Courseiva
Information Security ProgramhardMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

You are the CISO of a large healthcare organization that has recently experienced a data breach due to an insider who exfiltrated patient data over several months. The breach was discovered by an external partner. The organization's information security program includes data loss prevention (DLP) tools, but they were not configured to monitor outbound data from the compromised system. Additionally, user activity monitoring (UAM) was only applied to privileged users, not to regular staff. The board demands a comprehensive improvement plan that will prevent similar incidents. However, there are concerns about employee privacy and budget constraints. The organization has a strong culture of trust and minimal monitoring. Which of the following should be the first priority in the revised program?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Expand user activity monitoring to all employees with a clear policy on privacy and acceptable use.

Expanding user activity monitoring (UAM) to all users directly addresses the monitoring gap that allowed the exfiltration to go undetected for months. Implementing a clear policy on privacy and acceptable use balances security needs with employee privacy concerns. Option B (stricter access controls) is insufficient alone as it does not detect ongoing data exfiltration. Option C (new DLP solution) could be helpful but may not catch slow, low-volume exfiltration and does not address the monitoring gap. Option D (security awareness training) is important but is a long-term preventive measure and does not immediately close the detection gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Expand user activity monitoring to all employees with a clear policy on privacy and acceptable use.

    Why this is correct

    Detects anomalous behavior; privacy guidelines address concerns.

  • Implement stricter access controls and review user permissions quarterly.

    Why it's wrong here

    Access controls reduce risk but do not detect malicious activity already permitted.

  • Deploy a new DLP solution with advanced analytics and block all external data transfers.

    Why it's wrong here

    DLP is important but may not detect all exfiltration methods; blocking could impact operations.

  • Conduct additional security awareness training focused on insider threats.

    Why it's wrong here

    Training may not deter determined insiders and does not provide detection.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.