Certified Information Security Manager CISM Exam Questions & Answers

Practice 131 free Certified Information Security Manager CISM exam questions with answers and community-discussed explanations. Each question has its own page where you can reveal the correct answer and debate it in the comments.

All 131 questions

  1. Q1 Under what circumstances would an organization elect to disregard a regulation and pay fines instead of complying?
  2. Q2 An auditor is examining a network schematic for a typical remote business location. What kind of a document is the auditor viewing?
  3. Q3 Younger employees in an organization often log in to social media sites during working hours. How should the organization respond?
  4. Q4 An organization has published a document describing the configuration settings for mobile devices. This is an example of a:
  5. Q5 What type of attack involves obtaining high-level system authority through unauthorized methods?
  6. Q6 You are the Information Security Manager of HDA Inc. You are tasked with proactively preventing the exploitation of vulnerabilities in operating system…
  7. Q7 During which phase of the system development life cycle (SDLC) are access control and encryption algorithms selected?
  8. Q8 You are the Information Security Manager of HDA Inc. You are tasked with ensuring data protection upon the termination of an employee's…
  9. Q9 You are the Information Security Manager of HDA Inc. You are addressing considerations for the retention of business records. You are the…
  10. Q10 All of the following methods should be used to train incident responders except which one?
  11. Q11 Which authentication factor is represented by a fingerprint scan?
  12. Q12 Recovery time objectives (RTOs) result from which of the following processes?
  13. Q13 What risk does an organization face if it is not compliant with an applicable cybersecurity regulation?
  14. Q14 When creating a backup plan aligned with a disaster recovery strategy, what is the main consideration to be taken into account?
  15. Q15 Which authentication factor is represented by a smart card?
  16. Q16 What is the MAIN advantage of incorporating information security risk into enterprise risk management?
  17. Q17 What is a key benefit of implementing a security information and event management (SIEM) system?
  18. Q18 A security manager wants to enact several strategic improvements in the organization and needs to sell these ideas to executives. What type…
  19. Q19 What is the primary factor an information security manager should assess when selecting controls to counteract emerging threat vectors?
  20. Q20 You are the Information Security Manager of HDA Inc. You want to assess the effectiveness of security controls in your organization. What…
  21. Q21 You are the Information Security Manager of HDA Inc. You are tasked with establishing guidelines for the use of social networking sites…
  22. Q22 You are the Information Security Manager of HDA Inc. What is the MAIN objective of providing senior management with a regular threat…
  23. Q23 A CISO considers the use of artificial intelligence (AI) in future security solutions for all of the following reasons except which one?
  24. Q24 A security governance council is unable to assign an owner to a specific risk. How should the council proceed?
  25. Q25 When preparing for a disaster recovery test, what is the utmost important factor for you to consider?
  26. Q26 Software developers should receive security training in all of the following subjects except which one?
  27. Q27 You are the Information Security Manager of HDA Inc. You want to implement an effective method to detect an intruder who has…
  28. Q28 What assumption can a CISO make about a third-party service provider that has returned a security questionnaire and responded “yes” to every…
  29. Q29 How can an organization best ensure the effectiveness of its incident response evaluation process?
  30. Q30 What kind of a document should a CISO produce that will inform business executives of the security team’s capabilities?
  31. Q31 Which encryption standard is considered the strongest for wireless networks?
  32. Q32 What distinguishes double blind testing from blind testing in penetration testing?
  33. Q33 What is the purpose of knowing the financial health of a service provider?
  34. Q34 You are the Information Security Manager of HDA Inc. You are tasked with establishing an information security program. What should be the…
  35. Q35 You are the Information Security Manager of HDA Inc. You are tasked with presenting the goals and advantages of the information security…
  36. Q36 What role does an Information Security Manager play in incident response?
  37. Q37 Which of the following documents is considered optional guidance?
  38. Q38 What is the purpose of forensic analysis tools?
  39. Q39 What is the best way to process a risk in the risk treatment phase?
  40. Q40 Typical requirements for a security awareness program include all of the following except which one?
  41. Q41 In the context of information risk management, what is the FIRST step an organization should take?
  42. Q42 In a properly functioning risk management program, which party assumes cyber risk?
  43. Q43 What is the PRIMARY result to prioritize from vulnerability scanning among the options provided?
  44. Q44 What is a key metric for evaluating the success of a recovery plan during testing?
  45. Q45 In the development of a long-term strategy, a security manager should consider all of the following external factors except which one?
  46. Q46 You are the Information Security Manager of HDA Inc. You are evaluating security measures related to personnel. Making it mandatory for all…
  47. Q47 What is the purpose of classifying third parties according to risk level?
  48. Q48 You are the Information Security Manager of HDA Inc. You need to minimize the risk of an attacker altering a message and…
  49. Q49 All of the following personnel should attend a post-incident review except which one?
  50. Q50 When choosing a third-party vendor for security services, what is the most critical risk management consideration?
  51. Q51 Security architecture is primarily concerned with:
  52. Q52 How would the emergence of ransomware impact an organization’s incident response plan?
  53. Q53 How is GDPR likely to affect online retail organizations?
  54. Q54 Who should approve access requests to a particular application that stores and processes customer information?
  55. Q55 What is the MOST suitable change management process for managing emergency program changes?
  56. Q56 A security manager is developing a long-term security strategy and examines a security policy on the topic of access management that was…
  57. Q57 A company is experiencing frequent data breaches due to insufficient configuration management in their IT environment. Which of the following actions should…
  58. Q58 What is the MOST effective means to safeguard against the disclosure of data?
  59. Q59 You are the Information Security Manager of HDA Inc. You are evaluating adherence to the "separation of duties" principle. Which of the…
  60. Q60 You are the Information Security Manager of HDA Inc. You need to provide senior management with the most compelling evidence of the…
  61. Q61 You are the Information Security Manager of HDA Inc. You want to assess the effectiveness of the security procedures within your organization.…
  62. Q62 For an organization that outsources its payroll processing, what is the MOST effective key risk indicator to monitor the information security of…
  63. Q63 Which of the following is NOT a characteristic of a strong password?
  64. Q64 What is the PRIMARY objective of information security governance?
  65. Q65 You are the Information Security Manager of HDA Inc. You are focused on establishing an effective approach to ensure that management takes…
  66. Q66 You are the Information Security Manager of HDA Inc. What is the MOST efficient method for disseminating general information security responsibilities throughout…
  67. Q67 What strategic approach should a security manager prioritize to ensure effective policy enforcement in a decentralized organization?
  68. Q68 Which is the best description of risk avoidance?
  69. Q69 A new security manager has discovered that the security policy is not published. What is the best course of action?
  70. Q70 Failures of information security programs have been caused by all of the following except which one?
  71. Q71 An organization may opt to use an outside expert to conduct tabletop exercises for all of the following reasons except which one?
  72. Q72 What is the purpose of information security governance?
  73. Q73 What is the MOST effective way to evaluate the maturity level of an information security program among the options provided?
  74. Q74 An organization is considering implementing a new incident management tool to improve its response capabilities. What is the most critical factor to…
  75. Q75 Before implementing a security information and event management (SIEM) tool, what is the MOST crucial factor that the organization should take into…
  76. Q76 What is the most significant factor to assess when evaluating an organization's preparedness for incident management?
  77. Q77 What is the primary purpose of performing asset valuation in the context of information security management?
  78. Q78 You are the Information Security Manager of HDA Inc. You are tasked with identifying external factors influencing the organization's information security. What…
  79. Q79 What is the purpose of a penetration test?
  80. Q80 You are the Information Security Manager of HDA Inc. You are considering the primary goal of engaging an external company for penetration…
  81. Q81 What does "Risk Capacity" refer to in the context of an organization's risk management?
  82. Q82 In the course of responding to a security incident, the legal department has directed that all internal communications use special marking and…
  83. Q83 To guarantee the segregation of duties, which of the subsequent tasks is MOST effectively carried out by an individual other than the…
  84. Q84 Requiring all personnel to report security issues provides all of the following benefits except which one?
  85. Q85 A risk assessment has determined that the control is being operated improperly. How should this matter best be remedied?
  86. Q86 What is the most important consideration when designing a security metrics dashboard to effectively inform senior management?
  87. Q87 In light of civil unrest in the city where a contracted regional data center of a multinational organization is located, what should…
  88. Q88 Which method is most effective in controlling access to sensitive data stored in a cloud environment?
  89. Q89 What is the PRIMARY justification for incorporating business representation when assigned to develop an information security strategy for an organization?
  90. Q90 Why is it crucial to separate short-term plans from long-term plans in the information security roadmap?
  91. Q91 Which of the following best describes degaussing?
  92. Q92 Security incident responders have identified a malware attack on a specific server. Incident responders removed the server from the network. Which step…
  93. Q93 How frequently should business process documents be reviewed and updated?
  94. Q94 What most effectively aids the risk assessment process in determining the criticality of an asset?
  95. Q95 What is the purpose of defining severity levels for security incidents?
  96. Q96 A CISO is building a new incident response capability. All of the following resources are required except which one?
  97. Q97 Which of the following is a KEY benefit of aligning IT security policies with business objectives?
  98. Q98 To balance secrecy with proper due diligence, what is the best approach to the analysis of an upcoming merger or acquisition?
  99. Q99 A security manager has discovered that employees are using personally owned computers for remote access to internal networks, which is in conflict…
  100. Q100 Risk Appetite is best described as:
  101. Q101 You are the Information Security Manager of HDA Inc. You are conducting a Business Impact Analysis (BIA) to assess the impact of…
  102. Q102 In the context of developing a new information security strategy, what should be the Chief Information Security Officer's (CISO's) primary focus to…
  103. Q103 You are the Information Security Manager of HDA Inc. You need to determine the individual responsible for raising awareness about the need…
  104. Q104 When conducting a business impact analysis (BIA), which of the following should determine the estimates for recovery time and cost?
  105. Q105 Your organization is planning to adopt a cloud-based service to improve operational efficiency. What is the most crucial initial step for ensuring…
  106. Q106 What option among the following would MOST effectively offer stakeholders the necessary information to decide the suitable course of action in response…
  107. Q107 You are the Information Security Manager of HDA Inc. You discover that employees who reported security breaches are involved in investigating and…
  108. Q108 As the Information Security Manager of HDA Inc., what poses the GREATEST challenge in ensuring the security of Internet of Things (IoT)…
  109. Q109 Achieving compliance of activities conducted by outsourcing providers with information security policies is MOST effectively accomplished by using:
  110. Q110 You are the Information Security Manager of HDA Inc. You want to assess the effectiveness of a control. What provides the MOST…
  111. Q111 When considering the success of an information security program within a corporate setting, what factor is MOST likely to contribute to its…
  112. Q112 What is the utmost critical justification for conducting vulnerability assessments at regular intervals?
  113. Q113 How do international standards like ISO/IEC 27001 benefit an organization's security program?
  114. Q114 The MOST significant advantage arising from well-documented information security procedures is that:
  115. Q115 When developing an information security program, what should be the primary criterion for success?
  116. Q116 What source among the options provides the most valuable information for identifying gaps in security controls on an application server?
  117. Q117 When considering the selection of a key risk indicator (KRI), what holds the utmost significance among the options below?
  118. Q118 What is the UTMOST crucial factor to guarantee the successful recovery of a business in the event of a disaster?
  119. Q119 Which of the following best defines 'social engineering' in the context of information security?
  120. Q120 The impact of an incident is an indication of:
  121. Q121 Which of the following best describes the primary goal of the Data Protection Act (DPA) 2018 in the United Kingdom?
  122. Q122 What task is MOST effectively carried out by the security department?
  123. Q123 You are the Information Security Manager of HDA Inc. The CRUCIAL elements in establishing the range and schedule for testing a business…
  124. Q124 A new CISO is developing a long-term strategy and needs to develop several business case documents. What elements should be included in…
  125. Q125 When should users be required to undergo security awareness training?
  126. Q126 During an audit of a data center's IT architecture, the information security manager uncovers the absence of necessary encryption for data communications.…
  127. Q127 We are implementing some new standards and framework in our organization. We chose to use scoping on one of the standards we…
  128. Q128 Which of the following is a primary objective of an information security strategy?
  129. Q129 Lack of competent security architects leads to:
  130. Q130 What role does 'separation of duties' play in information security?
  131. Q131 Which action should an information security manager prioritize to ensure effective vulnerability management in aligning with business objectives?

More ISACA certifications

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need