Courseiva

CISM Information Security Programme Practice Question

Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security architect

The security architect designs and reviews the security architecture, ensuring it meets business needs and security requirements. Other roles focus on operations, analysis, or awareness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SOC analyst

    Why it's wrong here

    A SOC analyst performs real-time monitoring, alert triage and incident escalation within the SOC; architecture design and standards alignment is the security architect's remit. SOC analyst is the right choice when the question concerns detection, response or shift-based monitoring duties.

  • ✗

    GRC analyst

    Why it's wrong here

    A GRC analyst maps controls to frameworks, assesses risk and tracks compliance evidence; architecture design and review sits with the security architect. GRC work is the right answer when the question asks who owns policy alignment, risk registers or audit readiness rather than technical design.

  • ✓

    Security architect

    Why this is correct

    The security architect designs and reviews security architectures, ensuring controls align with business requirements and security standards. This satisfies the stem's requirement for the role primarily accountable for architectural design and review, distinguishing it from operational roles such as analysts or administrators who implement and monitor rather than design.

  • ✗

    Security analyst

    Why it's wrong here

    A security analyst monitors alerts, triages incidents and analyses threats; designing and reviewing security architectures against business requirements belongs to the security architect. Security analyst is correct when the task is operational detection, investigation or reporting rather than architecture governance.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.