Courseiva
hardMultiple SelectObjective-mapped

CISM Practice Question: Which TWO of the following are key…

Which TWO of the following are key responsibilities of an information security governance committee?

⚠ Common exam trap

A common mix-up: candidates confuse governance-level responsibilities (policy approval, strategy review) with operational or tactical tasks (vulnerability assessments, daily monitoring), or they mistakenly assign risk appetite setting to the governance committee instead of the board of directors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Approve major changes to information security policies.

The information security governance committee is a high-level body responsible for strategic oversight. Approving major changes to information security policies (Option C) is a core governance function, ensuring that policy updates align with business objectives and regulatory requirements before implementation. This is distinct from operational tasks like vulnerability assessments or daily monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform vulnerability assessments on critical systems.

    Why it's wrong here

    Technical assessments are not a governance committee responsibility.

  • Set the organization's risk appetite.

    Why it's wrong here

    Risk appetite is set by the board of directors.

  • Approve major changes to information security policies.

    Why this is correct

    Policy approval is a key governance function.

  • Review and approve the information security strategy.

    Why this is correct

    The committee provides strategic direction.

  • Conduct daily monitoring of security events.

    Why it's wrong here

    This is an operational task, not governance.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.