Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISM Exam Dumps - Isaca Certification Questions and Answers

Question # 4

In a cloud technology environment, which of the following would pose the GREATEST challenge to the investigation of security incidents?

Options:

A.

Access to the hardware

B.

Data encryption

C.

Non-standard event logs

D.

Compressed customer data

Buy Now
Question # 5

Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?

Options:

A.

Revisit the business objective.

B.

Escalate to senior management.

C.

Perform a cost-benefit analysis.

D.

Recommend risk acceptance.

Buy Now
Question # 6

Which of the following MUST be established to maintain an effective information security governance framework?

Options:

A.

Security controls automation

B.

Defined security metrics

C.

Change management processes

D.

Security policy provisions

Buy Now
Question # 7

Which of the following should be an information security manager ' s FIRST course of action when a newly introduced privacy regulation affects the business?

Options:

A.

Consult with IT staff and assess the risk based on their recommendations

B.

Update the security policy based on the regulatory requirements

C.

Propose relevant controls to ensure the business complies with the regulation

D.

Identify and assess the risk in the context of business objectives

Buy Now
Question # 8

Which of the following BEST mitigates the risk of information loss caused by a cloud service provider becoming insolvent?

Options:

A.

Contractual provisions for the right to audit

B.

Contractual provisions for data repatriation

C.

Effective data loss prevention (DLP) controls

D.

The purchase of cybersecurity insurance

Buy Now
Question # 9

Which of the following would provide the BEST input to a business case for a technical solution to address potential system vulnerabilities?

Options:

A.

Risk assessment

B.

Business impact analysis (BIA)

C.

Penetration test results

D.

Vulnerability scan results

Buy Now
Question # 10

An organization finds it necessary to quickly shift to a work-fromhome model with an increased need for remote access security.

Which of the following should be given immediate focus?

Options:

A.

Moving to a zero trust access model

B.

Enabling network-level authentication

C.

Enhancing cyber response capability

D.

Strengthening endpoint security

Buy Now
Question # 11

Which of the following establishes the minimum technical baseline for security controls?

Options:

A.

Procedures

B.

Policies

C.

Standards

D.

Guidelines

Buy Now
Question # 12

Which of the following is the BEST strategy when determining an organization ' s approach to risk treatment?

Options:

A.

Implementing risk mitigation controls that are considered quick wins

B.

Prioritizing controls that directly mitigate the organization ' s most critical risks

C.

Advancing the maturity of existing controls based on risk tolerance

D.

Implementing a one-size-fits-all set of controls across all organizational units

Buy Now
Question # 13

An organization is creating a risk mitigation plan that considers redundant power supplies to reduce the business risk associated with critical system outages. Which type of control is being considered?

Options:

A.

Preventive

B.

Corrective

C.

Detective

D.

Deterrent

Buy Now
Question # 14

Which of the following BEST facilitates recovery of data lost as a result of a cybersecurity incident?

Options:

A.

Removable storage media

B.

Disaster recovery plan (DRP)

C.

Offsite data backups

D.

Encrypted data drives

Buy Now
Question # 15

Which of the following risks is an example of risk transfer?

Options:

A.

Utilizing third-party applications

B.

Moving risk ownership to another department

C.

Conducting off-site backups

D.

Purchasing cybersecurity insurance

Buy Now
Question # 16

The MOST useful technique for maintaining management support for the information security program is:

Options:

A.

informing management about the security of business operations.

B.

implementing a comprehensive security awareness and training program.

C.

identifying the risks and consequences of failure to comply with standards.

D.

benchmarking the security programs of comparable organizations.

Buy Now
Question # 17

Which of the following is MOST important to emphasize when presenting information to gain senior management support for control enhancements?

Options:

A.

Residual risk exposure

B.

Threats against internal systems

C.

Control gaps within defense-in-depth architecture

D.

Recent data breaches in the same industry sector

Buy Now
Question # 18

Which of the following BEST enables the design of an effective incident escalation process?

Options:

A.

Enforceable control baselines

B.

Controls designed for defense in depth

C.

A well-defined organizational hierarchy

D.

A comprehensive risk register

Buy Now
Question # 19

Which of the following is MOST important when defining how an information security budget should be allocated?

Options:

A.

Regulatory compliance standards

B.

Information security strategy

C.

Information security policy

D.

Business impact assessment

Buy Now
Question # 20

Which of the following is the PRIMARY reason for executive management to be involved in establishing an enterprise ' s security management framework?

Options:

A.

To ensure industry best practices for enterprise security are followed

B.

To establish the minimum level of controls needed

C.

To determine the desired state of enterprise security

D.

To satisfy auditors ' recommendations for enterprise security

Buy Now
Question # 21

What should be the PRIMARY objective of an information classification scheme?

Options:

A.

To meet legislative and regulatory requirements

B.

To develop an asset inventory

C.

To define data retention requirements

D.

To implement controls proportionate to risk

Buy Now
Question # 22

A backdoor has been identified that enabled a cyberattack on an organization’s systems. Integrating which of the following into the software development life cycle would BEST enable the organization to mitigate similar attacks in the future?

Options:

A.

Enhanced user acceptance testing (UAT)

B.

Separation of duties

C.

Customized developer training

D.

Vulnerability testing

Buy Now
Question # 23

An organization requires that business-critical applications be recovered within 30 minutes in the event of a disaster. Which of the following metrics should be defined in the business continuity plan (BCP) to manage this requirement?

Options:

A.

Recovery time objective (RTO)

B.

Recovery point objective (RPO)

C.

Maximum tolerable downtime (MTD)

D.

Service level agreement (SLA)

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Aug 20, 2026
Questions: 1191
CISM pdf

CISM PDF

$59.7  $199
CISM Engine

CISM Testing Engine

$67.5  $225
CISM PDF + Engine

CISM PDF + Testing Engine

$74.7  $249