Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 304

Which of the following elements of a service contract would BEST enable an organization to monitor the information security risk associated with a cloud service provider?

Options:

A.

Indemnification clause

B.

Breach detection and notification

C.

Compliance status reporting

D.

Physical access to service provider premises

Buy Now
Question # 305

The information security manager of a multinational organization has been asked to consolidate the information security policies of its regional locations. Which of the following would be of

GREATEST concern?

Options:

A.

Varying threat environments

B.

Disparate reporting lines

C.

Conflicting legal requirements

D.

Differences in work culture

Buy Now
Question # 306

When preventive controls to appropriately mitigate risk are not feasible, which of the following is the MOST important action for the information security manager?

Options:

A.

Managing the impact

B.

Identifying unacceptable risk levels

C.

Assessing vulnerabilities

D.

Evaluating potential threats

Buy Now
Question # 307

Which of the following would BEST enable the timely execution of an incident response plan?

Options:

A.

The introduction of a decision support tool

B.

Definition of trigger events

C.

Clearly defined data classification process

D.

Centralized service desk

Buy Now
Question # 308

An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?

Options:

A.

Employees use smartphone tethering when accessing from remote locations.

B.

Employees physically lock PCs when leaving the immediate area.

C.

Employees are trained on the acceptable use policy.

D.

Employees use the VPN when accessing the organization ' s online resources.

Buy Now
Question # 309

A serious vulnerability was detected in a business application that can be exploited by external attackers to compromise the system. What is the information security manager’s BEST course of action?

Options:

A.

Ask the business application owner to apply the fix immediately

B.

Implement temporary remediation

C.

Immediately shut down the application

D.

Report the risk to the business application owner

Buy Now
Question # 310

Which of the following is MOST important for an information security manager to verify when selecting a third-party forensics provider?

Options:

A.

Existence of a right-to-audit clause

B.

Results of the provider ' s business continuity tests

C.

Technical capabilities of the provider

D.

Existence of the provider ' s incident response plan

Buy Now
Question # 311

Which type of policy BEST helps to ensure that all employees, contractors, and third-party users receive formal communication regarding an organization’s security program?

Options:

A.

Management review policy

B.

Business continuity management policy

C.

Information security training policy

D.

Security incident management policy

Buy Now
Question # 312

Which of the following is the BEST indication of an effective information security awareness training program?

Options:

A.

An increase in the frequency of phishing tests

B.

An increase in positive user feedback

C.

An increase in the speed of incident resolution

D.

An increase in the identification rate during phishing simulations

Buy Now
Question # 313

Which type of plan is PRIMARILY intended to reduce the potential impact of security events that may occur?

Options:

A.

Security awareness plan

B.

Business continuity plan (BCP)

C.

Disaster recovery plan (DRP)

D.

Incident response plan

Buy Now
Question # 314

Which of the following is the BEST way to improve an organization’s ability to detect and respond to incidents?

Options:

A.

Perform a security gap analysis.

B.

Conduct a business impact analysis (BIA).

C.

Conduct periodic awareness training.

D.

Perform network penetration testing.

Buy Now
Question # 315

What should be the FIRST step when an Internet of Things (loT) device in an organization ' s network is confirmed to have been hacked?

Options:

A.

Monitor the network.

B.

Perform forensic analysis.

C.

Disconnect the device from the network,

D.

Escalate to the incident response team

Buy Now
Question # 316

After the occurrence of a major information security incident, which of the following will BEST help an information security manager determine corrective actions?

Options:

A.

Calculating cost of the incident

B.

Conducting a postmortem assessment

C.

Performing an impact analysis

D.

Preserving the evidence

Buy Now
Question # 317

Which of the following is a desired outcome of information security governance?

Options:

A.

Penetration test

B.

Improved risk management

C.

Business agility

D.

A maturity model

Buy Now
Question # 318

Which of the following has the GREATEST influence on the successful integration of information security within the business?

Options:

A.

Organizational structure and culture

B.

Risk tolerance and organizational objectives

C.

The desired state of the organization

D.

Information security personnel

Buy Now
Question # 319

Following an information security risk assessment of a critical system, several significant issues have been identified. Which of the following is MOST important for the information security manager to confirm?

Options:

A.

The risks are reported to the business unit’s senior management

B.

The risks are escalated to the IT department for remediation

C.

The risks are communicated to the central risk function

D.

The risks are entered in the organization ' s risk register

Buy Now
Question # 320

Which of the following would BEST enable senior management to integrate security into all organizational processes following an increase in cyberattacks on business applications?

Options:

A.

Updating process diagrams to align with organizational strategy

B.

Requiring developers to attend customized training on secure application development

C.

Providing security training to key stakeholders within each business area

D.

Establishing security policies that align with business objectives

Buy Now
Question # 321

Which of the following presents the GREATEST challenge when assessing the impact of emerging risk?

Options:

A.

Complexity of the emerging risk

B.

Insufficient data related to the emerging risk

C.

Outdated risk management strategy

D.

Lack of resources to perform risk assessments

Buy Now
Question # 322

Which of the following is the BEST way to ensure the capability to restore clean data after a ransomware attack?

Options:

A.

Purchase cyber insurance

B.

Encrypt sensitive production data

C.

Perform Integrity checks on backups

D.

Maintain multiple offline backups

Buy Now
Question # 323

Which of the following factors would have the MOST significant impact on an organization ' s information security governance mode?

Options:

A.

Outsourced processes

B.

Security budget

C.

Number of employees

D.

Corporate culture

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249