CISM Information Security Programme Practice Question
Which of the following best describes the role of a security architect in a security program?
⚠ Common exam trap
CISM often tests the distinction between strategic/design roles (architect) and operational/tactical roles (SOC analyst, pentester, awareness trainer).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Designs security controls and integrates them into IT systems
A security architect's core responsibility is designing security controls and integrating them into IT systems — translating business and compliance requirements into technical architectures, frameworks, and control designs. This is a design and strategy role, distinct from operational or testing functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Designs security controls and integrates them into IT systems
Why this is correct
Security architects translate policy and risk requirements into technical control designs, then integrate those controls into system and network architectures. This satisfies the stem by distinguishing the role from governance-focused or operational roles, which respectively set policy or run controls rather than design their technical implementation.
- ✗
Performs penetration testing to identify vulnerabilities
Why it's wrong here
Penetration testing is performed by offensive security or assessment specialists who exploit vulnerabilities under scope; an architect designs defensive architecture and control requirements. It is tempting because architects review test findings and threat models, and it would be correct for a role whose deliverable is exploitation evidence and remediation reporting.
- ✗
Develops and delivers security awareness training
Why it's wrong here
Security awareness training is the remit of the security awareness or training function, which designs campaigns and measures user behaviour; an architect defines control frameworks and reference designs. It is tempting because architects often contribute content, and it would be correct for a role whose primary deliverable is user education and phishing simulation.
- ✗
Monitors security alerts and responds to incidents
Why it's wrong here
Alert monitoring and incident response belong to the SOC or incident response function, which triages detections and contains threats; an architect designs the logging and detection architecture those teams consume. It is tempting because architects specify monitoring controls, and it would be correct for an analyst role handling live security events.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.