Courseiva

CCNA Cism Security Program Questions

75 of 139 questions · Page 1/2 · Cism Security Program topic · Answers revealed

1
MCQeasy

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

A.Outsource incident response to a managed security service provider (MSSP).
B.Create a dedicated incident response team that reports directly to the CISO.
C.Purchase a new SIEM solution to improve detection accuracy.
D.Develop a detailed incident response coordination plan with defined roles and communication channels, and conduct quarterly joint exercises.
AnswerD

Cross-department coordination gaps, not detection, caused containment delays. A coordination plan assigns explicit roles and communication channels across IT, legal and public affairs, while quarterly joint exercises rehearse them. This directly fixes the procedural void at minimal cost, satisfying leadership's quick, low-budget constraint.

Why this answer

The gap identified in the tabletop exercise is coordination, not detection or tooling, so the fix must address cross-department roles and communication. Developing a formal coordination plan with defined roles and quarterly joint exercises directly closes that gap at low cost, since it leverages existing staff and processes rather than new technology.

Exam trap

CISM often tests the principle that people and process gaps require people and process solutions, so candidates who jump to technology purchases (SIEM, MSSP) miss that the scenario explicitly says detection is already strong.

How to eliminate wrong answers

Option A is wrong because outsourcing to an MSSP does not fix internal coordination between IT, legal, and public affairs, and it adds recurring cost contrary to the minimal-budget constraint. Option B is wrong because a dedicated IR team reporting to the CISO still doesn't establish the cross-department communication channels and roles that the exercise showed were missing. Option C is wrong because the scenario explicitly states detection capabilities are strong, so a new SIEM addresses a problem that doesn't exist and incurs significant cost.

2
MCQmedium

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

A.Include security requirements after contract signing
B.Require third parties to self-attest compliance
C.Embed security clauses in request for proposals (RFPs)
D.Conduct periodic security audits of third parties
AnswerC

Embedding security clauses directly into RFPs forces vendors to demonstrate compliance before selection, making security a scored procurement criterion rather than an afterthought. This satisfies the requirement to integrate security requirements into the procurement process at the earliest, most influential stage, when contractual leverage is greatest.

Why this answer

Embedding security clauses in RFPs ensures that security requirements are formally communicated to potential vendors before any contractual agreement, making them a mandatory part of the procurement process. This proactive approach aligns with the CISM principle of integrating security into business processes from the outset, rather than retrofitting controls after contracts are signed. By specifying requirements such as encryption standards (e.g., AES-256), incident response SLAs, and compliance with frameworks like ISO 27001 in the RFP, the organization can evaluate vendor capabilities upfront and avoid costly renegotiations.

Exam trap

The trap here is that candidates often choose option D (periodic audits) because it seems like a thorough security measure, but they fail to recognize that without security clauses embedded in the RFP, the organization lacks contractual authority to enforce audit findings or require specific technical controls. In CISM, security requirements should be integrated during the procurement process, not after contracts are signed.

How to eliminate wrong answers

Option A is wrong because including security requirements after contract signing is reactive and often leads to weak or unenforceable controls, as vendors may resist changes or lack the technical capability to implement them retroactively. Option B is wrong because self-attestation lacks independent verification and is inherently unreliable; vendors may claim compliance with controls like access logging or data encryption without providing evidence, leaving the organization vulnerable to misrepresentation. Option D is wrong because periodic security audits are a detective control that occurs after the vendor is already engaged, and without contractual security clauses in the RFP, the organization has no legal basis to enforce audit findings or mandate remediation.

3
MCQmedium

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

A.Provide annual security training to all developers.
B.Assign a security champion to each development team and create a lightweight secure coding checklist.
C.Establish a separate security team that reviews all code after development is complete.
D.Implement a mandatory security gate before each release, requiring a full security review.
AnswerB

Embedding a security champion within each agile team and supplying a lightweight secure coding checklist integrates controls directly into rapid sprints, satisfying the moderate risk appetite and the constraint of avoiding the friction that formal security reviews previously caused.

Why this answer

Assigning a security champion to each development team and providing a lightweight secure coding checklist integrates security into agile workflows without imposing heavy gates. It leverages existing team structures, keeps friction low, and aligns with a moderate risk appetite by embedding security early rather than blocking releases.

Exam trap

CISM often tests the misconception that adding a mandatory security gate or a separate review team is the best way to integrate security, when the exam favors enabling and embedding security within existing agile teams.

How to eliminate wrong answers

Option A is wrong because annual training alone is too infrequent and passive to change day-to-day development behavior or catch issues during rapid releases. Option C is wrong because post-development security review creates a bottleneck and rework, directly conflicting with agile rapid release cycles. Option D is wrong because a mandatory full security gate before every release introduces the exact friction the team has resisted and is disproportionate to a moderate risk appetite.

4
MCQhard

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

A.SSL/TLS encryption and VPN access
B.Web application firewall (WAF) and intrusion detection system (IDS)
C.WAF, input validation, and security logging
D.Regular patching and vulnerability scanning
AnswerC

Layered web application defence combines a WAF filtering malicious HTTP traffic, input validation rejecting malformed data at the application, and security logging enabling detection and forensics. Together these satisfy the stem's defence-in-depth objective across preventive and detective control types at the application layer.

Why this answer

Defense-in-depth for the web application layer requires multiple overlapping controls: a WAF filters malicious HTTP traffic, input validation prevents injection attacks at the application layer, and security logging provides detection and forensic capability. Together they address prevention, detection, and response. This combination covers network, application, and monitoring layers.

Exam trap

CISM often tests the confusion between preventive controls (WAF, input validation) and detective/administrative controls (logging, patching), tempting candidates to pick a combination that lacks a key layer.

How to eliminate wrong answers

Option A is wrong because SSL/TLS and VPN address transport encryption and network access, not web application layer threats like SQL injection or XSS. Option B is wrong because WAF and IDS provide prevention and detection but omit input validation, which is a critical application-layer control against injection. Option D is wrong because patching and vulnerability scanning are vulnerability management activities, not layered web application controls; they do not filter or validate live traffic.

5
MCQmedium

A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?

A.Develop a security awareness training program for all employees.
B.Adopt an industry-recognized framework such as ISO/IEC 27001 to structure the program.
C.Implement a security information and event management (SIEM) system to monitor for threats.
D.Conduct a comprehensive risk assessment to identify and prioritize threats to business objectives.
AnswerD

A risk assessment identifies which assets and processes are most critical to achieving business objectives, and prioritizes threats accordingly. This ensures that security investments are directly tied to protecting what matters most to the business. Without this foundational step, subsequent activities like policy development or control selection lack a business-driven rationale, making alignment difficult to demonstrate to the board.

Why this answer

The correct answer is to conduct a risk assessment first. This step identifies which business objectives are at risk and prioritizes threats, enabling the CISO to align security investments with what the business values most. It provides the evidence needed to justify budget allocation and ensures that subsequent security activities are driven by business needs rather than technology or compliance alone.

Exam trap

The trap here is assuming that adopting a framework or implementing a technical control immediately aligns security with business objectives, when alignment actually starts with understanding the business through risk assessment.

6
MCQmedium

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

A.Allow exceptions for senior executives
B.Delay implementation until user acceptance improves
C.Revoke remote access for non-compliant users
D.Provide training on the importance of MFA
AnswerD

User resistance to MFA typically stems from unfamiliarity rather than the control itself. Training explains the rationale and correct enrolment, improving compliance without weakening the policy. Removing or exempting MFA would undermine the remote-access protection the organisation mandated.

Why this answer

Providing training helps users understand the necessity of MFA for security, addressing their concerns and gaining buy-in. Allowing exceptions (A) weakens security, delaying implementation (B) postpones protection, and revoking access (C) is too punitive as a first step.

7
Multi-Selecthard

Which of the following are key components of a mature information security program? (Select 2)

Select 2 answers
A.Comprehensive risk management process
B.Adoption of cloud security tools
C.Continuous monitoring and improvement
D.Single point of failure for security decisions
AnswersA, C

Why this answer

A comprehensive risk management process is a foundational component of a mature information security program because it ensures that security controls are aligned with business objectives through systematic identification, assessment, and treatment of risks. This process, often guided by frameworks like ISO 31000 or NIST SP 800-39, enables prioritization of resources based on risk appetite and tolerance, rather than relying on ad-hoc or reactive measures. Without this, the program lacks the structured governance needed to adapt to evolving threats and regulatory requirements.

Exam trap

The trap here is that candidates mistake tactical tools or organizational shortcuts (like a single security decision-maker) for program maturity, when CISM emphasizes that maturity is defined by process integration, governance, and continuous improvement, not by technology adoption or centralized authority.

Why the other options are wrong

B

Tool adoption is not a program component; it's an implementation detail.

D

Mature programs distribute accountability.

8
MCQeasy

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

A.Regularly meeting with business unit leaders to understand needs and risks.
B.Conducting vulnerability scans twice a year.
C.Developing a security awareness campaign.
D.Purchasing an advanced threat detection system.
AnswerA

Regular engagement with business unit leaders surfaces their objectives and risk tolerance, letting security strategy be shaped around them. This satisfies the alignment goal directly, since security priorities derive from documented business needs rather than from technical or compliance-driven assumptions.

Why this answer

Regularly meeting with business unit leaders to understand needs and risks is the most important activity because it ensures the security program is directly aligned with business objectives, risk appetite, and operational priorities. This engagement allows the CISO to perform a business impact analysis (BIA) and integrate security controls that support strategic goals rather than operating in isolation. Without this alignment, even technically sound security measures may be rejected or underfunded by leadership.

Exam trap

The trap here is that candidates often mistake a tactical security activity (like vulnerability scanning or buying a tool) for strategic alignment, failing to recognize that only direct engagement with business leaders can ensure the security program supports organizational goals.

How to eliminate wrong answers

Option B is wrong because conducting vulnerability scans twice a year is a tactical, reactive activity that identifies technical weaknesses but does not address whether those vulnerabilities align with business priorities or risk tolerance. Option C is wrong because developing a security awareness campaign, while valuable for reducing human risk, is a specific control that does not by itself ensure the security program supports business objectives. Option D is wrong because purchasing an advanced threat detection system is a technology procurement decision that may improve detection capabilities but does not guarantee the security program is aligned with business needs or that the investment is justified by business risk.

9
MCQeasy

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

A.Identify assets and their value
B.Calculate the level of risk
C.Establish the risk assessment context
D.Determine the likelihood of threats
AnswerC

Establishing the risk assessment context defines scope, objectives, criteria and assumptions before any identification or analysis occurs. Without this framing, subsequent risk identification and evaluation lack consistent boundaries, making the context step the necessary first action.

Why this answer

Establishing the risk assessment context (C) is the first step because it defines the scope, objectives, and criteria for the assessment, ensuring alignment with organizational goals and risk appetite. Without this foundational step, subsequent activities like asset identification or risk calculation lack direction and may produce irrelevant or misleading results. In the CISM framework, context setting precedes all technical analysis to ensure the assessment is meaningful and actionable.

Exam trap

The trap here is that candidates often confuse 'identify assets' as the first step because it seems intuitive, but CISM emphasizes that context must be set first to ensure the assessment is scoped and relevant, not just a generic inventory exercise.

How to eliminate wrong answers

Option A is wrong because identifying assets and their value is a subsequent step that occurs after the context is established, as the context determines which assets are in scope and how their value should be measured. Option B is wrong because calculating the level of risk is a later analytical step that depends on first understanding the context, identifying assets, and determining threats and likelihoods. Option D is wrong because determining the likelihood of threats requires a defined context to know which threats are relevant and what baseline assumptions apply, making it premature without context.

10
MCQmedium

Which of the following best describes the primary purpose of an Information Security Program?

A.To reduce the number of security incidents to zero.
B.To ensure compliance with all relevant laws and regulations.
C.To align security efforts with business objectives and manage risk.
D.To implement technical security controls across all systems.
AnswerC

An Information Security Program exists to integrate security controls with organisational goals, ensuring risk is managed at a level the business accepts. It satisfies the stem's requirement by framing security as an enabler of objectives rather than a purely technical or compliance exercise.

Why this answer

The primary purpose of an Information Security Program is to align security efforts with business objectives and manage risk to an acceptable level. This ensures that security investments and activities directly support the organization's mission, rather than operating in isolation. A program focused solely on compliance or technical controls may fail to address the dynamic risk landscape and business needs.

Exam trap

The trap here is that candidates often mistake compliance (Option B) as the primary goal, but CISM emphasizes that compliance is a subset of risk management, and the program's core purpose is to enable business objectives by managing risk, not just to satisfy auditors.

Why the other options are wrong

A

Zero incidents is unrealistic; the program aims to manage risk, not eliminate all incidents.

B

Compliance is part of the program but not the primary purpose; the program should support business goals.

D

Technical controls are a component, but the program includes governance, policies, and processes.

11
Multi-Selecthard

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Select 3 answers
A.Reactive approach to incidents
B.Continuous improvement
C.Automated security controls
D.Ad hoc processes
E.Quantitative performance metrics
AnswersB, C, E

Mature programs regularly refine processes based on lessons learned.

Why this answer

Continuous improvement (B) is a hallmark of higher maturity because it indicates the security program systematically evaluates and enhances its processes based on lessons learned, shifting from static compliance to adaptive risk management. In CISM terms, this aligns with the 'Optimizing' level (Level 5) in the Capability Maturity Model (CMM), where feedback loops drive iterative refinement of controls and policies.

Exam trap

A common misconception is that 'reactive' or 'ad hoc' processes can be part of a mature program if they are fast, but the CMM framework explicitly defines maturity by predictability, measurement, and optimization, not speed or intuition.

12
Multi-Selecthard

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Select 3 answers
A.Cultural resistance to security controls from business units.
B.Overreliance on automated security tools.
C.Inconsistent enforcement of security policies across subsidiaries.
D.Lack of security awareness training for end users.
E.Legacy systems that cannot be patched or upgraded.
AnswersA, C, E

Often seen when security is perceived as hindering productivity.

Why this answer

Cultural resistance to security controls from business units is a common challenge because security teams must balance risk mitigation with operational efficiency. Business units often perceive controls like mandatory encryption or access restrictions as hindrances to productivity, leading to shadow IT or workarounds that undermine the program's effectiveness.

Exam trap

The trap here is that candidates may confuse 'challenges in implementing' with 'consequences of poor implementation,' leading them to select options like D (lack of training) which is a result, not a root implementation hurdle.

13
MCQmedium

A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?

A.Update the information security strategy to include merger integration goals.
B.Conduct a security risk assessment of the target company's environment.
C.Implement security controls from the acquiring company on the target's systems.
D.Develop a security integration plan for post-merger activities.
AnswerB

This is correct because a security risk assessment of the target company identifies vulnerabilities, control gaps, and potential threats that could affect the merged entity. It provides the board with the necessary information to make informed decisions about integration and risk mitigation, aligning security with the business objective of a successful merger.

Why this answer

The correct answer is to conduct a security risk assessment of the target company's environment. This step is foundational because it identifies risks that must be managed during the merger. It enables the CISO to provide the board with a clear picture of the security landscape, ensuring that subsequent actions such as strategy updates or control implementations are based on actual risks rather than assumptions.

Exam trap

The trap here is assuming that updating the security strategy or implementing controls should come first, but without a risk assessment, these actions may not address the actual risks of the merger.

14
MCQeasy

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

A.Implement technical controls
B.Conduct a risk assessment
C.Purchase security tools
D.Develop security policies
AnswerB

A risk assessment identifies threats, vulnerabilities and business impacts, establishing which controls and priorities the programme needs. It satisfies the stem's first-step requirement by grounding the information security programme in the organisation's actual risk profile before policies, controls or budgets are selected.

Why this answer

Conducting a risk assessment is the foundational first step in developing an information security program because it identifies and prioritizes the specific threats, vulnerabilities, and business impacts that the program must address. Without a risk assessment, any subsequent policies, controls, or tools would be based on assumptions rather than the organization's actual risk profile, leading to misallocated resources and ineffective security. This aligns with the CISM framework, which emphasizes that risk management drives the entire security program lifecycle.

Exam trap

The trap here is that candidates often confuse the logical sequence by thinking 'policies come first' (Option D) because policies seem foundational, but CISM emphasizes that risk assessment must precede policy development to ensure policies are risk-driven and not just compliance checklists.

How to eliminate wrong answers

Option A is wrong because implementing technical controls before understanding the risks can result in deploying irrelevant or misconfigured controls (e.g., a WAF without knowing which web application vulnerabilities exist), wasting budget and potentially creating a false sense of security. Option C is wrong because purchasing security tools without a prior risk assessment leads to tool sprawl and integration issues, such as buying an SIEM without first identifying which log sources are critical to monitor. Option D is wrong because developing security policies without a risk assessment may produce generic, non-contextual policies (e.g., a password policy that doesn't account for the specific threat of credential stuffing against the company's legacy authentication system), making them unenforceable or irrelevant.

15
MCQeasy

A CISO is defining the scope of the information security program. The organization has multiple locations and uses cloud services extensively. Which factor is MOST important to consider when defining the program's scope?

A.The business processes and information assets that support the organization's mission
B.The geographic locations of the organization's offices
C.The number of employees at each location
D.The specific cloud service providers used by the organization
AnswerA

The scope of the security program should be defined by the business processes and information assets that are critical to the organization's mission. This ensures that security efforts are focused on what matters most to the business, regardless of location or technology. By starting with the mission and identifying supporting assets, the CISO can develop a comprehensive program that addresses risks to those assets, including those in the cloud. This approach aligns security with business objectives and ensures resources are allocated effectively.

Why this answer

The most important factor is the business processes and information assets that support the organization's mission. This ensures the security program is aligned with business objectives and covers all critical assets, whether on-premises or in the cloud. By defining scope based on mission-critical processes, the CISO can prioritize risks and allocate resources effectively, ensuring comprehensive protection.

Exam trap

The trap here is focusing on technology or location factors instead of starting with the business mission and its supporting information assets.

16
Multi-Selectmedium

A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)

Select 2 answers
A.Number of security policies approved by management.
B.Percentage of critical vulnerabilities remediated within defined timeframes.
C.Annual security budget as a percentage of IT budget.
D.Total number of security tools deployed.
E.Mean time to detect (MTTD) security incidents.
AnswersB, E

This KPI measures how well the organization manages vulnerabilities on critical assets, directly reflecting risk reduction. Meeting remediation timeframes indicates an effective vulnerability management process. It is a performance measure because it tracks the speed and completeness of a key security activity, and can be tied to risk tolerance.

Why this answer

The correct answers are mean time to detect (MTTD) and percentage of critical vulnerabilities remediated within defined timeframes. Both are performance-oriented metrics that measure the speed and effectiveness of key security processes, providing insight into how well the program reduces risk. They are actionable and can be trended over time to show improvement or deterioration.

Exam trap

The trap here is selecting activity or input metrics like number of policies or budget percentage, which measure effort or resources rather than the effectiveness of security processes.

17
MCQeasy

Which of the following is the PRIMARY responsibility of a steering committee in an information security program?

A.Approving individual security policies
B.Providing strategic direction and oversight
C.Conducting vulnerability assessments
D.Implementing security controls
AnswerB

Providing strategic direction and oversight is the steering committee's core mandate: aligning the security programme with business objectives, approving risk appetite, and prioritising funding. This satisfies the stem's demand for the *primary* responsibility, distinguishing governance-level direction from the operational execution handled by security management and practitioners.

Why this answer

The steering committee's primary role is to provide strategic direction and oversight for the information security program, ensuring alignment with business objectives and risk appetite. This includes approving the overall security strategy, budget, and major initiatives, rather than engaging in operational tasks like policy drafting or technical assessments.

Exam trap

The trap here is that candidates confuse the steering committee's strategic oversight role with the tactical or operational duties of other roles, such as the CISO or security analysts, leading them to select options like approving policies or conducting assessments.

Why the other options are wrong

A

Policy approval is an operational task, not the primary strategic role of the steering committee.

C

Technical assessments are performed by operational teams, not the steering committee.

D

Implementation is an operational responsibility, not a steering committee function.

18
MCQhard

An organization has multiple business units with different risk tolerances. How should the security program address this?

A.Develop risk-based security policies for each business unit
B.Apply a single enterprise-wide security policy
C.Define a minimum baseline and allow units to exceed it
D.Decentralize security management to each unit
AnswerA

Tailored policies align with varying risk tolerances.

Why this answer

A is correct because risk-based security policies allow each business unit to tailor controls to its specific risk appetite, ensuring that high-risk units implement stronger safeguards (e.g., stricter access controls, enhanced logging) while low-risk units avoid unnecessary overhead. This aligns with the CISM principle that security governance must accommodate varying risk tolerances through differentiated policy frameworks rather than a one-size-fits-all approach.

Exam trap

The trap here is that candidates confuse 'minimum baseline' (Option C) with risk-based differentiation, not realizing that a baseline still imposes a uniform minimum that fails to accommodate units with lower risk tolerance that require less stringent controls.

How to eliminate wrong answers

Option B is wrong because a single enterprise-wide security policy ignores differing risk tolerances, forcing all units into the same control baseline, which can over-constrain low-risk units or under-protect high-risk units. Option C is wrong because defining a minimum baseline and allowing units to exceed it still imposes a uniform floor that may be too restrictive for low-risk units or insufficient for high-risk units, failing to address the core need for risk-based differentiation. Option D is wrong because decentralizing security management to each unit without central oversight leads to inconsistent security postures, policy conflicts, and loss of enterprise-wide visibility, violating the CISM requirement for coordinated governance.

19
MCQhard

An organization's information security program has a documented risk management process. During a review, the CISO finds that risk assessments are performed annually but do not account for changes in the threat landscape or business environment. Which of the following is the BEST recommendation to improve the program?

A.Outsource risk assessments to a third-party specialist.
B.Increase the frequency of risk assessments to quarterly.
C.Adopt a risk assessment framework such as OCTAVE or FAIR.
D.Implement a continuous risk assessment process integrated with change management.
AnswerD

Integrating continuous risk assessment with change management ensures that risks are evaluated whenever there are changes in the business environment, technology, or threat landscape. This dynamic approach allows the organization to adapt quickly to new risks, improving the effectiveness of the risk management process and aligning with business objectives.

Why this answer

Implementing a continuous risk assessment process integrated with change management is the best recommendation because it ensures that risk assessments are performed whenever significant changes occur, not just annually. This dynamic approach keeps the risk register current and enables the organization to respond to emerging threats and business changes effectively, improving overall risk management.

Exam trap

The trap here is assuming that increasing assessment frequency or adopting a new framework will solve the problem, but without integration with change management, assessments remain disconnected from real-time changes.

20
MCQmedium

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget, and they report to their respective business unit leaders. The CISO has limited authority over these teams. A recent incident revealed inconsistent security controls across business units, and the board is concerned about the overall risk posture. Which of the following should the CISO recommend to improve the program's effectiveness?

A.Implement a security awareness program across all business units to improve adherence to policies.
B.Outsource all security operations to a managed security service provider (MSSP) to achieve uniform controls.
C.Centralize all security functions under the CISO to ensure consistent implementation of controls.
D.Establish a federated security model with a central governance framework and common standards, while allowing business units to implement controls tailored to their specific risks.
AnswerD

A federated model balances central governance with local implementation. It provides consistent standards and oversight through a central framework, while enabling business units to adapt controls to their unique risks and regulatory requirements. This approach addresses the inconsistency issue without alienating business units, and it works within the CISO's limited authority by using influence and collaboration rather than direct control.

Why this answer

A federated security model with central governance and common standards addresses the inconsistency while respecting the decentralized structure. It allows the CISO to set minimum requirements and oversight without stripping business units of their autonomy. This approach is practical given the CISO's limited authority and the need for tailored controls based on specific business unit risks.

Exam trap

The trap here is thinking that only full centralization or outsourcing can solve inconsistency, when a federated model often better fits a decentralized organization with limited CISO authority.

21
MCQmedium

During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?

A.Require all system administrators to manually approve patches before deployment.
B.Increase the frequency of vulnerability scans to weekly.
C.Conduct additional security awareness training for system administrators.
D.Implement a configuration management database (CMDB) linked to an automated patch deployment tool.
AnswerD

A CMDB provides the authoritative inventory linking each system to its patch state, so the automated deployment tool can target every asset rather than relying on inconsistent manual tracking. This directly closes the coverage gap by making patch status auditable and enforcing deployment across all discovered systems.

Why this answer

A configuration management database (CMDB) provides a centralized, authoritative inventory of all IT assets, including their current patch status. Linking the CMDB to an automated patch deployment tool ensures that patches are consistently and systematically applied to all systems based on their configuration records, directly addressing the inconsistency in the patch management process. This control enforces a standardized, repeatable workflow that eliminates reliance on manual, ad-hoc patching.

Exam trap

The trap here is that candidates often choose increased vulnerability scanning (Option B) thinking it solves the patching inconsistency, but scanning only identifies gaps—it does not enforce the actual deployment of patches, which is the core deficiency.

How to eliminate wrong answers

Option A is wrong because requiring manual approval for every patch introduces a human bottleneck and does not enforce consistent application across all systems; it relies on administrators to manually approve each patch, which can lead to delays and inconsistencies. Option B is wrong because increasing vulnerability scan frequency only identifies missing patches but does not remediate them; it is a detection control, not a corrective or preventive control for the patch application process. Option C is wrong because additional security awareness training does not address the procedural or technical gap in patch deployment; it may improve knowledge but does not enforce consistent, automated patching across all systems.

22
Multi-Selecteasy

Which TWO of the following are primary objectives of a security awareness program?

Select 2 answers
A.Improve password sharing practices
B.Increase the security budget
C.Reduce the number of security incidents
D.Change employee security behavior
E.Ensure compliance with regulations
AnswersC, D

Reducing incidents is a direct outcome of effective awareness.

Why this answer

A primary objective of a security awareness program is to reduce the number of security incidents by educating employees on threats like phishing, social engineering, and unsafe practices. By raising awareness, employees are less likely to fall for attacks that could lead to data breaches or malware infections, directly lowering incident frequency.

Exam trap

The trap here is that candidates often confuse compliance (Option E) as a primary objective, but CISM emphasizes that awareness programs are fundamentally about behavior change and incident reduction, not just meeting regulatory requirements.

23
MCQmedium

An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?

A.Percentage of employees who completed training
B.Number of security incidents
C.Number of policy violations
D.Reduction in phishing click-through rate
AnswerD

A falling phishing click-through rate directly evidences changed employee behaviour, which is the outcome a security awareness programme exists to produce. Unlike completion or attendance figures, it measures resistance to a real attack technique, giving the board quantifiable proof that awareness training reduced organisational susceptibility between quarterly reporting periods.

Why this answer

The phishing click-through rate directly measures behavioral change—the primary goal of security awareness training. A sustained reduction indicates that employees are applying training to recognize and avoid phishing attempts, which is a more valid effectiveness metric than completion rates or lagging indicators like incidents or violations.

Exam trap

The CISM exam often tests the distinction between activity metrics (e.g., training completion) and effectiveness metrics (e.g., behavioral change), trapping candidates who confuse 'did they take the training' with 'did the training work'.

How to eliminate wrong answers

Option A is wrong because completion of training does not measure knowledge retention or behavioral change; it only tracks attendance. Option B is wrong because the number of security incidents is a lagging indicator influenced by many factors beyond awareness (e.g., patch levels, access controls), so it cannot isolate training effectiveness. Option C is wrong because policy violations may stem from intentional misconduct or system misconfigurations, not lack of awareness, and a decrease could also result from stricter enforcement rather than improved behavior.

24
MCQhard

A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?

A.Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.
B.Adopt ISO 27001 as the single framework and map it loosely to all regulations.
C.Create three separate security programs, one for each major regulation (GDPR, CCPA, financial directives).
D.Use the most stringent regulation (e.g., GDPR) as the baseline and accept potential gaps with other regulations.
AnswerA

A unified control set satisfies GDPR, CCPA and financial directives simultaneously, then maps each control to individual regulatory clauses. This removes duplicated regional programmes, cutting cost and inconsistency while giving the board one auditable framework demonstrating compliance everywhere.

Why this answer

A unified set of controls that satisfies the common requirements of all regulations and maps to each regulation's specific needs provides a single, efficient control framework while ensuring compliance with each regulation. This balances compliance, efficiency, and cost by avoiding duplication and gaps.

Exam trap

CISM often tests whether candidates choose a single framework or the most stringent regulation as a shortcut, when the best practice is a harmonized control set mapped to each regulation to avoid both gaps and duplication.

How to eliminate wrong answers

Option B is wrong because adopting ISO 27001 as the single framework and mapping it loosely to all regulations risks gaps, since ISO 27001 is a security management standard, not a prescriptive compliance mapping for GDPR, CCPA, or financial directives. Option C is wrong because creating three separate programs duplicates effort, increases cost, and creates inconsistent enforcement, which is the problem the firm is trying to solve. Option D is wrong because using the most stringent regulation as the baseline and accepting gaps with others leaves the firm non-compliant with the other regulations, which is unacceptable for a global financial firm.

25
Multi-Selectmedium

A CISO is reviewing the organization's information security program and wants to improve its maturity. Which of the following are characteristics of a mature information security program? (Choose two.)

Select 2 answers
A.The security team operates independently without interaction with other business units.
B.Security awareness training is conducted annually for all employees.
C.Security controls are implemented based solely on regulatory requirements.
D.Risk management processes are integrated into business decision-making.
E.Security metrics are aligned with business objectives and reported to executive management.
AnswersD, E

Integrating risk management into business decision-making means that security risks are considered alongside other business risks. This ensures that risk treatment is aligned with business strategy and that security is embedded in processes such as project management and procurement. This integration is a hallmark of a mature security program.

Why this answer

The two characteristics are: security metrics aligned with business objectives and reported to executive management, and risk management processes integrated into business decision-making. These indicate that security is governed at the highest level, aligned with business strategy, and embedded in organizational processes, which are key aspects of maturity.

Exam trap

The trap here is confusing activity-based practices (like annual training) with maturity, which is defined by strategic alignment and integration with business processes.

26
MCQmedium

An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?

A.The grace period allows non-compliance for 7 days
B.Employees are unaware of the encryption requirement
C.The policy does not explicitly require encryption
D.MDM is not configured to enforce encryption automatically
AnswerD

Unenforced MDM configuration leaves encryption as a manual user action, so devices lacking it remain non-compliant despite the six-month-old policy. Compliance requires the MDM profile to mandate encryption at enrolment; without that technical control, policy alone cannot satisfy the requirement.

Why this answer

MDM systems can enforce encryption policies automatically by requiring devices to comply before granting access to corporate resources. If the MDM is not configured to enforce encryption, devices will remain non-compliant even if the policy requires encryption. The logs showing several devices without encryption after six months strongly indicate that the MDM is not actively enforcing the encryption requirement, making D the most likely reason.

Exam trap

The trap here is that candidates may assume the policy itself is flawed (option C) or that user awareness is the root cause (option B), but the question specifically highlights MDM logs showing non-compliance, pointing to a technical enforcement gap rather than a policy or awareness issue.

How to eliminate wrong answers

Option A is wrong because a 7-day grace period would not explain persistent non-compliance after six months; the grace period would have expired long ago. Option B is wrong because while employee awareness is important, MDM enforcement is a technical control that can override user behavior; the core issue is the lack of automatic enforcement, not just awareness. Option C is wrong because the scenario states the BYOD policy has been in effect for six months and the auditor notes non-compliance with encryption; if the policy did not explicitly require encryption, there would be no basis for the auditor to flag non-compliance, so the policy must include the requirement.

27
MCQeasy

A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?

A.Implement an automated policy enforcement system
B.Deploy an asset inventory management tool
C.Conduct security awareness training for all employees
D.Perform a comprehensive penetration test
AnswerC

With a small team and tight budget, awareness training delivers the broadest risk reduction per pound, since most breaches begin with human error such as phishing or weak credential handling, and it scales across the whole workforce without new tooling.

Why this answer

Security awareness training is the most cost-effective initial investment because human error remains the leading cause of security incidents, especially in resource-constrained environments. By educating employees on phishing, social engineering, and safe data handling, the organization reduces the attack surface without requiring expensive tools or specialized staff. This foundational control directly addresses the most common threat vector—user behavior—which automated systems alone cannot fully mitigate.

Exam trap

The trap here is that candidates often overvalue technical controls like penetration tests or automated enforcement, assuming they provide immediate risk reduction, while underestimating the foundational role of human-centric controls in a budget-constrained environment.

How to eliminate wrong answers

Option A is wrong because an automated policy enforcement system typically requires a mature asset inventory and defined policies to function correctly; without those prerequisites, the tool may enforce incorrect rules or miss unmanaged devices, wasting limited budget on a solution that cannot be properly configured. Option B is wrong because deploying an asset inventory management tool, while important, does not directly reduce risk; it provides visibility but requires additional processes and tools to act on that data, and a small team may lack the capacity to remediate findings promptly. Option D is wrong because a comprehensive penetration test is a point-in-time assessment that identifies vulnerabilities but does not build ongoing security capabilities; without a foundation of security awareness and basic controls, the findings may overwhelm the small team and lead to no sustainable improvement.

28
MCQmedium

An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?

A.Develop information security policies and procedures
B.Conduct a risk assessment
C.Select and implement security controls
D.Define security metrics and reporting
AnswerB

A risk assessment identifies threats, vulnerabilities and impacts to patient data, giving the programme its scope and priorities. This satisfies the stem's requirement to establish the programme first, since controls and policies should follow identified risk.

Why this answer

Conducting a risk assessment is the foundational first step because it identifies and prioritizes the specific threats and vulnerabilities facing the healthcare organization's sensitive data (e.g., PHI under HIPAA). Without this baseline understanding, any subsequent policies, controls, or metrics would be misaligned with actual risk exposure, leading to ineffective or wasteful security investments.

Exam trap

ISACA often tests the misconception that policy development is the logical starting point, but CISM emphasizes that risk assessment must precede all other program elements to ensure alignment with business objectives and regulatory requirements.

Why the other options are wrong

A

Policies should be based on risk assessment results, not developed first.

C

Controls are selected after risks are identified.

D

Metrics are defined after program objectives and controls are established.

29
Multi-Selectmedium

A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?

Select 2 answers
A.Focusing exclusively on the most stringent regulatory requirement to satisfy all others
B.Establishing a governance structure with defined roles, responsibilities, and oversight
C.Creating a control framework that maps common controls to multiple regulatory requirements
D.Adopting a single security framework such as ISO 27001 for all regions
E.Implementing separate security programs for each business unit to address unique needs
AnswersB, C

A governance structure provides the foundation for consistent decision-making and accountability across the organization.

Why this answer

A governance structure with defined roles, responsibilities, and oversight (Option B) is critical because it provides the authority, accountability, and decision-making framework needed to align security activities with diverse business units and regulatory requirements. Without clear governance, the program lacks the mechanisms to enforce policies, manage exceptions, and adapt to regional legal variations, such as GDPR in Europe or CCPA in California.

Exam trap

The trap here is that candidates often confuse 'comprehensive' with 'uniform,' leading them to choose Option D (single framework) or Option A (most stringent rule), when in reality, adaptability requires a governance structure that can manage multiple frameworks and exceptions, not a one-size-fits-all approach.

30
MCQhard

An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?

A.The cost of implementing the control
B.The residual risk after compensating controls
C.The number of users affected by the exception
D.The duration of the exception
AnswerB

Approving a critical-control bypass hinges on the residual risk remaining once compensating controls are applied, since that figure determines whether the exposure is acceptable. This satisfies the stem's requirement to weigh the true remaining risk rather than the original control's importance.

Why this answer

The most important factor when reviewing an exception request to bypass a critical control is the residual risk after compensating controls. This ensures that the organization's risk appetite is not exceeded and that the compensating controls adequately mitigate the risk to an acceptable level, as required by frameworks like ISO 27001 and NIST SP 800-53.

Exam trap

The trap here is that candidates often focus on operational or business factors (cost, user count, duration) instead of the core risk management principle that the residual risk must be acceptable to the organization.

Why the other options are wrong

A

Cost is a factor but not the most important; risk acceptance is paramount.

C

Number of users is less important than the risk exposure.

D

Duration matters but is secondary to the risk level.

31
Multi-Selecthard

An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)

Select 2 answers
A.All security incidents are resolved within 24 hours
B.Security metrics are included in regular executive reports
C.The program uses the latest encryption standards
D.A formal risk acceptance process is in place and used
E.The security team conducts annual penetration tests
AnswersB, D

Why this answer

Including security metrics in regular executive reports demonstrates that security performance is being measured, tracked, and communicated to leadership as part of ongoing governance. This aligns with a mature security program where security is integrated into business decision-making, not treated as a siloed technical function.

Exam trap

The trap here is that candidates confuse operational effectiveness (e.g., fast incident resolution or use of modern encryption) with process maturity, which is about governance, measurement, and continuous improvement rather than technical speed or tooling.

Why the other options are wrong

A

Resolution time is not necessarily an indicator of maturity; process consistency is more important.

C

Using latest technology is a tactical choice, not a maturity indicator.

E

Annual testing is a good practice but not a strong indicator of overall program maturity.

32
MCQeasy

An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?

A.An incident response plan.
B.A security awareness training program.
C.A comprehensive risk assessment.
D.A formal security charter approved by executive management.
AnswerD

A formal security charter approved by executive management provides the program with authority, scope, and resources. It defines the CISO's mandate, establishes accountability, and ensures alignment with business objectives. Without a charter, the program may lack the necessary support and legitimacy to enforce policies and implement controls effectively.

Why this answer

A formal security charter approved by executive management is the most important first step because it establishes the program's authority, scope, and resources. It ensures that security is aligned with business objectives and provides the CISO with the mandate to implement and enforce the program. Without this foundation, other activities may lack support and effectiveness.

Exam trap

The trap here is focusing on operational activities like training or risk assessments before securing executive mandate and governance.

33
MCQmedium

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

A.Adopt the more stringent security program from the acquirer across the entire entity.
B.Merge the two programs by combining all controls from each.
C.Implement a completely new framework that meets both regulations.
D.Perform a gap analysis against the requirements and prioritize remediation.
AnswerD

A gap analysis against PCI DSS and GDPR requirements identifies where each legacy programme falls short, letting the CISO prioritise remediation by risk and compliance impact. This harmonises differing maturity levels using a common control baseline rather than adopting one company's programme wholesale.

Why this answer

A gap analysis against the combined requirements of PCI DSS and GDPR identifies exactly where each legacy program falls short, allowing the CISO to prioritize remediation based on risk and regulatory obligation. This is the standard, defensible approach for harmonizing programs during M&A because it is evidence-based, accounts for differing maturity levels, and produces a prioritized roadmap rather than a blunt consolidation. It also respects that the two regulations have different scopes (PCI DSS for cardholder data, GDPR for personal data of EU residents).

Exam trap

The trap is choosing the seemingly decisive option ('adopt the stricter program' or 'build a new framework') over the methodical one; CISM emphasizes risk-based, evidence-driven approaches, so gap analysis is almost always the correct answer for harmonization questions.

How to eliminate wrong answers

Option A is wrong because simply adopting the acquirer's program ignores the acquired company's regulatory context and may leave GDPR or PCI DSS gaps if the acquirer's program was not designed for those obligations. Option B is wrong because merging all controls from both programs creates redundancy, conflict, and bloat without identifying which controls actually satisfy the combined requirements — it is a union, not a harmonization. Option C is wrong because building an entirely new framework is costly, slow, and unnecessary when existing frameworks (ISO 27001, NIST) can be mapped to both regulations; it also introduces new risk during integration.

34
MCQeasy

A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?

A.A detailed list of all security controls that will be implemented and their associated costs.
B.A comparison of the company's security posture to industry benchmarks and competitor practices.
C.An analysis of the potential financial impact of security incidents and how the program will mitigate those risks to protect revenue and reputation.
D.A timeline for achieving compliance with relevant regulations such as GDPR or HIPAA.
AnswerC

Executives prioritize risk and financial impact. By quantifying potential losses from incidents and showing how the security program reduces those risks, the CISO directly ties security to business objectives like revenue protection and reputation management. This approach speaks the language of the business and makes a compelling case for investment. It demonstrates that security is not just a cost center but a business enabler.

Why this answer

An analysis of potential financial impact and risk mitigation directly aligns the security program with business objectives by showing how it protects revenue and reputation. Executives are more likely to fund initiatives that clearly address business risk and demonstrate a return on investment. This approach makes the business case compelling and strategic.

Exam trap

The trap here is focusing on technical controls or compliance instead of framing the business case in terms of financial risk and business enablement, which resonates with executives.

35
MCQeasy

Based on the risk register entry, what is the primary gap in the current controls?

A.The policy exists but is not enforced technically
B.MDM is not a suitable control
C.The risk score is too low to require action
D.The likelihood of occurrence is low
AnswerA

The register shows a documented policy with no technical enforcement mechanism, so the control gap is compliance rather than design. Without automated enforcement, adherence depends on user behaviour, leaving the identified risk untreated. Closing this requires a technical control that compels the required action rather than relying on the written policy alone.

Why this answer

The risk register entry indicates that a mobile device management (MDM) policy exists but is not enforced through technical controls, such as device compliance checks or automated policy application. This creates a gap because the policy remains a paper-based directive without active enforcement mechanisms like certificate-based authentication or conditional access rules, leaving devices vulnerable to non-compliance and potential data breaches.

Exam trap

The trap here is that candidates assume a policy exists means the control is effective, but CISM emphasizes that a policy without technical enforcement (e.g., via MDM or NAC) is a gap, not a control.

How to eliminate wrong answers

Option B is wrong because MDM is a suitable control for managing mobile devices; the issue is not the suitability of MDM itself but the lack of technical enforcement of the existing policy. Option C is wrong because the risk score being low does not justify inaction; the gap in controls means the residual risk may be higher than assessed, and a low score does not eliminate the need for enforcement. Option D is wrong because a low likelihood of occurrence does not address the control gap; even if likelihood is low, the absence of technical enforcement means the control is ineffective, and the risk could materialize under changing conditions.

36
MCQmedium

A multinational corporation has a decentralized information security program. Each business unit manages its own security budget and controls, leading to inconsistent practices and duplicated efforts. The CISO wants to improve program efficiency and effectiveness while respecting business unit autonomy. Which of the following is the BEST approach?

A.Outsource all security functions to a managed security service provider (MSSP).
B.Centralize all security decision-making and budgets under the CISO.
C.Establish a common security framework and governance model that defines minimum standards while allowing business units flexibility.
D.Allow each business unit to continue independently but require them to report security metrics to the CISO.
AnswerC

This approach balances central governance with local autonomy. A common framework ensures consistent risk management and compliance, while flexibility allows units to address unique risks. It promotes efficiency by reducing duplication and leverages shared services. CISM supports such hybrid models to align security with business objectives across diverse environments.

Why this answer

The best approach is to establish a common security framework and governance model that sets minimum standards while allowing flexibility. This hybrid model enables consistent risk management and compliance across the organization, reduces duplication, and respects business unit autonomy. It aligns with CISM principles of balancing enterprise-wide security with business-specific needs.

Exam trap

The trap here is assuming that full centralization or full decentralization is the only solution, overlooking the benefits of a federated governance model.

37
MCQhard

A CISO has implemented a security program based on ISO/IEC 27001. During a management review, the CIO asks how the program contributes to business value. Which of the following metrics would BEST demonstrate the program's contribution to business value?

A.Reduction in the likelihood of material breaches affecting critical business processes.
B.Number of security incidents detected and resolved within service level agreements.
C.Total number of security controls implemented across the enterprise.
D.Percentage of employees who completed security awareness training.
AnswerA

This metric directly ties security efforts to business value by focusing on the protection of critical processes. It demonstrates how the program reduces the risk of disruptions that could impact revenue, reputation, or compliance. By quantifying risk reduction in business terms, it provides a clear link between security investments and the preservation of business objectives, which resonates with executive leadership.

Why this answer

The correct answer is the reduction in likelihood of material breaches affecting critical business processes. This metric translates security efforts into business terms by focusing on risk reduction for what matters most. It demonstrates that the program is not just implementing controls but actively protecting the organization's ability to achieve its objectives, which is the essence of business value.

Exam trap

The trap here is equating activity metrics like training completion or number of controls with business value, when business value is best demonstrated by risk reduction for critical business processes.

38
MCQmedium

An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?

A.Compliance with industry regulations
B.Reducing information security costs
C.Achieving the organization's strategic goals
D.Implementing the latest security technologies
AnswerC

Aligning security with business objectives ensures controls enable rather than obstruct the organisation's strategic goals, satisfying the stem's requirement for a primary driver. Security exists to support mission delivery, so strategic alignment directs investment and risk decisions toward outcomes the business actually needs.

Why this answer

The primary driver for aligning the security program with business objectives is to ensure that security initiatives directly support and enable the organization's strategic goals. Without this alignment, security becomes a cost center rather than a business enabler, and resources may be misallocated to activities that do not advance the enterprise's mission. CISM emphasizes that security governance must be integrated with business strategy to justify investment and demonstrate value to stakeholders.

Exam trap

The trap here is that candidates often mistake compliance (A) as the primary driver because it is a visible and mandatory requirement, but CISM stresses that compliance is a subset of governance, not the overarching goal of program alignment.

Why the other options are wrong

A

Compliance is a requirement but not the primary driver; the program must support business goals to be effective.

B

Cost reduction is a possible outcome but not the primary driver for alignment.

D

Adopting new technologies is a tactic, not the primary driver.

39
MCQhard

An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?

A.The risk assessment methodology is not quantitative.
B.Risk treatment responsibilities and decision authorities are not clearly defined.
C.The organization lacks a formal risk register.
D.Senior management does not review the risk assessment results.
AnswerB

When it is unclear who is responsible for making risk treatment decisions and who owns the risk, decisions can stall. Clear definition of roles, responsibilities, and decision authorities (e.g., risk owners, steering committee) ensures timely action. Without this, even well-assessed risks may languish because no one feels accountable for the next step.

Why this answer

The most likely root cause is that risk treatment responsibilities and decision authorities are not clearly defined. Effective risk management requires that each risk has an owner who is accountable for treatment decisions, and that decision-making authority is established. Without this clarity, risks may be assessed but not acted upon, causing delays and leaving high-risk items unaddressed.

Exam trap

The trap here is blaming the risk assessment methodology or lack of a register, when the real issue is often unclear ownership and decision rights.

40
MCQmedium

You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?

A.Restructure the compliance team into a risk management function.
B.Expand the compliance team to cover more regulations and increase auditing frequency.
C.Increase security awareness training across the organization.
D.Evolve the program to a risk-based approach that integrates threat intelligence and adapts controls dynamically, while keeping compliance as a baseline.
AnswerD

A risk-based model prioritises controls by likelihood and business impact, using threat intelligence to address supply chain attacks and APTs, and adapts dynamically as the threat landscape shifts. Compliance remains the baseline, so PCI DSS and GDPR obligations are still met while the programme becomes proactive rather than checklist-driven.

Why this answer

Evolving the program to a risk-based approach (Option D) integrates threat intelligence and dynamically adapts controls, directly addressing the need for proactive management of emerging threats while maintaining compliance as a baseline. This balances strategic evolution with the compliance team's continued role. Option A (restructuring the compliance team) risks political friction and does not inherently shift to risk management.

Option B (expanding compliance coverage) increases focus on compliance, not proactive risk. Option C (increasing awareness training) is too narrow and does not address the program's strategic direction.

41
MCQeasy

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

A.A board-level risk committee oversees the information security program without management involvement.
B.An executive steering committee with representatives from business units, legal, and IT meets quarterly to review program status.
C.The CISO reports to the chief legal officer (CLO).
D.The information security function reports directly to the IT operations manager.
AnswerB

An executive steering committee gives senior management direct ownership of the security programme, satisfying the accountability requirement. Cross-functional representation from business units, legal and IT ensures security decisions align with business objectives rather than remaining an isolated technical function.

Why this answer

An executive steering committee with cross-functional representation (business units, legal, IT) ensures the information security program is aligned with business objectives and provides direct accountability to senior management through regular quarterly reviews. This structure enables strategic oversight, resource allocation, and risk acceptance decisions that tie security initiatives to organizational goals, as recommended by the CISM framework for governance.

Exam trap

The trap here is that candidates may confuse operational reporting structures (like CISO reporting to CLO or IT ops) with effective governance, overlooking the need for cross-functional management oversight that directly ties security to business objectives.

How to eliminate wrong answers

Option A is wrong because a board-level risk committee without management involvement lacks the operational insight and authority to align security with day-to-day business objectives, creating a disconnect between governance and execution. Option C is wrong because reporting to the chief legal officer (CLO) can prioritize legal compliance over broader business risk management, potentially sidelining strategic alignment and senior management accountability. Option D is wrong because reporting to the IT operations manager places security under operational IT, which typically focuses on system uptime and efficiency rather than enterprise-wide risk governance, undermining the CISO's ability to influence business strategy.

42
MCQhard

A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?

A.Conduct a security awareness campaign focused on telehealth and cloud security.
B.Implement additional security controls for cloud and telehealth based on industry best practices.
C.Perform a new risk assessment that includes the cloud and telehealth environments.
D.Update the information security policy to include cloud and telehealth security requirements.
AnswerC

A new risk assessment is the foundational step to identify and evaluate risks introduced by cloud services, telehealth, and regulatory changes. It provides the basis for updating security controls and strategies. Without a current risk assessment, any control adjustments would be based on outdated assumptions, potentially leaving critical gaps. CISM emphasizes that risk assessment should be ongoing and triggered by significant changes.

Why this answer

The CISO should first perform a new risk assessment because significant changes such as cloud adoption, telehealth, and new regulations alter the risk landscape. A current risk assessment identifies new threats, vulnerabilities, and regulatory requirements, enabling the organization to update controls and policies effectively. This aligns with CISM's emphasis on continuous risk management as the core of an information security program.

Exam trap

The trap here is jumping to control implementation or policy updates without first reassessing risks, which can lead to misaligned security investments.

43
MCQhard

A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?

A.Increase the frequency of security audits for all regional offices
B.Provide additional training to regional IT staff on the importance of security baselines
C.Allow each regional office to maintain its own security program as long as it meets minimum standards
D.Establish a mandatory global security baseline with a formal exception process requiring CISO approval for any deviation
AnswerD

A mandatory global baseline with CISO-approved exceptions closes the loophole regional staff exploited, since deviations require central sign-off rather than local self-assessment. It preserves operational flexibility through the formal exception route while enforcing the control the breach exposed as missing.

Why this answer

Establishing a mandatory global security baseline with a formal exception process ensures consistency while allowing for justified deviations that are formally approved by the CISO, addressing the root cause of non-compliance. Option A is wrong because increasing audits may detect issues but does not enforce compliance without binding standards. Option B is wrong because training alone does not ensure implementation when local IT can claim unique requirements.

Option C is wrong because allowing each office to maintain its own program perpetuates fragmentation and does not enforce a consistent baseline.

44
MCQhard

A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?

A.Composite risk score based on threat, vulnerability, and control assessments.
B.Number of security incidents per quarter.
C.Mean time to detect (MTTD) incidents.
D.Percentage of employees who completed security training.
AnswerA

A composite risk score aggregates threat, vulnerability and control assessments into a single weighted measure, so it reflects residual risk reduction across the whole programme. Individual metrics such as patch compliance or incident counts capture only one dimension and cannot demonstrate overall effectiveness.

Why this answer

A composite risk score aggregates threat, vulnerability, and control assessment data into a single metric that directly reflects the organization's residual risk posture. This metric is the most holistic indicator of program effectiveness because it quantifies how well security controls reduce the likelihood and impact of threats exploiting vulnerabilities, aligning with the CISM focus on risk management.

Exam trap

The trap here is that candidates confuse operational metrics (incident count, MTTD, training completion) with risk-based metrics, assuming any positive trend in a security metric automatically indicates reduced overall risk, when only a composite risk score directly measures risk reduction.

How to eliminate wrong answers

Option B is wrong because the number of security incidents per quarter is a lagging indicator that does not measure risk reduction; a low incident count could result from luck or under-detection, not effective controls. Option C is wrong because Mean Time to Detect (MTTD) measures detection speed, not overall risk reduction; an organization could detect incidents quickly but still have high residual risk due to weak preventive controls. Option D is wrong because the percentage of employees who completed security training measures awareness activity, not risk reduction; training completion does not guarantee behavior change or control effectiveness against specific threats.

45
MCQeasy

Which document should be reviewed and updated at least annually?

A.Vendor contracts
B.Incident response plan
C.Network topology diagram
D.User manuals
AnswerB

The incident response plan documents contacts, roles, escalation paths and procedures that change as systems, personnel and threats evolve. Annual review satisfies the stem's requirement by keeping response actions current and validated, ensuring the plan remains executable during a live incident.

Why this answer

The incident response plan is a living document that must be reviewed and updated at least annually to reflect changes in the organization's environment, threat landscape, and lessons learned from incidents. Regular updates ensure that contact information, escalation procedures, and response strategies remain current and effective. This annual review is a core requirement of frameworks like NIST SP 800-61 and ISO 27001.

Exam trap

CISM often tests the misconception that any security document must be updated annually, but the incident response plan is specifically highlighted because it directly affects response effectiveness and is a common audit finding.

How to eliminate wrong answers

Option A is wrong because vendor contracts are typically reviewed at renewal or when terms change, not necessarily annually. Option C is wrong because network topology diagrams are updated as the network changes, not on a fixed annual schedule. Option D is wrong because user manuals are updated when software or procedures change, not annually.

46
Multi-Selectmedium

Which THREE of the following are key performance indicators (KPIs) for an information security program?

Select 3 answers
A.Number of security awareness training completions per quarter.
B.Total number of security staff.
C.Percentage of critical vulnerabilities remediated within SLA.
D.Average number of firewall rules per device.
E.Mean time to respond (MTTR) to incidents.
AnswersA, C, E

Indicates program reach.

Why this answer

The number of security awareness training completions per quarter directly measures the reach and effectiveness of the human-centric security program, which is a key driver for reducing phishing and social engineering risks. This KPI aligns with the NIST SP 800-50 framework for security awareness and training metrics, as it tracks behavioral adoption rather than just policy existence.

Exam trap

ISACA CISM often tests the distinction between resource metrics (like staff count) and true performance indicators (like remediation rates or response times), and the trap here is that candidates mistake operational metrics (firewall rules) for program-level KPIs.

47
Multi-Selectmedium

Which TWO of the following are essential components of a security program governance structure?

Select 2 answers
A.Security charter
B.Vulnerability scanning schedule
C.Security steering committee
D.Incident response plan
E.Help desk ticketing system
AnswersA, C

A security charter formally authorises the programme, defining scope, mandate and accountability from executive leadership. It satisfies the governance requirement for documented direction and assigned ownership, establishing who decides and who is answerable. Without this mandate, security activities lack organisational legitimacy and enforcement power.

Why this answer

A security charter is a foundational governance document that formally authorizes the security program, defines its scope, objectives, and assigns authority and accountability, making it an essential component of the governance structure. A security steering committee provides ongoing oversight, strategic direction, and cross-functional decision-making, which is central to governing a security program. By contrast, a vulnerability scanning schedule is an operational activity, an incident response plan is a tactical/operational document, and a help desk ticketing system is an operational tool—none of these establish the authority, oversight, or accountability mechanisms that define governance.

Exam trap

The trap is confusing operational artifacts (scanning schedules, IR plans, ticketing systems) with governance structures — candidates may pick the most 'security-sounding' option rather than the one that establishes authority and oversight.

48
MCQhard

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

A.Inadequate security awareness training
B.Lack of enforcement mechanisms
C.Outdated data classification policy
D.Insufficient budget for security tools
AnswerB

Documented standards without monitoring, consequences, or automated controls let business units deviate unchecked. The absence of enforcement mechanisms, rather than unclear policy, explains why units are not following the mandated data classification standard despite a mature programme.

Why this answer

A mature security program with documented policies and standards indicates that the classification rules are already defined. The audit finding that business units are not following the mandated standard points to a failure in enforcement mechanisms—such as automated Data Loss Prevention (DLP) rules, access control policies, or mandatory labeling in SharePoint—rather than a lack of awareness or outdated policy. Without enforcement (e.g., Group Policy Objects blocking unclassified data uploads or SIEM alerts for missing classification tags), even well-trained staff may bypass the standard.

Exam trap

ISACA often tests the distinction between 'lack of awareness' and 'lack of enforcement'—the trap here is that candidates assume training is the solution to non-compliance, but in a mature program with documented policies, the root cause is almost always the absence of automated enforcement or consequences.

Why the other options are wrong

A

Training may exist; the issue is lack of consequence for non-compliance.

C

The policy is documented and mature; outdatedness is not indicated.

D

Budget may affect tools but not directly cause non-compliance with a standard.

49
MCQhard

A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?

A.Restrict users' ability to receive emails from external domains except from approved senders
B.Implement a next-generation email security gateway with AI-based threat detection
C.Deploy endpoint detection and response (EDR) on all workstations
D.Increase the frequency of phishing simulations and enforce mandatory remedial training for employees who fall for them
AnswerD

Simulations test real behaviour rather than passive knowledge, exposing who actually clicks. Mandatory remediation closes the loop by targeting those individuals, directly addressing the stem's finding that employees ignore suspicious emails despite annual training, thereby reducing phishing-driven ransomware likelihood.

Why this answer

The root cause is human behaviour — employees ignore suspicious emails despite annual training. Increasing the frequency of phishing simulations with mandatory remedial training directly targets that behaviour through continuous reinforcement and consequence, which is the most effective way to reduce click rates. It addresses the actual gap (behaviour) rather than adding more technology layers.

Exam trap

CISM often tests the reflex to add more technology (AI gateway, EDR) when the root cause is human behaviour — candidates who default to technical controls miss that the question asks for the most effective action to change employee behaviour.

How to eliminate wrong answers

Option A is wrong because blocking all external email except approved senders is operationally impractical for a healthcare organization that must receive email from patients, partners, and regulators, and it doesn't address internal phishing or compromised trusted senders. Option B is wrong because a next-gen email gateway is a technical control that the existing gateway already failed to catch; adding another layer doesn't fix employee behaviour and may still be bypassed. Option C is wrong because EDR detects and responds to endpoint compromise after the fact — it does not prevent the initial phishing click or reduce the likelihood of recurrence.

50
Drag & Dropmedium

Arrange the steps for implementing a new firewall rule in an enterprise environment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Firewall changes require clear objectives, change control, testing, implementation, and verification.

51
Multi-Selecthard

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Select 2 answers
A.Number of security tools deployed
B.Risk management integrated into business processes
C.Low number of security incidents
D.Trend of improving security metrics over time
AnswersB, D

Why this answer

Risk management integrated into business processes (B) is a key indicator of a mature security program because it demonstrates that security is not a siloed function but is embedded in strategic decision-making, resource allocation, and operational workflows. This alignment ensures that security controls and investments are directly tied to business objectives and risk appetite, which is a hallmark of maturity as defined by frameworks like the CMMI and the ISACA CISM model.

Exam trap

The trap here is that candidates often mistake a low number of security incidents as a sign of success, but CISM emphasizes that a mature program is defined by integrated risk management and measurable improvement trends, not by the absence of incidents, which can be deceptive due to detection gaps or reporting biases.

Why the other options are wrong

A

More tools do not equal maturity; could indicate complexity.

C

May be coincidental; not a reliable maturity metric.

52
MCQeasy

A small business is developing its first information security program. Which approach is most effective?

A.Hire an external security consultant to design the entire program.
B.Adopt a comprehensive framework like ISO 27001 immediately.
C.Conduct a risk assessment to identify key assets and threats.
D.Purchase and deploy a next-generation firewall.
AnswerC

Conducting a risk assessment first identifies the small business's key assets, threats, and vulnerabilities, allowing controls to be prioritised against actual exposure rather than guesswork. This satisfies the stem's constraint of a first programme with limited resources, since risk-based prioritisation directs scarce budget and effort to the highest-impact areas.

Why this answer

Conducting a risk assessment (Option C) is the foundational step in building an information security program because it identifies the specific assets, threats, vulnerabilities, and impacts unique to the small business. Without this context, any controls or frameworks applied would be misaligned with the actual risk profile, leading to wasted resources and potential security gaps. The CISM framework emphasizes that risk assessment drives the selection of cost-effective, prioritized controls tailored to the organization's needs.

Exam trap

The trap here is that candidates often confuse 'security tools' or 'frameworks' with 'program development,' mistakenly believing that deploying a specific technology or adopting a standard immediately constitutes an effective security program, when in fact the CISM exam requires that risk assessment must precede any control selection or framework adoption.

How to eliminate wrong answers

Option A is wrong because hiring an external consultant to design the entire program bypasses the necessary internal risk assessment and ownership, resulting in a generic program that may not address the business's specific threat landscape or operational constraints. Option B is wrong because adopting a comprehensive framework like ISO 27001 immediately is premature and overly complex for a small business; it requires a mature risk management process and significant resources, and without a prior risk assessment, the controls implemented may be irrelevant or excessive. Option D is wrong because purchasing and deploying a next-generation firewall (NGFW) is a point solution that addresses only network perimeter threats, ignoring other critical areas such as data classification, access controls, incident response, and employee training, which are essential for a holistic security program.

53
MCQhard

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget. The CISO wants to improve consistency and reduce duplication of efforts. Which of the following is the MOST effective approach?

A.Outsource all security operations to a managed security service provider (MSSP).
B.Centralize all security functions under the CISO to ensure uniform control.
C.Mandate that each business unit follows the same security tools and technologies.
D.Establish a security governance framework with common policies, standards, and a steering committee.
AnswerD

A governance framework with common policies and a steering committee enables consistency and coordination while respecting business unit autonomy. It provides a structure for decision-making, aligns security with business objectives, and reduces duplication by sharing best practices and resources. This approach is a hallmark of mature security programs.

Why this answer

Establishing a security governance framework with common policies, standards, and a steering committee is the most effective approach. It provides centralized direction while allowing business units to adapt to local needs, reducing duplication and improving consistency. This balances control with flexibility, which is essential for a multinational organization.

Exam trap

The trap here is thinking that centralizing all security functions or mandating identical tools is the only way to achieve consistency, ignoring the need for business alignment and flexibility.

54
MCQhard

Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?

A.A SYN flood attack is in progress.
B.A single host is using multiple IP addresses to scan the server.
C.Multiple users are accessing the web server normally.
D.A distributed denial-of-service (DDoS) attack is occurring.
AnswerC

Traffic from three internal hosts to one web server, using standard HTTP/HTTPS ports with normal request-response patterns and no scanning or spoofing signatures, indicates routine browsing. Multiple clients reaching the same server is expected behaviour, so the traffic reflects ordinary user access rather than an attack.

Why this answer

The exhibit shows multiple internal hosts (10.0.0.1, 10.0.0.2, 10.0.0.3) each establishing a normal TCP three-way handshake with the web server (192.168.1.100) on port 80, with varying source ports and no abnormal flags or packet rates. This pattern indicates legitimate concurrent user access, as each host completes the handshake and exchanges data without flooding or scanning behavior.

Exam trap

The trap here is that candidates may misinterpret any traffic from multiple hosts as a DDoS attack, failing to notice the normal handshake completion and low packet volume that indicate legitimate user access rather than an attack.

How to eliminate wrong answers

Option A is wrong because a SYN flood attack would show a high volume of SYN packets from a single source with no corresponding SYN-ACK completions, often with spoofed source IPs, not the clean three-way handshakes seen here. Option B is wrong because a single host using multiple IP addresses to scan the server would typically send probes to multiple ports or show incomplete connections (e.g., SYN scans with RST responses), not full handshakes to the same port from distinct internal IPs. Option D is wrong because a DDoS attack would involve a massive number of packets from many sources overwhelming the server, often with incomplete connections or unusual traffic patterns, not the orderly, low-rate connections from three hosts.

55
Multi-Selectmedium

Which of the following are key components of an information security program's strategic plan? (Select two.)

Select 2 answers
A.Annual budget allocation
B.Security program vision and objectives
C.Incident response procedures
D.Roadmap for security initiatives
AnswersB, D

The strategic plan needs a stated direction, so the security programme vision and objectives define the desired end state and measurable outcomes. They satisfy the requirement for a key component by aligning security effort with business goals before initiatives are sequenced.

Why this answer

The strategic plan for an information security program defines the long-term direction and governance framework. The security program vision and objectives (B) establish the overarching goals and alignment with business strategy, while the roadmap for security initiatives (D) provides the phased implementation plan to achieve those objectives. These are foundational components of strategic planning, not operational or tactical elements.

Exam trap

ISACA often tests the distinction between strategic (vision, roadmap) and operational/tactical (budget, procedures) components, leading candidates to mistakenly select annual budget allocation as a strategic element because it is a common management activity.

Why the other options are wrong

A

Budgeting is operational, not strategic.

C

Procedures are operational.

56
Multi-Selecthard

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to the business and driving continuous improvement. Which of the following are the MOST appropriate key performance indicators (KPIs) for the information security program? (Choose two.)

Select 2 answers
A.Number of security policies approved by the steering committee.
B.Percentage of critical systems covered by the vulnerability management program.
C.Total number of security incidents reported by employees.
D.Percentage of employees who completed security awareness training.
E.Mean time to remediate critical vulnerabilities.
AnswersB, E

This KPI measures the coverage and effectiveness of a core security control. A high percentage indicates that the program is systematically identifying and addressing vulnerabilities across critical assets, which directly reduces risk. It is a performance indicator that can drive improvement by highlighting gaps in coverage. It also demonstrates to the business that the program is proactively managing a key risk area, making it a valuable KPI.

Why this answer

The most appropriate KPIs are those that measure the effectiveness of security controls and processes in reducing risk. The percentage of critical systems covered by vulnerability management and mean time to remediate critical vulnerabilities both directly reflect the program's ability to manage a key risk area. They are actionable, quantifiable, and demonstrate value to the business by showing risk reduction over time.

Exam trap

The trap here is selecting activity-based metrics like policy approvals or training completion, which measure effort rather than effectiveness, instead of outcome-based KPIs that demonstrate risk reduction.

57
MCQmedium

An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?

A.Number of vulnerabilities identified
B.Number of patches deployed per month
C.Percentage of systems scanned weekly
D.Mean time to remediate (MTTR) vulnerabilities
AnswerD

MTTR measures elapsed time from vulnerability discovery to remediation, directly reflecting how quickly the process reduces exposure. Unlike raw counts of findings or scan coverage, it captures the operational efficiency of the entire remediation workflow, making it the strongest indicator of whether the vulnerability management process actually works.

Why this answer

Mean time to remediate (MTTR) directly measures how quickly the organization closes the window of exposure after a vulnerability is identified. A lower MTTR indicates a more effective vulnerability management process because it reduces the risk window, whereas raw counts of vulnerabilities or patches do not reflect the timeliness or completeness of remediation.

Exam trap

The trap here is that candidates confuse activity metrics (number of patches, scan coverage) with outcome metrics (MTTR), which is the only option that directly measures the effectiveness of closing vulnerabilities in a timely manner.

How to eliminate wrong answers

Option A is wrong because the number of vulnerabilities identified is a detection metric, not an effectiveness metric; a high count could simply reflect a larger attack surface or more aggressive scanning, not better management. Option B is wrong because patches deployed per month measures patching throughput but ignores whether critical vulnerabilities are being prioritized or whether patches are actually closing the identified exposures. Option C is wrong because the percentage of systems scanned weekly measures coverage of the scanning process, not the outcome of remediation; an organization can scan 100% of systems yet never fix the vulnerabilities found.

58
MCQmedium

A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?

A.Report the non-compliance to the board of directors and request their intervention.
B.Revise the policy to extend the training deadline to 60 days to improve compliance.
C.Implement a technical control that blocks network access for employees who have not completed training.
D.Conduct a root cause analysis to determine why employees are not completing the training.
AnswerD

Before implementing solutions, the CISO must understand the reasons for non-compliance. Root cause analysis can reveal issues such as lack of awareness, inconvenient training times, or ineffective content. This ensures that the chosen remedy addresses the actual problem and is more likely to succeed.

Why this answer

Conducting a root cause analysis is the essential first step. It identifies why employees are not completing the training, allowing the CISO to implement targeted and effective solutions. This approach is consistent with continuous improvement and ensures that resources are used efficiently.

Exam trap

The trap here is jumping to a technical enforcement or policy change without diagnosing the underlying reasons for non-compliance.

59
MCQmedium

During a security audit, several deviations from policy are found. What should the security manager do first?

A.Accept the risk and move on
B.Investigate the root cause of the deviations
C.Update the policies immediately
D.Take disciplinary action against responsible employees
AnswerB

Investigating root cause determines why deviations occurred, distinguishing systemic control failures from isolated human error. This satisfies the audit scenario by directing remediation at the underlying cause, preventing recurrence rather than merely correcting individual findings.

Why this answer

The security manager must first investigate the root cause of the deviations to understand why the policy was not followed. This aligns with the corrective action phase of the incident response lifecycle, where identifying the underlying issue (e.g., misconfigured access controls, lack of awareness, or technical gaps) is essential before implementing any remediation. Without root cause analysis, subsequent actions like policy updates or disciplinary measures may address symptoms rather than the actual problem, leading to recurring non-compliance.

Exam trap

The trap here is that candidates often jump to 'update the policy' (Option C) because they assume the policy is outdated, but CISM emphasizes that policy deviations are typically symptoms of deeper issues, and immediate updates without root cause analysis can create compliance gaps or bypass the formal policy lifecycle.

How to eliminate wrong answers

Option A is wrong because accepting risk without understanding the root cause violates the principle of risk management; deviations may indicate a systemic vulnerability that requires mitigation, not acceptance. Option C is wrong because updating policies immediately without investigating why the existing policy was bypassed could introduce new inconsistencies or fail to address the actual control failure (e.g., a misconfigured SIEM rule rather than a policy gap). Option D is wrong because taking disciplinary action before root cause analysis is premature and could demoralize staff if the deviation resulted from inadequate training, unclear policy language, or a technical flaw (e.g., a firewall rule that conflicts with the policy).

60
MCQeasy

Which of the following is the primary purpose of an Information Security Program?

A.To implement the latest security technologies
B.To align security with business objectives and manage risk
C.To comply with all applicable regulations
D.To eliminate all security risks
AnswerB

An Information Security Programme exists to align security investment with business objectives and manage risk to acceptable levels. Frameworks, controls and policies are mechanisms serving that end. This option names the governance and risk-management purpose that defines the programme's primary function, rather than a narrower technical or compliance outcome.

Why this answer

The primary purpose of an Information Security Program is to align security initiatives with business objectives and manage risk to an acceptable level. While technology implementation, compliance, and risk elimination are components, they are means to the end of supporting the organization's mission and risk appetite. A program that does not align with business goals will lack executive support and fail to prioritize resources effectively.

Exam trap

ISACA often tests the misconception that an Information Security Program is primarily about technology or compliance, when in fact it is a governance mechanism to align security with business strategy and manage risk.

Why the other options are wrong

A

Technology is a tool, not the program's purpose.

C

Compliance is a component, not the primary purpose.

D

Eliminating all risks is impossible and impractical.

61
Multi-Selecteasy

Which TWO of the following are essential components of an information security program charter?

Select 2 answers
A.List of specific security tools to be deployed.
B.Roles and responsibilities of key stakeholders.
C.Vendor selection criteria.
D.Program scope and objectives.
E.Detailed budget allocation.
AnswersB, D

Assigning roles and responsibilities names who owns, operates and oversees the security programme, satisfying the charter's need for clear accountability. It establishes decision rights and reporting lines across stakeholders, ensuring governance duties are not left ambiguous as the programme is authorised and resourced.

Why this answer

The information security program charter is a high-level document that establishes the authority, scope, and governance of the security program. Roles and responsibilities of key stakeholders (Option B) are essential because they define accountability and decision-making authority, ensuring the program has clear ownership and oversight. Program scope and objectives (Option D) are equally essential as they set the boundaries and goals of the security program, aligning it with business strategy and risk appetite.

Exam trap

ISACA often tests the distinction between strategic governance documents (charter) and operational or tactical artifacts (tool lists, budgets, vendor criteria), leading candidates to select detailed implementation items that are not part of the charter's high-level scope.

62
MCQhard

A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?

A.Requiring each business unit to achieve ISO/IEC 27001 certification within one year.
B.Establishing a central security operations center (SOC) that monitors all business units.
C.Implementing a single security toolset across all business units to ensure uniformity.
D.Defining clear roles, responsibilities, and decision rights between central and business unit security teams.
AnswerD

In a federated governance model, clear roles, responsibilities, and decision rights are essential to avoid confusion, duplication, and conflict. This ensures that central and business unit teams understand who decides what, how policies are set, and how exceptions are handled. Without this clarity, federated models often fail due to ambiguity and turf battles. It is the most critical factor because it provides the framework for consistent yet flexible security management.

Why this answer

A federated governance model balances central oversight with business unit autonomy. The most critical factor is defining clear roles, responsibilities, and decision rights, which prevents confusion and ensures consistent application of security policies while allowing local flexibility. Other options focus on technology, compliance, or centralization, which do not address the core governance challenge.

Without clear decision rights, federated models often stall.

Exam trap

The trap here is equating federated governance with centralization or compliance mandates, rather than focusing on decision rights and accountability.

63
Multi-Selecthard

A CISO is establishing a security governance framework for a decentralized organization where each business unit operates independently. The CISO wants to ensure that security policies are consistently applied while respecting business unit autonomy. Which two actions are MOST appropriate to achieve this? (Choose two.)

Select 2 answers
A.Implement a centralized security policy that mandates compliance from all business units
B.Develop a set of high-level security principles and allow business units to tailor implementation
C.Allow each business unit to develop its own security policies independently without central oversight
D.Establish a security steering committee with representatives from each business unit
E.Outsource all security operations to a managed security service provider (MSSP) to ensure uniformity
AnswersB, D

This approach provides a common security foundation while accommodating the unique needs of each business unit. High-level principles ensure consistency in risk management and compliance, while tailored implementation allows business units to address their specific risks and operational contexts. It strikes a balance between central governance and local autonomy, which is essential in a decentralized organization. The CISO can monitor adherence through metrics and audits, ensuring that the tailored implementations meet the principles.

Why this answer

Establishing a security steering committee with business unit representatives and developing high-level security principles with tailored implementation both balance central governance with local autonomy. The committee fosters collaboration and shared decision-making, while the principles provide a consistent framework that business units can adapt to their specific contexts. Together, they enable consistent risk management without stifling the flexibility required in a decentralized organization.

Exam trap

The trap here is assuming that either strict centralization or complete decentralization is the answer, when a hybrid governance approach is most effective.

64
MCQhard

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

A.The VPN broker itself is misconfigured
B.A legitimate user forgot their password
C.An attacker has compromised a remote employee's device and is brute-forcing the admin account
D.The alert is a false positive due to SIEM rule threshold
AnswerC

A compromised remote endpoint tunnelling through the trusted VPN broker would present that broker's source IP while the attacker brute-forces the admin account, explaining the SIEM alert. This satisfies the stem's constraint that the source IP belongs to a legitimate VPN service.

Why this answer

A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.

Exam trap

The trap here is that candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.

How to eliminate wrong answers

Option A is wrong because a misconfigured VPN broker would typically cause connectivity issues or authentication failures, not generate brute-force alerts against an admin account from a trusted IP. Option B is wrong because a legitimate user forgetting their password would result in a few failed login attempts, not a sustained brute-force pattern that triggers a SIEM alert. Option D is wrong because the alert is not a false positive; the SIEM rule threshold is correctly identifying anomalous brute-force behavior from a trusted source, which is a known attack vector.

65
Multi-Selecteasy

Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?

Select 2 answers
A.Number of security policies approved.
B.Mean time to detect (MTTD) security incidents.
C.Employee satisfaction score from annual survey.
D.Percentage of critical systems patched within 30 days.
E.Percentage of security budget spent on tools.
AnswersB, D

Mean time to detect measures how quickly monitoring and alerting capabilities identify security incidents, directly evidencing the programme's detective effectiveness. As a quantifiable KPI, MTTD satisfies the stem's requirement for performance measurement, unlike qualitative artefacts such as policy documents or risk registers, which indicate governance inputs rather than operational security performance.

Why this answer

Option B is correct because Mean Time to Detect (MTTD) is a recognized operational security KPI that quantifies how quickly an organization identifies security incidents, directly reflecting the effectiveness of monitoring, SIEM, and detection capabilities. Option D is correct because the percentage of critical systems patched within 30 days is a vulnerability-management KPI that measures how promptly known vulnerabilities are remediated, a core indicator of an information security program's preventive effectiveness. Option A is not a true effectiveness KPI because counting approved policies measures documentation activity, not whether controls actually reduce risk or improve security outcomes.

Option C is unrelated to security program performance, as employee satisfaction is an HR metric rather than a security indicator. Option E is a budgeting/spending ratio that describes resource allocation, not the effectiveness of the security program's controls or outcomes.

Exam trap

CISM often tests the confusion between activity metrics (policies approved, budget spent) and outcome-based KPIs (MTTD, patch compliance), tempting candidates to pick easily countable but non-meaningful numbers.

66
MCQmedium

An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?

A.Conduct a root cause analysis and update risk assessment
B.Implement multi-factor authentication for all systems
C.Disable email links and attachments
D.Increase the frequency of security awareness training
AnswerA

A root cause analysis identifies why existing controls fail to stop social engineering, and the risk assessment is then updated to reflect the true threat exposure. This evidence-based step precedes selecting or tuning new controls.

Why this answer

A root cause analysis (RCA) is the correct first step because it identifies the specific weaknesses in people, processes, or technology that allowed the social engineering attacks to bypass existing controls. Updating the risk assessment based on RCA findings ensures that remediation efforts are prioritized against actual threats, rather than applying generic fixes. This aligns with the CISM principle that program management decisions must be data-driven and risk-based.

Exam trap

The trap here is that candidates often jump to a technical or training solution (B, C, or D) without first performing a root cause analysis, failing to recognize that the CISM framework requires a risk-based, diagnostic approach before implementing any control change.

How to eliminate wrong answers

Option B is wrong because implementing multi-factor authentication (MFA) for all systems is a broad technical control that does not address the root cause of social engineering—it may reduce credential theft but does not prevent manipulation of authorized users. Option C is wrong because disabling email links and attachments is a drastic, operational disruption that ignores other vectors (e.g., phone calls, SMS, in-person) and fails to address the underlying human or process gaps. Option D is wrong because increasing the frequency of security awareness training without first analyzing why current training failed may reinforce ineffective content; training must be tailored to the specific attack patterns identified in the RCA.

67
MCQeasy

Which document should be created FIRST when establishing an information security program?

A.Information security policy
B.Risk assessment report
C.Incident response plan
D.Business continuity plan
AnswerA

The information security policy is the foundational document, stating management's intent, scope and principles before any standards, procedures or controls are drafted. Creating it first ensures all subsequent program artefacts align with approved direction, satisfying the stem's sequencing requirement.

Why this answer

The information security policy is the foundational document that establishes management's intent, direction, and support for the security program. It defines the scope, objectives, and responsibilities, and all other security documents (risk assessments, incident response plans, BCPs) derive their authority and alignment from this policy. Without an approved policy, subsequent activities lack governance and executive backing.

Exam trap

ISACA often tests the sequence of program development, and the trap here is that candidates mistake a risk assessment (Option B) as the first step because it seems logical to 'know your risks first,' but the policy must precede it to define the risk management framework and governance.

Why the other options are wrong

B

Risk assessment is informed by policy.

C

Incident response is a later operational plan.

D

BCP is related but separate and typically follows policy.

68
Multi-Selectmedium

Which of the following are key components of an effective information security program? (Select TWO.)

Select 2 answers
A.State-of-the-art security tools and technologies
B.A risk management framework
C.Security awareness and training programs
D.A large security operations center
E.Compliance with all applicable laws
AnswersB, C

Why this answer

A risk management framework is a key component because it provides a structured, repeatable process for identifying, assessing, and mitigating information security risks. It ensures that security investments and controls are aligned with business objectives and risk appetite, rather than being ad hoc or technology-driven. Without a risk management framework, an information security program lacks the foundational governance to prioritize threats and allocate resources effectively.

Exam trap

The trap here is that candidates often mistake operational components (like a SOC or advanced tools) or compliance outcomes as foundational pillars, whereas CISM emphasizes that governance through a risk management framework and the human element via security awareness are the true core components of a sustainable program.

Why the other options are wrong

A

Tools are important but not a key component; the program must include processes and people.

D

Size is not a key component; effectiveness matters more.

E

Compliance is a goal, not a component of the program itself.

69
MCQmedium

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

A.Conduct a root cause analysis to determine why controls failed.
B.Increase the frequency of control testing.
C.Report the findings to management and accept the risk.
D.Implement compensating controls immediately.
AnswerA

Root cause analysis identifies why the controls failed before remediation, satisfying the need to address underlying deficiencies rather than symptoms. Auditors expect corrective action to be risk-based; understanding causation lets the security manager reassess the risk assessment and prioritise fixes, preventing recurrence across the control set.

Why this answer

When controls are found ineffective, the security manager must first conduct a root cause analysis to identify why the controls failed. This aligns with the CISM's emphasis on corrective action based on understanding the underlying failure, such as misconfigured firewall rules, outdated signature databases, or improper access control lists (ACLs). Without this analysis, any subsequent remediation (like implementing compensating controls or increasing testing frequency) may address symptoms rather than the actual cause, leading to recurring failures.

Exam trap

The trap here is that candidates often jump to 'implement compensating controls' (Option D) as a quick fix, but CISM emphasizes that the first step must always be to understand the failure through root cause analysis before selecting any corrective action.

How to eliminate wrong answers

Option B is wrong because increasing the frequency of control testing does not fix the underlying failure; it only detects the same failure more often, wasting resources without addressing the root cause (e.g., a flawed SIEM correlation rule or a misapplied patch). Option C is wrong because reporting findings and accepting risk prematurely bypasses the obligation to first investigate and remediate the control failure; risk acceptance is a decision made after understanding the failure's impact and likelihood, not as an immediate first step. Option D is wrong because implementing compensating controls immediately may introduce new complexity or false sense of security without knowing why the original controls failed (e.g., adding a WAF without fixing a broken IDS rule could leave other attack vectors open).

70
Multi-Selectmedium

An information security program must include elements to ensure continuous improvement. Which TWO of the following are MOST essential for continuous improvement?

Select 2 answers
A.Annual risk assessment
B.Quarterly board meetings
C.Monthly patching
D.Post-incident reviews
E.Regular security awareness training
AnswersA, D

Risk assessment identifies evolving threats and areas for improvement.

Why this answer

Annual risk assessments are essential for continuous improvement because they systematically identify, evaluate, and prioritize changes in the threat landscape, business objectives, and regulatory requirements. This process ensures the information security program adapts to new risks and aligns with organizational goals, driving iterative enhancements. Without a periodic risk assessment, the program would lack a data-driven foundation for prioritizing improvements.

Exam trap

The trap is confusing operational activities (patching, training) with the strategic feedback mechanisms (annual risk assessment, post-incident review) that are required for continuous improvement in an information security program as per CISM's governance framework.

71
MCQmedium

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

A.Number of security incidents reported
B.Percentage of systems with critical vulnerabilities
C.Average patch deployment time
D.Number of security awareness training completions
AnswerB

Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.

Why this answer

The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.

Exam trap

The trap here is that candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.

Why the other options are wrong

A

Lagging indicator; board prefers leading indicators of risk.

C

Operational detail; not strategic.

D

Activity metric, not outcome.

72
Multi-Selecteasy

Which of the following are key components of an information security program? (Select TWO)

Select 2 answers
A.A set of security policies and standards
B.A network architecture diagram
C.A risk management process
D.An incident response log
AnswersA, C

Why this answer

A set of security policies and standards is a key component because it establishes the governance framework that defines acceptable use, access control, and compliance requirements for the entire organization. Without documented policies and standards, the security program lacks the authoritative baseline to enforce controls or measure effectiveness. These documents are the foundation for all other security activities, including training, audits, and incident response.

Exam trap

The trap here is that candidates often confuse operational artifacts (like network diagrams or logs) with programmatic components, failing to recognize that the core of an information security program is the governance and risk management framework, not the technical outputs or diagrams.

Why the other options are wrong

B

This is a technical artifact, not a core program component.

D

This is an operational record, not a program component.

73
MCQhard

An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?

A.Implement new security controls based on industry best practices.
B.Conduct a maturity assessment of the current program.
C.Increase the security awareness training budget.
D.Revise the information security policy.
AnswerB

A maturity assessment first establishes the programme's current capability baseline against a recognised model, exposing gaps before any remediation is proposed. This satisfies the stem's requirement to improve effectiveness by grounding changes in measured evidence rather than assumption.

Why this answer

Before making any changes, the security manager must first understand the current state of the program. A maturity assessment (e.g., using the CMMI or COBIT framework) evaluates the effectiveness, gaps, and capability levels of existing processes and controls. This baseline ensures that subsequent improvements are targeted and justified, rather than arbitrary or misaligned with the organization's actual needs.

Exam trap

ISACA often tests the principle that assessment must precede action; the trap here is that candidates may jump to implementing controls or revising policies as a quick fix, ignoring the foundational step of measuring current maturity to ensure changes are evidence-based and effective.

Why the other options are wrong

A

This may introduce unnecessary controls without understanding existing gaps.

C

Training is important but not the first step; assessment should precede resource allocation.

D

Policy revision may be needed, but first understand the program's strengths and weaknesses.

74
Drag & Dropmedium

Arrange the steps for performing a vulnerability scan on a network segment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Vulnerability scanning requires authorization, configuration, execution, analysis, and prioritization.

75
MCQhard

A healthcare organization's information security program has a risk register with several high-risk items. The CISO is allocating budget for risk treatment. Which of the following is the MOST important factor when deciding whether to mitigate, transfer, or accept a risk?

A.Regulatory requirements for the specific risk.
B.The organization's risk appetite and tolerance levels.
C.The cost of the control versus the potential financial impact of the risk.
D.The likelihood and impact ratings from the risk assessment.
AnswerB

Risk appetite and tolerance define how much risk the organization is willing to accept in pursuit of its objectives. They provide the criteria for determining whether a risk should be mitigated, transferred, or accepted. Without considering these, decisions may not align with business strategy and could lead to excessive risk-taking or unnecessary spending.

Why this answer

The organization's risk appetite and tolerance levels are the most important factor because they establish the boundaries for acceptable risk. They guide whether to mitigate, transfer, or accept a risk, ensuring that decisions align with business strategy. Other factors like cost, likelihood, and regulations inform the decision but do not override the fundamental risk appetite.

Exam trap

The trap here is focusing on quantitative factors like cost or likelihood/impact while overlooking that risk appetite and tolerance provide the qualitative framework for all risk treatment decisions.

Page 1 of 2 · 139 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cism Security Program questions.