Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 204

When taking a risk-based approach to vulnerability management, which of the following is MOST important to consider when prioritizing a vulnerability?

Options:

A.

The information available about the vulnerability

B.

The sensitivity of the asset and the data it contains

C.

IT resource availability and constraints

D.

Whether patches have been developed and tested

Buy Now
Question # 205

Which of the following BEST enables an organization to maintain legally admissible evidence7

Options:

A.

Documented processes around forensic records retention

B.

Robust legal framework with notes of legal actions

C.

Chain of custody forms with points of contact

D.

Forensic personnel training that includes technical actions

Buy Now
Question # 206

To confirm that a third-party provider complies with an organization ' s information security requirements, it is MOST important to ensure:

Options:

A.

security metrics are included in the service level agreement (SLA).

B.

contract clauses comply with the organization ' s information security policy.

C.

the information security policy of the third-party service provider is reviewed.

D.

right to audit is included in the service level agreement (SLA).

Buy Now
Question # 207

Which of the following is the BEST indicator of an organization ' s information security status?

Options:

A.

Intrusion detection log analysis

B.

Controls audit

C.

Threat analysis

D.

Penetration test

Buy Now
Question # 208

Which of the following is the PRIMARY objective of a cyber resilience strategy?

Options:

A.

Employee awareness

B.

Business continuity

C.

Executive support

D.

Regulatory compliance

Buy Now
Question # 209

An organization is performing due diligence when selecting a third party. Which of the following is MOST helpful to reduce the risk of unauthorized sharing of information during this process?

Options:

A.

Using secure communication channels

B.

Establishing mutual non-disclosure agreements (NDAs)

C.

Requiring third-party privacy policies

D.

Obtaining industry references

Buy Now
Question # 210

Which of the following is the MOST important issue in a penetration test?

Options:

A.

Having an independent group perform the test

B.

Obtaining permission from audit

C.

Performing the test without the benefit of any insider knowledge

D.

Having a defined goal as well as success and failure criteria

Buy Now
Question # 211

Which of the following is the BEST way to monitor the effectiveness of security controls?

Options:

A.

Benchmark security controls against similar organizations

B.

Review application and system audit logs

C.

Establish and report security metrics

D.

Conduct regular threat assessments

Buy Now
Question # 212

Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?

Options:

A.

Identifying vulnerabilities within organizational processes

B.

Identifying potential risks posed by devices on the network

C.

Automating the information security risk analysis program

D.

Ensuring complex vulnerabilities are not missed

Buy Now
Question # 213

Which of the following is the MOST important security consideration when planning to use a cloud service provider in a different country?

Options:

A.

Ability to logically separate client data

B.

Ability to meet service level agreements (SLAs)

C.

Ability to meet business resiliency requirements

D.

Ability to enforce contractual obligations

Buy Now
Question # 214

Which of the following is the MOST effective way to demonstrate improvement in security performance?

Options:

A.

Report the results of a security control self-assessment (CSA).

B.

Provide a summary of security project return on investments (ROIs).

C.

Present vulnerability testing results.

D.

Present trends in a validated metrics dashboard.

Buy Now
Question # 215

Which of the following BEST indicates that information assets are classified accurately?

Options:

A.

Appropriate prioritization of information risk treatment

B.

Increased compliance with information security policy

C.

Appropriate assignment of information asset owners

D.

An accurate and complete information asset catalog

Buy Now
Question # 216

An organization ' s HR department requires that employee account privileges be removed from all corporate IT systems within three days of termination to comply with a government regulation However, the systems all have different user directories, and it currently takes up to four weeks to remove the privileges Which of the following would BEST enable regulatory compliance?

Options:

A.

Multi-factor authentication (MFA) system

B.

Identity and access management (IAM) system

C.

Privileged access management (PAM) system

D.

Governance, risk, and compliance (GRC) system

Buy Now
Question # 217

Which of the following would be the BEST way to reduce the risk of disruption resulting from an emergency system change?

Options:

A.

Confirm the change implementation is scheduled.

B.

Verify the change request has been approved.

C.

Confirm rollback plans are in place.

D.

Notify users affected by the change.

Buy Now
Question # 218

Which of the following would BEST enable a new information security manager to obtain senior management support for an information security governance program?

Options:

A.

Demonstrating the program ' s value to the organization

B.

Discussing governance programs found in similar organizations

C.

Providing the results of external audits

D.

Providing examples of information security incidents within the organization

Buy Now
Question # 219

Which of the following is the BEST method for determining whether new risks exist in legacy systems?

Options:

A.

Frequent updates to the risk register

B.

Regularly scheduled security audits

C.

Frequent security architecture reviews

D.

Regularly scheduled risk assessments

Buy Now
Question # 220

Which of the following BEST enables an incident response team to determine appropriate actions during an initial investigation?

Options:

A.

Feedback from affected departments

B.

Historical data from past incidents

C.

Technical capabilities of the team

D.

Procedures for incident triage

Buy Now
Question # 221

Of the following, who is BEST positioned to be accountable for risk acceptance decisions based on risk appetite?

Options:

A.

Information security manager

B.

Chief risk officer (CRO)

C.

Information security steering committee

D.

Risk owner

Buy Now
Question # 222

Which of the following is the PRIMARY reason to involve stakeholders from various business units when developing an information security policy?

Options:

A.

To reduce the overall cost of policy development

B.

To share responsibility for addressing security breaches

C.

To decrease the workload of the IT department

D.

To gain acceptance of the policy across the organization

Buy Now
Question # 223

Which of the following is the BEST course of action after management has reviewed an identified risk and determines the risk is below the defined risk appetite?

Options:

A.

Accept

B.

Avoid

C.

Transfer

D.

Mitigate

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249