Courseiva

CISM · topic practice

Information Security Program practice questions

This domain covers building, governing, and continuously improving an information security program. CISM questions here test how you align security with business objectives, assign ownership, apply policies and standards, and move an organization from reactive to proactive. Expect scenario-based questions about governance structures, data classification, metrics, and program maturity rather than hands-on tool configuration.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Security Program

What the exam tests

What to know about Information Security Program

You must be able to select governance, policy, and program-management actions that align security with business goals and enforce standards. The single most important thing is to identify who owns the risk and the control, then choose the action that improves accountability and proactive risk management.

Aligning security strategy, policies, and standards with business objectives and risk appetite

Assigning security roles, responsibilities, and accountability across business units and the CISO

Establishing data classification, ownership, and handling standards, and enforcing compliance

Using metrics, audits, and maturity models to move from reactive to proactive security

Why learners struggle

Why Information Security Program questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Information Security Program exam traps

  • ▸Choosing a technical control or tool when the real issue is governance, policy enforcement, or unclear ownership.
  • ▸Treating policy noncompliance as a training problem instead of an accountability and enforcement gap.
  • ▸Selecting a reactive activity, such as incident response, when the question asks for a proactive program initiative.

Practice set

Information Security Program questions

20 questions · select your answer, then reveal the explanation

Match the following security program components with their primary purpose by dragging each component to the correct description.

An organization has implemented a balanced scorecard to measure the effectiveness of its information security program. Which of the following metrics would be MOST appropriate for the 'internal processes' perspective?

An information security manager is developing a security program for a multinational organization. Which of the following should be considered when defining the program scope? (Select THREE)

Match each information security program component with its correct description.

An organization is designing its information security program and needs to ensure it supports business continuity. Which TWO of the following should be integrated into the program?

An information security manager is developing a program metric to report to senior management. Which metric best demonstrates the effectiveness of the information security program?

Match each information security program component to its primary focus area.

Component: 1. Risk Assessment, 2. Security Awareness Training, 3. Incident Response Plan, 4. Policy Framework

Focus Areas: A. Human factors and behavior B. Structured response to events C. Identification and analysis of threats D. Governance and compliance requirements

Drag each component to its matching focus area.

Arrange the steps in order for conducting a business impact analysis (BIA) in business continuity management.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each CISM domain to its focus area.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Establish and maintain a framework to align security with business objectives

Identify and manage information risk to achieve business objectives

Design and implement a security program to manage risk

Plan and manage the incident response process

Oversee and improve the security program's performance

Match each security framework to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Specify requirements for an ISMS

Provide risk-based guidance for critical infrastructure

Govern and manage enterprise IT

Align IT services with business needs

Protect cardholder data

Match each security role to its primary responsibility.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Senior executive responsible for security strategy

Oversees daily security operations and team

Designs security infrastructure and controls

Evaluates compliance and effectiveness of controls

Executes incident response procedures

A small business owner wants to establish an information security program but has limited budget and staff. Which of the following frameworks would be most appropriate to guide the program?

A company's security program includes a policy that prohibits the use of personal devices for work. However, the CISO discovers that several executives are using personal tablets to access corporate email. What is the most appropriate action for the CISO to take?

Which of the following best describes the primary purpose of an information security program?

Which TWO of the following are key performance indicators (KPIs) that demonstrate the effectiveness of a security awareness program?

Which THREE of the following are typically included in an information security program budget?

Which of the following is the primary purpose of an information security program?

Which THREE of the following are critical success factors for implementing an information security program?

Based on the exhibit, what is the most likely vulnerability that an attacker could exploit?

Exhibit

Refer to the exhibit.

Exhibit: Network Architecture Description

The network consists of three zones: External, DMZ, and Internal. The external interface connects to the internet. The DMZ hosts public-facing web servers and an email relay. The internal zone hosts database servers and application servers. A firewall separates External from DMZ, and another firewall separates DMZ from Internal. The firewall rules are:
- External to DMZ: allow HTTP, HTTPS, SMTP.
- DMZ to Internal: allow MySQL (3306) from web servers to database servers, and allow LDAP (389) from application servers to domain controllers.
- Internal to External: allow outbound HTTP/HTTPS from application servers.
- All other traffic is denied.
The IDS is placed on the DMZ segment, monitoring traffic between DMZ and Internal. The IDS signatures include critical, high, and medium severity, and the action is 'alert and log'.

A company is implementing an information security program. Which of the following is the PRIMARY reason to align the program with business objectives?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Security Program sessions

Start a Information Security Program only practice session

Every question in these sessions is drawn from the Information Security Program domain — nothing else.

Related practice questions

Related CISM topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISM exam test about Information Security Program?
You must be able to select governance, policy, and program-management actions that align security with business goals and enforce standards. The single most important thing is to identify who owns the risk and the control, then choose the action that improves accountability and proactive risk management.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Security Program questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Security Program domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISM topics?
Use the topic links above to move to related areas, or go back to the CISM question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISM exam covers. They are not copied from any real exam or dump site.