easyMultiple SelectObjective-mapped
CISM Practice Question: Which TWO of the following are primary objectives…
Which TWO of the following are primary objectives of information security governance? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse compliance (Option E) with governance, but CISM emphasizes that governance is about strategic alignment and accountability, not just meeting regulatory checklists, which is a common misconception in exam questions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Align security strategy with business goals.
Information security governance's primary objective is to ensure that security strategy is aligned with business goals, enabling the organization to protect assets while supporting its mission. This alignment is achieved through governance frameworks like COBIT or ISO 38500, which mandate that security investments and controls are directly tied to business objectives, not isolated technical measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eliminate all information security risks.
Why it's wrong here
Risk elimination is impossible; governance manages risk.
- ✓
Align security strategy with business goals.
Why this is correct
Core objective of governance.
- ✗
Maximize profitability through security investments.
Why it's wrong here
Profit is a business goal, not governance objective.
- ✓
Ensure accountability for security decisions.
Why this is correct
Essential governance objective.
- ✗
Achieve compliance with all applicable regulations.
Why it's wrong here
Compliance is a requirement, but not the primary objective of governance.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.