Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 184

As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?

Options:

A.

The risk owner is able to reassess the risk following remediation.

B.

The risk owner has the authority to take action on the risk.

C.

The risk owner is able to make timely updates to the risk register.

D.

The risk owner also owns the associated control that failed.

Buy Now
Question # 185

An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?

Options:

A.

Standards

B.

Policies

C.

Guidelines

D.

Procedures

Buy Now
Question # 186

A multinational organization is introducing a security governance framework. The information security manager ' s concern is that regional security practices differ. Which of the following should be evaluated FIRST?

Options:

A.

Local regulatory requirements

B.

Global framework standards

C.

Cross-border data mobility

D.

Training requirements of the framework

Buy Now
Question # 187

An information security team plans to strengthen authentication requirements for a customer-facing site, but there are concerns it will negatively impact the user experience. Which of the following is the information security manager ' s BEST course of action?

Options:

A.

Assess business impact against security risk.

B.

Provide security awareness training to customers.

C.

Refer to industry best practices.

D.

Quantify the security risk to the business.

Buy Now
Question # 188

Which of the following considerations is MOST important when selecting a third-party intrusion detection system (IDS) vendor?

Options:

A.

The vendor ' s proposal allows for contract modification during technology refresh cycles.

B.

The vendor ' s proposal aligns with the objectives of the organization.

C.

The vendor ' s proposal requires the provider to have a business continuity plan (BCP).

D.

The vendor ' s proposal allows for escrow in the event the third party goes out of business.

Buy Now
Question # 189

Which of the following is the BEST security control to minimize the risk of successful ransomware attacks?

Options:

A.

Application deny list

B.

Web security gateway

C.

Host intrusion detection system

D.

Application allow list

Buy Now
Question # 190

A security incident has been reported within an organization. When should an information security manager contact the information owner?

Options:

A.

After the incident has been contained

B.

After the incident has been mitigated

C.

After the incident has been confirmed

D.

After the potential incident has been logged

Buy Now
Question # 191

Which of the following is the FIRST step to establishing an effective information security program?

Options:

A.

Conduct a compliance review.

B.

Assign accountability.

C.

Perform a business impact analysis (BIA).

D.

Create a business case.

Buy Now
Question # 192

Which of the following is the MOST common cause of cybersecurity breaches?

Options:

A.

Lack of adequate password rotation

B.

Human error

C.

Abuse of privileged accounts

D.

Lack of control baselines

Buy Now
Question # 193

It is MOST important that risk owners understand they are accountable for:

Options:

A.

Reporting risk metrics and control compliance status to the information security manager

B.

Escalating control deficiencies associated with the risk to the steering committee for decision making

C.

Collaborating with stakeholders to evaluate the effectiveness of controls associated with the risk

D.

Overseeing and monitoring the effectiveness of controls associated with the risk

Buy Now
Question # 194

An organization ' s main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated task?

Options:

A.

The information security manager

B.

The data owner

C.

The application owner

D.

The security engineer

Buy Now
Question # 195

Which of the following is the BEST source of information to support an organization ' s information security vision and strategy?

Options:

A.

Metrics dashboard

B.

Governance policies

C.

Capability maturity model

D.

Enterprise information security architecture

Buy Now
Question # 196

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager ' s MOST important course of action?

Options:

A.

Engage an independent audit of the third party ' s external provider.

B.

Recommend canceling the contract with the third party.

C.

Evaluate the third party ' s agreements with its external provider.

D.

Conduct an external audit of the contracted third party.

Buy Now
Question # 197

Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?

Options:

A.

Documentation of control procedures

B.

Standardization of compliance requirements

C.

Automation of controls

D.

Integration of assurance efforts

Buy Now
Question # 198

Which of the following processes BEST supports the evaluation of incident response effectiveness?

Options:

A.

Root cause analysis

B.

Post-incident review

C.

Chain of custody

D.

Incident logging

Buy Now
Question # 199

Which of the following is the MOST critical input to developing policies, standards, and procedures to secure information assets?

Options:

A.

Vulnerability assessment

B.

Regulatory requirements

C.

Industry best practices

D.

Enterprise goals

Buy Now
Question # 200

Which of the following is the PRIMARY benefit achieved when an information security governance framework is aligned with corporate governance?

Options:

A.

Protection of business value and assets

B.

Identification of core business strategiesC, Easier entrance into new businesses and technologies

C.

Improved regulatory compliance posture

Buy Now
Question # 201

Which of the following should be triggered FIRST when unknown malware has infected an organization ' s critical system?

Options:

A.

Incident response plan

B.

Disaster recovery plan (DRP)

C.

Business continuity plan (BCP)

D.

Vulnerability management plan

Buy Now
Question # 202

Which of the following should be the NEXT step after a security incident has been reported?

Options:

A.

Recovery

B.

Investigation

C.

Escalation

D.

Containment

Buy Now
Question # 203

Which of the following is MOST important to the effectiveness of an information security program?

Options:

A.

Security metrics

B.

Organizational culture

C.

IT governance

D.

Risk management

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249