Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 24

In a business proposal, a potential vendor promotes being certified for international security standards as a measure of its security capability.

Before relying on this certification, it is MOST important that the information security manager confirms that the:

Options:

A.

current international standard was used to assess security processes.

B.

certification will remain current through the life of the contract.

C.

certification scope is relevant to the service being offered.

D.

certification can be extended to cover the client ' s business.

Buy Now
Question # 25

Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?

Options:

A.

Alignment with industry benchmarks

B.

Results of business impact analyses (BIAs)

C.

Possibility of reputational loss due to incidents

D.

Availability of security budget

Buy Now
Question # 26

Application data integrity risk is MOST directly addressed by a design that includes:

Options:

A.

reconciliation routines such as checksums, hash totals, and record counts.

B.

strict application of an authorized data dictionary.

C.

application log requirements such as field-level audit trails and user activity logs.

D.

access control technologies such as role-based entitlements.

Buy Now
Question # 27

The GREATEST challenge when attempting data recovery of a specific file during forensic analysis is when:

Options:

A.

the partition table on the disk has been deleted.

B.

the tile has been overwritten.

C.

all files in the directory have been deleted.

D.

high-level disk formatting has been performed.

Buy Now
Question # 28

Which of the following BEST indicates misalignment of security policies with business objectives?

Options:

A.

Low completion rate of employee awareness training

B.

Lack of adequate funding for the security program

C.

A large number of long-term policy exceptions

D.

A large number of user noncompliance incidents

Buy Now
Question # 29

Which of the following would BEST help to ensure appropriate security controls are built into software?

Options:

A.

Integrating security throughout the development process

B.

Performing security testing prior to deployment

C.

Providing standards for implementation during development activities

D.

Providing security training to the software development team

Buy Now
Question # 30

Which of the following roles is BEST suited to validate user access requirements during an annual user access review?

Options:

A.

Access manager

B.

IT director

C.

System administrator

D.

Business owner

Buy Now
Question # 31

When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:

Options:

A.

consider the organizations business strategy.

B.

consider the strategic objectives of the program.

C.

leverage industry benchmarks.

D.

identify the program ' s risk and compensating controls.

Buy Now
Question # 32

Which of the following is the GREATEST benefit of classifying information security incidents?

Options:

A.

Reporting capabilities

B.

Improved chain of custody

C.

Comprehensive documentation

D.

Prioritized recovery

Buy Now
Question # 33

An information security manager learns through a threat intelligence service that the organization may be targeted for a major emerging threat. Which of the following is the information security manager ' s FIRST course of action?

Options:

A.

Conduct an information security audit.

B.

Validate the relevance of the information.

C.

Perform a gap analysis.

D.

Inform senior management

Buy Now
Question # 34

When a critical system incident is reported, the FIRST step of the incident handler should be to:

Options:

A.

Notify the appropriate parties

B.

Determine the scope of the incident

C.

Validate the incident

D.

Power off the system

Buy Now
Question # 35

An organization is selecting security metrics to measure security performance, and a firewall specialist suggests tracking the number of external attacks blocked by the firewalls. Which of the following is the GREATEST concern with using this metric?

Options:

A.

The number of blocked external attacks is not representative of the true threat profile.

B.

The number of blocked external attacks will vary by month, causing inconsistent graphs.

C.

The number of blocked external attacks is an indicator of the organization ' s popularity.

D.

The number of blocked external attacks over time does not explain the attackers ' motivations.

Buy Now
Question # 36

Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?

Options:

A.

Up-to-date vulnerability scanning tools

B.

Signature-based malware detection tools

C.

Cybersecurity threat intelligence groups

D.

Penetration test findings

Buy Now
Question # 37

Which of the following BEST supports the incident management process for attacks on an organization ' s supply chain?

Options:

A.

Including service level agreements (SLAs) in vendor contracts

B.

Establishing communication paths with vendors

C.

Requiring security awareness training for vendor staff

D.

Performing integration testing with vendor systems

Buy Now
Question # 38

Which of the following incident response phases involves actions to help safeguard critical systems while maintaining business operations?

Options:

A.

Recovery

B.

Identification

C.

Containment

D.

Preparation

Buy Now
Question # 39

The GREATEST benefit of an effective information security awareness program is the organization’s ability to:

Options:

A.

Meet compliance requirements

B.

Reduce security incidents

C.

Establish accountability

D.

Develop meaningful metrics

Buy Now
Question # 40

Which of the following should an information security manager do FIRST after a new cybersecunty regulation has been introduced?

Options:

A.

Conduct a cost-benefit analysis.

B.

Consult corporate legal counsel

C.

Update the information security policy.

D.

Perform a gap analysis.

Buy Now
Question # 41

Which of the following is the BEST approach for managing user access permissions to ensure alignment with data classification?

Options:

A.

Enable multi-factor authentication on user and admin accounts.

B.

Review access permissions annually or whenever job responsibilities change

C.

Lock out accounts after a set number of unsuccessful login attempts.

D.

Delegate the management of access permissions to an independent third party.

Buy Now
Question # 42

Which of the following is the MOST important consideration when updating procedures for managing security devices?

Options:

A.

Updates based on the organization ' s security framework

B.

Notification to management of the procedural changes

C.

Updates based on changes m risk technology and process

D.

Review and approval of procedures by management

Buy Now
Question # 43

Due to changes in an organization ' s environment, security controls may no longer be adequate. What is the information security manager ' s BEST course of action?

Options:

A.

Review the previous risk assessment and countermeasures.

B.

Perform a new risk assessment,

C.

Evaluate countermeasures to mitigate new risks.

D.

Transfer the new risk to a third party.

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249