Courseiva

CISM · topic practice

Information Security Programme practice questions

This domain covers building, governing and operating the information security programme: strategy, frameworks, control prioritisation, budget justification, roles and awareness. Questions are scenario-based, asking you to pick the FIRST or BEST action for a security manager, weighing business alignment, risk, resource limits and defence-in-depth sequencing over technical tooling detail.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Security Programme

What the exam tests

What to know about Information Security Programme

You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.

Selecting control implementation groups and prioritising safeguards against ransomware exposure with limited resources

Applying defence-in-depth sequencing to framework adoption and control prioritisation decisions

Defining the purpose of a security champions programme in embedding security across business teams

Justifying security budget increases using risk reduction and business value metrics

Why learners struggle

Why Information Security Programme questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Information Security Programme exam traps

  • ▸Choosing the most technically complete control set instead of the FIRST priority given resource constraints and threat exposure.
  • ▸Treating security champions as a technical escalation team rather than business-side advocates who extend the security function.
  • ▸Justifying budget with fear, compliance mandates or incident anecdotes instead of quantified risk reduction and business alignment.

Practice set

Information Security Programme questions

20 questions · select your answer, then reveal the explanation

Which TWO budget components are considered 'services' in a typical security budget?

An organization's security budget is 12% of the IT budget. Which of the following best describes the maturity of this security program?

A CISO is evaluating security metrics for reporting to the board. Which TWO of the following are leading indicators?

A security architect is designing a defense-in-depth strategy. Which combination of controls best exemplifies this approach?

A CISO is preparing the security budget for the next fiscal year. The current IT budget is $10 million. For a mature security program, what is the recommended security budget range?

Which metric is considered a lagging indicator of security program performance?

An organization is redesigning its information security program to better align with business objectives. The CISO reports to the CIO, but business leaders feel security decisions are too IT-centric. Which reporting structure would best address this concern?

A security manager is developing metrics for the C-suite dashboard. Which combination of metrics would provide the best view of security program effectiveness, including both leading and lagging indicators?

During a third-party risk assessment, the security team discovers that a critical vendor has subcontracted data processing to another company without notification. This represents which type of risk?

An organization wants to implement a defense-in-depth strategy for its web application. Which set of controls best exemplifies this approach?

A security manager needs to justify an increase in the security budget to the board. The current budget is 0.15% of revenue. Which approach would most effectively demonstrate the need for additional funding?

Which THREE components are essential for a comprehensive third-party risk management (TPRM) program?

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

A security manager is developing metrics for the executive dashboard. Which combination of metrics provides a balanced view of security program performance?

A CISO wants to present a high-level security status to the board using a one-page dashboard. Which of the following metrics is MOST appropriate for this audience?

Which of the following is a leading indicator of security program effectiveness?

In a security operations center (SOC), which function is PRIMARILY responsible for analyzing alerts and determining whether they represent actual security incidents?

An organization uses ISO 27001 Annex A as its control framework. During a risk assessment, a control weakness is identified that could lead to a high-impact data breach. However, implementing the recommended control is cost-prohibitive. Which approach BEST addresses this situation?

A security manager is designing a metrics dashboard for the CISO. Which TWO metrics are leading indicators of security performance? (Select TWO)

Which of the following is a leading indicator of security program effectiveness?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Security Programme sessions

Start a Information Security Programme only practice session

Every question in these sessions is drawn from the Information Security Programme domain — nothing else.

Related practice questions

Related CISM topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISM exam test about Information Security Programme?
You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Security Programme questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Security Programme domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISM topics?
Use the topic links above to move to related areas, or go back to the CISM question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISM exam covers. They are not copied from any real exam or dump site.