Courseiva

CCNA Cism Security Program Questions

64 of 139 questions · Page 2/2 · Cism Security Program topic · Answers revealed

76
MCQeasy

An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?

A.Develop a security awareness training program.
B.Identify business strategy and risk appetite.
C.Design the security architecture based on industry frameworks.
D.Conduct a comprehensive risk assessment.
AnswerB

Aligning security with business objectives requires first understanding the organisation's strategic direction and its tolerance for risk. Identifying business strategy and risk appetite establishes the foundation on which all subsequent security decisions, controls and priorities are built.

Why this answer

Identifying business strategy and risk appetite is the most critical first step because the information security program must be designed to support the organization's objectives and operate within the risk tolerance defined by leadership. Without this alignment, subsequent security controls and investments may conflict with business goals or fail to address the risks the organization is willing to accept. This ensures that security is a business enabler rather than a technical silo.

Exam trap

The trap here is that candidates often mistake conducting a comprehensive risk assessment (Option D) as the first step, but without a defined risk appetite and business strategy, the assessment lacks the context needed to evaluate risk severity and prioritize remediation effectively.

How to eliminate wrong answers

Option A is wrong because developing a security awareness training program is an operational control that should be implemented only after the program's strategic direction, risk appetite, and governance structure are defined; starting with training assumes a baseline of security culture that does not yet exist. Option C is wrong because designing security architecture based on industry frameworks (e.g., NIST, ISO 27001) without first understanding the business strategy and risk appetite can lead to over-engineering or misalignment, wasting resources on controls that do not address the organization's specific risk profile. Option D is wrong because conducting a comprehensive risk assessment requires a predefined risk appetite and business context to determine which risks are acceptable and which require mitigation; without this, the assessment lacks the criteria to prioritize findings effectively.

77
MCQeasy

An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?

A.Implement a security incident response plan
B.Perform regular vulnerability scans
C.Involve business stakeholders in the security steering committee
D.Conduct annual security awareness training
AnswerC

A security steering committee containing business stakeholders aligns the information security programme with business objectives by giving business owners direct governance input into risk decisions, priorities and funding. This satisfies the stem's alignment goal, unlike purely technical measures that lack business representation and accountability.

Why this answer

Involving business stakeholders in the security steering committee ensures that security initiatives are directly aligned with business objectives, as stakeholders provide input on risk tolerance, regulatory requirements, and strategic goals. This collaborative governance model allows the security program to prioritize resources and controls based on business impact, rather than operating in isolation. It is the most effective approach because it integrates security decision-making with business planning, which is a core principle of the CISM framework.

Exam trap

The trap here is that candidates often choose a technical or operational control (like vulnerability scans or incident response) because they seem directly related to security, but CISM emphasizes that strategic alignment with business objectives requires governance-level involvement, not just technical activities.

How to eliminate wrong answers

Option A is wrong because implementing a security incident response plan is a reactive operational measure that addresses how to handle breaches, not how to align the security program with business objectives. Option B is wrong because performing regular vulnerability scans is a technical assessment activity that identifies system weaknesses but does not involve business input or strategic alignment. Option D is wrong because conducting annual security awareness training is a compliance and education activity that reduces human risk but does not directly link security program governance to business goals.

78
MCQhard

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

A.Cost of security incidents as a percentage of revenue
B.Percentage of security incidents detected within defined SLAs
C.Number of security training hours per employee
D.Customer satisfaction survey scores on data protection
AnswerB

Percentage of security incidents detected within defined SLAs measures operational efficiency of the security function itself, which maps directly to COBIT's Internal Processes perspective. It satisfies the board's need for a balanced scorecard metric reflecting process capability and execution, rather than financial, customer or learning-and-growth outcomes.

Why this answer

The 'Internal Processes' perspective of a balanced scorecard focuses on the efficiency and effectiveness of internal operational processes. The percentage of security incidents detected within defined SLAs directly measures the performance of the security monitoring and incident response processes, which are core internal processes in a COBIT-based information security program.

Exam trap

In this CISM question, the trap is that candidates confuse 'Internal Processes' with 'Learning and Growth' (training hours) or 'Financial' (cost metrics), failing to recognize that SLAs directly measure the operational effectiveness of security processes themselves in a COBIT-based program.

How to eliminate wrong answers

Option A is wrong because 'Cost of security incidents as a percentage of revenue' is a financial metric, aligning with the 'Financial' perspective, not 'Internal Processes'. Option C is wrong because 'Number of security training hours per employee' is a learning and growth metric, measuring human capital development, not internal process efficiency. Option D is wrong because 'Customer satisfaction survey scores on data protection' is a customer perspective metric, focusing on external stakeholder perception, not internal operational processes.

79
MCQhard

An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:

A.Update the information security policy
B.Establish a centralized security oversight function
C.Increase security awareness training frequency
D.Conduct a risk assessment for each department
AnswerB

Inconsistent control application across departments stems from fragmented ownership. A centralized security oversight function standardises policy enforcement, monitoring and accountability across all business units, directly satisfying ISO 27001's requirement for consistent control operation organisation-wide rather than leaving each department to interpret controls independently.

Why this answer

The core issue is inconsistent control application across departments, which indicates a lack of governance and oversight rather than a policy or awareness deficiency. Establishing a centralized security oversight function directly addresses this by creating a single authority to enforce, monitor, and standardize control implementation, ensuring alignment with ISO 27001 requirements for management commitment and resource allocation (Clause 5.1 and 7.1). This corrective action provides the necessary organizational structure to drive consistent execution, which is the most effective long-term solution.

Exam trap

The trap here is that candidates confuse the symptom (inconsistent application) with the root cause (lack of governance), leading them to choose awareness training or policy updates, which are tactical fixes rather than strategic corrective actions.

Why the other options are wrong

A

Policy likely exists; issue is execution.

C

Training addresses knowledge, not enforcement.

D

Risk assessment would identify gaps but not fix consistency.

80
MCQmedium

An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?

A.Automate security compliance monitoring across all business units.
B.Update the information security policy to mandate compliance.
C.Conduct a risk assessment to identify gaps and prioritize remediation.
D.Implement additional security controls across all business units.
AnswerC

A risk assessment establishes which control gaps matter most and their business impact, giving the CISO evidence to prioritise remediation across business units. Acting on audit findings without this analysis risks misallocating limited resources to lower-impact issues.

Why this answer

Conducting a risk assessment first (Option C) is the correct initial step because it systematically identifies where controls are failing or missing across business units, quantifies the associated risks, and prioritizes remediation based on business impact. Without this foundational analysis, any subsequent actions—such as automation, policy updates, or new controls—would lack direction and could waste resources on low-priority areas. This aligns with the CISM program lifecycle, where risk assessment drives all other program improvements.

Exam trap

ISACA often tests the principle that a risk assessment must precede any control implementation or policy change, tempting candidates to jump to automation or enforcement actions without first understanding the specific gaps.

How to eliminate wrong answers

Option A is wrong because automating compliance monitoring without first understanding which controls are inconsistently applied and why would simply automate the detection of known gaps without addressing root causes or prioritizing fixes. Option B is wrong because updating the policy to mandate compliance does not address the underlying issue of inconsistent application; it only reiterates requirements without providing a mechanism to identify or remediate the specific gaps. Option D is wrong because implementing additional controls across all business units without a prior risk assessment could introduce unnecessary complexity, increase costs, and fail to target the actual weaknesses, potentially creating new compliance gaps.

81
MCQeasy

Which of the following is the most important factor for ensuring the long-term success of an information security program?

A.Deployment of advanced security technologies.
B.Comprehensive security awareness training.
C.Strong support from top management.
D.Regular penetration testing.
AnswerC

Sustained funding, resourcing and enforcement of security policy depend on executive sponsorship; without top-management backing, controls erode as competing priorities displace them. This directly satisfies the long-term success constraint in the stem, which technical measures alone cannot guarantee.

Why this answer

Strong support from top management is the most important factor because it ensures the information security program receives adequate budget, organizational authority, and strategic alignment with business objectives. Without executive sponsorship, even the best technical controls can be undermined by resource constraints, policy non-compliance, or lack of cross-departmental cooperation. The CISM framework emphasizes that governance and leadership commitment are foundational to sustaining a security program over time.

Exam trap

The trap here is that candidates often mistake operational effectiveness (e.g., training or testing) for strategic success, overlooking that without top management support, no security initiative can be sustained or enforced across the organization.

Why the other options are wrong

A

Technology is a tool, not the foundation; it requires management support to be effective.

B

Training is important but not the most critical factor; without management support, training may lack resources.

D

Penetration testing is a tactical activity; it does not ensure program success without executive backing.

82
MCQhard

A security program lacks executive support. What is the best strategy to gain support?

A.Hire a security consultant to advise
B.Implement quick-win security improvements
C.Show risk quantification in business terms
D.Threaten regulatory fines for non-compliance
AnswerC

Quantifying risk in financial and business-impact terms translates security exposure into language executives already use for investment decisions, making the programme's value and consequences concrete. This directly addresses the missing executive support by aligning security with business objectives.

Why this answer

C is correct because executive stakeholders prioritize business outcomes over technical details. By quantifying risks in financial terms (e.g., potential loss exposure, ROI of mitigation), the security manager aligns with the organization's strategic language, making the case for investment compelling and actionable. This approach directly addresses the root cause—lack of perceived business value—rather than relying on technical arguments or fear.

Exam trap

ISACA CISM tests the misconception that technical demonstrations or fear-based tactics (like regulatory threats) are more effective than business-aligned communication, when in reality, executives require risk expressed in financial terms to justify resource allocation.

How to eliminate wrong answers

Option A is wrong because hiring a consultant may provide expertise but does not inherently build executive buy-in; it can even be seen as an external cost without demonstrated internal alignment. Option B is wrong because quick-win improvements, while visible, often address low-impact risks and can create a false sense of security, failing to address the systemic lack of executive engagement. Option D is wrong because threatening regulatory fines introduces a negative, adversarial tone that can damage trust and collaboration; executives may view it as coercion rather than a partnership in risk management.

83
MCQeasy

An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?

A.Aligns security investments with business priorities
B.Reduces the number of security incidents
C.Increases employee awareness of security policies
D.Ensures compliance with regulatory requirements
AnswerA

Embedding security risk management in strategic planning ties control selection and spending to the business objectives and risk appetite the organisation has already prioritised, so security investments directly support business priorities rather than being justified in isolation after the fact.

Why this answer

Integrating security risk management into strategic planning ensures that security investments are directly tied to the organization's business priorities and risk appetite. This alignment allows for optimal allocation of resources to protect the most critical assets and processes, rather than spending on generic or low-priority controls. The primary benefit is that security becomes a business enabler, not a cost center, by focusing on what matters most to the organization's objectives.

Exam trap

The trap here is that candidates often confuse operational benefits (like incident reduction or compliance) with the strategic, business-alignment benefit that is the core purpose of integrating risk management into planning.

How to eliminate wrong answers

Option B is wrong because reducing the number of security incidents is an operational outcome of effective controls, not the primary strategic benefit of integrating risk management into planning; incidents can still occur despite alignment. Option C is wrong because increasing employee awareness is a tactical training or communication activity, not a strategic planning outcome, and it does not directly tie security to business goals. Option D is wrong because ensuring compliance with regulatory requirements is a baseline necessity and a tactical obligation, but it is not the primary benefit of strategic integration; compliance alone does not guarantee alignment with business objectives or optimized investment.

84
MCQhard

After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?

A.Establish a policy that legacy systems must be upgraded annually.
B.Disconnect the legacy system from the network immediately.
C.Implement a process for periodic reassessment of accepted risks.
D.Require immediate remediation of all legacy systems.
AnswerC

The breach occurred because an accepted risk was never revisited as the threat landscape and asset criticality changed. Periodic reassessment ensures accepted risks remain valid, triggering re-evaluation or treatment when conditions shift, directly closing the governance gap that allowed the legacy vulnerability to persist.

Why this answer

Risk acceptance is not a one-time decision; it must be periodically reassessed to account for changes in the threat landscape, business context, or compensating controls. The breach exploited a known vulnerability that was accepted two years ago, indicating the risk environment has shifted (e.g., new exploit code, increased attacker interest). Implementing a periodic reassessment process ensures that accepted risks are re-evaluated against current threats and vulnerabilities, allowing the organization to either renew acceptance, apply mitigations, or retire the system.

Exam trap

The trap here is that candidates confuse risk acceptance with a permanent decision, failing to recognize that accepted risks must be periodically re-evaluated as part of a continuous risk management process.

How to eliminate wrong answers

Option A is wrong because a blanket annual upgrade policy is impractical for legacy systems that may lack vendor support or compatible upgrades, and it does not address the root cause of failing to reassess risk. Option B is wrong because immediately disconnecting the legacy system may disrupt critical business operations without a planned migration or compensating control, and it is a reactive rather than programmatic improvement. Option D is wrong because requiring immediate remediation of all legacy systems is often infeasible due to cost, operational dependencies, or lack of patches, and it ignores the risk management principle of prioritizing based on current risk appetite.

85
MCQmedium

A CISO is developing a business case for a new security initiative. The organization's executives are focused on cost reduction and operational efficiency. Which of the following approaches is BEST to gain executive support?

A.Provide a detailed list of vulnerabilities that the initiative will address.
B.Emphasize the technical superiority of the proposed security controls.
C.Present the initiative in terms of risk reduction and its impact on business objectives.
D.Highlight compliance requirements that mandate the security controls.
AnswerC

Framing security in business terms—such as protecting revenue, enabling safe expansion, or reducing potential losses—resonates with executives. It connects security to strategic goals and demonstrates return on investment. This approach aligns with CISM principles of integrating security with business objectives and ensures that the initiative is seen as an enabler, not a cost center.

Why this answer

Presenting the initiative in terms of risk reduction and its impact on business objectives is most effective because it speaks the language of executives. It demonstrates how security contributes to the organization's strategic goals, such as protecting revenue, enabling growth, and reducing potential financial losses, thereby making a compelling business case.

Exam trap

The trap here is focusing on technical details or compliance alone, which may not resonate with executives who prioritize business value and cost efficiency.

86
MCQhard

A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?

A.Deploy an automated compliance monitoring tool.
B.Implement a bug bounty program to uncover vulnerabilities.
C.Establish a threat intelligence unit that analyzes adversary tactics and shares indicators across the organization.
D.Increase the number of security operations center (SOC) analysts.
AnswerC

Threat intelligence shifts the programme from reacting to incidents toward anticipating them, because analysing adversary tactics and sharing indicators lets controls be tuned before attacks succeed. This directly satisfies the stem's requirement to move from a reactive to a proactive posture.

Why this answer

Establishing a threat intelligence unit directly supports a proactive posture by enabling the organization to anticipate and prepare for emerging threats based on adversary tactics, techniques, and procedures (TTPs). Unlike reactive measures, this initiative shifts focus from responding to incidents to preventing them by sharing actionable indicators across the enterprise, aligning with the CISM goal of maturing the security program toward proactive risk management.

Exam trap

The trap here is that candidates often confuse proactive security with reactive vulnerability management or detection improvements, mistakenly selecting bug bounty programs or SOC staffing increases because they seem forward-looking, when in fact only threat intelligence directly addresses the proactive shift by focusing on adversary behavior and prevention.

How to eliminate wrong answers

Option A is wrong because deploying an automated compliance monitoring tool is primarily a reactive or detective control that ensures adherence to existing policies and regulations, not a proactive initiative that anticipates or prevents threats. Option B is wrong because implementing a bug bounty program is a reactive vulnerability discovery mechanism that relies on external researchers to find flaws after deployment, rather than proactively analyzing adversary behavior to prevent attacks. Option D is wrong because increasing the number of SOC analysts enhances incident detection and response capabilities, which is still a reactive function focused on handling alerts and incidents as they occur, not on proactively identifying and mitigating threats before they materialize.

87
MCQmedium

A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?

A.Conduct quarterly password audits with manual checks
B.Increase the frequency of security awareness training
C.Implement technical controls to enforce password strength
D.Extend the password change interval to 180 days
AnswerC

Technical enforcement removes reliance on user behaviour, which the audit proved unreliable at 60% non-compliance. Password complexity filters and expiry settings applied through directory policy or Microsoft Entra ID password protection automatically block weak credentials, directly correcting the gap rather than merely restating the requirement through training or revised policy.

Why this answer

The most effective corrective action is to implement technical controls to enforce password strength. This ensures that all passwords meet the policy requirements by preventing users from setting weak passwords. Technical controls are more reliable than manual audits or training because they automatically enforce compliance and reduce the risk of human error.

Exam trap

CISM often tests the difference between preventive, detective, and corrective controls, and candidates may choose training or audits over technical enforcement, not realizing that technical controls are preventive and most effective.

How to eliminate wrong answers

Option A is wrong because quarterly manual audits are reactive and do not prevent weak passwords from being set. Option B is wrong because increasing security awareness training may improve understanding but does not guarantee compliance. Option D is wrong because extending the password change interval to 180 days does not address the strength issue and may even worsen security by allowing weak passwords to remain longer.

88
MCQmedium

A CISO is establishing an information security governance framework to ensure that security activities are aligned with business strategy. The organization has multiple business units, each with its own IT and security staff. Which of the following is the MOST effective way to ensure ongoing alignment?

A.Conduct an annual penetration test to identify and prioritize vulnerabilities.
B.Create a security steering committee composed of business unit leaders and the CISO.
C.Delegate all security decisions to the IT department to ensure technical consistency.
D.Implement a monthly security awareness training program for all employees.
AnswerB

A security steering committee with business unit leaders ensures that security priorities are directly linked to business objectives. It provides a forum for discussing risks, allocating resources, and making decisions that balance security needs with business goals. This structure promotes accountability and continuous alignment, which is essential for effective governance.

Why this answer

A security steering committee that includes business unit leaders and the CISO provides a governance structure where security decisions are made collaboratively and aligned with business strategy. It ensures that security is not an isolated IT function but an integral part of business operations, enabling continuous alignment and effective risk management.

Exam trap

The trap here is assuming that technical measures like training or penetration testing alone can achieve strategic alignment, when governance requires cross-functional oversight.

89
MCQeasy

Which is a key component of an information security program?

A.Encryption technology
C.Antivirus software
D.Security policy
AnswerD

A security policy is the foundational governance document that defines management's intent, scope and mandatory requirements for protecting information assets. It satisfies the stem's demand for a program component by authorising and directing all subordinate controls, standards and procedures. Without it, security activities lack formal mandate, accountability and alignment with organisational objectives.

Why this answer

A security policy is the foundational component of an information security program because it defines the organization's strategic direction, governance structure, and high-level principles for protecting information assets. Unlike specific technologies (encryption, firewalls, antivirus), the policy establishes the rules, roles, and responsibilities that drive the selection and implementation of all security controls. Without a policy, technical measures lack context, authority, and alignment with business objectives.

Exam trap

CISM often tests the distinction between governance (policy) and operational controls (technology), trapping candidates who confuse a tactical tool like a firewall or antivirus with the strategic program component that defines the security program's scope and authority.

How to eliminate wrong answers

Option A is wrong because encryption technology is a specific technical control that protects data confidentiality, but it is not a program-level component; it is a tool deployed under the policy's guidance. Option B is wrong because a firewall is a network security device that filters traffic based on rules, but it is an operational control, not a strategic program component. Option C is wrong because antivirus software is a host-based endpoint protection tool that detects and removes malware, but it is a tactical solution, not a governance element of the security program.

90
MCQmedium

Based on the exhibit, what is the most significant security gap in this configuration?

A.The intrusion detection system is set to alert-only, so it cannot block attacks.
B.The vendor baseline is CIS Level 1, which may be too permissive.
C.The firewall allows inbound HTTPS from any source to web servers.
D.The database port 3306 is exposed to web servers without encryption.
AnswerA

An IDS deployed in alert-only mode detects and logs malicious traffic but cannot drop or block it, leaving attacks unimpeded. This satisfies the stem's requirement by identifying the most significant gap: no preventive enforcement, only passive monitoring.

Why this answer

The intrusion detection system (IDS) is configured in alert-only mode, meaning it can only generate alerts and cannot take action to block or drop malicious traffic. This is a significant security gap because, unlike an intrusion prevention system (IPS), an IDS operates out-of-band and relies on manual intervention or separate security controls to stop attacks, leaving the network vulnerable during the response delay.

Exam trap

ISACA often tests the distinction between IDS (alert-only) and IPS (inline blocking) to catch candidates who assume any detection system can automatically stop attacks.

How to eliminate wrong answers

Option B is wrong because CIS Level 1 is a foundational baseline that focuses on essential security controls with minimal operational impact; it is not inherently 'too permissive' and is widely recommended as a starting point for hardening. Option C is wrong because allowing inbound HTTPS (TCP/443) from any source to web servers is a standard and necessary configuration for public-facing web services, provided the web servers are properly hardened and patched. Option D is wrong because exposing database port 3306 (MySQL) to web servers without encryption is a risk, but it is less significant than the IDS being unable to block attacks; database traffic can be encrypted with TLS or SSH tunneling, and the web server is a trusted internal component in many architectures.

91
MCQeasy

An organization's information security program is being developed. The CISO needs to ensure that the program's objectives are aligned with the organization's strategic goals. Which of the following is the BEST source of input for defining the security program's objectives?

A.The results of the most recent vulnerability assessment.
B.Regulatory compliance requirements applicable to the industry.
C.The organization's business strategy and objectives.
D.Industry best practices and standards such as ISO 27001.
AnswerC

The security program exists to support the organization's mission and business objectives. Therefore, the business strategy is the primary input for defining security objectives. This ensures that security efforts are prioritized based on business impact and risk, and that they enable rather than hinder business goals.

Why this answer

The organization's business strategy and objectives are the best source of input. The security program must be aligned with the business to ensure it supports and enables the achievement of strategic goals. This alignment ensures that security investments are justified and prioritized based on business risk and value.

Exam trap

The trap here is selecting compliance requirements or best practices as the primary driver, forgetting that the security program must first serve the business strategy.

92
Multi-Selectmedium

Which THREE elements are essential for an effective information security governance framework?

Select 3 answers
A.Clear accountability structure
B.Board or executive oversight
C.Free and open-source security tools
D.Comprehensive security policies
E.Formal risk appetite statement
AnswersA, B, D

Assigning responsibilities ensures governance is implemented.

Why this answer

A clear accountability structure is essential because it defines who is responsible for specific security decisions and actions, ensuring that no critical task falls through the cracks. Without defined roles, security gaps emerge, and incident response becomes chaotic. This aligns with the CISM principle that governance requires unambiguous ownership of security outcomes.

Exam trap

The trap here is that candidates confuse operational tools or risk appetite statements with the foundational governance elements, but CISM specifically tests that governance is about oversight, accountability, and policy—not the tools or risk quantification methods.

93
MCQmedium

A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?

A.Implement technical controls
B.Develop policies based on industry standards
C.Perform a risk assessment
D.Use the COBIT framework
AnswerD

COBIT provides a governance framework explicitly linking IT objectives to enterprise goals through its governance and management domains, letting the CISO demonstrate that security investment and controls trace back to business outcomes rather than standing alone.

Why this answer

The COBIT framework (Control Objectives for Information and Related Technologies) is specifically designed to bridge the gap between IT governance and business goals, providing a comprehensive set of controls and processes that align security program objectives with enterprise strategy. Unlike other options, COBIT directly addresses governance, risk management, and performance measurement in a way that ensures the security program supports business objectives rather than operating in isolation.

Exam trap

The trap here is that candidates often choose 'Perform a risk assessment' (Option C) because risk assessment is a foundational security activity, but the question asks for the 'best approach' to ensure alignment with business objectives, which requires a governance framework like COBIT that systematically links risk management to strategy, not just a one-time assessment.

How to eliminate wrong answers

Option A is wrong because implementing technical controls without first understanding business objectives and risk appetite can lead to misaligned security measures that either over-constrain operations or leave critical assets unprotected. Option B is wrong because developing policies based solely on industry standards (e.g., ISO 27001, NIST) may achieve compliance but does not inherently ensure alignment with the company's specific business goals, strategic priorities, or risk tolerance. Option C is wrong because performing a risk assessment is a critical input to alignment but is a tactical activity, not a governance framework; it identifies risks but does not provide the structured governance mechanisms to continuously align security program decisions with business objectives.

94
MCQmedium

Which of the following best describes the primary purpose of a security program's governance framework?

A.To implement technical security controls
B.To provide oversight and alignment with business objectives
C.To conduct vulnerability assessments
D.To manage security incidents
AnswerB

A governance framework establishes decision rights, accountability and reporting structures that keep the security programme aligned with business objectives, satisfying the oversight requirement. It differs from operational controls, which execute protections rather than direct and monitor the programme's strategic direction.

Why this answer

The primary purpose of a security program's governance framework is to provide oversight and ensure that security activities are aligned with business objectives, risk appetite, and regulatory requirements. It establishes the policies, roles, and accountability structures that guide decision-making, rather than directly executing technical tasks. This alignment is critical for the program to be sustainable and supported by executive management.

Exam trap

The trap here is that candidates confuse the governance framework with the operational security program itself, mistakenly selecting a tactical activity (like implementing controls or managing incidents) instead of recognizing that governance is the strategic oversight layer that directs and constrains those activities.

Why the other options are wrong

A

Technical controls are operational, not governance.

C

Vulnerability assessments are part of ongoing operations.

D

Incident management is a process within the program.

95
MCQhard

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

A.Consolidate all security tools
B.Conduct a comprehensive risk assessment of the target
C.Merge the security teams into one reporting structure
D.Standardize security policies immediately
AnswerB

A comprehensive risk assessment of the target identifies inherited vulnerabilities, control gaps and compliance exposure before integration decisions are made. It satisfies the merger scenario's highest-priority need by informing every subsequent integration choice with the target's actual risk posture.

Why this answer

Conducting a comprehensive risk assessment of the target company is the highest priority because it identifies vulnerabilities, gaps, and threats that must be understood before any integration decisions are made. Without this assessment, consolidating tools, merging teams, or standardizing policies could introduce unacceptable risk or overlook critical exposures. Risk assessment informs all subsequent integration actions and ensures the acquiring company's security posture is not weakened.

Exam trap

CISM often tests the principle that risk assessment must precede any integration action; candidates are tempted to pick visible actions like tool consolidation or policy standardization.

How to eliminate wrong answers

Option A is wrong because consolidating security tools before understanding the target's risk profile may remove controls that are actually mitigating unknown threats. Option C is wrong because merging security teams into one reporting structure is an organizational change that should follow, not precede, a risk assessment; doing it first can disrupt incident response and lose institutional knowledge. Option D is wrong because standardizing security policies immediately may be impossible or harmful if the target's environment has unique regulatory or technical constraints that the assessment would reveal.

96
MCQeasy

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

A.To ensure compliance with regulations
B.To assign accountability to individuals
C.To track the budget for security initiatives
D.To measure the effectiveness of security controls
AnswerD

KPIs quantify how well implemented controls reduce risk, directly satisfying the stem's demand for performance measurement rather than activity tracking. Unlike metrics counting outputs, effectiveness indicators reveal whether controls actually mitigate threats, enabling management to judge programme value and justify resource decisions.

Why this answer

KPIs are designed to provide measurable evidence of how well the security program is achieving its objectives, specifically by quantifying the effectiveness of security controls. For example, a KPI like 'mean time to detect (MTTD)' directly measures the performance of detection controls, enabling data-driven decisions on control improvements. This aligns with the CISM focus on governance and performance management, not just compliance or budgeting.

Exam trap

The trap here is that candidates often confuse KPIs with compliance metrics or operational tasks, mistakenly thinking the primary purpose is to ensure regulatory adherence rather than to measure and improve the effectiveness of security controls.

How to eliminate wrong answers

Option A is wrong because compliance with regulations is a baseline requirement, not the primary purpose of KPIs; KPIs measure performance beyond mere compliance, such as control effectiveness. Option B is wrong because assigning accountability is a function of roles and responsibilities within the governance structure, not a direct purpose of KPIs, which are metrics, not assignment tools. Option C is wrong because tracking the budget for security initiatives is a financial management activity, typically measured by cost-related metrics (e.g., cost per incident), not the primary purpose of KPIs, which focus on operational and strategic effectiveness.

97
MCQhard

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

A.Slower incident response
B.Inconsistent security levels across business units
C.Higher cost of compliance
D.Duplication of controls
AnswerB

Decentralised governance lets each business unit set its own controls, so enforcement, risk tolerance and reporting diverge across the institution. That inconsistency directly undermines the uniform, auditable control baseline the new regulatory framework demands, creating gaps regulators can cite. Centralised models instead impose one standard, which is why this is the most significant risk.

Why this answer

In a decentralized governance model, each business unit may implement its own security controls, leading to inconsistent security levels across the organization. This is the most significant risk because it creates gaps and vulnerabilities that can be exploited, especially in a regulated financial institution. While other risks exist, inconsistency directly undermines the overall security posture.

Exam trap

CISM often tests governance models, and candidates may choose 'duplication of controls' or 'higher cost' as the most significant risk, overlooking that inconsistent security levels directly increase the likelihood of breaches and regulatory non-compliance.

How to eliminate wrong answers

Option A is wrong because slower incident response is a possible consequence but not the most significant risk; inconsistency can cause incidents in the first place. Option C is wrong because higher cost of compliance is a financial concern, but not as critical as security gaps. Option D is wrong because duplication of controls is inefficient but less severe than inconsistent security levels that can lead to breaches.

98
MCQmedium

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

A.Percentage of budget spent on security
B.Number of security patches applied
C.Number of security policies created
D.Mean time to detect incidents
AnswerD

Mean time to detect incidents quantifies how quickly the security function identifies threats, a capability executives directly link to reduced breach impact and programme effectiveness. It demonstrates operational value more concretely than activity counts or compliance percentages, satisfying the requirement to show programme worth.

Why this answer

Mean time to detect (MTTD) incidents directly measures how quickly the security program identifies threats, which is a core outcome executives care about — reduced exposure window and improved resilience. It demonstrates program effectiveness in a business-relevant way rather than just activity or spend.

Exam trap

The trap is selecting activity or spend metrics (patches, policies, budget) that are easy to count but do not demonstrate value — CISM consistently favors outcome-based metrics tied to risk reduction.

How to eliminate wrong answers

Option A is wrong because percentage of budget spent is an input/resource metric, not an outcome — spending more does not prove the program is effective. Option B is wrong because the number of patches applied is an activity metric that says nothing about risk reduction or whether critical vulnerabilities were addressed in time. Option C is wrong because the number of policies created is a documentation activity metric with no direct link to security outcomes or business value.

99
MCQeasy

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

A.Immediately mandate compliance with a new enterprise-wide security policy.
B.Develop a minimum security standard (MSS) and a phased implementation roadmap based on risk.
C.Centralize all security operations and disband local teams.
D.Adopt the most mature subsidiary's program as the enterprise standard.
AnswerB

A minimum security standard sets non-negotiable controls every subsidiary must meet, while the risk-based phased roadmap sequences remediation according to each unit's maturity and exposure. This balances central control with local flexibility and respects the constrained budget.

Why this answer

Correct answer is B because developing a minimum security standard (MSS) and a phased implementation roadmap based on risk allows each subsidiary to implement controls based on their unique risk profiles while ensuring a common baseline. This approach balances flexibility with control, respects varying maturity levels, and avoids disruption. Option A (immediate enterprise-wide policy) ignores diverse operational processes and may cause resistance.

Option C (centralize all security operations) is costly and impractical given the budget and local teams. Option D (adopt the most mature subsidiary's program) may not fit the context of less mature units.

100
MCQmedium

A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?

A.Highlight the technical sophistication of the proposed security controls
B.Emphasize the potential cost savings from preventing security incidents
C.Present industry benchmarks showing the average cost of a data breach
D.Demonstrate how security enables the achievement of business objectives and protects revenue streams
AnswerD

This approach aligns security with the executives' priorities by showing that security is not just a cost center but a business enabler. It highlights how security measures can protect revenue, facilitate market expansion, and build customer trust. By directly linking security to business objectives, the CISO can secure executive support and funding more effectively. This strategic alignment is a core principle of a mature information security program and is essential for gaining buy-in from business leaders.

Why this answer

The most effective approach is to demonstrate how security enables business objectives and protects revenue streams. This aligns security with the executives' strategic priorities, positioning it as a value driver rather than a cost. By showing that security supports growth, innovation, and customer trust, the CISO can build a compelling business case that resonates with executive leadership and secures necessary funding.

Exam trap

The trap here is focusing on technical or fear-based arguments instead of linking security to the business outcomes executives care about.

101
MCQhard

A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?

A.Outsource security governance to a managed security service provider (MSSP).
B.Fully centralized security governance with global standards enforced uniformly.
C.Federated governance: global standards with local implementation and oversight.
D.Fully decentralized security governance, each region independent.
AnswerC

Federated governance balances centralised standards with regional autonomy: global policies set minimum security baselines, while local teams adapt implementation to jurisdictional, regulatory and cultural constraints. This directly satisfies the stem's dual requirement of consistency and regional flexibility, unlike purely centralised or fully devolved models that sacrifice one objective for the other.

Why this answer

Federated governance (Option C) is the correct choice because it establishes a global security framework with mandatory standards (e.g., ISO 27001 controls, encryption baselines like AES-256) while delegating implementation and oversight to regional units. This structure balances consistency with local legal requirements (e.g., GDPR in Europe, PIPL in China) and operational needs, avoiding the rigidity of full centralization or the fragmentation of full decentralization.

Exam trap

The trap here is that candidates often confuse 'federated governance' with 'decentralized governance' (Option D). In the context of ISACA CISM, federated governance enforces a mandatory global baseline (e.g., security standards, risk management framework) while permitting local adaptation to comply with regional laws and operational needs. Decentralized governance lacks any central authority or consistent standards, which is unacceptable for a global program.

How to eliminate wrong answers

Option A is wrong because outsourcing security governance to an MSSP abdicates strategic control and does not inherently provide a structure for consistent global standards with regional flexibility; MSSPs typically execute operational tasks (e.g., SIEM monitoring) rather than define governance frameworks. Option B is wrong because fully centralized governance with uniform enforcement ignores regional legal variations (e.g., data residency laws) and local risk appetites, leading to non-compliance or operational friction. Option D is wrong because fully decentralized governance creates inconsistent security postures, making it impossible to enforce global baselines (e.g., minimum encryption standards or incident response timelines) and increasing overall risk exposure.

102
MCQhard

A CISO is presenting the information security program's annual report to the board. The board is concerned about the rising cost of cyber insurance and wants to understand how the program can help reduce premiums. Which of the following actions would MOST directly influence the cost of cyber insurance?

A.Implementing and documenting a formal risk management process with regular assessments.
B.Outsourcing security monitoring to a managed security service provider (MSSP).
C.Increasing the number of security awareness training sessions per year.
D.Purchasing additional security tools to enhance the defense-in-depth strategy.
AnswerA

Insurers assess risk based on the maturity of an organization's risk management practices. A formal, documented process with regular assessments demonstrates proactive risk reduction, which can lead to lower premiums. It provides evidence that the organization understands and manages its cyber risk, making it a more attractive insurance candidate.

Why this answer

The correct answer is implementing and documenting a formal risk management process with regular assessments. Insurers evaluate the maturity and effectiveness of an organization's risk management to determine premiums. A documented process with regular assessments provides tangible evidence of risk reduction, which is a key factor in negotiating lower premiums.

Exam trap

The trap here is assuming that adding more tools or training sessions directly lowers premiums, when insurers primarily value a mature, documented risk management process.

103
MCQhard

A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?

A.Implement the strictest regulatory requirements globally to ensure compliance everywhere.
B.Adopt a baseline of controls that meet the lowest common denominator of all regulations.
C.Develop a risk-based framework that allows for tailored controls based on local risk assessments.
D.Allow each business unit to define its own security controls based on local requirements.
AnswerC

A risk-based framework lets the corporation apply controls proportionate to assessed local risk, accommodating differing legal requirements across regulated jurisdictions while preserving business agility. Uniform or purely compliance-driven controls cannot flex to each region's distinct regulatory and risk profile.

Why this answer

A risk-based framework, such as ISO 27001 or NIST SP 800-53, allows the organization to establish a baseline of controls while tailoring them to address specific local legal requirements and risk profiles. This approach balances security and business agility by avoiding unnecessary overhead from overly strict global mandates while ensuring that critical regulatory obligations are met through localized risk assessments.

Exam trap

The trap here is that candidates often confuse 'strictest globally' (Option A) with 'best practice' due to a desire for simplicity, but CISM emphasizes that a risk-based approach is the only method that effectively balances compliance, security, and business agility in a multi-regulatory environment.

How to eliminate wrong answers

Option A is wrong because implementing the strictest regulatory requirements globally (e.g., GDPR's data protection rules applied in jurisdictions with less stringent laws) can introduce excessive operational friction, reduce business agility, and may conflict with local laws that permit different practices. Option B is wrong because adopting a baseline that meets the lowest common denominator of all regulations (e.g., only complying with the weakest privacy law) would leave the organization non-compliant with stricter regulations like GDPR or HIPAA, exposing it to significant legal and financial penalties. Option D is wrong because allowing each business unit to define its own security controls based on local requirements without a centralized governance framework leads to inconsistent security postures, gaps in coverage, and increased risk of regulatory non-compliance across the multinational enterprise.

104
MCQeasy

An organization is establishing a new information security program. The CISO needs to ensure that the program's structure and processes are aligned with the organization's overall business strategy. Which of the following should be the CISO's FIRST step?

A.Meet with executive leadership to understand business objectives and risk appetite.
B.Develop a comprehensive set of security policies and procedures.
C.Implement a security awareness training program for all employees.
D.Conduct a risk assessment to identify and prioritize risks to the organization.
AnswerA

Understanding business objectives and risk appetite is foundational for aligning the security program with the organization's strategy. This step ensures that security initiatives support business goals and are prioritized according to the organization's tolerance for risk. It is the first step in establishing a program that adds value and is not seen as an impediment.

Why this answer

The CISO's first step should be to meet with executive leadership to understand business objectives and risk appetite. This ensures that the security program is aligned with the organization's strategy from the outset. Without this understanding, subsequent activities like risk assessment and policy development may not support business goals.

This step is fundamental to CISM's approach to information security governance.

Exam trap

The trap here is starting with tactical activities like policy writing or risk assessment without first understanding the business context and risk appetite.

105
MCQeasy

An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?

A.Regulatory requirements only
B.Likelihood of exploitation
C.Risk level (likelihood × impact)
D.Ease of remediation
AnswerC

Risk level combines likelihood and impact, giving a quantified measure of exposure that reflects both probability and business consequence. Prioritising by this score directs remediation to vulnerabilities posing the greatest overall threat, rather than by severity rating or ease of fixing alone.

Why this answer

Risk level, calculated as likelihood multiplied by impact, is the primary factor for prioritizing remediation because it quantifies the overall exposure to the organization. While regulatory requirements, likelihood alone, or ease of remediation are important considerations, they do not capture the combined effect of both probability and consequence, which is essential for effective risk management in an information security program.

Exam trap

The trap here is that candidates often choose 'Likelihood of exploitation' (Option B) because they confuse frequency with overall risk, ignoring that a high-likelihood but low-impact vulnerability (e.g., a minor misconfiguration) may be less critical than a low-likelihood but catastrophic one (e.g., a zero-day in a core database).

How to eliminate wrong answers

Option A is wrong because regulatory requirements are only one component of risk prioritization; focusing solely on them ignores vulnerabilities with high business impact that may not be regulated. Option B is wrong because likelihood of exploitation alone does not account for the severity of the impact, leading to misallocation of resources toward frequent but low-damage threats. Option D is wrong because ease of remediation prioritizes quick fixes over addressing the most critical risks, which can leave high-risk vulnerabilities unmitigated.

106
MCQeasy

The security team is designing a security awareness program. Which topic should be prioritized FIRST?

A.Phishing recognition and reporting
B.Password creation and management
C.Incident reporting procedures
D.Data classification and handling
AnswerA

Phishing remains the leading initial access vector, so teaching staff to recognise and report suspicious messages addresses the highest-likelihood human risk first. Prioritising it satisfies the stem's requirement to sequence the awareness programme by greatest organisational exposure, ahead of less frequent threats.

Why this answer

Phishing remains the leading initial access vector in real-world breaches, and humans are the primary target. A security awareness program should prioritize phishing recognition and reporting because it directly addresses the most exploited attack surface and produces measurable reductions in successful compromises. Teaching users to spot and report suspicious emails creates a human sensor network that feeds the SOC with early threat intelligence.

Exam trap

CISM often tests the distinction between awareness (broad, preventive, human-focused) and training (role-specific, technical) — candidates who pick password or incident topics confuse a control with the highest-priority awareness need.

How to eliminate wrong answers

Option B is wrong because password management, while important, is increasingly mitigated by technical controls like MFA and password managers, and it is a narrower topic than phishing. Option C is wrong because incident reporting procedures are a process/training item that assumes users already recognize an incident — without phishing awareness, they will not know to report. Option D is wrong because data classification is a policy and governance topic typically aimed at specific roles, not the broad first-line priority for all staff.

107
MCQeasy

Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?

A.Internet traffic to 10.0.0.5 is permitted only if from 192.168.1.0/24.
B.All traffic from the internet to the internal network is denied.
C.Traffic from the internet to 10.0.0.5 port 80 is permitted.
D.Traffic from 192.168.1.0/24 to 10.0.0.5 port 80 is permitted.
AnswerB

First rule denies all IP traffic to 10.0.0.0/8.

Why this answer

The exhibit shows an access control list (ACL) that denies all traffic from any source to the 10.0.0.0/8 network. Since the ACL is applied inbound on the internet-facing interface, any traffic originating from the internet destined for the internal network 10.0.0.0/8 is implicitly denied by the explicit deny statement. Therefore, option B is correct: all traffic from the internet to the internal network is denied.

Exam trap

The trap here is that candidates often misread the direction of the ACL permit statement (10.0.0.0/8 to 192.168.1.0/24) and incorrectly assume it permits traffic from the internet to the internal network, when in fact it only permits outbound traffic from the internal network to the specified destination.

How to eliminate wrong answers

Option A is wrong because the ACL does not permit any traffic from 192.168.1.0/24 to 10.0.0.5; the only permit statement is for traffic from 10.0.0.0/8 to 192.168.1.0/24, not the reverse. Option C is wrong because the ACL contains no permit statement for traffic from the internet to 10.0.0.5 port 80; the only permit is for traffic from 10.0.0.0/8 to 192.168.1.0/24, and the explicit deny blocks all other traffic. Option D is wrong because the permit statement allows traffic from 10.0.0.0/8 to 192.168.1.0/24, not from 192.168.1.0/24 to 10.0.0.5; the direction is reversed, and the ACL does not permit any inbound traffic to the 10.0.0.0/8 network.

108
MCQeasy

Which metric is most indicative of security program effectiveness?

A.Security budget spent
B.Time to patch critical vulnerabilities
C.Number of security tools deployed
D.Number of security incidents
AnswerB

Time to patch critical vulnerabilities measures how quickly exposure windows close after a flaw is disclosed. Unlike counts of incidents or controls, it directly reflects operational remediation capability, making it the strongest indicator of whether the security programme actually reduces risk.

Why this answer

Time to patch critical vulnerabilities directly reflects the organization's ability to reduce exposure to known exploits, which is a key outcome of an effective security program. Unlike input metrics (budget, tools) or lagging indicators (incident count), this metric measures the speed of a critical risk-reduction process, aligning with CISM's focus on program governance and risk management.

Exam trap

The trap here is that candidates confuse activity metrics (budget spent, tools deployed) with outcome-based metrics, failing to recognize that CISM emphasizes measuring the effectiveness of risk management processes, not the volume of resources or incidents.

How to eliminate wrong answers

Option A is wrong because security budget spent is an input metric that does not measure effectiveness; a program can spend heavily yet fail to reduce risk due to poor allocation or execution. Option C is wrong because the number of security tools deployed is a vanity metric; more tools can increase complexity and blind spots without improving security posture. Option D is wrong because the number of security incidents is a lagging indicator that can be influenced by detection capabilities; a low incident count may reflect poor detection rather than true program effectiveness.

109
MCQmedium

A healthcare organization's information security program has a policy that requires all ePHI to be encrypted at rest. During a review, the CISO discovers that a legacy application storing ePHI does not support encryption. The application is critical for patient care and cannot be replaced immediately. Which of the following should the CISO do FIRST?

A.Grant a policy exception for the legacy application and document the compensating controls.
B.Immediately disconnect the legacy application from the network to prevent a breach.
C.Update the security policy to allow unencrypted ePHI for legacy systems.
D.Conduct a risk assessment to evaluate the potential impact and likelihood of a data breach.
AnswerD

The first step is to conduct a risk assessment to understand the specific risks associated with the unencrypted ePHI. This assessment will inform whether an exception is warranted, what compensating controls are needed, and how to prioritize remediation. It is a fundamental risk management practice and aligns with the CISO's responsibility to manage risk to acceptable levels. Without it, any decision would be based on assumptions rather than data.

Why this answer

The CISO should first conduct a risk assessment to quantify the risk posed by the unencrypted ePHI. This assessment will identify the likelihood and impact of a breach, and inform decisions about compensating controls, exceptions, or remediation timelines. Other actions, such as granting an exception or disconnecting the application, are premature without understanding the risk.

The risk assessment ensures a balanced approach that considers patient care and compliance.

Exam trap

The trap here is jumping to an exception or policy change without first assessing the risk, which could lead to inadequate risk management.

110
MCQmedium

An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?

A.The awareness program is not regularly updated or evaluated for effectiveness.
B.Lack of a security awareness program.
C.Insufficient budget for security tools.
D.Insufficient firewall rules.
AnswerA

Incidents persisting two years after programme launch point to a static awareness programme that is neither refreshed to reflect current threats nor measured for effectiveness. Without periodic evaluation and content updates, users retain outdated knowledge, so awareness fails despite the programme's existence.

Why this answer

The scenario states the security program has been in place for two years, yet incidents persist due to lack of user awareness. This indicates the awareness program exists but is not being regularly updated or evaluated for effectiveness, which is a common root cause in mature programs where content becomes stale and fails to address evolving threats like phishing or social engineering.

Exam trap

The trap here is that candidates assume any security program automatically includes an effective awareness component, but CISM emphasizes that programs must be evaluated and updated regularly; a static program is as ineffective as having none.

How to eliminate wrong answers

Option B is wrong because the scenario implies a security program exists, so the root cause is not the absence of an awareness program but its lack of updates or evaluation. Option C is wrong because insufficient budget for security tools does not directly address user awareness failures; the incidents are due to human behavior, not tooling gaps. Option D is wrong because insufficient firewall rules are a technical control issue unrelated to user awareness; firewall misconfigurations would not cause incidents stemming from a lack of user knowledge.

111
MCQmedium

A global financial services firm has a mature information security program. The CISO wants to ensure that the program's strategic objectives remain aligned with changing business goals, such as a new push into mobile banking. Which of the following is the MOST effective way to achieve this alignment?

A.Increase the security awareness training budget for all employees.
B.Update the information security policy to include mobile banking security requirements.
C.Establish a security steering committee that includes business unit leaders to review and adjust security strategy regularly.
D.Conduct an annual penetration test on all mobile banking applications.
AnswerC

A security steering committee with business representation ensures that security strategy is continuously aligned with business objectives. It provides a forum for discussing business changes and their security implications, enabling proactive adjustments. This approach is a key governance mechanism in CISM for maintaining alignment between information security and organizational goals, especially in dynamic environments like mobile banking expansion.

Why this answer

The most effective way to align the security program with changing business goals is to establish a governance structure that includes business stakeholders. A security steering committee facilitates ongoing communication and ensures that security strategy is adjusted in response to business shifts. This proactive approach is central to CISM's focus on aligning security with organizational objectives.

Exam trap

The trap here is confusing tactical security activities, such as penetration testing or policy updates, with strategic alignment mechanisms that require business engagement.

112
MCQeasy

An organization is developing its information security program and wants to ensure that security roles and responsibilities are clearly defined and communicated across the enterprise. Which of the following should be established FIRST to achieve this?

A.A security awareness training program for all employees.
B.An incident response plan that specifies team members and their duties.
C.A formal security governance structure with defined roles and responsibilities.
D.A comprehensive risk assessment to identify critical assets and threats.
AnswerC

A formal security governance structure defines who is accountable for what, including the CISO, security managers, business unit leaders, and employees. It provides the foundation for communicating responsibilities across the enterprise. Without this structure, efforts to assign tasks or train staff lack authority and clarity. It is the first step because it establishes the framework for all subsequent security program activities, including policy development and awareness.

Why this answer

Establishing a formal security governance structure is the foundational step for defining and communicating security roles and responsibilities. It clarifies accountability, authority, and reporting lines, which are prerequisites for effective policy development, risk management, and awareness training. Other options are important but depend on governance being in place first.

Therefore, governance should be established initially.

Exam trap

The trap here is selecting a tactical activity like risk assessment or training before establishing the governance framework that gives them direction and authority.

113
MCQmedium

A financial services firm has a mature information security program. The Chief Information Security Officer (CISO) is asked by the board to demonstrate that the program is aligned with the organization's strategic objectives. Which of the following is the MOST effective way for the CISO to provide this assurance?

A.Present the results of the latest penetration test and vulnerability remediation statistics.
B.Map security program objectives and metrics to specific business goals and report on their contribution.
C.Conduct a gap analysis against ISO/IEC 27001:2022 and present the results to the board.
D.Provide a summary of security incidents and the associated financial losses over the past year.
AnswerB

Mapping security objectives and metrics to specific business goals directly demonstrates how the security program enables and supports the organization's strategy. This approach provides the board with clear line-of-sight from security activities to business outcomes, such as protecting revenue streams or enabling safe digital transformation. It is the most effective way to show strategic alignment because it uses business language and measurable contributions.

Why this answer

The board wants assurance that security is not a siloed function but is integrated with business strategy. Mapping security objectives and metrics to business goals provides that assurance by showing how security enables business outcomes. Other options focus on compliance, technical posture, or incident history, which do not directly address strategic alignment.

The CISO should use business language and measurable contributions to demonstrate value.

Exam trap

The trap here is assuming that compliance with a standard or reporting technical metrics automatically demonstrates strategic alignment.

114
MCQhard

You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?

A.Encrypt all data in transit and at rest using the organization's own encryption keys.
B.Implement compensating controls such as tokenization for all cardholder data stored in the cloud.
C.Conduct a detailed security assessment of the cloud service provider's controls and contractually require an annual SOC 2 Type II report.
D.Require the mobile app development team to undergo formal security training and implement a peer review process for all code deployments.
AnswerC

Assessing the CSP's controls and contractually mandating an annual SOC 2 Type II report closes the identified assurance gap, since no independent third-party audit currently exists. This addresses the cloud-specific risk first, before tackling the mobile app's absent security reviews.

Why this answer

The correct first course of action because the absence of an independent third-party audit report (e.g., SOC 2 Type II) means the organization has no verified assurance that the cloud service provider (CSP) has adequate security controls in place. As CISO, you must immediately assess the CSP's security posture and contractually mandate a SOC 2 Type II report to gain visibility into the effectiveness of the CSP's controls over time, which is foundational before implementing any compensating technical controls. This aligns with the CISM domain of Information Security Program governance, where vendor risk management and due diligence are critical first steps when expanding into cloud environments.

Exam trap

The trap here is that candidates often jump to implementing a technical control (like encryption or tokenization) as the immediate fix, but the CISM exam emphasizes that governance and vendor risk management—specifically obtaining independent assurance of the CSP's controls—must come first before deploying compensating technical measures.

How to eliminate wrong answers

Option A is wrong because encrypting data with the organization's own keys (client-side encryption) does not address the root cause—lack of visibility into the CSP's overall security posture; encryption is a compensating control that should follow a proper vendor risk assessment. Option B is wrong because implementing tokenization for cardholder data is a tactical data-centric control that does not resolve the immediate governance gap of having no independent audit report on the CSP; tokenization should be considered after contractual assurance is established. Option D is wrong because requiring security training and peer review for the mobile app development team, while beneficial, does not address the most critical risk—the unverified cloud provider—and would not be the first priority when the CSP's controls are completely unknown.

115
MCQmedium

A financial services firm has completed a risk assessment and identified that its customer-facing web application has a high risk of SQL injection. The CISO must ensure the risk is treated appropriately. Which of the following should be the FIRST action?

A.Implement a web application firewall (WAF) in front of the application.
B.Immediately patch the application to remove the SQL injection vulnerability.
C.Present the risk to the business owner and obtain a decision on risk treatment.
D.Transfer the risk by purchasing cyber insurance.
AnswerC

Risk treatment decisions should be made by the business owner, not solely by the security team. The CISO's role is to facilitate and ensure that the risk is understood and addressed in line with the organization's risk appetite. Obtaining a formal decision ensures accountability and alignment with business objectives.

Why this answer

The correct answer is to present the risk to the business owner and obtain a decision on risk treatment. In CISM, risk management is a business responsibility, and the CISO facilitates the process. The business owner must decide whether to mitigate, transfer, avoid, or accept the risk, ensuring alignment with organizational risk appetite and objectives.

Exam trap

The trap here is assuming that the CISO should directly implement a technical control without involving the business owner in the risk treatment decision.

116
MCQmedium

A security manager is reviewing the organization's information security strategy and notices that it focuses heavily on technology controls but lacks integration with business processes. Which action should the manager take to improve alignment with business objectives?

A.Increase the budget for security technology to cover more advanced tools
B.Hire additional security staff to monitor and respond to incidents more effectively
C.Conduct a gap analysis to identify where security processes are not integrated with business processes
D.Implement a new security awareness program to educate employees about security policies
AnswerC

A gap analysis will pinpoint specific areas where security is disconnected from business processes, providing a roadmap for integration. It helps the manager understand which business functions lack security considerations and prioritize efforts to embed security into those areas. This approach ensures that security becomes an enabler of business objectives rather than a standalone technical function. The gap analysis should involve stakeholders from both security and business units to ensure comprehensive insights.

Why this answer

Conducting a gap analysis is the most appropriate action because it systematically identifies where security is not integrated with business processes. This understanding enables the manager to develop targeted initiatives to embed security into business operations, ensuring that security supports and enables business objectives. The gap analysis should be collaborative, involving business stakeholders to accurately capture requirements and priorities.

Exam trap

The trap here is opting for more technology, training, or staff when the core issue is a lack of integration between security and business processes.

117
MCQeasy

A newly appointed CISO is reviewing the existing information security program. The program has many documented policies and procedures, but the CISO notices that they have not been updated in over three years. What should the CISO do FIRST?

A.Schedule a management review to approve the existing policies as they are.
B.Immediately rewrite all policies to reflect current best practices.
C.Delegate the policy update task to the security team without further direction.
D.Conduct a gap analysis to determine which policies are outdated and need revision.
AnswerD

A gap analysis will systematically identify which policies are outdated, missing, or misaligned with current business needs and risks. This provides a prioritized list for updates and ensures that revisions are based on actual deficiencies rather than assumptions. It is the logical first step to bring the program up to date efficiently and effectively.

Why this answer

The correct answer is to conduct a gap analysis first. This step identifies which policies are outdated or missing, allowing the CISO to prioritize updates based on risk and business impact. It ensures that subsequent efforts are targeted and justified, rather than a blanket rewrite that could waste resources and still miss critical issues.

Exam trap

The trap here is assuming that updating all policies immediately or delegating without analysis is efficient, when a gap analysis is needed to prioritize and justify changes.

118
MCQhard

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

A.Segregation of duties
B.Access review frequency
C.Provisioning delay
D.Audit log retention
AnswerA

One person approving without oversight is a segregation of duties deficiency.

Why this answer

The finding that 20% of privileged accounts were approved by the same manager without secondary review directly violates the principle of segregation of duties (SoD). In privileged access management (PAM), SoD requires that the approval of privileged account access be performed by a different individual than the requester or the manager who supervises the requester, to prevent a single point of failure and reduce the risk of unauthorized access or fraud. Without a secondary review, a single manager could approve accounts for themselves or their subordinates without independent oversight, undermining the control objective of preventing conflicts of interest.

Exam trap

The CISM exam often tests the distinction between a process control (like requiring a second approver) and a detective control (like access reviews or log retention), and candidates mistakenly choose access review frequency because they think 'review' solves the approval gap, but reviews happen after the fact and cannot prevent the initial improper approval.

How to eliminate wrong answers

Option B (Access review frequency) is wrong because the issue is not about how often access reviews occur (e.g., quarterly or annually), but about the lack of a secondary approval during the initial provisioning process; even frequent reviews would not catch a single manager approving their own accounts without oversight. Option C (Provisioning delay) is wrong because the finding does not relate to the timeliness of account creation or modification; a delay in provisioning does not address the control deficiency of a single manager approving privileged accounts without a second reviewer. Option D (Audit log retention) is wrong because the problem is not about how long logs are kept (e.g., 90 days vs. 1 year), but about the absence of a mandatory secondary approval step; even with perfect log retention, the control deficiency of a single approver remains unaddressed.

119
MCQhard

A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?

A.Conduct a comprehensive asset inventory and vulnerability assessment
B.Purchase and deploy an advanced endpoint detection and response (EDR) solution
C.Translate the board's risk appetite into specific security requirements and objectives
D.Implement a security awareness training program for all employees
AnswerC

The board's risk appetite statement provides the direction for the security program. Translating it into actionable security requirements and objectives ensures that security initiatives are directly linked to business goals and risk tolerance. This step is essential before allocating resources or conducting assessments, as it defines what the program must achieve. It also facilitates communication with stakeholders and helps justify budget requests by showing alignment with business strategy.

Why this answer

The correct answer is to translate the board's risk appetite into specific security requirements and objectives. This step ensures the security program is aligned with business goals and provides a basis for resource allocation, prioritization, and measurement. It bridges the gap between high-level risk tolerance and operational security activities, enabling the CISO to build a program that effectively manages risk in line with the organization's strategic direction.

Exam trap

The trap here is assuming that technical assessments or tool deployments should come first, when strategic alignment must precede tactical execution.

120
MCQhard

After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?

A.Percentage of employees who completed security awareness training
B.Number of security incidents detected and contained within defined SLAs
C.Total cost of security investments compared to industry benchmarks
D.Number of vulnerabilities identified in the latest penetration test
AnswerB

Tracking incidents detected and contained within defined SLAs demonstrates the programme's operational effectiveness, showing both detection capability and response maturity over the year. This metric directly evidences whether controls and processes function as intended, which is what the board needs to assess programme performance.

Why this answer

The most useful metric to demonstrate the effectiveness of an information security program is the number of security incidents detected and contained within defined SLAs. This metric directly measures the program's ability to detect and respond to incidents in a timely manner, which is a key indicator of operational effectiveness. It shows how well the program is performing in real-world scenarios.

Exam trap

CISM often tests the difference between activity-based metrics (e.g., training completion) and outcome-based metrics (e.g., incident containment); candidates may choose activity metrics because they are easier to measure, but effectiveness requires outcome measures.

Why the other options are wrong

A

Training completion is a leading indicator but does not measure program effectiveness in handling incidents.

C

Cost comparison does not indicate how well the program performed.

D

Vulnerability counts are point-in-time and not a comprehensive measure of program effectiveness.

121
MCQeasy

A small e-commerce company with 50 employees and limited IT budget is establishing its first formal information security program. The company processes customer payment data and must comply with PCI DSS. The CEO wants to balance security with operational costs. The IT manager proposes investing in a state-of-the-art security information and event management (SIEM) system costing $100,000 annually. The CISO, however, recommends a more phased approach. Considering the company's size, budget constraints, and compliance requirements, what should be the CISO's primary recommendation?

A.Implement the SIEM system immediately to achieve real-time threat detection.
B.Outsource all security operations to a managed security service provider (MSSP).
C.Develop a custom security software solution tailored to the company's payment processing system.
D.Deploy a firewall, antivirus software, and enforce strong access controls as baseline security measures.
AnswerD

Deploying a firewall, antivirus and strong access controls directly satisfies PCI DSS's foundational requirements while remaining affordable for a 50-employee firm with limited budget. These controls address the realistic threat surface of a small e-commerce operation, unlike a $100,000 SIEM whose monitoring complexity exceeds the company's staffing capacity.

Why this answer

For a 50-person e-commerce company with limited budget and PCI DSS obligations, the CISO should recommend foundational controls first: firewall, antivirus/endpoint protection, and strong access controls. These address the PCI DSS baseline requirements (Req 1, 5, 7, 8) at a fraction of the SIEM cost and deliver immediate risk reduction. A phased approach aligns security investment with maturity and budget, which is the core of the CISO's recommendation.

Exam trap

CISM often tests the temptation to pick the most technically advanced control (SIEM) when the scenario emphasizes budget and maturity — the correct answer is almost always the risk-proportionate, foundational control.

How to eliminate wrong answers

Option A is wrong because a $100,000 annual SIEM is disproportionate to a 50-employee company's budget and maturity; without foundational controls, the SIEM would generate alerts the team cannot triage, and it does not satisfy PCI DSS baseline requirements on its own. Option B is wrong because fully outsourcing security operations to an MSSP is a valid long-term option but not the primary first step — the company still needs internal baseline controls and accountability, and MSSP costs may also exceed budget. Option C is wrong because building custom security software is expensive, slow, and distracts from core business; it is almost never the right first move for a small company.

122
MCQmedium

A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?

A.Number of security incidents detected per month.
B.Estimated financial exposure from unmitigated risks.
C.Percentage of systems patched within 30 days.
D.Hours spent on security training.
AnswerB

Estimated financial exposure translates residual risk into monetary terms, the language executives use for capital allocation decisions. Senior management weighs security investment against potential loss, so quantifying unmitigated risk in financial figures directly satisfies the business-case constraint, unlike technical metrics such as vulnerability counts or control coverage percentages.

Why this answer

Senior management is primarily concerned with financial impact and risk exposure. Estimated financial exposure from unmitigated risks directly translates technical vulnerabilities into monetary terms, enabling informed budget decisions. This aligns with the CISM focus on aligning security programs with business objectives.

Exam trap

ISACA CISM often tests the distinction between operational/technical metrics and business/risk metrics, trapping candidates who confuse activity-based measures (e.g., training hours) with outcome-based financial justification.

How to eliminate wrong answers

Option A is wrong because the number of incidents detected per month is an operational metric that does not convey financial risk or business impact; it can even be misleading if detection capabilities improve. Option C is wrong because patch compliance percentage is a tactical, IT-focused metric that does not quantify residual risk or financial exposure to the organization. Option D is wrong because hours spent on training is an activity metric, not an outcome metric; it measures effort rather than risk reduction or financial benefit.

123
Multi-Selectmedium

Which of the following are essential components of an information security program governance framework? (Select TWO.)

Select 2 answers
A.A security steering committee with executive representation.
B.A formal risk appetite statement.
C.Documented information security policies and procedures.
D.An incident response plan.
AnswersA, C

Why this answer

A security steering committee with executive representation is essential because it provides strategic oversight, aligns security initiatives with business objectives, and ensures resource allocation and governance accountability. This committee typically includes C-level executives who approve security policies, review risk posture, and enforce compliance across the organization.

Exam trap

ISACA often tests the distinction between governance components (steering committee, policies) and operational or risk management artifacts (risk appetite statement, incident response plan), leading candidates to select familiar but incorrect operational items.

Why the other options are wrong

B

Risk appetite is part of risk management, not governance framework per se.

D

Operational plan, not a governance component.

124
MCQhard

During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?

A.Non-compliance with regulatory requirements
B.Higher financial costs due to inefficiencies
C.Increased recovery time after an incident
D.Ineffective response leading to greater damage during an incident
AnswerD

Untested procedures mean responders lack validated playbooks, so containment, eradication and recovery actions may be improvised or delayed. The stem's two-year gap directly produces prolonged attacker dwell time and greater damage during a live incident.

Why this answer

The most significant risk of not testing incident response procedures for over two years is that the response will be ineffective when a real incident occurs, leading to greater damage, longer downtime, and potentially uncontrolled escalation. Untested procedures may contain outdated contacts, incorrect escalation paths, or missing steps, so the organization cannot rely on them. While compliance and cost are concerns, the primary security risk is the inability to contain and recover effectively, which directly increases business impact.

Exam trap

CISM often tests the distinction between compliance risk and operational risk; candidates may pick 'non-compliance' because it sounds like an audit finding, but the MOST significant risk is always the actual security impact of an ineffective response.

How to eliminate wrong answers

Option A is wrong because non-compliance with regulatory requirements is a secondary concern; the question asks for the MOST significant risk, which is the operational failure to respond effectively, not the regulatory penalty. Option B is wrong because higher financial costs due to inefficiencies are a downstream consequence, not the primary risk; the core issue is the compromised ability to respond. Option C is wrong because increased recovery time is a symptom of ineffective response, but the broader and more severe risk is the overall ineffectiveness leading to greater damage, which encompasses recovery time and more.

125
MCQmedium

An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?

A.Percentage of employees who completed the training.
B.Number of security incidents caused by human error.
C.Average score on post-training tests.
D.Time taken to complete the training modules.
AnswerB

Human-error incident counts directly measure whether awareness training changed behaviour, since reduced incidents indicate improved security culture. This outcome-based metric reflects training effectiveness better than completion rates or quiz scores, which only show attendance rather than real-world impact.

Why this answer

The most appropriate metric for measuring the effectiveness of security awareness training is the reduction in security incidents caused by human error. While completion rates and test scores measure participation and knowledge retention, they do not directly indicate whether the training has changed employee behavior and reduced real-world risk. A decrease in human-error-related incidents provides direct evidence that the training is effectively influencing secure practices.

Exam trap

The trap here is that candidates often confuse training completion or test scores with effectiveness, but CISM emphasizes outcome-based metrics that demonstrate actual risk reduction, not just activity completion.

Why the other options are wrong

A

Completion does not measure learning or behavior change.

C

Test scores measure knowledge retention, but not application in real situations.

D

Time is irrelevant to effectiveness; fast completion may indicate skipping content.

126
Multi-Selectmedium

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Select 3 answers
A.Legal and regulatory requirements across jurisdictions
B.Current technology architecture
C.Business strategy and objectives
D.Organizational culture and risk appetite
AnswersA, C, D

Why this answer

Legal and regulatory requirements across jurisdictions are foundational because a multinational organization must comply with diverse data protection laws (e.g., GDPR in Europe, CCPA in California, LGPD in Brazil) that directly dictate security controls, breach notification timelines, and data residency rules. The governance structure must incorporate these obligations to avoid legal penalties and ensure consistent policy enforcement across borders.

Exam trap

ISACA often tests the distinction between governance (strategy, culture, compliance) and management (architecture, tools, implementation), leading candidates to mistakenly select technology architecture as a governance factor.

Why the other options are wrong

B

Technology architecture is an operational concern, not governance.

127
MCQmedium

A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?

A.Adopt ISO 27001 as the sole framework for the program.
B.Implement a regulatory compliance framework that maps controls to applicable laws and standards.
C.Comply with the strictest regulation and ignore others.
D.Engage external legal counsel to review policies quarterly.
AnswerB

A mapped framework consolidates overlapping obligations into one control set, letting the programme satisfy multiple jurisdictions without duplicated effort. This directly addresses the cross-jurisdiction regulatory requirement by tracing each control to the specific laws and standards that mandate it.

Why this answer

A regulatory compliance framework that maps controls to applicable laws and standards provides a structured, auditable method to address multiple, sometimes conflicting, jurisdictional requirements. This approach ensures that each control is explicitly linked to a specific legal or regulatory obligation, facilitating compliance verification and reducing the risk of oversight. It is the most comprehensive and adaptable method for a multi-jurisdictional environment, as it allows the organization to manage overlapping and unique requirements without relying on a single standard or external review alone.

Exam trap

A common mistake in CISM is assuming that adopting a single, comprehensive standard like ISO 27001 is sufficient for multi-jurisdictional compliance, when in reality it must be supplemented with a mapping framework to address specific legal requirements.

How to eliminate wrong answers

Option A is wrong because adopting ISO 27001 as the sole framework does not guarantee compliance with specific jurisdictional laws (e.g., GDPR, HIPAA, PCI DSS) that have unique requirements beyond the general controls of ISO 27001; it provides a management system but not a direct mapping to each regulation. Option C is wrong because complying with the strictest regulation and ignoring others can lead to non-compliance with laws that have different or additional requirements not covered by the strictest one, such as data localization rules in one jurisdiction that are not addressed by another's stricter privacy law. Option D is wrong because engaging external legal counsel to review policies quarterly is a reactive, periodic check that does not provide a continuous, integrated framework for managing and demonstrating compliance across multiple jurisdictions; it lacks the proactive control mapping and ongoing governance needed for a comprehensive program.

128
MCQmedium

An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?

A.Setting the organization's risk appetite
B.Designing and managing the security program
C.Owning all information security risks
D.Conducting internal audits of controls
AnswerB

The information security manager owns the programme's design and day-to-day management, translating the risk management framework into controls, processes and reporting. This satisfies the stem's requirement to define the role within a framework-based programme, since execution and maintenance of security activities sit with management rather than the board or risk committee.

Why this answer

The information security manager is responsible for designing and managing the security program based on the risk management framework. This includes translating risk assessment results into security controls, policies, and procedures, and ensuring the program aligns with the organization's risk posture. The manager does not set risk appetite (that is a board-level decision) nor own all risks (risk owners are business process owners).

Exam trap

The trap here is confusing the information security manager's operational role with strategic or assurance roles, leading candidates to select 'setting risk appetite' or 'conducting internal audits' instead of the correct program management function.

Why the other options are wrong

A

Risk appetite is set by the board of directors, not the security manager.

C

Risk ownership resides with business process owners; the security manager facilitates risk management.

D

Internal audits are performed by audit function, not security management.

129
MCQhard

A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?

A.Implement a unified privacy framework covering all regulations
B.Adopt the most restrictive requirements from any regulation
C.Outsource compliance to a third-party provider
D.Create separate security programs for each region
AnswerA

A unified privacy framework maps overlapping GDPR and CCPA obligations onto shared controls, avoiding duplicated or conflicting processes across jurisdictions. This satisfies the stem's multinational compliance constraint by establishing common data-subject rights, retention and breach-notification procedures that can be extended to additional regulations as they emerge.

Why this answer

A unified privacy framework (e.g., ISO/IEC 27701 or NIST Privacy Framework) allows the organization to map overlapping requirements from GDPR and CCPA into a single set of controls, reducing duplication and ensuring consistent data protection across jurisdictions. This approach leverages common principles like data minimization, consent management, and breach notification, which are foundational to both regulations, while accommodating specific differences such as GDPR's 72-hour breach notification versus CCPA's broader definition of personal information.

Exam trap

ISACA often tests the misconception that 'most restrictive' is always best, but the trap here is that regulatory compliance requires a tailored, risk-based approach rather than a blanket adoption of the strictest rule, which can lead to inefficiency and non-compliance with specific regional obligations.

How to eliminate wrong answers

Option B is wrong because adopting the most restrictive requirements from any regulation (e.g., GDPR's stricter consent rules) may impose unnecessary operational overhead and cost without addressing unique CCPA obligations like the right to opt out of data sales, leading to compliance gaps. Option C is wrong because outsourcing compliance to a third-party provider transfers accountability but not liability; the organization remains legally responsible under both GDPR (Article 28) and CCPA (Section 1798.140) for data processing activities, and a third party cannot fully manage internal security program governance. Option D is wrong because creating separate security programs for each region introduces fragmentation, increasing complexity and risk of inconsistent data handling, which contradicts the principle of a unified information security program and may violate GDPR's requirement for a single Data Protection Officer (DPO) overseeing cross-border operations.

130
MCQmedium

A mid-sized financial services firm has a newly appointed CISO. The board has asked for assurance that the information security program aligns with the organization's strategic goals and risk appetite. The CISO needs to establish a governance structure that provides ongoing oversight and ensures security decisions are made at the right level. Which of the following should the CISO implement FIRST?

A.A security steering committee composed of senior business and IT leaders that meets regularly to review security strategy, risk, and performance.
B.A comprehensive penetration test of all external-facing applications to identify vulnerabilities.
C.A detailed security awareness training program for all employees to reduce human risk.
D.A new security incident response plan that defines roles and responsibilities for handling breaches.
AnswerA

A security steering committee with senior business and IT leaders provides the necessary governance linkage between the security program and business strategy. It ensures that security decisions consider business objectives and risk appetite, and it gives the CISO a forum to report on program performance and escalate issues. This structure directly addresses the board's request for assurance and ongoing oversight, making it the foundational first step.

Why this answer

Establishing a security steering committee with senior business and IT leaders is the foundational governance step. It creates a direct link between the security program and business strategy, ensures security decisions are made at the appropriate level, and provides ongoing oversight. This structure enables the CISO to align security initiatives with the organization's risk appetite and gives the board the assurance they are seeking.

Exam trap

The trap here is focusing on tactical security activities like penetration testing or training instead of recognizing that the board's request for strategic alignment and oversight requires a governance structure first.

131
Multi-Selecthard

A CISO is establishing a security metrics program to measure the effectiveness of the information security program. The CISO wants to include both key goal indicators (KGIs) and key performance indicators (KPIs). Which of the following are examples of KGIs? (Choose two.)

Select 2 answers
A.Percentage of critical vulnerabilities remediated within 30 days.
B.Mean time to detect (MTTD) security incidents.
C.Percentage of employees who completed security awareness training.
D.Achievement of ISO/IEC 27001 certification within the planned timeframe.
E.Reduction in the number of successful security breaches year-over-year.
AnswersD, E

Achieving ISO/IEC 27001 certification is a KGI because it represents the accomplishment of a strategic goal. It is an outcome that the security program aimed to achieve. KGIs are used to track progress toward high-level objectives. Certification demonstrates that the program has met a recognized standard, which is a goal in itself. It is not a process performance measure but a milestone.

Why this answer

KGIs measure the achievement of strategic goals and outcomes, while KPIs measure the performance of processes. A reduction in successful breaches indicates that the goal of preventing breaches is being met, and achieving ISO/IEC 27001 certification represents the accomplishment of a strategic objective. The other options are process-oriented metrics that track efficiency or activity, not goal attainment.

Thus, the two KGIs are the breach reduction and certification achievement.

Exam trap

The trap here is confusing process metrics (KPIs) with outcome metrics (KGIs); many security metrics are KPIs, so it's easy to misclassify them.

132
MCQhard

A global financial services firm has a mature information security program with policies, standards, and procedures aligned to ISO/IEC 27001. The CISO is preparing for the annual management review of the program. The board has asked for assurance that the program remains effective as the threat landscape and business strategy evolve. Which activity BEST provides this assurance?

A.Increasing the security awareness training frequency and tracking completion rates across all business units.
B.Conducting a penetration test of all externally facing applications and reporting the number of critical findings.
C.Reviewing the results of independent audits, control testing, and metrics against program objectives to evaluate effectiveness.
D.Updating the information security policy to reflect the latest regulatory changes and obtaining executive sign-off.
AnswerC

This activity directly supports the management review requirement by consolidating independent assurance sources and performance metrics to evaluate whether the program meets its objectives. It considers governance, risk, and control effectiveness over time, providing the board with a holistic view. This aligns with CISM guidance on monitoring and reporting program effectiveness to stakeholders.

Why this answer

The board requires assurance that the program remains effective amid evolving threats and business strategy. Independent audits, control testing, and metrics provide objective, ongoing evidence of effectiveness across governance, risk, and controls. This integrated view supports informed management review and strategic decision-making, which is the core purpose of monitoring and reporting program performance.

Exam trap

The trap here is assuming that a technical activity such as penetration testing or awareness training alone constitutes sufficient evidence of program effectiveness for executive management.

133
MCQeasy

A CISO is establishing an information security governance framework. The organization operates in multiple countries with varying data protection laws. Which of the following should be the PRIMARY consideration when developing security policies?

A.Implementing a single global policy that meets the minimum legal requirements.
B.Adopting the strictest regulatory requirements across all jurisdictions.
C.Allowing each country to develop its own security policies independently.
D.Deferring to the legal department to determine policy requirements.
AnswerB

Adopting the strictest requirements ensures compliance in all jurisdictions and simplifies policy management. It may be more costly but reduces legal risk and demonstrates a strong commitment to data protection. This approach aligns with the goal of a unified governance framework that can be applied globally, avoiding conflicts between different legal standards.

Why this answer

Adopting the strictest regulatory requirements across all jurisdictions is the primary consideration because it ensures compliance everywhere and provides a consistent baseline for security policies. This approach avoids the complexity of managing multiple policy sets and reduces the risk of non-compliance in any location, supporting a robust governance framework.

Exam trap

The trap here is thinking that minimum legal requirements or per-country policies are sufficient, but they can lead to compliance gaps and inconsistent security, which undermines governance.

134
MCQhard

A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?

A.Develop three separate control sets for each regulation
B.Focus only on the requirements of the strictest regulation
C.Implement a single control set mapped to all applicable regulations
D.Engage external auditors to manage compliance for each regulation
AnswerC

A single unified control set mapped to PCI DSS, GDPR and SOX lets one implementation satisfy overlapping obligations, avoiding duplicated effort and evidence collection. Mapping each framework separately multiplies audit work and creates conflicting control definitions.

Why this answer

Implementing a single control set mapped to all applicable regulations (PCI DSS, GDPR, SOX) leverages common controls to satisfy overlapping requirements efficiently. This approach reduces duplication of effort, simplifies audit preparation, and ensures consistent security posture across the organization. For example, access control requirements under PCI DSS 7.1, GDPR Article 32, and SOX Section 404 can be addressed by a unified identity and access management (IAM) policy with role-based access controls (RBAC) and logging.

Exam trap

The trap here is that candidates may think focusing on the strictest regulation (Option B) is efficient, but they overlook that each regulation has unique non-overlapping requirements (e.g., GDPR's breach notification timeline vs. PCI DSS's quarterly scans) that must be addressed separately.

How to eliminate wrong answers

Option A is wrong because developing three separate control sets for each regulation leads to redundant work, increased complexity, and potential conflicts between controls, wasting resources without improving security. Option B is wrong because focusing only on the strictest regulation (e.g., PCI DSS) may miss unique requirements from other regulations (e.g., GDPR's data subject rights or SOX's financial reporting controls), causing non-compliance. Option D is wrong because engaging external auditors to manage compliance for each regulation does not address the underlying need for an efficient internal control framework; it outsources responsibility without resolving overlapping requirements and can be cost-prohibitive.

135
MCQhard

An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?

A.Revise the data classification policy to simplify categories.
B.Conduct random audits and reprimand employees who misclassify data.
C.Increase the frequency of data classification training for all employees.
D.Deploy a data loss prevention (DLP) system that automatically classifies documents based on content inspection.
AnswerD

Content inspection detects PII patterns such as national insurance numbers or payment card data, then applies the correct classification label automatically, removing reliance on employee judgement. This directly satisfies the stem's constraint: staff mislabel PII documents as 'internal use only'. DLP enforces classification at creation, closing the human error gap.

Why this answer

Deploying a data loss prevention (DLP) system that automatically classifies documents based on content inspection directly addresses the root cause of misclassification by removing reliance on user judgment. Option A (policy revision) alone does not enforce compliance. Option B (audits and reprimands) is punitive and may not change behavior.

Option C (training) can help but is less effective than automation for consistent classification.

136
MCQhard

During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?

A.Justify the existing objectives to management to demonstrate their value.
B.Revise the program objectives to align with business goals.
C.Implement additional security controls to compensate for the misalignment.
D.Escalate the issue to the board of directors without changes.
AnswerB

Revising the program objectives directly resolves the misalignment identified in the review, ensuring security strategy supports the organisation's strategic business goals. Governance frameworks such as COBIT require security to cascade from business objectives, so realigning objectives restores that linkage and enables meaningful risk-based decision-making.

Why this answer

The CISM framework emphasizes that an information security program must be directly aligned with the organization's strategic business goals to ensure that security investments support business objectives rather than hinder them. Revising the program objectives to align with business goals (Option B) is the correct course of action because it ensures that security controls, risk appetite, and resource allocation are driven by business needs, not isolated technical requirements. This alignment is a core principle of the Information Security Program domain, as misalignment can lead to wasted resources, reduced executive support, and increased business risk.

Exam trap

ISACA often tests the misconception that adding more controls or escalating issues can substitute for strategic alignment, but the CISM exam specifically requires candidates to recognize that program objectives must be revised to match business goals before any other action is taken.

Why the other options are wrong

A

This does not address the misalignment; the objectives should be revised to match business goals.

C

Adding controls does not fix the strategic misalignment.

D

Escalation is not the first step; the manager should propose a solution.

137
Multi-Selecthard

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to senior management. Which of the following are characteristics of effective security metrics? (Choose two.)

Select 2 answers
A.They are focused on technical vulnerabilities.
B.They are based on the number of security incidents.
C.They are directly linked to business objectives.
D.They are consistently measurable over time.
E.They are updated in real time.
AnswersC, D

Effective security metrics must align with business objectives to demonstrate value. For example, a metric showing reduced downtime from security incidents directly supports business continuity goals. When metrics are tied to business outcomes, senior management can see how security contributes to the bottom line, making it easier to justify investments and prioritize initiatives.

Why this answer

Effective security metrics are directly linked to business objectives and are consistently measurable over time. These characteristics ensure that metrics demonstrate how security supports the organization's strategic goals and allow for trend analysis and benchmarking. They provide senior management with meaningful information to make informed decisions about the security program.

Exam trap

The trap here is assuming that incident counts or technical vulnerabilities are sufficient, when effective metrics must align with business goals and be consistently measured.

138
Multi-Selecteasy

Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?

Select 3 answers
A.Risk assessment
B.Strategy alignment with business objectives
C.Monitoring and review
D.Implementation of controls
E.Policy development
AnswersA, B, E

Risk assessment is foundational to planning.

Why this answer

Risk assessment is a core component of the Plan phase in the ISO 27001 PDCA (Plan-Do-Check-Act) security program lifecycle. During this phase, the organization identifies, analyzes, and evaluates information security risks to establish the context, scope, and risk treatment criteria that will guide the selection of controls and objectives. Without a formal risk assessment, the subsequent phases lack a risk-based foundation, making the program reactive rather than proactive.

Exam trap

The trap here is that candidates often confuse the Plan phase with the Do phase, incorrectly selecting 'Implementation of controls' (Option D) because they assume planning includes deploying controls, whereas in the PDCA model, implementation is strictly a Do-phase activity.

139
Multi-Selectmedium

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Select 2 answers
A.A steering committee that includes senior management and business unit leaders.
B.An incident response plan that defines roles and procedures.
C.Regular reporting to the board of directors on security metrics and risks.
D.A vulnerability scanning schedule and remediation SLAs.
E.A firewall policy that specifies allowed and denied traffic.
AnswersA, C

A steering committee ensures alignment with business strategy and provides oversight.

Why this answer

A steering committee that includes senior management and business unit leaders is a key component of an information security program governance structure because it provides strategic oversight, aligns security initiatives with business objectives, and ensures accountability at the executive level. This committee typically authorizes policies, reviews risk appetite, and approves resource allocation, which are essential for effective governance.

Exam trap

ISACA often tests the distinction between governance (strategic oversight and decision-making) and management (operational execution and controls), so candidates mistakenly select operational items like incident response plans or vulnerability schedules as governance components.

← PreviousPage 2 of 2 · 139 questions total

Ready to test yourself?

Try a timed practice session using only Cism Security Program questions.