CISO) in a governance context?

A.The CISO delegates all strategic decisions to the CIO
B.The CISO is a peer to the board with voting rights
C.The CISO oversees the security program and reports to executive leadership
D.The CISO is primarily a technical role focused on firewall management
AnswerC

The CISO owns the information security programme and sits within the executive reporting line, giving security a seat in strategic decision-making. That governance positioning lets the CISO align security objectives with business goals and escalate risk directly to leadership, rather than merely operating controls at a technical level.

Why this answer

The CISO oversees the security program and reports to executive leadership, such as the CEO or CIO, to ensure that security risks are managed and aligned with business goals. This role involves strategic planning, policy development, and coordination across the organization. The CISO is not a board member with voting rights but may present to the board or its committees.

Exam trap

The trap is confusing the CISO's advisory role to the board with actual board membership; candidates may incorrectly assume the CISO has a voting seat or is purely technical.

How to eliminate wrong answers

Option A is wrong because the CISO does not delegate all strategic decisions to the CIO; while the CIO may be a superior, the CISO retains responsibility for security strategy and must collaborate with executive peers. Option B is wrong because the CISO is not a peer to the board with voting rights; the CISO is an executive manager who reports to leadership and may advise the board, but does not have a board seat by default. Option D is wrong because the CISO is not primarily a technical role focused on firewall management; that is a misconception.

The CISO's role is strategic and governance-oriented, focusing on risk management, policy, and program oversight.

86
Multi-Selectmedium

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Select 3 answers
A.Phishing simulation click rate
B.Training completion rate
C.Security budget as percentage of IT budget
D.Number of security policies published
E.Percentage of incidents due to human error
AnswersA, B, E

Phishing simulation click rate reveals how employees actually behave when targeted, exposing the gap between awareness and practice. It satisfies the stem by measuring culture through observed behaviour rather than policy existence or training attendance.

Why this answer

Phishing simulation click rate (A) is a direct behavioral metric that reveals how susceptible employees are to real-world social-engineering attacks, making it a strong indicator of security awareness culture. Training completion rate (B) measures how consistently the workforce engages with required security education, which reflects the organization's commitment to building security knowledge. Percentage of incidents due to human error (E) quantifies how often employee mistakes contribute to breaches, directly exposing cultural weaknesses in day-to-day security behavior.

Security budget as percentage of IT budget (C) is a financial resource metric, not a measure of employee attitudes or behavior, so it does not reflect security culture. Number of security policies published (D) is a documentation output metric and says nothing about whether employees understand or follow those policies.

Exam trap

CISM often tests the difference between culture metrics (behavioral) and program metrics (budget, policy counts) — candidates pick budget or policy counts because they are easy to quantify, but they don't measure culture.

87
MCQeasy

The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?

A.Percentage of users trained
B.Mean Time to Respond (MTTR)
C.Number of security incidents
D.Patch compliance percentage
AnswerB

MTTR quantifies how quickly the team detects, contains and resolves incidents, directly evidencing the incident response process's effectiveness. Shorter times demonstrate that procedures, escalation paths and tooling work, which is precisely what the board wants to see.

Why this answer

MTTR measures how quickly the incident response team detects, contains, and resolves incidents, directly reflecting the process's effectiveness. A lower MTTR indicates a mature, efficient IR capability, which is what the board wants to see.

Exam trap

The trap is picking 'number of incidents' as a proxy for IR effectiveness — candidates confuse volume with performance, but a high incident count can indicate good detection, not poor response.

How to eliminate wrong answers

Option A is wrong because user training percentage measures awareness program coverage, not incident response effectiveness. Option C is wrong because the number of incidents is a volume metric that says nothing about how well they were handled — more incidents could mean better detection or worse prevention. Option D is wrong because patch compliance measures vulnerability management hygiene, not IR process performance.

88
MCQmedium

A CISO is updating the organization's information security strategy to address emerging risks from cloud adoption and remote work. Which of the following should be the FIRST step in this process?

A.Implement a cloud access security broker (CASB) solution.
B.Revise the security awareness training program.
C.Benchmark the organization's security posture against industry peers.
D.Conduct a risk assessment to identify new threats and vulnerabilities.
AnswerD

The first step in updating the security strategy is to understand the current risk landscape through a risk assessment. This identifies threats, vulnerabilities, and potential business impacts related to cloud adoption and remote work. The results inform strategic priorities, resource allocation, and control selection, ensuring the strategy is risk-based and aligned with business objectives.

Why this answer

The first step in updating the security strategy is to conduct a risk assessment, as it provides the necessary understanding of new risks introduced by cloud adoption and remote work. This risk-based approach ensures that subsequent decisions on controls, training, and investments are prioritized according to business impact and risk appetite.

Exam trap

The trap here is assuming that implementing a technical control or benchmarking is the starting point, when a risk assessment must precede any strategic changes.

89
MCQmedium

An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?

A.Low number of incidents caused by human error
B.Low phishing simulation click rate
C.High near-miss reporting rate
D.High training completion percentage
AnswerC

Near-miss reporting reflects employees who recognise and voluntarily disclose potential incidents without fear of blame, evidencing genuine engagement rather than passive compliance. High rates show the workforce acts as a detection sensor, which is the strongest cultural indicator.

Why this answer

A high near-miss reporting rate is the most indicative metric of a positive security culture because it demonstrates that employees are proactively identifying and reporting potential security issues before they escalate into incidents. This behavior reflects trust in the reporting process, psychological safety, and a collective commitment to security—key attributes of a mature security culture. Unlike lagging indicators such as incident counts or phishing click rates, near-miss reporting is a leading indicator that shows engagement and vigilance.

It signals that security is integrated into daily operations rather than merely compliance-driven.

Exam trap

CISM often tests the difference between leading and lagging indicators, and candidates may mistakenly choose low incident counts or low phishing click rates as signs of a positive culture, overlooking that these can be misleading without considering reporting behavior.

How to eliminate wrong answers

Option A is wrong because a low number of incidents caused by human error is a lagging indicator that can be influenced by underreporting or luck, and does not necessarily reflect a positive culture; it may even indicate a culture of blame where incidents are hidden. Option B is wrong because a low phishing simulation click rate measures only one specific behavior and can be gamed through training without genuine cultural change; it does not capture broader security awareness or proactive reporting. Option D is wrong because high training completion percentage is a compliance metric that indicates participation, not engagement or behavior change; employees may complete training without internalizing security values.

90
MCQhard

A global retailer's CISO is establishing an information security governance framework. The company operates in 20 countries, each with different privacy laws. The board wants assurance that security investments are justified and risks are managed consistently. Which governance mechanism BEST provides this assurance?

A.A centralized security operations center (SOC) that monitors all countries 24/7.
B.A dashboard that reports security metrics to the board on a quarterly basis.
C.A security steering committee with representatives from each region, chaired by the CISO, that reviews risks and approves investments.
D.An annual penetration test conducted by an external firm across all locations.
AnswerC

This is correct because a security steering committee is a governance body that provides oversight, ensures alignment with business objectives, and facilitates consistent risk management across regions. By including regional representatives, it addresses local differences while maintaining a global view. The committee reviews and approves investments, which justifies spending and ensures accountability, directly meeting the board's need for assurance.

Why this answer

The correct answer is the security steering committee with regional representation. In CISM, governance is about directing and controlling the organization's security activities to achieve objectives. A steering committee provides the structure for oversight, decision-making, and accountability.

It ensures that security investments are justified by business needs and risk, and that risks are managed consistently across diverse regions. This mechanism directly addresses the board's need for assurance.

Exam trap

The trap here is confusing operational security functions, such as a SOC or penetration testing, with governance mechanisms that provide oversight and decision-making.

91
MCQmedium

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

A.Solid line to CEO, dotted line to CIO
B.Solid line to CIO, dotted line to CEO
C.Dotted line to both CEO and CIO
D.Solid line to both CEO and CIO
AnswerA

A solid line to the CEO grants the CISO authority, budget and escalation rights, while the dotted line to the CIO preserves operational coordination. This satisfies the stem's dual-reporting requirement by separating governance accountability from day-to-day IT alignment, preventing the CIO from filtering security concerns before they reach executive leadership.

Why this answer

The correct answer is A because a solid reporting line indicates primary authority, accountability, and usually administrative control (e.g., performance reviews, budget, hiring/firing). A dotted line indicates a secondary, functional, or operational reporting relationship. In this model, the CISO's primary accountability is to the CEO, ensuring independence from IT operations, while the dotted line to the CIO allows for coordination on operational matters like security tool deployment or incident response.

This dual reporting structure is common in organizations seeking to balance security independence with operational efficiency.

Exam trap

CISM often tests the distinction between solid and dotted reporting lines, and candidates frequently confuse which line represents primary authority versus secondary coordination, leading them to select an option that reverses the lines or creates dual solid reporting.

How to eliminate wrong answers

Option B is wrong because it reverses the reporting lines: a solid line to the CIO would make the CISO operationally subordinate to IT, undermining security independence, while a dotted line to the CEO would not give the CISO the authority needed to enforce security at the executive level. Option C is wrong because having only dotted lines to both executives means the CISO lacks a primary reporting authority, leading to ambiguity in accountability, resource allocation, and decision-making. Option D is wrong because two solid lines create a dual-reporting conflict where the CISO would be fully accountable to both the CEO and CIO simultaneously, which is impractical and violates the principle of unity of command.

92
MCQmedium

A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?

A.Number of security incidents
B.Percentage of budget spent on security
C.Security investment vs. loss avoidance
D.Time to implement the tool
AnswerC

Comparing the proposed spend against projected loss avoidance expresses security value in financial terms the business case requires. It satisfies the investment-justification constraint by demonstrating that the tool reduces expected loss exposure more than it costs.

Why this answer

Comparing security investment to potential loss avoidance quantifies ROI in business terms.

93
MCQmedium

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

A.Stakeholder consultation
B.Gap analysis
C.Training and communication
D.Legal review
AnswerC

An approved policy is inert until staff know and follow it. Training and communication disseminates the approved requirements to affected personnel, ensuring awareness and enabling subsequent enforcement, monitoring and compliance activities that depend on people understanding their obligations.

Why this answer

Once a security policy is formally approved, the organization must ensure everyone affected knows about it and understands how to comply — this is the training and communication phase. Awareness and training are what turn an approved document into actual behavior, and they are a required step in the policy lifecycle before enforcement and monitoring can be effective.

Exam trap

CISM often tests the ordering of the policy lifecycle, and candidates frequently confuse pre-approval activities (consultation, gap analysis, legal review) with post-approval activities (training, communication, enforcement).

How to eliminate wrong answers

Option A is wrong because stakeholder consultation happens during policy development, before approval, to gather input and build buy-in. Option B is wrong because gap analysis is performed before or during policy development to identify where current controls fall short of requirements — it informs the policy, it does not follow approval. Option D is wrong because legal review is part of the drafting/approval process, ensuring the policy is legally sound before it is signed off, not a post-approval activity.

94
MCQmedium

A healthcare organization is developing an information security governance framework. The CISO needs to ensure that the framework supports regulatory compliance with HIPAA and aligns with the organization's strategic goals. Which of the following should be the FIRST step in this process?

A.Define the scope and objectives of the governance framework.
B.Conduct a gap assessment against the HIPAA Security Rule.
C.Develop a security awareness program for all staff.
D.Select and implement a governance, risk, and compliance (GRC) tool.
AnswerA

Defining the scope and objectives is the essential first step in developing any governance framework. It clarifies what the framework will cover, its boundaries, and what it aims to achieve, ensuring alignment with business strategy and regulatory requirements. Without this, efforts may lack direction and fail to address key stakeholder needs. This step sets the foundation for all subsequent activities.

Why this answer

The first step in developing a governance framework is to define its scope and objectives. This ensures that the framework is aligned with business strategy and regulatory requirements, such as HIPAA. It provides a clear direction for subsequent activities, including risk assessments, policy development, and control implementation.

Without this foundational step, efforts may be unfocused and fail to meet stakeholder needs.

Exam trap

The trap here is jumping to implementation activities like gap assessments or tool selection before defining what the governance framework is supposed to achieve.

95
Multi-Selecthard

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

Select 3 answers
A.Average age of security patches in days
B.Patch compliance percentage for critical systems
C.Mean time to respond (MTTR) to incidents
D.Number of intrusion detection alerts per day
E.Security investment as a percentage of IT budget
AnswersB, C, E

Patch compliance percentage for critical systems translates operational vulnerability exposure into a governance-level risk indicator the board can track. It satisfies the stem's board-reporting constraint by measuring control effectiveness against a defined baseline, rather than raw technical counts. Directors can assess whether remediation keeps pace with threats, linking directly to risk appetite and oversight accountability.

Why this answer

Option B (Patch compliance percentage for critical systems) is correct because it expresses vulnerability-management effectiveness as a single risk-oriented ratio the board can track over time, showing how much of the most important estate is protected rather than raw operational detail. Option C (Mean time to respond (MTTR) to incidents) is correct because it is a standard resilience KPI that quantifies how quickly the organization contains and recovers from incidents, which is a governance-level measure of response capability. Option E (Security investment as a percentage of IT budget) is correct because it frames security spending in business and financial terms, letting the board judge whether resourcing is proportionate to risk appetite and peer benchmarks.

Option A is not appropriate because average patch age in days is a granular operational/tactical metric better suited to security operations or IT management than the board. Option D is not appropriate because the raw daily count of intrusion detection alerts is a high-volume operational metric that reflects sensor tuning and noise, not strategic security posture or business risk.

Exam trap

CISM often tests the distinction between operational metrics (alert counts, patch age) and strategic/governance metrics (compliance %, MTTR, investment %) — candidates pick the most technical-sounding metrics instead of the ones a board can act on.

96
MCQeasy

An organization has recently experienced a data breach that resulted in reputational damage and regulatory fines. The board has asked the CISO to improve the information security governance framework to prevent future incidents. Which of the following should the CISO do FIRST?

A.Implement a new security information and event management (SIEM) system.
B.Increase the security budget to hire more security staff.
C.Update the security policy to include stricter penalties for non-compliance.
D.Conduct a post-incident review to identify root causes and lessons learned.
AnswerD

Conducting a post-incident review is the first step to understand what went wrong and why. It identifies root causes, gaps in controls, and governance failures. This information is essential for making informed improvements to the governance framework. Without this analysis, any changes may be based on assumptions rather than evidence, and similar incidents could recur.

Why this answer

The first step after a breach is to conduct a post-incident review to identify root causes and lessons learned. This evidence-based approach ensures that subsequent improvements to the governance framework are targeted and effective. It helps the CISO understand whether the breach resulted from policy failures, control gaps, or other issues, enabling informed decisions about changes to governance, policies, and controls.

Exam trap

The trap here is jumping to solutions like policy updates or new technology before understanding the root cause of the breach through a post-incident review.

97
MCQmedium

An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?

A.Adopt a hybrid governance model with enterprise-wide standards and local execution
B.Conduct a risk assessment to prioritize controls
C.Implement a centralized security operations center (SOC) to monitor all units
D.Move to a fully centralized governance model
AnswerA

A hybrid model centralises standards, policy and oversight while letting business units execute locally, directly resolving the inconsistent-controls problem. It satisfies the stem's constraint by retaining decentralised delivery yet imposing enterprise-wide baselines, which pure decentralisation cannot achieve.

Why this answer

A hybrid governance model combines enterprise-wide standards, policies, and oversight from the CISO with local execution by embedded security teams in each business unit. This addresses inconsistency by establishing common controls and frameworks while preserving the agility and business alignment of decentralized teams. It is the best recommendation because it directly resolves the root cause — lack of standardized controls — without sacrificing the benefits of decentralization.

Exam trap

CISM often tests whether candidates overcorrect to full centralization when the scenario calls for balancing enterprise consistency with local flexibility, so the trap is selecting a fully centralized model instead of a hybrid approach.

How to eliminate wrong answers

Option B is wrong because conducting a risk assessment to prioritize controls is a tactical step that does not address the governance inconsistency itself; it may inform priorities but does not establish enterprise-wide standards. Option C is wrong because implementing a centralized SOC improves monitoring but does not fix inconsistent governance or control implementation across business units. Option D is wrong because moving to a fully centralized governance model may be too disruptive, reduce business unit responsiveness, and is not necessary when a hybrid model can achieve consistency while retaining local execution.

98
MCQmedium

A financial services firm with a federated governance model is revising its information security strategy. The board has mandated that security investments must demonstrably support business objectives. The CISO is asked to define the MOST effective way to align security governance with business strategy. Which of the following should the CISO do FIRST?

A.Conduct a comprehensive vulnerability assessment across all business units to identify technical gaps.
B.Implement a security awareness program tailored to each business unit's specific risks.
C.Adopt a recognized security framework such as ISO/IEC 27001 to standardize controls across the organization.
D.Map information security objectives to the organization's strategic business goals and key performance indicators.
AnswerD

Mapping security objectives to business goals and KPIs directly aligns security governance with business strategy, ensuring investments support mandated outcomes. This first step establishes traceability and allows the CISO to prioritize initiatives based on business value, which is essential for board-level justification in a federated model where accountability is shared.

Why this answer

The board's mandate requires demonstrating that security investments support business objectives. Mapping security objectives to strategic business goals and KPIs creates a clear line of sight from security activities to business value, enabling prioritization and justification. This alignment step is foundational; technical assessments, awareness programs, and framework adoption are effective only after strategic alignment is established.

Exam trap

The trap here is assuming that adopting a standard framework or conducting technical assessments automatically aligns security with business strategy, when alignment first requires explicit mapping to business goals.

99
MCQmedium

An organization is updating its information security policy framework. The CISO wants to ensure that the policies are effectively communicated and understood by all employees. Which of the following is the MOST effective method to achieve this?

A.Publish the policies on the corporate intranet and send an email announcement to all staff.
B.Include a summary of the policies in the employee handbook provided at hire.
C.Conduct regular, role-based training sessions that include practical examples and quizzes to reinforce policy concepts.
D.Require all employees to sign an acknowledgment form after reading the policies.
AnswerC

Role-based training with practical examples and quizzes actively engages employees and verifies understanding. It tailors the content to specific job functions, making policies relevant and easier to apply. Quizzes provide measurable feedback on comprehension. This method goes beyond mere dissemination and ensures that employees not only receive but also understand and can apply the policies in their daily work.

Why this answer

Role-based training with practical examples and quizzes is the most effective method because it actively engages employees, tailors content to their responsibilities, and measures comprehension. It ensures that policies are not just distributed but understood and applied, which is essential for effective security governance.

Exam trap

The trap here is equating acknowledgment or passive communication with effective understanding, when active learning and assessment are required.

100
Multi-Selectmedium

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

Select 2 answers
A.HIPAA
B.SOX
C.GDPR
D.CCPA
E.PCI DSS
AnswersC, E

GDPR governs the processing of EU residents' personal data, imposing lawful-basis, breach-notification and data-subject rights obligations. Because the organisation handles such data, GDPR applies directly, satisfying the stem's EU personal-data constraint alongside the separate payment card regime.

Why this answer

Option C (GDPR) is correct because the organization handles personal data of EU residents, and the EU General Data Protection Regulation imposes requirements on any entity processing that data regardless of where the organization is located, covering lawful processing, data subject rights, breach notification, and cross-border transfers. Option E (PCI DSS) is correct because the organization processes credit card payments, and the Payment Card Industry Data Security Standard mandates controls for protecting cardholder data, including encryption, access control, and network segmentation. Option A (HIPAA) does not apply because it governs protected health information in the US healthcare context, which is not described here.

Option B (SOX) does not apply because it concerns financial reporting and internal controls for publicly traded US companies, not payment card or EU personal data. Option D (CCPA) is not the best fit because it addresses California consumers' personal information, whereas the scenario specifically involves EU residents, making GDPR the relevant privacy regulation.

Exam trap

The trap is that candidates might select CCPA instead of GDPR because both are privacy regulations, but the question specifies EU residents, making GDPR the correct choice.

101
Multi-Selecthard

A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)

Select 3 answers
A.Drafting the policy based on input
B.Conducting penetration testing
C.Stakeholder consultation to gather input
D.Implementing the policy in firewalls
E.Gap analysis against existing policies and standards
AnswersA, C, E

Drafting the policy converts gathered input and gap-analysis findings into documented statements of intent, scope, and controls. This satisfies the lifecycle requirement by producing the actual policy artefact, which then proceeds to review, approval, and publication.

Why this answer

Option A (Drafting the policy based on input) is correct because drafting is the core authoring phase of the policy development lifecycle, where gathered requirements and feedback are turned into the actual written policy document. Option C (Stakeholder consultation to gather input) is correct because the lifecycle begins with identifying affected parties and collecting their requirements, which ensures the policy is accurate, practical, and enforceable. Option E (Gap analysis against existing policies and standards) is correct because comparing the proposed policy against current policies, regulations, and frameworks such as ISO/IEC 27001 or NIST SP 800-53 identifies overlaps, conflicts, and missing controls before finalization.

Option B (Conducting penetration testing) does not belong because penetration testing is a technical security assessment activity performed after policy implementation, not a policy authoring step. Option D (Implementing the policy in firewalls) does not belong because configuring firewall rules is a technical enforcement action that follows policy approval, not part of the development lifecycle itself.

Exam trap

The trap here is confusing policy development (governance authoring) with policy implementation or technical enforcement — candidates pick penetration testing or firewall deployment because they sound security-relevant, but they belong to later lifecycle phases.

102
Multi-Selecthard

An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)

Select 3 answers
A.Risk appetite and tolerance levels defined by the board
B.Compliance requirements from applicable regulations
C.Daily monitoring schedule for security operations center
D.A detailed list of firewall ports to block
E.Multi-year roadmap with key milestones
AnswersA, B, E

Board-defined risk appetite and tolerance set the boundaries within which security investment is justified, translating business objectives into measurable acceptance criteria. This satisfies the stem's alignment requirement by ensuring security decisions reflect the organisation's stated willingness to accept risk.

Why this answer

Option A is correct because risk appetite and tolerance levels defined by the board translate business objectives into an explicit statement of how much risk the organization is willing to accept, which is the foundation for aligning security strategy with business goals. Option B is correct because compliance requirements from applicable regulations (e.g., GDPR, HIPAA, PCI DSS) are mandatory business constraints that the security strategy must incorporate to avoid legal, financial, and reputational consequences. Option E is correct because a multi-year roadmap with key milestones provides the strategic planning horizon and measurable checkpoints that connect security initiatives to long-term business objectives and enable governance oversight.

Option C is not appropriate here because a daily SOC monitoring schedule is a tactical operational artifact, not a strategic alignment element. Option D is also not appropriate because a detailed list of firewall ports to block is a low-level technical control, not a strategic component of an information security strategy.

Exam trap

CISM often tests the confusion between strategic and tactical/operational elements — candidates select SOC schedules or firewall rules because they are concrete, but strategy questions require governance-level, business-aligned components.

103
Multi-Selectmedium

A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?

Select 3 answers
A.Milestones for achieving target capability maturity levels
B.Current vulnerability scan results
C.Detailed network architecture diagrams
D.Resource allocation for each initiative
E.Alignment with business strategic goals
AnswersA, D, E

Milestones tied to target capability maturity levels give the roadmap measurable progression across years, satisfying the multi-year horizon constraint. Maturity milestones let the CISO sequence capability uplift, evidence progress to the board, and align investment with business objectives rather than isolated point-in-time controls.

Why this answer

A multi-year security roadmap must define measurable progress, so option A is correct: milestones tied to target capability maturity levels (for example, moving from CMMI level 2 to level 3 in specific domains) give the roadmap verifiable checkpoints over its multi-year horizon. Option D is correct because a roadmap is only executable if it specifies resource allocation—budget, headcount, and technology investments—for each initiative across the planning years. Option E is correct because the roadmap must align with business strategic goals so security investments directly support organizational objectives and priorities rather than existing as an isolated technical plan.

Option B does not belong because current vulnerability scan results are point-in-time operational data that inform tactical remediation, not multi-year strategic planning elements. Option C does not belong because detailed network architecture diagrams are technical documentation artifacts used for design and troubleshooting, not roadmap components.

Exam trap

CISM often tests the distinction between strategic roadmap elements and operational artifacts, tempting candidates to include tactical details like vulnerability scan results or network diagrams.

104
MCQhard

An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?

A.Assign each regulation to a separate compliance team
B.Develop a control framework that maps to all regulations
C.Implement the most stringent requirements for all
D.Focus only on the regulation with the highest fines
AnswerB

Developing a unified control framework that maps to GDPR, PCI DSS, and SOX satisfies the constraint of regulatory overlap by enabling a single set of controls to satisfy multiple requirements simultaneously, thereby eliminating redundant audits and reducing compliance friction across all three regimes.

Why this answer

A unified control framework that maps controls to multiple regulations eliminates duplicate effort and ensures each regulatory requirement is satisfied by a single, well-understood control set. Because GDPR, PCI DSS, and SOX share many overlapping controls (access management, logging, encryption, change management), mapping them once to a common framework lets the organization demonstrate compliance with all three without redundant audits or conflicting processes. This is the standard CISM-aligned approach: harmonize, don't silo.

Exam trap

CISM often tests the misconception that the 'most stringent' or 'highest-fine' regulation is the safe default, when the correct governance answer is always harmonization through a mapped control framework.

How to eliminate wrong answers

Option A is wrong because separate compliance teams per regulation create silos, duplicate controls, conflicting interpretations, and higher cost with no assurance that overlapping requirements are consistently met. Option C is wrong because blindly implementing the 'most stringent' requirement for every control ignores scoping, business context, and cost-benefit — it can over-engineer controls that don't apply and still miss regulation-specific obligations. Option D is wrong because focusing only on the highest-fine regulation leaves the organization non-compliant with the others, exposing it to legal, contractual, and reputational consequences regardless of fine size.

105
MCQmedium

A CISO at a healthcare insurer is revising the information security strategy after a merger with a smaller regional provider. The board has asked how security will support the combined company's growth targets while protecting patient data. Which action BEST aligns the security strategy with the business objectives?

A.Map security initiatives to the business goals and regulatory obligations of the merged entity, then validate them with executive stakeholders.
B.Adopt the stricter of the two pre-merger security policies and enforce it across both organizations immediately.
C.Delegate the development of a new security strategy to the IT operations team, since they understand the technical infrastructure.
D.Benchmark the merged company's security program against industry peers and adopt their best practices.
AnswerA

This is correct because CISM emphasizes that security strategy must be driven by and aligned with business objectives, not developed in isolation. In a merger, the business goals and regulatory landscape change, so mapping security initiatives to those goals and validating with executives ensures the strategy supports growth while addressing compliance. It also secures executive buy-in, which is critical for governance.

Why this answer

The correct answer is the one that maps security initiatives to business goals and regulatory obligations and validates them with executives. In CISM, information security governance requires that security strategy be aligned with business objectives and driven by top management. After a merger, the business context changes, so the CISO must ensure the strategy supports the new goals while meeting compliance requirements.

Executive validation ensures the strategy is owned at the right level.

Exam trap

The trap here is assuming that adopting the stricter policy or benchmarking peers automatically aligns security with business objectives, when alignment requires explicit mapping and executive validation.

106
MCQmedium

Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?

A.Level 4 - Managed
B.Level 1 - Initial
C.Level 3 - Defined
D.Level 2 - Repeatable
AnswerC

Level 3 – Defined satisfies the stem's requirement for organisation-wide standardisation and documentation. At this level, security processes are established, documented and integrated into enterprise-wide standards, moving beyond Level 2's repeatable but project-specific practices. The defining axis is that processes become institutionalised across the organisation rather than managed per project.

Why this answer

In a Capability Maturity Model (CMM), Level 3 - Defined is characterized by processes being standardized and documented across the organization. At this level, processes are proactive rather than reactive, and there is a defined set of standard processes. Level 2 is Repeatable, where processes are documented but not yet standardized across the organization.

Level 4 is Managed, where processes are quantitatively managed. Level 1 is Initial, where processes are ad hoc.

Exam trap

CISM often tests the specific characteristics of each CMM level, and candidates may confuse Level 3 with Level 2 or Level 4, especially regarding standardization versus quantitative management.

How to eliminate wrong answers

Option A is wrong because Level 4 - Managed focuses on quantitative management and continuous improvement, not just standardization. Option B is wrong because Level 1 - Initial is ad hoc and chaotic, with no standardized processes. Option D is wrong because Level 2 - Repeatable involves basic project management but processes are not yet standardized across the organization.

107
MCQeasy

A newly appointed CISO is reviewing the organization's information security governance framework. The CISO finds that security responsibilities are not clearly defined across business units, leading to gaps and overlaps. Which of the following should the CISO do FIRST to address this issue?

A.Conduct a risk assessment to identify critical assets and threats.
B.Develop a RACI chart to clarify roles and responsibilities for security activities.
C.Revise the information security policy to include detailed role descriptions.
D.Implement a security awareness program to educate employees on their security responsibilities.
AnswerB

Developing a RACI chart is a foundational step to clearly define who is responsible, accountable, consulted, and informed for security tasks. This addresses the immediate issue of unclear roles and helps eliminate gaps and overlaps. It is a practical tool that can be implemented quickly and facilitates communication and accountability across business units.

Why this answer

The first step to address unclear security responsibilities is to develop a RACI chart. This tool clearly defines roles and responsibilities for specific security activities, eliminating gaps and overlaps. It provides a practical framework that can be used immediately to improve governance.

Other actions like awareness, risk assessment, and policy revision are important but should follow after roles are clarified to ensure they are effective.

Exam trap

The trap here is jumping to awareness or policy changes before establishing a clear responsibility assignment matrix, which is the foundational governance step.

108
Multi-Selecthard

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Select 3 answers
A.Approval by the CISO or designated authority
B.Automatic approval if no response within 24 hours
C.Formal documentation of the exception request
D.Ability for any employee to request an exception
E.An expiration date for the exception
AnswersA, C, E

Requiring approval from the CISO or another designated authority ensures exceptions are granted only by someone holding the risk ownership and authority to accept the residual risk. This satisfies the accountability element, preventing business units from unilaterally bypassing policy.

Why this answer

Option A is correct because an exception to a security policy must be authorized by the CISO or another designated authority who owns the risk, ensuring accountability and preventing unauthorized deviations from the baseline. Option C is correct because formal documentation of the exception request captures the justification, scope, risk assessment, compensating controls, and approver, providing an auditable record for compliance and future review. Option E is correct because every exception should carry an expiration date so it is time-bound and automatically reviewed or revoked, preventing permanent, unmanaged risk acceptance.

Option B is incorrect because automatic approval after 24 hours of silence would grant exceptions without any risk review or authorization, which is the opposite of effective governance. Option D is incorrect because allowing any employee to request an exception is not itself a critical control; the process must define who is authorized to request and, more importantly, who can approve, so unrestricted requesting does not make the process effective.

Exam trap

CISM often tests the misconception that speed or convenience (auto-approval, open request channels) is a control objective, when the exam expects you to recognize that accountability, documentation, and time-bound risk acceptance are the governance essentials.

← PreviousPage 2 of 2 · 108 questions total

Ready to test yourself?

Try a timed practice session using only Cism Governance questions.