Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 64

Which of the following should an information security manager do FIRST when a vulnerability has been disclosed?

Options:

A.

Perform a patch update.

B.

Conduct a risk assessment.

C.

Perform a penetration test.

D.

Conduct an impact assessment.

Buy Now
Question # 65

Which of the following would be MOST effective in reducing the impact of a distributed denial of service (DDoS) attack?

Options:

A.

Impose state limits on servers.

B.

Spread a site across multiple ISPs.

C.

Block the attack at the source.

D.

Harden network security.

Buy Now
Question # 66

An incident management team is alerted ta a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:

Options:

A.

notify the business process owner.

B.

follow the business continuity plan (BCP).

C.

conduct an incident forensic analysis.

D.

follow the incident response plan.

Buy Now
Question # 67

To inform a risk treatment decision, which of the following should the information security manager compare with the organization ' s risk appetite?

Options:

A.

Gap analysis results

B.

Level of residual risk

C.

Level of risk treatment

D.

Configuration parameters

Buy Now
Question # 68

Which of the following BEST provides an information security manager with sufficient assurance that a service provider complies with the organization ' s information security requirements?

Options:

A.

Alive demonstration of the third-party supplier ' s security capabilities

B.

The ability to i third-party supplier ' s IT systems and processes

C.

Third-party security control self-assessment (CSA) results

D.

An independent review report indicating compliance with industry standards

Buy Now
Question # 69

An organization has purchased an Internet sales company to extend the sales department. The information security manager ' s FIRST step to ensure the security policy framework encompasses the new business model is to:

Options:

A.

perform a gap analysis.

B.

implement both companies ' policies separately

C.

merge both companies ' policies

D.

perform a vulnerability assessment

Buy Now
Question # 70

Which of the following is the BEST method for determining whether a firewall has been configured to provide a comprehensive perimeter defense9

Options:

A.

A validation of the current firewall rule set

B.

A port scan of the firewall from an internal source

C.

A ping test from an external source

D.

A simulated denial of service (DoS) attack against the firewall

Buy Now
Question # 71

Which of the following is MOST important when developing an AI security awareness program?

Options:

A.

Creating an interactive training environment

B.

Aligning the training to user roles

C.

Defining the level of user interaction with AI

D.

Assessing the maturity of the organization

Buy Now
Question # 72

An organization is considering using a third party to host sensitive archived data. Which of the following is MOST important to verify before entering into the relationship?

Options:

A.

The vendor ' s data centers are in the same geographic region.

B.

The encryption keys are not provisled to the vendor.

C.

The vendor ' s controls are in line with the organization ' s security standards.

D.

Independent audits of the vendor ' s operations are regularly conducted.

Buy Now
Question # 73

Which of the following groups is MOST important to involve in the development of information security procedures?

Options:

A.

Audit management

B.

Senior management

C.

Operational units

D.

End users

Buy Now
Question # 74

Which of the following is the FIRST step when conducting a post-incident review?

Options:

A.

Identify mitigating controls.

B.

Assess the costs of the incident.

C.

Perform root cause analysis.

D.

Assign responsibility for corrective actions.

Buy Now
Question # 75

An organization is considering the feasibility of implementing a big data solution to analyze customer data. In order to support this initiative, the information security manager should FIRST:

Options:

A.

inventory sensitive customer data to be processed by the solution.

B.

determine information security resource and budget requirements.

C.

assess potential information security risk to the organization.

D.

develop information security requirements for the big data solution.

Buy Now
Question # 76

Which of the following would provide the BEST evidence to senior management that security control performance has improved?

Options:

A.

Demonstrated return on security investment

B.

Reduction in inherent risk

C.

Results of an emerging threat analysis

D.

Review of security metrics trends

Buy Now
Question # 77

Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?

Options:

A.

Place the web server in quarantine.

B.

Rebuild the server from the last verified backup.

C.

Shut down the server in an organized manner.

D.

Rebuild the server with relevant patches from the original media.

Buy Now
Question # 78

Which of the following should be the FIRST step when performing triage of a malware incident?

Options:

A.

Containing the affected system

B.

Preserving the forensic image

C.

Comparing backup against production

D.

Removing the malware

Buy Now
Question # 79

Which of the following should have the MOST influence on the development of information security policies?

Options:

A.

Business strategy

B.

Past and current threats

C.

IT security framework

D.

Industry standards

Buy Now
Question # 80

Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?

Options:

A.

Adhere to regulatory requirements

B.

Conduct security awareness

C.

Document and distribute security procedures

D.

Communicate and enforce security policies

Buy Now
Question # 81

Which of the following BEST encourages staff to report issues related to information security?

Options:

A.

Tabletop exercises are performed on a regular basis

B.

Incentives are offered for security skills training

C.

The leaders set a positive security culture

D.

Formal incident response processes are in place

Buy Now
Question # 82

Which of the following is the BEST course of action when confidential information is inadvertently disseminated outside the organization?

Options:

A.

Review compliance requirements.

B.

Communicate the exposure.

C.

Declare an incident.

D.

Change the encryption keys.

Buy Now
Question # 83

Management of a financial institution accepted an operational risk that consequently led to the temporary deactivation to a critical monitoring process. Which of the following should be the information security manager ' s GREATEST concern with this situation?

Options:

A.

Impact on compliance risk.

B.

Inability to determine short-term impact.

C.

Impact on the risk culture.

D.

Deviation from risk management best practices

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249