ISACA Certification

CISM — Information Security Manager Study Guide

60 practice questions with correct answers and detailed explanations. Use this guide to review concepts before taking the practice exam.

▶ Take Practice Exam 60 questions  ·  Free  ·  No registration

About the CISM Exam

The ISACA Information Security Manager (CISM) certification validates professional expertise in ISACA technologies. This study guide covers all 60 practice questions from our CISM practice test, complete with correct answers and explanations to help you understand each concept thoroughly.

Review each question and explanation below, then test yourself with the full interactive practice exam to measure your readiness.

60 Practice Questions & Answers

Q1 Easy

Which of the following best describes the primary purpose of an Information Security Manager?

  • A To implement technical controls and manage firewalls
  • B To manage the IT help desk and user support
  • C To conduct penetration testing on all systems
  • D To establish and maintain an organizational security strategy aligned with business objectives ✓ Correct
Explanation

An Information Security Manager's primary role is to develop comprehensive security strategies that align with business goals, not to perform technical implementations or IT support functions.

Q2 Medium

What is the main objective of conducting a Business Impact Analysis (BIA) in the context of information security?

  • A To determine the potential consequences of security incidents on business operations and prioritize recovery efforts ✓ Correct
  • B To calculate the total cost of ownership for security tools
  • C To evaluate employee compliance with security policies
  • D To identify all technical vulnerabilities in the organization's infrastructure
Explanation

BIA identifies critical business functions and the impact of their disruption, enabling organizations to prioritize security investments and disaster recovery efforts based on business criticality.

Q3 Medium

An organization experiences a data breach affecting customer personal information. Which phase of incident management should be prioritized immediately after detection?

  • A Post-incident analysis and lessons learned documentation
  • B Recovery and restoration of systems to normal operations
  • C Containment and eradication to prevent further compromise ✓ Correct
  • D Investigation and forensic examination only
Explanation

After detection, containment and eradication are critical to stop the ongoing attack and prevent additional data loss or system compromise before moving to recovery.

Q4 Medium

Which framework provides guidance on information security governance and aligns security with organizational strategy?

  • A NIST Cybersecurity Framework focuses primarily on technical implementation details
  • B ISO/IEC 27001 establishes requirements for information security management systems including governance structures
  • C COBIT provides a framework for IT governance with security as a component aligned to business objectives
  • D Both B and C are equally appropriate ✓ Correct
Explanation

Both ISO/IEC 27001 and COBIT provide comprehensive frameworks for security governance; COBIT is specifically designed for IT governance alignment with business strategy, while ISO/IEC 27001 focuses on ISMS implementation.

Q5 Medium

What is a critical success factor when implementing a security awareness training program?

  • A Focus exclusively on compliance requirements and policy documentation
  • B Training content tailored to specific roles with regular reinforcement and measurement of behavioral change ✓ Correct
  • C Mandatory annual training sessions for all employees without customization
  • D Limiting training to IT department personnel only
Explanation

Effective awareness programs require role-specific, ongoing training with metrics to measure actual behavioral improvement, not just compliance checkboxes.

Q6 Medium

In risk management, what distinguishes risk mitigation from risk acceptance?

  • A Both approaches are identical in their application and outcomes
  • B Mitigation is only for technical risks, while acceptance applies to business risks
  • C Acceptance is cheaper and always preferred over mitigation strategies
  • D Mitigation implements controls to reduce risk, while acceptance acknowledges residual risk that remains after mitigation efforts ✓ Correct
Explanation

Risk mitigation involves implementing controls to reduce likelihood or impact, while risk acceptance is the conscious decision to tolerate remaining risk after mitigation has been applied.

Q7 Medium

Which component of a security policy framework typically provides the most detailed technical requirements for system implementation?

  • A Guidelines that provide recommendations and best practices
  • B Security procedures that document step-by-step operational processes
  • C High-level security policies that establish organizational direction
  • D Security standards that define specific technical configurations and baseline requirements ✓ Correct
Explanation

Security standards specify detailed technical requirements and configurations, while policies set direction, procedures define processes, and guidelines offer recommendations.

Q8 Easy

What is the primary benefit of implementing defense-in-depth security architecture?

  • A It reduces the need for security monitoring and incident response capabilities
  • B Multiple overlapping security layers ensure that compromise of one control does not result in total system compromise ✓ Correct
  • C It eliminates the need for user education and awareness programs
  • D It guarantees complete elimination of all security risks
Explanation

Defense-in-depth provides redundant controls so that if one layer is breached, additional layers remain to protect assets and detect intrusions.

Q9 Medium

An organization must decide whether to implement an expensive security control. Which analysis should guide this decision?

  • A Only the initial purchase cost of the control
  • B Matching whatever competitors are implementing regardless of organizational risk profile
  • C The opinion of the most senior security officer without quantitative analysis
  • D Cost-benefit analysis comparing implementation and maintenance costs against risk reduction value ✓ Correct
Explanation

Security investments should be justified through cost-benefit analysis that compares total cost of ownership against the value of risk reduction, enabling informed decision-making.

Q10 Medium

What is the most critical aspect of vendor management from an information security perspective?

  • A Negotiating the lowest possible contract prices
  • B Allowing vendors unlimited access to systems for support purposes
  • C Ensuring vendors meet security requirements and maintain compliance throughout the relationship ✓ Correct
  • D Conducting security assessments only at contract initiation
Explanation

Vendor management must include security requirement definition, ongoing monitoring, and compliance verification to manage third-party risks effectively.

Q11 Medium

How should an organization approach the management of privileged access?

  • A Share privileged credentials among team members for operational convenience
  • B Eliminate all privileged access by moving to cloud-only systems
  • C Implement least privilege principle with segregation of duties, monitoring, and formal approval processes ✓ Correct
  • D Grant administrative privileges to trusted employees without monitoring or restriction
Explanation

Privileged access management requires least privilege implementation, segregation of duties to prevent abuse, and continuous monitoring of administrative actions.

Q12 Hard

Which metric most accurately measures the effectiveness of a security control?

  • A The percentage of IT budget allocated to security
  • B The number of security tools deployed in the organization
  • C The reduction in risk exposure or number of prevented security incidents correlated to the control ✓ Correct
  • D The number of employees who pass security certification exams
Explanation

Control effectiveness is measured by actual risk reduction and incident prevention, not by budget allocation, tool quantity, or certification pass rates.

Q13 Easy

What is the primary purpose of a security incident response plan?

  • A To eliminate the possibility of security incidents from occurring
  • B To ensure that every security incident results in criminal prosecution
  • C To transfer all incident response responsibility to external security vendors
  • D To establish procedures for detecting, responding to, and recovering from security incidents with minimal business impact ✓ Correct
Explanation

An incident response plan provides documented procedures and roles to minimize incident impact, restore operations quickly, and preserve evidence for investigation.

Q14 Medium

In the context of security governance, what does 'accountability' require?

  • A Clear assignment of security responsibilities with defined consequences for non-compliance across the organization ✓ Correct
  • B Documenting security incidents but taking no corrective action
  • C Holding only the Chief Information Security Officer responsible for all security outcomes
  • D Creating security policies without mechanisms to enforce them
Explanation

Accountability means assigning clear security responsibilities at all organizational levels and establishing consequences for non-compliance to ensure security is taken seriously.

Q15 Hard

What is the relationship between risk tolerance and security control selection?

  • A Organizations should implement maximum controls regardless of risk tolerance or business needs
  • B Risk tolerance determines which employees require security training
  • C Security controls should be selected based on organizational risk tolerance, ensuring control costs are justified by acceptable risk levels ✓ Correct
  • D Risk tolerance is irrelevant to security decision-making and should be ignored
Explanation

Risk tolerance defines the level of risk an organization is willing to accept; security controls should be tailored to meet this tolerance level efficiently.

Q16 Hard

Which approach best addresses insider threat risk?

  • A Implement extensive monitoring of all employees without any privacy considerations
  • B Trust-based approach with no monitoring or segregation of duties implemented
  • C Only addressing insider threats after a breach has occurred
  • D Combination of preventive controls, detection mechanisms, and investigation procedures balanced with employee privacy ✓ Correct
Explanation

Insider threat management requires preventive controls like access management, detection capabilities, and investigation procedures while respecting employee rights.

Q17 Medium

What should be the primary focus when developing security requirements for a new system?

  • A Focusing solely on technical security without considering operational feasibility
  • B Copying security requirements from competitors without customization
  • C Implementing the most advanced security technology available regardless of cost
  • D Aligning security requirements with business objectives, regulatory requirements, and risk assessment results ✓ Correct
Explanation

Security requirements should be driven by business needs, applicable regulations, and risk assessment to ensure appropriate and cost-effective protection.

Q18 Hard

How does security architecture contribute to organizational resilience?

  • A It eliminates all security risks permanently through technical controls alone
  • B It focuses exclusively on preventing attacks without considering recovery capabilities
  • C It transfers all security responsibility to external service providers
  • D It provides layered defenses and redundant controls that maintain business continuity despite security incidents ✓ Correct
Explanation

Security architecture builds resilience through defense-in-depth, redundancy, and recovery capabilities that enable organizations to maintain operations despite incidents.

Q19 Medium

What is the primary objective of security metrics and key performance indicators (KPIs)?

  • A To justify increasing security budgets without demonstrating value
  • B To demonstrate that the organization has zero security incidents and perfect security
  • C To comply with regulations by collecting unnecessary data
  • D To provide quantifiable data on security program effectiveness and identify areas for improvement ✓ Correct
Explanation

Security metrics and KPIs measure program effectiveness, track progress toward objectives, and identify improvement opportunities through quantifiable data.

Q20 Medium

Which governance structure best ensures security decisions receive appropriate executive sponsorship?

  • A Security decisions made entirely by IT operations staff without management involvement
  • B No formal governance structure for security decision-making
  • C A security steering committee with representation from business units, IT, and executive leadership that reviews major security initiatives ✓ Correct
  • D Security decisions made exclusively by external consultants
Explanation

A security steering committee with cross-functional representation ensures security receives executive support and aligns with business objectives.

Q21 Hard

What is critical when implementing data protection controls?

  • A Implement encryption only for data in transit, ignoring data at rest
  • B Encrypt all data identically regardless of sensitivity level or regulatory requirements
  • C Focus data protection efforts only on financial information
  • D Classify data by sensitivity, apply proportionate controls based on classification, and maintain control effectiveness over time ✓ Correct
Explanation

Effective data protection requires classification, applying controls proportionate to data sensitivity and risk, and ongoing verification of control effectiveness.

Q22 Medium

How should security configuration management be approached?

  • A Document baseline security configurations, implement change control processes, and maintain compliance through regular assessments ✓ Correct
  • B Continuously make security changes without documenting or testing modifications
  • C Implement security configurations once during system setup with no ongoing management
  • D Allow each system administrator to configure security settings based on personal preference
Explanation

Configuration management requires documented baselines, formal change control, and continuous compliance verification to maintain security standards.

Q23 Hard

What distinguishes a mature information security program from an immature one?

  • A A mature program integrates security into business processes with clear governance, measurable controls, continuous improvement, and executive accountability ✓ Correct
  • B Maturity is achieved by implementing the most expensive security solutions
  • C Maturity is determined solely by the number of security tools deployed
  • D Mature programs eliminate all need for incident response planning
Explanation

Program maturity is evidenced by governance structures, integrated security processes, measurable outcomes, and continuous improvement rather than tool quantity or cost.

Q24 Medium

In security risk assessment, what is the significance of likelihood and impact evaluation?

  • A They are used only for compliance documentation with no practical application
  • B Likelihood is important but impact should be ignored in risk decisions
  • C Together they determine risk level, which guides prioritization and resource allocation for control implementation ✓ Correct
  • D They are unnecessary metrics that should be avoided in risk analysis
Explanation

Likelihood and impact together determine overall risk; this risk rating guides control prioritization and ensures resources address the most significant threats.

Q25 Medium

What role does continuous monitoring play in an information security program?

  • A It should only occur after a security incident has been discovered through other means
  • B Continuous monitoring is only required for regulatory compliance, not for operational security
  • C It provides real-time visibility into security posture, detects anomalies, and enables rapid response to threats ✓ Correct
  • D It is an unnecessary expense that provides no value to the organization
Explanation

Continuous monitoring enables organizations to maintain visibility, detect security issues early, and respond to threats before significant damage occurs.

Q26 Easy

Which of the following best describes the primary purpose of an information security program?

  • A To ensure compliance with all applicable regulations and standards
  • B To protect organizational assets and enable business objectives while managing risk to acceptable levels ✓ Correct
  • C To implement the most advanced security technologies available
  • D To eliminate all cybersecurity risks completely
Explanation

An information security program aims to protect assets and support business goals while maintaining risk at acceptable levels, not to achieve zero risk, which is impossible.

Q27 Medium

In the context of information security governance, which role is primarily responsible for establishing the organization's risk appetite and oversight of the security program?

  • A System Administrator
  • B Chief Information Security Officer (CISO)
  • C Board of Directors or Executive Leadership ✓ Correct
  • D Security Operations Center Manager
Explanation

Executive leadership and the board establish organizational risk appetite and provide governance oversight, while the CISO implements the security program within those parameters.

Q28 Easy

Which of the following is NOT a typical component of a comprehensive information security risk assessment?

  • A Determining threat likelihood and impact
  • B Evaluating existing controls and their effectiveness
  • C Documenting employee salary information and performance reviews ✓ Correct
  • D Identifying and valuing organizational assets
Explanation

Risk assessments focus on assets, threats, vulnerabilities, and controls. Employee salary and performance data are personnel matters unrelated to security risk assessment.

Q29 Medium

An organization discovers that a critical vulnerability has been exploited in its production environment. Which incident management phase should be prioritized immediately after initial detection?

  • A Post-incident review and lessons learned documentation
  • B Containment to limit the scope and impact of the incident ✓ Correct
  • C Notification to external regulatory bodies
  • D Recovery of systems to normal operations
Explanation

Containment must be prioritized immediately after detection to prevent further compromise and limit damage before beginning recovery efforts.

Q30 Medium

When designing access controls for a financial institution, which principle should guide the implementation to minimize risk while maintaining operational efficiency?

  • A Grant all users administrative privileges for flexibility
  • B Provide permanent access once granted to reduce administrative overhead
  • C Establish access based on seniority level within the organization
  • D Implement role-based access control aligned with job functions and duties ✓ Correct
Explanation

Role-based access control (RBAC) ensures users have only the access necessary for their job functions, supporting both security and operational needs.

Q31 Medium

Which of the following best represents a proactive security management approach rather than a reactive one?

  • A Conducting regular vulnerability assessments and threat modeling before incidents occur ✓ Correct
  • B Responding to security alerts generated by monitoring systems
  • C Implementing patches immediately after public vulnerability disclosures
  • D Investigating security breaches after they have impacted the organization
Explanation

Threat modeling and regular vulnerability assessments are proactive measures taken before incidents, while investigations and patch responses are reactive to discovered issues.

Q32 Medium

An information security manager is evaluating whether to implement a security control that would reduce risk by 30% but would significantly impact user productivity. What is the most appropriate approach?

  • A Implement the control immediately as risk reduction is the only priority
  • B Conduct a cost-benefit analysis and present findings to stakeholders for informed decision-making ✓ Correct
  • C Delay implementation until a less intrusive alternative is found
  • D Reject the control as productivity concerns outweigh security benefits
Explanation

Security decisions require balancing risk reduction against business impact; stakeholders should make informed decisions based on comprehensive cost-benefit analysis.

Q33 Medium

Which framework is most commonly referenced for establishing information security governance across international organizations?

  • A ISO/IEC 27001 and ISO/IEC 27002 ✓ Correct
  • B PCI DSS exclusively
  • C NIST Cybersecurity Framework only
  • D HIPAA Privacy Rule
Explanation

ISO/IEC 27001 and 27002 are internationally recognized standards for information security management systems and controls, applicable across industries and regions.

Q34 Hard

In analyzing the business impact of a potential security incident, which scenario would typically have the highest priority for mitigation?

  • A Loss of access to non-critical internal communication systems for 2 hours
  • B Unauthorized access to a test environment containing anonymized data
  • C Temporary degradation of a secondary backup system with no immediate customer impact
  • D Compromise of customer payment information affecting thousands of transactions with potential legal liability ✓ Correct
Explanation

Scenarios with high financial impact, legal liability, and broad customer effects warrant highest priority mitigation due to significant business consequences.

Q35 Hard

Which approach to security culture development is most effective for sustainable, long-term behavioral change?

  • A Conducting security awareness campaigns exclusively during incident response
  • B Annual mandatory security training with enforcement through disciplinary action
  • C Publishing security policies and expecting employees to self-educate
  • D Integrating security awareness into daily operations, leadership modeling, and continuous reinforcement ✓ Correct
Explanation

Sustainable security culture requires ongoing reinforcement, leadership commitment, and integration into daily work rather than isolated training events.

Q36 Hard

When conducting a third-party risk assessment, which factor is LEAST important in determining the level of scrutiny required?

  • A The potential business impact if the vendor fails to deliver
  • B The sensitivity level of data the vendor will access
  • C The vendor's existing security certifications and controls
  • D The vendor's industry and geographic location only ✓ Correct
Explanation

While industry and location provide some context, the critical factors are data sensitivity, existing controls, and business impact—not location or industry alone.

Q37 Hard

An organization is implementing a business continuity plan that includes backup processing sites. Which consideration is most critical for ensuring plan effectiveness?

  • A Ensuring the backup site is located at least 100 miles from the primary facility
  • B Purchasing backup hardware identical to primary systems
  • C Documenting all procedures in a comprehensive manual stored at the backup site
  • D Conducting regular testing and exercises to validate the plan's actual functionality ✓ Correct
Explanation

Regular testing and exercises are critical to identify gaps and ensure the plan actually functions when needed; untested plans often fail during real incidents.

Q38 Medium

Which type of security control is exemplified by requiring multi-factor authentication for privileged account access?

  • A Detective control
  • B Compensating control
  • C Preventive control ✓ Correct
  • D Corrective control
Explanation

Multi-factor authentication prevents unauthorized access by adding additional authentication factors before access is granted, functioning as a preventive control.

Q39 Hard

An information security manager discovers that 40% of critical servers lack current patch management. What is the most appropriate immediate action?

  • A Implement compensating controls without patching the systems
  • B Schedule patches during the next quarterly maintenance window
  • C Accept the risk as a normal operational condition
  • D Assess risk exposure, prioritize critical patches, and develop an urgent remediation plan with business stakeholders ✓ Correct
Explanation

Unpatched critical systems represent significant risk; immediate risk assessment and urgent remediation planning with stakeholders is appropriate before exploitation occurs.

Q40 Medium

Which of the following BEST describes the relationship between information security strategy and business strategy?

  • A Information security strategy and business strategy are parallel but unrelated initiatives
  • B Information security strategy must be aligned with and support business objectives and goals ✓ Correct
  • C Business strategy determines all information security decisions without input from security teams
  • D Information security strategy should be developed independently of business objectives
Explanation

Effective information security strategy is integrated with and supports business objectives, enabling secure business operations rather than imposing unrelated requirements.

Q41 Hard

In security metrics and key performance indicators (KPIs), which metric would be MOST useful for assessing the maturity of an organization's incident response program?

  • A Annual budget allocated to incident response
  • B Average time to detect and respond to critical incidents with trends over time ✓ Correct
  • C Number of incident response team members employed
  • D Total number of security incidents reported per month
Explanation

Time to detect and respond indicates actual program effectiveness and improvement trends, whereas incident volume, staffing, and budget don't reflect true capability or maturity.

Q42 Easy

Which regulatory framework is specifically designed to protect the privacy of health information in the United States?

  • A HIPAA (Health Insurance Portability and Accountability Act) ✓ Correct
  • B NIST Cybersecurity Framework
  • C PCI DSS (Payment Card Industry Data Security Standard)
  • D GDPR (General Data Protection Regulation)
Explanation

HIPAA specifically governs the privacy, security, and breach notification of protected health information (PHI) in the United States healthcare industry.

Q43 Medium

An organization is considering cloud migration for its critical applications. Which security assessment should be prioritized BEFORE migration occurs?

  • A Disaster recovery testing in the cloud environment
  • B Post-migration performance testing and optimization
  • C User acceptance testing of cloud-based systems
  • D Cloud provider security controls evaluation and shared responsibility model clarification ✓ Correct
Explanation

Understanding the cloud provider's controls and clarifying the shared responsibility model is essential before migration to ensure adequate security posture is maintained.

Q44 Medium

When establishing information security policies, what is the primary purpose of a baseline standard regarding acceptable password complexity requirements?

  • A To ensure all passwords are identical across the organization
  • B To establish consistent minimum requirements that reduce the risk of unauthorized access through weak passwords ✓ Correct
  • C To make it impossible for users to remember their passwords
  • D To eliminate the need for other security controls
Explanation

Password complexity standards establish minimum requirements across the organization to reduce vulnerability to brute force and dictionary attacks.

Q45 Medium

Which of the following scenarios best exemplifies the principle of segregation of duties in financial systems?

  • A All financial personnel having identical system access and permissions
  • B One employee authorized to request, approve, and reconcile all financial transactions
  • C Financial processes requiring no approval steps to improve efficiency
  • D Different individuals responsible for requesting, approving, and reconciling financial transactions ✓ Correct
Explanation

Segregation of duties requires different individuals to handle different phases of critical transactions to prevent fraud and error through independent verification.

Q46 Medium

An organization experiences a significant data breach affecting customer personal information. Which action should be prioritized alongside immediate incident response?

  • A Focusing entirely on internal investigation before considering external notifications
  • B Notifying shareholders exclusively before informing regulatory bodies
  • C Maximizing delay before notifying affected individuals to minimize panic
  • D Determining breach scope and notifying affected parties within legally required timeframes ✓ Correct
Explanation

Breach notification laws require timely notification of affected individuals and regulators; determining scope and following legal requirements are critical parallel actions.

Q47 Hard

Which information security management practice is most critical for reducing the likelihood of successful social engineering attacks against an organization?

  • A Developing and maintaining a strong security culture through ongoing awareness and training ✓ Correct
  • B Restricting internet access to critical systems only
  • C Installing advanced firewall technology throughout the network
  • D Implementing biometric authentication on all systems
Explanation

Social engineering targets human vulnerabilities; a security culture emphasizing awareness, skepticism, and proper procedures is most effective against these attacks.

Q48 Hard

In the context of security architecture, which principle suggests that systems should be designed so that if a security mechanism fails, the system should default to a state that denies rather than grants access?

  • A Least privilege
  • B Defense in depth
  • C Zero trust
  • D Fail secure ✓ Correct
Explanation

Fail secure (or fail-closed) ensures that when mechanisms fail, access is denied rather than granted, preventing unauthorized access during unexpected failures.

Q49 Medium

Which of the following best describes the primary difference between a vulnerability and a threat in risk management?

  • A Threats are technical flaws while vulnerabilities are only policy violations
  • B Vulnerabilities are threats that have already caused damage to the organization
  • C There is no meaningful distinction between vulnerabilities and threats
  • D A vulnerability is a weakness; a threat is an entity or force that could exploit that weakness ✓ Correct
Explanation

Vulnerabilities are exploitable weaknesses in systems or controls, while threats are potential attackers or forces that could exploit those vulnerabilities.

Q50 Medium

When prioritizing security investments, an organization should PRIMARILY focus on protecting which types of assets?

  • A Assets that are easiest to protect from a technical standpoint
  • B All IT assets equally regardless of criticality or business value
  • C Only the most technically sophisticated systems available
  • D Assets that are critical to business operations and contain valuable or sensitive information ✓ Correct
Explanation

Security investments should prioritize assets critical to business continuity and those containing sensitive or high-value information to maximize risk reduction.

Q51 Medium

Which of the following best describes the primary purpose of information security governance?

  • A To establish a framework that aligns security with business objectives and ensures accountability for information protection ✓ Correct
  • B To conduct regular penetration testing of all organizational systems
  • C To ensure compliance with ISO 27001 standards exclusively
  • D To implement firewalls and intrusion detection systems across all network segments
Explanation

Information security governance focuses on aligning security initiatives with business goals, establishing accountability structures, and ensuring strategic oversight—not just technical controls. This is a foundational CISM domain concept.

Q52 Medium

An organization experiences a data breach affecting 50,000 customer records. What should be the information security manager's first priority in the immediate aftermath?

  • A Activate the incident response plan and contain the breach to prevent further data loss ✓ Correct
  • B Implement additional security controls to prevent similar incidents
  • C Issue a public statement explaining the security measures in place
  • D Conduct a full forensic investigation to identify the attacker's identity
Explanation

Containment and incident response activation are critical first steps to limit damage. Investigation, communications, and remediation follow after the breach is contained.

Q53 Hard

Which metric would be most appropriate for measuring the effectiveness of a security awareness program?

  • A The total budget allocated to awareness training initiatives
  • B The number of employees who completed training modules within the fiscal year
  • C The percentage of employees who passed the final assessment exam on their first attempt
  • D The reduction in security-related incidents attributable to human error over time ✓ Correct
Explanation

Measuring the reduction in human error incidents demonstrates actual behavioral change and program effectiveness, whereas completion rates and exam scores only measure participation and knowledge recall.

Q54 Hard

An information security manager is designing a risk assessment methodology. Which approach would be most suitable for evaluating risks across a large, complex organization with diverse asset types?

  • A Quantitative risk assessment exclusively, calculating Annualized Loss Expectancy (ALE) for every asset
  • B Qualitative risk assessment using standardized scoring matrices with defined probability and impact levels
  • C Automated risk assessment using machine learning without human involvement or validation
  • D A hybrid approach combining both quantitative and qualitative methods based on asset criticality and available data ✓ Correct
Explanation

A hybrid approach leverages the strengths of both methods: quantitative precision for high-value assets and qualitative judgment where data is limited, making it most practical for complex environments.

Q55 Medium

Which of the following is a key responsibility of the information security manager regarding third-party risk management?

  • A Requiring all vendors to obtain ISO 27001 certification before engagement
  • B Conducting annual penetration tests on all vendor systems and networks
  • C Ensuring that all vendors use identical security controls as the organization
  • D Establishing security requirements, evaluating vendor compliance, and maintaining ongoing oversight of third-party risks ✓ Correct
Explanation

Third-party risk management involves defining security expectations, assessing vendor compliance against those requirements, and continuously monitoring risk—not mandating specific certifications or identical controls.

Q56 Easy

What is the primary objective of a Business Continuity Plan (BCP) in the context of information security?

  • A To ensure critical business functions can be restored or maintained within acceptable timeframes after a disruption ✓ Correct
  • B To eliminate all potential security threats before they occur
  • C To provide detailed technical specifications for all IT infrastructure components and their redundancy
  • D To reduce the organization's insurance premiums by demonstrating preparedness
Explanation

A BCP focuses on ensuring business resilience by defining recovery objectives (RTO/RPO) and procedures to restore critical operations, which is essential for information security continuity.

Q57 Medium

An organization is evaluating whether to implement a new enterprise resource planning (ERP) system. From a security perspective, at which stage should the information security manager become involved in this decision-making process?

  • A During the vendor selection and requirements definition phase, before contracts are finalized ✓ Correct
  • B During the post-implementation review to identify any security gaps that need remediation
  • C Only during the security testing phase immediately before go-live
  • D After the system is purchased, during the implementation phase only
Explanation

Early involvement in vendor selection and requirements definition allows security considerations to influence purchasing decisions and contract terms, preventing costly rework later. This aligns with secure development lifecycle principles.

Q58 Medium

Which of the following best represents a limitation of relying solely on technical security controls to protect information assets?

  • A Technical controls prevent all types of security breaches if implemented correctly by qualified personnel
  • B Technical controls require constant updates and patches that disrupt normal business operations
  • C Technical controls are too expensive for most mid-sized organizations to implement comprehensively
  • D Technical controls cannot detect insider threats or social engineering attacks that exploit human vulnerabilities ✓ Correct
Explanation

Technical controls alone cannot address human-centric risks like social engineering, insider threats, or policy violations; they must be complemented by administrative and physical controls, plus security awareness.

Q59 Hard

An information security manager discovers that sensitive data classification standards are not consistently applied across different departments. What would be the most appropriate first action to address this issue?

  • A Implement automated data discovery tools to classify all data without department involvement
  • B Conduct a detailed audit to identify all non-compliant data and move it to secure storage pending reclassification
  • C Immediately impose penalties on departments that have not complied with classification standards
  • D Develop a comprehensive, organization-wide data classification policy and conduct training to ensure consistent understanding and application ✓ Correct
Explanation

Establishing clear policy and providing education creates sustainable compliance through shared understanding, whereas punitive measures, automated approaches without context, or reactive audits don't address the root cause of inconsistency.

Q60 Hard

Which of the following scenarios represents the greatest challenge for an information security manager in implementing a zero-trust security model within a legacy organization?

  • A Legacy systems and applications may not support continuous authentication and authorization mechanisms required by zero-trust principles ✓ Correct
  • B Zero-trust models are incompatible with cloud-based services and cannot be implemented in hybrid environments
  • C The cost of implementing zero-trust architecture exceeds the organization's annual IT budget
  • D Employees will inevitably resist any change to their access patterns regardless of security benefits
Explanation

Legacy systems often lack the capability for continuous verification and fine-grained access control that zero-trust requires, necessitating significant technical remediation, whereas costs and resistance can be managed through planning and change management.

Ready to test your knowledge?

You've reviewed all 60 questions. Take the interactive practice exam to simulate the real test environment.

▶ Start Practice Exam — Free