Question 1
Which of the following would provide the MOST value to senior management when presenting the results of a risk assessment?
Which of the following would provide the MOST value to senior management when presenting the results of a risk assessment?
Which of the following devices, when placed in a demilitarized zone (DMZ), would be considered the MOST significant exposure?
The executive management of a domestic organization has announced plans to expand operations to multiple international locations. Which of the following should be the information security manager's FIRST step upon learning of these plans?
The first step is to research legal and regulatory requirements for the new locations. Different countries have varying security and privacy laws, and understanding these is critical before adapting policies or procedures.
''Security requirements will vary depending on local legal and regulatory obligations, which must be understood as part of international expansion.''
--- CISM Review Manual 15th Edition, Chapter 1: Information Security Governance, Section: Compliance Requirements
The ISACA CISM practice database also highlights this step as the initial and critical move in international expansions.
Risk treatment options should PRIMARILY focus on:
The correct answer is B because the purpose of risk treatment is to bring risk within the organization's acceptable level, based on risk appetite and risk tolerance. Risk treatment may involve mitigating, avoiding, transferring, or accepting risk. The objective is not simply to focus on inherent and residual risk as concepts, but to select and apply treatment options that reduce or manage risk to a level approved by the organization. Asset criticality is an important input because more critical assets may require stronger controls, but it is not the primary purpose of treatment. High- and medium-rated risks often receive priority, but risk treatment should still be based on business impact, likelihood, cost, risk appetite, and treatment effectiveness. Inherent and residual risk must be understood, but they describe risk before and after controls rather than the main focus of selecting treatment. CISM risk management principles emphasize that management must choose treatment options that align risk with business objectives and acceptable risk levels.
Which of the following should be established FIRST when implementing an information security governance framework?
This is the most urgent and effective action to prevent further damage or compromise of the organization's network and data. The other options are less important or irrelevant in this situation.
According toHow to identify suspicious insider activity using Active Directory, one of the steps to detect and respond to suspicious activity is to isolate the affected device from the network.This can be done by disabling the network adapter, unplugging the network cable, or blocking the device's IP address on the firewall1. This will prevent the device from communicating with any malicious actors or spreading malware to other devices on the network.
`
Which of the following is MOST important for the improvement of a business continuity plan (BCP)?
An organization's research department plans to apply machine learning algorithms on a large data set containing customer names and purchase history. The risk of personal data leakage is considered high impact. Which of the following is the BEST risk treatment option in this situation?
A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?
Standards are the most important thing to review, as they define the specific and mandatory requirements for setting up new user accounts, such as the naming conventions, access rights, password policies, and expiration dates. Standards help to ensure consistency, security, and compliance across the organization's information systems and users. If the standards are not followed, the organization may face increased risks of unauthorized access, data breaches, or audit failures.
References= CISM Review Manual 2022, page 341; CISM Exam Content Outline, Domain 1, Knowledge Statement 1.32;CISM 2020: IT Security Policies;Information Security Policy, Standards, and Guidelines
A new application has entered the production environment with deficient technical security controls. Which of the following is MOST Likely the root cause?
Change control is the process of ensuring that changes to an information system are authorized, tested, documented and implemented in a controlled manner. Inadequate change control can result in deficient technical security controls, such as missing patches, misconfigurations, vulnerabilities or errors in the new application.
References= CISM Review Manual, 27th Edition, Chapter 4, Section 4.3.2, page 2291
Which of the following is the MOST effective way to demonstrate improvement in security performance?
Presenting trends in a validated metrics dashboard is the most effective way to demonstrate improvement in security performance because CISM emphasizes measurement over time, not isolated point-in-time results. A metrics dashboard allows senior management to see whether controls are becoming more effective, risks are being reduced, and objectives are being met consistently. Control self-assessments (A) and vulnerability test results (C) provide snapshots but lack context and trend analysis. ROI summaries (B) focus on financial performance rather than security effectiveness. CISM stresses that meaningful metrics must be aligned to business objectives, risk appetite, and key risk indicators, and must be repeatable and validated. Trending metrics demonstrate maturity, continuous improvement, and governance effectiveness, which are critical elements of an effective information security program.
Application data integrity risk is MOST directly addressed by a design that includes:
Reconciliation routines are methods to verify the integrity of data by comparing the input and output of a process or a system. They can detect errors, omissions, duplications or unauthorized modifications of data.They are more directly related to data integrity than the other options, which are more concerned with data definition, logging or access control.References= CISM Review Manual, 16th Edition, Chapter 3, Section 3.4.21
Which of the following sources is MOST useful when planning a business-aligned information security program?
A business-aligned information security program is one that supports the organization's business objectives and aligns the information security strategy with the business functions. A business impact analysis (BIA) is a process that identifies the critical business processes, assets, and functions of an organization, and assesses their potential impact in the event of a disruption or loss. A BIA helps to prioritize the information security requirements and controls that are needed to protect the organization's critical assets and functions from various threats and risks. Therefore, a BIA is one of the most useful sources when planning a business-aligned information security program.References= CISM Review Manual 15th Edition, page 254; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 229.
The most useful source when planning a business-aligned information security program is a Business Impact Analysis (BIA). A BIA is a process of identifying and evaluating the potential effects of disruptions to an organization's operations, and helps to identify the security controls and measures that should be implemented to reduce the impact of those disruptions. The BIA should include an assessment of the organization's information security posture, including its security policies, risk register, and enterprise architecture. With this information, organizations can develop an information security program that is aligned to the organization's business objectives.
Which of the following is the BEST approach to incident response for an organization migrating to a cloud-based solution?
The best approach to incident response for an organization migrating to a cloud-based solution is to revise the existing incident response procedures to encompass the cloud environment. This is because the cloud environment introduces new challenges and risks that may not be adequately addressed by the current procedures. For example, the cloud provider may have different roles and responsibilities, service level agreements, notification and escalation processes, data protection and privacy requirements, and legal and regulatory obligations than the organization. Therefore, the organization should review and update its incident response procedures to align with the cloud provider's policies and practices, as well as the organization's business objectives and risk appetite. The organization should also ensure that the incident response team members are trained and aware of the changes in the procedures and the cloud environment.
The other options are not the best approaches because they do not consider the specific characteristics and implications of the cloud environment. Adopting the cloud provider's incident response procedures may not be feasible or desirable, as the organization may have different needs and expectations than the cloud provider. Transferring responsibility for incident response to the cloud provider may not be possible or advisable, as the organization may still retain some accountability and liability for the security and availability of its data and services in the cloud. Continuing to use the existing incident response procedures may not be effective or efficient, as the procedures may not cover the scenarios and issues that may arise in the cloud environment.References=
CISM Review Manual (Digital Version)1, Chapter 4: Information Security Incident Management, pages 191-192, 195-196, 199-200.
Cloud Incident Response Framework -- A Quick Guide2, pages 3-4, 6-7, 9-10.
CISM ITEM DEVELOPMENT GUIDE3, page 18, Question 1.
Which of the following should be the FIRST consideration for an information security manager after a security incident has been confirmed?
Once a security incident has been confirmed, the first consideration for the information security manager is executing containment procedures (A). According to CISM incident management principles, containment is prioritized immediately after confirmation to limit the spread of the incident, prevent further damage, and protect unaffected systems and data. Delaying containment increases potential impact, data loss, and operational disruption.
Determining the root cause (B) is an important activity but occurs after containment, once the situation is stabilized. Developing incident reporting criteria (C) is part of incident response planning and should already be defined before an incident occurs. Restoring business operations (D) is a recovery-phase activity that follows containment and eradication.
CISM emphasizes a structured incident response lifecycle: confirmation containment eradication recovery post-incident review. Immediate containment ensures the organization retains control of the incident while preserving evidence and enabling informed decisions for subsequent steps.
ISACA CISM Review Manual, Information Security Incident Management --- incident response lifecycle and containment
ISACA CISM Exam Content Outline, Domain 4: Information Security Incident Management
A financial company executive is concerned about recently increasing cyberattacks and needs to take action to reduce risk. The organization would BEST respond by:
The best response for the organization to reduce risk from increasing cyberattacks is to revalidate and mitigate risks to an acceptable level. This means that the organization should review its current risk profile, identify any new or emerging threats, vulnerabilities, or impacts, and evaluate the effectiveness of its existing controls and countermeasures. Based on this analysis, the organization should implement appropriate risk treatment strategies, such as avoiding, transferring, accepting, or reducing the risks, to achieve its desired risk appetite and tolerance. The organization should also monitor and review the risk situation and the implemented controls on a regular basis, and update its risk management plan accordingly.This approach is consistent with the ISACA Risk IT Framework, which provides guidance on how to align IT risk management with business objectives and value12.
The other options are not the best responses because they are either too narrow or too reactive. Increasing budget and staffing levels for the incident response team may improve the organization's ability to respond to and recover from cyberattacks, but it does not address the root causes or the prevention of the attacks. Implementing an intrusion detection system (IDS) may enhance the organization's detection and analysis capabilities, but it does not guarantee the protection or mitigation of the attacks. Testing the business continuity plan (BCP) may verify the organization's readiness and resilience to continue its critical operations in the event of a cyberattack, but it does not reduce the likelihood or the impact of the attack.References=
Risk IT Framework1
CISM Review Manual, 16th Edition | Print | English2, Chapter 3: Information Risk Management, pages 97-98, 103-104, 107-108, 111-112.