
CISM Premium Exam Engine - Download Free PDF Questions
Instant Download CISM Free Updated Test Dumps
The CISM certification is designed for professionals who are responsible for managing and implementing information security programs in organizations. It covers four domains of information security management: information security governance, risk management, information security program development and management, and incident management and response. CISM exam is comprehensive and covers a wide range of topics related to information security management, including security frameworks, risk assessment and management, security program development and implementation, and incident response and management.
NEW QUESTION # 61
Which of the following would be helpful to reduce the amount of time needed by an incident response team to determine appropriate actions?
- A. Providing annual awareness training regarding incident response for team members
- B. Defining incident severity levels during a business impact analysis (BIA)
- C. Validating the incident response plan against industry best practices
- D. Rehearsing incident response procedures, roles, and responsibilities
Answer: D
NEW QUESTION # 62
An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?
- A. Initiate incident response
- B. Conduct a risk assessment
- C. Disable remote access
- D. Initiate a device reset
Answer: B
NEW QUESTION # 63
Which of the following is MOST important for an information security manager to communicate to senior management regarding the security program?
- A. Potential risks and exposures
- B. User roles and responsibilities
- C. Impact analysis results
- D. Security architecture changes
Answer: C
NEW QUESTION # 64
An organization's security policy is to disable access to USB storage devices on laptops and desktops. Which of the following is the STRONGEST justification for granting an exception to the policy?
- A. USB storage devices are enabled based on user roles.
- B. Access is restricted to read-only.
- C. Users accept the risk of noncompliance.
- D. The benefit is greater than the potential risk.
Answer: D
Explanation:
Explanation
The strongest justification for granting an exception to the security policy that disables access to USB storage devices on laptops and desktops is that the benefit is greater than the potential risk. A security policy is a document that defines the goals, objec-tives, principles, roles, responsibilities, and requirements for protecting information and systems in an organization. A security policy should be based on a risk assessment that identifies and evaluates the threats and vulnerabilities that affect the organiza-tion's assets, as well as the potential impact and likelihood of incidents. A security pol-icy should also be aligned with the organization's business objectives and risk appe-tite1. However, there may be situations where a security policy cannot be fully enforced or complied with due to technical, operational, or business reasons. In such cases, an exception to the policy may be requested and granted by an authorized person or body, such as a security manager or a policy committee. An exception to a security policy should be justified by a clear and compelling reason that outweighs the risk of non-compliance. An exception to a security policy should also be documented, approved, monitored, reviewed, and revoked as necessary2. The strongest justification for grant-ing an exception to the security policy that disables access to USB storage devices on laptops and desktops is that the benefit is greater than the potential risk. USB storage devices are portable devices that can store large amounts of data and can be easily connected to laptops and desktops via USB ports. They can provide several benefits for users and organizations, such as:
*Enhancing data mobility and accessibility
*Improving data backup and recovery
*Supporting data sharing and collaboration
*Enabling data encryption and authentication
However, USB storage devices also pose significant security risks for users and organi-zations, such as:
*Introducing malware or viruses to laptops and desktops
*Exposing sensitive data to unauthorized access or disclosure
*Losing or stealing data due to device loss or theft
*Violating security policies or regulations
Therefore, an exception to the security policy that disables access to USB storage de-vices on laptops and desktops should only be granted if the benefit of using them is greater than the potential risk of compromising them. For example, if a user needs to transfer a large amount of data from one laptop to another in a remote location where there is no network connection available, and the data is encrypted and protected by a strong password on the USB device, then the benefit of using the USB device may be greater than the risk of losing or exposing it. The other options are not the strongest justifications for granting an exception to the security policy that disables access to USB storage devices on laptops and desktops. Enabling USB storage devices based on user roles is not a justification, but rather a possible way of implementing a more gran-ular or flexible security policy that allows different levels of access for different types of users3. Users accepting the risk of noncompliance is not a justification, but rather a requirement for requesting an exception to a security policy that acknowledges their responsibility and accountability for any consequences of noncompliance4.
Accessing being restricted to read-only is not a justification, but rather a possible control that can reduce the risk of introducing malware or viruses from USB devices to laptops and desktops5. References: 1: Information Security Policy - NIST 2: Policy Exception Man-agement - ISACA 3: Deploy and manage Removable Storage Access Control using In-tune - Microsoft Learn 4: Policy Exception Request Form - University of California
5: Re-movable Media Policy Writing Tips - CurrentWare
NEW QUESTION # 65
In addition to backup data, which of the following is the MOST important to store offsite in the event of a disaster?
- A. List of emergency numbers of service providers
- B. Copies of the business continuity plan
- C. Copies of critical contracts and service level agreements (SLAs)
- D. Key software escrow agreements for the purchased systems
Answer: B
Explanation:
Without a copy of the business continuity plan, recovery efforts would be severely hampered or may not be effective. All other choices would not be as immediately critical as the business continuity plan itself. The business continuity plan would contain a list of the emergency numbers of service providers.
NEW QUESTION # 66
An organization's information security processes are currently defined as ad hoc. In seeking to improve their performance level, the next step for the organization should be to:
- A. implement monitoring of key performance indicators for security processes.
- B. enforce baseline security levels across the organization.
- C. ensure that security processes are fully documented.
- D. ensure that security processes are consistent across the organization.
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
The organization first needs to move from ad hoc to repeatable processes. The organization then needs to document the processes and implement process monitoring and measurement. Baselining security levels will not necessarily assist in process improvement since baselining focuses primarily on control improvement. The organization needs to standardize processes both before documentation, and before monitoring and measurement.
NEW QUESTION # 67
Which of the following is the MOST effective way for an organization to ensure its third-party service providers are aware of information security requirements and expectations?
- A. Inducting information security clauses within contracts
- B. Providing information security training to third-party personnel
- C. Requiring third parties to sign confidentiality agreements
- D. Auditing the service delivery of third-party providers
Answer: A
NEW QUESTION # 68
The fundamental purpose of establishing security metrics is to:
- A. provide feedback on control effectiveness
- B. adopt security best practices
- C. increase return on investment (ROI)
- D. establish security benchmarks
Answer: A
Explanation:
Security metrics are used to measure the effectiveness of controls and evaluate the overall security posture of an organization. This feedback provides an understanding of the progress made towards achieving security objectives and allows organizations to make necessary adjustments.
NEW QUESTION # 69
Which of the following is the MOST effective way to detect security incidents?
- A. Analyze vulnerability assessments.
- B. Analyze penetration test results.
- C. Analyze recent security risk assessments.
- D. Analyze security anomalies.
Answer: D
Explanation:
Explanation
Analyzing security anomalies is the most effective way to detect security incidents, as it involves comparing the current state of the information system and network with the expected or normal state, and identifying any deviations or irregularities that may indicate a security breach or compromise. Security anomalies can be detected by using various tools and techniques, such as security information and event management (SIEM) systems, intrusion detection and prevention systems (IDS/IPS), log analysis, network traffic analysis, and behavioral analysis. (From CISM Review Manual 15th Edition) References: CISM Review Manual 15th Edition, page 181, section 4.3.2.4; CISM: Information Security Incident Management Part 11, section recognize security anomalies.
NEW QUESTION # 70
Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?
- A. Increased influence of security management
- B. Consistent execution of information security strategy
- C. Improved accountability to shareholders
- D. Optimized information security resources
Answer: B
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
NEW QUESTION # 71
For virtual private network (VPN) access to the corporate network, the information security manager is requiring strong authentication. Which of the following is the strongest method to ensure that logging onto the network is secure?
- A. Two-factor authentication
- B. Biometrics
- C. Secure Sockets Layer (SSL)-based authentication
- D. Symmetric encryption keys
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Two-factor authentication requires more than one type of user authentication. While biometrics provides unique authentication, it is not strong by itself, unless a PIN or some other authentication factor is used with it. Biometric authentication by itself is also subject to replay attacks. A symmetric encryption method that uses the same secret key to encrypt and decrypt data is not a typical authentication mechanism for end users. This private key could still be compromised. SSL is the standard security technology for establishing an encrypted link between a web server and a browser. SSL is not an authentication mechanism. If SSL is used with a client certificate and a password, it would be a two-factor authentication.
NEW QUESTION # 72
Which of the following BEST indicates senior management support for an information security program?
- A. Regular security awareness training
- B. Steering committee involvement
- C. Top-down communication
- D. Participation in a certification program
Answer: B
Explanation:
The correct answer is C because active involvement in an information security steering committee demonstrates senior management's ongoing participation in governance, prioritization, decision-making, and oversight. Senior management support is not shown only by words or occasional communication; it is demonstrated through active engagement, resource allocation, risk decisions, and accountability. Top-down communication is useful and may show support, but it is less meaningful than direct participation in a governance body. Regular security awareness training is important for employees, but it does not necessarily prove senior management support. Participation in a certification program may improve professional skills or demonstrate individual commitment, but it is not the best indicator of organizational leadership support. In CISM, information security governance requires senior management direction and oversight to ensure that security objectives align with business objectives. A steering committee provides a formal mechanism for that oversight and involvement. Therefore, steering committee involvement is the best indicator of senior management support.
Reference: CISM Information Security Governance; senior management commitment, steering committee oversight, and governance accountability principles.
NEW QUESTION # 73
Evidence from a compromised server has to be acquired for a forensic investigation. What would be the BEST source?
- A. Backup servers
- B. The last verified backup stored offsite
- C. A bit-level copy of all hard drive data
- D. Data from volatile memory
Answer: C
Explanation:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation:
The bit-level copy image file ensures forensic quality evidence that is admissible in a court of law. Choices B and D may not provide forensic quality data for investigative work, while choice C alone may not provide enough evidence.
NEW QUESTION # 74
Which of the following is the MOST important incident management consideration for an organization subscribing to a cloud service?
- A. Expertise of personnel providing incident response
- B. An agreement on the definition of a security incident
- C. Implementation of a SIEM in the organization
- D. Decision on the classification of cloud-hosted data
Answer: B
NEW QUESTION # 75
An organization has implemented an enterprise resource planning (ERP) system used by 500 employees from various departments. Which of the following access control approaches is MOST appropriate?
- A. Role-based
- B. Rule-based
- C. Discretionary
- D. Mandatory
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Role-based access control is effective and efficient in large user communities because it controls system access by the roles defined for groups of users. Users are assigned to the various roles and the system controls the access based on those roles. Rule-based access control needs to define the access rules, which is troublesome and error prone in large organizations. In mandatory access control, the individual's access to information resources needs to be defined, which is troublesome in large organizations. In discretionary access control, users have access to resources based on predefined sets of principles, which is an inherently insecure approach.
NEW QUESTION # 76
The configuration management plan should PRIMARILY be based upon input from:
- A. the information security manager.
- B. the security steering committee.
- C. IT senior management.
- D. business process owners.
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
Although business process owners, an information security manager and the security steering committee may provide input regarding a configuration management plan, its final approval is the primary responsibility of IT senior management.
NEW QUESTION # 77
A security manager meeting the requirements for the international flow of personal data will need to ensure:
- A. subject access procedures.
- B. a data protection registration.
- C. a data processing agreement.
- D. the agreement of the data subjects.
Answer: D
Explanation:
Section: INFORMATION SECURITY GOVERNANCE
Explanation:
Whenever personal data are transferred across national boundaries, the awareness and agreement of the data subjects are required. Choices A, B and D are supplementary data protection requirements that are not key for international data transfer.
NEW QUESTION # 78
An organization's information security processes are currently defined as ad hoc. In seeking to improve their performance level, the next step for the organization should be to:
- A. implement monitoring of key performance indicators for security processes.
- B. enforce baseline security levels across the organization.
- C. ensure that security processes are fully documented.
- D. ensure that security processes are consistent across the organization.
Answer: D
Explanation:
Explanation
The organization first needs to move from ad hoc to repeatable processes. The organization then needs to document the processes and implement process monitoring and measurement. Baselining security levels will not necessarily assist in process improvement since baselining focuses primarily on control improvement. The organization needs to standardize processes both before documentation, and before monitoring and measurement.
NEW QUESTION # 79
Several significant risks have been identified after a centralized risk register was compiled and prioritized.
The information security manager's most important action is to:
- A. ensure that employees are aware of the risk.
- B. consult external third parties on how to treat the risk.
- C. design and implement controls to reduce the risk.
- D. provide senior management with risk treatment options.
Answer: D
Explanation:
Section: INFORMATION RISK MANAGEMENT
NEW QUESTION # 80
Which of the following should be the information security manager's NEXT step following senior management approval of the information security strategy?
- A. Develop a security policy.
- B. Form a steering committee.
- C. Develop a budget.
- D. Perform a gap analysis.
Answer: A
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION # 81
The MOST complete business case for security solutions is one that.
- A. includes appropriate justification.
- B. details regulatory requirements.
- C. identifies incidents and losses.
- D. explains the current risk profile.
Answer: A
Explanation:
Explanation
Management is primarily interested in security solutions that can address risks in the most cost-effective way.
To address the needs of an organization, a business case should address appropriate security solutions in line with the organizational strategy.
NEW QUESTION # 82
Priority should be given to which of the following to ensure effective implementation of information security governance?
- A. Negotiation
- B. Consultation
- C. Planning
- D. Facilitation
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Planning is the key to effective implementation of information security governance. Consultation, negotiation and facilitation come after planning.
NEW QUESTION # 83
......
ISACA Certified Information Security Manager CISM Exam
ISACA Certified Information Security Manager CISM Exam is related to Certified Information Security Manager CISM certification. This CISM Exam validates the ability to maintain and establish an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives. Candidate must have the ability to manage information risk appropriately and program resources are managed responsibly. It also deals with the ability to ensure that organizational goals and objectives are supported by the information security program communicate managements directives and guide the development of standards, procedures, and guidelines and develop business cases to support investments in information security. Security Managers Industry Leaders and Industry Practitioners usually hold or pursue this certification and you can expect the same job roles after completion of this certification.
Free CISM Exam Braindumps ISACA Pratice Exam: https://examsboost.pass4training.com/CISM-test-questions.html

