CISM Practice Test.
159 free practice questions with answers and explanations.
No signup required. Choose a topic and review each answer.
Start practicing →About these practice questions
These are original study questions written from published exam objectives—not recalled, copied, or confidential live-exam items. Always confirm current coverage with the official sources linked on this page.
Exam format and study resources
The CISM is administered by ISACA, with 150 scored questions, a 4 hours time limit and a 450 on a scale of 200 to 800 result.
This free CISM practice test has 159 original questions written to ISACA's official content outline, last checked against it on July 18, 2026. Every question shows a worked explanation, and nothing here requires a signup.
As of 2026, the CISM exam fee is $760 (non-members; $575 ISACA members).
Browse all questions & answers
1. A candidate wants to know how the CISM exam is delivered. Which of the following correctly describes the available delivery modes?
- A. Only in-person at a test center, with no remote option
- B. Candidates may choose either an in-person test center or an online remote-proctored option
- C. Only through a mobile app with no proctoring
- D. Exclusively through employer-sponsored on-site testing
Show answer & explanation
Answer: B
Candidates select between an in-person test center delivery or an online remote-proctored exam, giving flexibility in how they sit for the CISM exam. There is a remote option, so in-person only (A) is incorrect. There is no unproctored mobile app option (C). Testing is not restricted to employer-sponsored on-site sessions (D).2. Which of the following BEST demonstrates that an organization's information security strategy is aligned with business objectives?
- A. The security budget increases every fiscal year
- B. Security initiatives are prioritized and funded based on their support of documented business goals
- C. The security team reports directly to the CEO
- D. All security policies have been reviewed within the past 12 months
Show answer & explanation
Answer: B
Strategic alignment means security decisions and investments are driven by business objectives, which is best evidenced by prioritization and funding tied to those goals. A growing budget (A) does not prove alignment, only spending. Reporting structure (C) may support governance but does not itself demonstrate alignment. Policy review cadence (D) reflects maintenance, not strategic linkage.3. An information security steering committee is being formed. Which composition BEST supports effective governance oversight?
- A. Only members of the IT department, since they understand the technical risks
- B. Senior representatives from business units, IT, legal, HR, and risk management
- C. External auditors exclusively, to ensure independence
- D. The information security manager alone, to avoid conflicting priorities
Show answer & explanation
Answer: B
A steering committee needs cross-functional representation from business and support functions so that security decisions reflect enterprise-wide risk appetite and objectives, which is a core governance principle. Limiting membership to IT (A) ignores business context. External auditors only (C) removes internal accountability. A single individual (D) is not a committee and lacks diverse input.4. An organization's information security policy has not been updated in five years, though the business has since adopted cloud computing and remote work extensively. What is the GREATEST risk of this situation?
- A. Employees may not have read the policy
- B. The policy no longer reflects the current risk environment, leaving gaps in governance and control coverage
- C. The policy document is a different font than newer documents
- D. Legal counsel was not involved in the original drafting
Show answer & explanation
Answer: B
Governance frameworks and policies must evolve with the business and technology landscape; an outdated policy fails to address new risk domains like cloud and remote access, creating real control gaps. Whether employees read it (A) is a separate awareness issue. Formatting (C) is irrelevant. Legal involvement in drafting (D) does not address the current relevance problem.5. During a risk assessment, an information security manager identifies a legacy application with a known vulnerability, but the business unit refuses to fund remediation because the system will be decommissioned in six months. What is the MOST appropriate next step?
- A. Force decommissioning immediately regardless of business needs
- B. Document the risk, ensure it is formally accepted by an authorized business owner, and implement compensating controls if feasible
- C. Ignore the finding since the system will soon be retired
- D. Escalate directly to external regulators
Show answer & explanation
Answer: B
Risk management requires that residual risk be formally accepted by someone with the authority to do so, and compensating controls should be applied where practical to reduce exposure in the interim. Forcing decommissioning (A) is outside the security manager's authority and may harm the business. Ignoring the finding (C) abdicates the manager's responsibility to track and report risk. Escalating to regulators (D) is disproportionate for an internally manageable risk decision.6. When calculating risk during a quantitative risk assessment, which formula BEST represents the relationship between the key variables typically used?
- A. Risk = Asset Value / Threat Frequency
- B. Risk = Likelihood of a threat exploiting a vulnerability × Impact of that occurrence
- C. Risk = Number of controls implemented
- D. Risk = Cost of the asset minus insurance coverage
Show answer & explanation
Answer: B
Risk is fundamentally a function of the likelihood that a threat will exploit a vulnerability and the resulting impact, which is the basis of both qualitative and quantitative risk models. Dividing asset value by frequency (A) is not a recognized risk formula. Counting controls (C) measures mitigation effort, not risk itself. Subtracting insurance from cost (D) relates to financial risk transfer, not the underlying risk calculation.7. An organization decides to purchase cyber insurance to address the financial impact of a potential ransomware attack rather than investing further in prevention controls. This is an example of which risk treatment option?
- A. Risk avoidance
- B. Risk transfer
- C. Risk acceptance
- D. Risk mitigation
Show answer & explanation
Answer: B
Purchasing insurance shifts the financial consequence of a risk event to a third party, which is the definition of risk transfer. Risk avoidance (A) would mean eliminating the activity that creates the risk entirely. Risk acceptance (C) means retaining the risk without further action or transfer. Risk mitigation (D) involves reducing likelihood or impact through controls, which the organization explicitly chose not to do further.8. A risk register lists a high-likelihood, high-impact risk with no assigned owner or treatment plan. What is the BEST immediate action for the information security manager?
- A. Delete the entry since it lacks an owner
- B. Assign an accountable risk owner and drive development of a treatment plan with a target date
- C. Wait until the next annual risk assessment cycle
- D. Transfer the risk to the audit department by default
Show answer & explanation
Answer: B
A high-likelihood, high-impact risk without ownership represents a governance gap that must be closed by assigning accountability and driving a concrete treatment plan promptly, given the severity. Deleting the entry (A) hides the risk rather than managing it. Waiting a full cycle (C) is inappropriate given the severity. Defaulting ownership to audit (D) is inappropriate since audit provides independent assurance, not risk ownership.9. Which of the following is the MOST important reason to perform periodic reassessment of previously identified and accepted risks?
- A. To satisfy an arbitrary documentation requirement
- B. Because the threat landscape, asset value, and control environment can change, altering the risk's likelihood or impact over time
- C. To reduce the size of the risk register
- D. Because auditors always require it regardless of business context
Show answer & explanation
Answer: B
Risk is dynamic; changes in threats, business context, asset criticality, or controls can shift a previously acceptable risk into an unacceptable one, so periodic reassessment ensures acceptance decisions remain valid. Documentation for its own sake (A) misses the substantive purpose. Reducing register size (C) is not a legitimate driver of reassessment. Framing it purely as an audit requirement (D) ignores the risk-management rationale that underlies the practice.10. An organization is evaluating two risk treatment options for a vulnerable legacy system: patching it now for a moderate cost, or replacing it next year at a much higher cost with lower risk reduction in the interim. What should PRIMARILY drive this decision?
- A. The personal preference of the IT manager
- B. A cost-benefit analysis comparing the risk reduction achieved against the cost and timing of each option
- C. Whichever option requires less paperwork
- D. The vendor offering the largest discount
Show answer & explanation
Answer: B
Risk treatment decisions should be grounded in a cost-benefit analysis that weighs the reduction in risk exposure against implementation cost and timeline, ensuring resources are allocated efficiently. Personal preference (A) is subjective and unaccountable. Minimizing paperwork (C) is an administrative convenience, not a risk-based criterion. Vendor discounts (D) should not override a proper risk-based evaluation.11. A company's risk appetite statement specifies that it will not accept any risk with the potential for regulatory fines exceeding a defined threshold. A newly identified risk exceeds this threshold but is inexpensive to remediate. What should the information security manager recommend?
- A. Accept the risk since remediation cost is a separate consideration
- B. Remediate the risk to bring it within the defined risk appetite
- C. Escalate to the board only if the fine is actually imposed
- D. Transfer all responsibility to the compliance department without further security involvement
Show answer & explanation
Answer: B
When a risk exceeds the organization's documented risk appetite, and remediation is feasible and low-cost, treatment should be pursued to bring the risk within acceptable bounds, which is the direct purpose of a risk appetite statement. Accepting it anyway (A) violates the organization's own stated risk tolerance. Waiting for an actual fine (C) is reactive rather than proactive risk management. Fully offloading responsibility (D) ignores the security manager's role in risk treatment recommendations.12. An information security program is being designed for a mid-sized organization. Which of the following BEST reflects a properly structured security program?
- A. A single antivirus product deployed across all endpoints
- B. A set of coordinated policies, standards, processes, and controls aligned to the security strategy and risk appetite
- C. An annual penetration test with no other ongoing activity
- D. A dedicated incident response team with no supporting policies
Show answer & explanation
Answer: B
An information security program is the coordinated set of policies, standards, processes, and controls that implement the strategy and manage risk to an acceptable level; it is holistic, not a single tool or event. A single antivirus deployment (A) is one control, not a program. An isolated annual pen test (C) is a point-in-time activity, not an ongoing program. A response team without governing policies (D) lacks the structural foundation a program requires.13. Which of the following is the PRIMARY purpose of a security awareness training program within an information security program?
- A. To satisfy a checkbox requirement for annual audits
- B. To reduce human-related risk by ensuring employees understand their security responsibilities and recognize common threats
- C. To replace the need for technical controls
- D. To provide a source of revenue through internal training fees
Show answer & explanation
Answer: B
Awareness training exists to reduce the human element of risk by equipping staff to recognize threats like phishing and understand their security obligations, directly supporting the program's risk-reduction goals. Treating it as a mere audit checkbox (A) misses its substantive purpose. It does not replace technical controls (C); it complements them. Internal revenue generation (D) is not a legitimate program objective.14. An information security manager is selecting metrics to report program performance to the board. Which characteristic is MOST important for these metrics to have?
- A. They should be highly technical to demonstrate the team's expertise
- B. They should be meaningful to a business audience and tied to risk reduction or business impact
- C. They should change every quarter to appear dynamic
- D. They should focus solely on the number of security incidents, regardless of severity
Show answer & explanation
Answer: B
Board-level metrics must translate security activity into business-relevant terms, such as risk reduction or impact avoidance, so non-technical leadership can make informed decisions. Overly technical metrics (A) fail to communicate to the intended audience. Constantly changing metrics (C) prevent meaningful trend analysis. Raw incident counts without severity context (D) can be misleading and do not convey actual risk posture.15. A security program includes a control requiring segregation of duties between developers and production system administrators. What is the PRIMARY security benefit of this control?
- A. It reduces the number of employees needed
- B. It reduces the risk of unauthorized or unreviewed changes being introduced into production
- C. It eliminates the need for change management processes
- D. It guarantees compliance with all data privacy regulations
Show answer & explanation
Answer: B
Segregation of duties between development and production administration prevents a single individual from introducing and deploying unreviewed or malicious changes, reducing fraud and error risk. It does not reduce headcount needs (A) as a security rationale. It does not eliminate change management (C); rather it complements it. It also does not guarantee full regulatory compliance (D), which depends on many other controls.16. An organization is implementing a data classification scheme as part of its security program. What is the MOST important reason for classifying data BEFORE applying protective controls?
- A. Classification is required only for marketing purposes
- B. It ensures that controls are proportionate to the sensitivity and value of the data, avoiding both under- and over-protection
- C. It allows the organization to charge different prices for data storage
- D. It removes the need for encryption on all data
Show answer & explanation
Answer: B
Classification allows security resources and controls to be applied proportionately, protecting highly sensitive data appropriately while avoiding wasteful over-controlling of low-sensitivity data. It has no marketing purpose (A). It is not a billing mechanism (C). It does not remove the need for encryption (D); rather it helps determine where encryption and other controls are most necessary.17. A vulnerability management program consistently identifies critical vulnerabilities that remain unpatched for over six months due to competing IT priorities. What is the BEST course of action for the information security manager?
- A. Accept the delays as normal since IT is busy
- B. Work with IT leadership to establish and enforce risk-based remediation SLAs tied to vulnerability severity
- C. Personally patch the systems without IT involvement
- D. Stop scanning for vulnerabilities to avoid generating findings IT cannot address
Show answer & explanation
Answer: B
Establishing enforceable, risk-based service level agreements for remediation aligns IT priorities with actual risk severity and creates accountability, addressing the root cause of chronic delays. Simply accepting delays (A) allows unacceptable risk exposure to persist. Bypassing IT to patch directly (C) violates change control and role boundaries. Stopping scans (D) hides risk rather than managing it and is a serious governance failure.18. When integrating security requirements into the systems development life cycle (SDLC), at which phase is it MOST cost-effective to identify and address security requirements?
- A. During production after deployment
- B. During the requirements and design phases, before development begins
- C. Only during user acceptance testing
- D. During the post-incident review after a breach
Show answer & explanation
Answer: B
Addressing security requirements early, during requirements gathering and design, is the most cost-effective point because defects and gaps are far cheaper to fix before code is written than after deployment. Fixing issues in production (A) is significantly more expensive and risky. Limiting security review to UAT (C) misses architectural issues that are hard to retrofit. Waiting for a post-incident review (D) means damage has already occurred.19. An information security manager is developing key performance indicators (KPIs) for the vulnerability management process. Which KPI provides the MOST meaningful insight into program effectiveness?
- A. Total number of vulnerability scans run per month
- B. Average time to remediate critical vulnerabilities compared to defined SLA targets
- C. Number of security tools purchased for scanning
- D. Number of employees on the vulnerability management team
Show answer & explanation
Answer: B
Time-to-remediate against SLA targets directly measures whether the organization is closing high-risk exposures promptly, which is the actual goal of vulnerability management. Scan counts (A) measure activity, not outcomes. Tool purchases (C) and headcount (D) are inputs/resources, not indicators of program effectiveness.20. Which of the following BEST describes the role of an information security program in supporting business continuity?
- A. The security program is entirely separate from business continuity and should not interact with it
- B. The security program provides controls and processes, such as backup protection and access continuity, that support the organization's ability to maintain and recover critical operations
- C. Business continuity planning is solely the responsibility of facilities management
- D. Security controls should be disabled during a declared disaster to speed up recovery
Show answer & explanation
Answer: B
An effective security program integrates with business continuity by protecting the confidentiality, integrity, and availability of the resources and processes needed for recovery, such as securing backups and ensuring continued access controls. Treating the two as unrelated (A) ignores this necessary integration. Continuity planning is a cross-functional responsibility, not exclusively facilities' domain (C). Disabling controls during a disaster (D) increases risk exactly when the organization is most vulnerable.21. Which of the following is the MOST important consideration when selecting security controls to include in an information security program?
- A. Selecting the newest technology available regardless of fit
- B. Ensuring controls are proportionate to identified risks and aligned with business and regulatory requirements
- C. Selecting controls solely based on vendor marketing claims
- D. Choosing the least expensive controls available
Show answer & explanation
Answer: B
Controls should be selected based on a proportionate response to actual identified risks and must satisfy applicable business and regulatory requirements, ensuring resources are well spent and compliance obligations are met. Chasing the newest technology (A) without a risk basis wastes resources. Relying on vendor marketing (C) is not a sound evaluation method. Choosing purely on cost (D) ignores whether the control actually addresses the risk.22. During an active ransomware incident, which action should the incident response team take FIRST after detecting the compromise?
- A. Immediately notify all customers before understanding the scope
- B. Contain the affected systems to prevent further spread while preserving evidence
- C. Wait for the next scheduled incident review meeting
- D. Restore from backups without investigating the cause
Show answer & explanation
Answer: B
Containment is the priority immediately after detection, to stop lateral spread and limit damage, while also preserving evidence for forensic analysis and root-cause determination. Notifying customers before scope is understood (A) risks inaccurate or premature communication. Waiting for a scheduled meeting (C) delays a time-critical response. Restoring from backups without investigation (D) risks reintroducing the same vulnerability or malware.23. An organization's incident response plan has not been tested in three years. What is the GREATEST risk this poses?
- A. The plan document may use outdated formatting
- B. Response roles, contact information, and procedures may be outdated or ineffective when a real incident occurs
- C. The plan will automatically expire and become legally invalid
- D. Employees will refuse to follow the plan regardless of its content
Show answer & explanation
Answer: B
Untested plans risk containing outdated contact details, obsolete procedures, or unaddressed changes to systems and personnel, meaning the response team may be unprepared or ineffective during an actual incident. Formatting (A) is a cosmetic concern. Plans do not have automatic legal expiration (C). Employee willingness to follow the plan (D) is unrelated to whether the plan's content itself has become stale.24. Which of the following BEST defines the purpose of a post-incident review (lessons learned) process?
- A. To assign blame to individuals involved in the incident
- B. To identify root causes and process improvements to reduce the likelihood or impact of similar future incidents
- C. To close the incident ticket as quickly as possible without further analysis
- D. To satisfy a public relations requirement only
Show answer & explanation
Answer: B
Post-incident reviews exist to identify root causes and drive process, control, or training improvements that reduce recurrence or impact of similar incidents, feeding continuous improvement of the program. Assigning blame (A) undermines a constructive review culture and discourages honest reporting. Rushing to close tickets (C) forfeits the value of the analysis. Treating it as merely a PR exercise (D) misses its operational purpose.25. During incident response, which of the following is MOST important for maintaining the integrity of digital evidence that may later support legal action?
- A. Allowing any staff member to access and copy the evidence as needed
- B. Maintaining a documented chain of custody for all evidence collected
- C. Deleting evidence once the incident is resolved to save storage space
- D. Storing evidence on the affected system itself for convenience
Show answer & explanation
Answer: B
A documented chain of custody establishes who handled evidence, when, and how, which is essential to prove the evidence has not been altered and is admissible in legal proceedings. Unrestricted access (A) risks tampering or contamination. Deleting evidence (C) destroys material that may be needed later. Storing evidence on the compromised system (D) risks further tampering or loss and is poor forensic practice.26. An organization experiences a data breach involving customer personal information. Which factor is MOST important in determining the appropriate notification timeline and recipients?
- A. The personal preference of the CEO
- B. Applicable legal and regulatory breach notification requirements based on the data and jurisdictions involved
- C. Whichever timeline is easiest for the marketing department
- D. The size of the IT budget for the current year
Show answer & explanation
Answer: B
Breach notification obligations are governed by specific legal and regulatory requirements that vary by data type and jurisdiction, and these requirements dictate timelines and required recipients, making compliance the primary driver. Executive preference (A), marketing convenience (C), and budget size (D) are not valid bases for determining legally mandated notification obligations.27. Which of the following is the PRIMARY benefit of classifying incidents by severity level as part of an incident management process?
- A. It allows the security team to ignore lower severity events entirely
- B. It ensures response resources, escalation, and communication are proportionate to the incident's actual business impact
- C. It reduces the total number of incidents that occur
- D. It eliminates the need for a formal incident response plan
Show answer & explanation
Answer: B
Severity classification allows the organization to allocate response effort, escalation paths, and communication proportionately, ensuring critical incidents get appropriate urgency while minor ones do not consume excessive resources. It does not mean ignoring lower-severity events (A), which still require some response. It has no effect on the actual occurrence rate of incidents (C). It also does not replace the need for a formal response plan (D); rather, severity levels are typically defined within that plan.28. An organization wants to reduce the mean time to detect (MTTD) security incidents. Which investment would MOST directly support this goal?
- A. Increasing the frequency of security awareness training sessions only
- B. Implementing centralized log monitoring and correlation through a SIEM with defined use cases
- C. Reducing the number of firewalls in the network
- D. Publishing the incident response plan on the company intranet
Show answer & explanation
Answer: B
Centralized log monitoring and correlation, such as through a SIEM with tuned detection use cases, directly improves the organization's ability to detect anomalous or malicious activity faster, reducing MTTD. Awareness training alone (A) helps prevent certain incidents but does not directly improve technical detection speed. Reducing firewalls (C) would likely increase risk, not improve detection. Publishing the plan (D) supports response readiness but does not improve detection capability itself.29. During a multi-day incident affecting critical systems, business executives are demanding hourly technical updates that are consuming significant analyst time needed for containment. What is the BEST way for the incident manager to address this?
- A. Refuse to provide any updates until the incident is fully resolved
- B. Designate a dedicated communications liaison to provide scheduled executive updates, freeing technical staff to focus on response
- C. Allow executives to directly interrupt analysts whenever they want an update
- D. Shut down the incident response effort until executive demands subside
Show answer & explanation
Answer: B
Establishing a dedicated communications liaison role is a standard incident management practice that satisfies stakeholder information needs on a predictable schedule while protecting technical responders' focus on containment and eradication. Refusing all updates (A) damages stakeholder trust and violates governance expectations. Allowing direct interruptions (C) worsens the productivity problem. Halting response efforts (D) is an unacceptable escalation that increases organizational harm.30. Which of the following BEST illustrates the difference between an information security incident and a disaster recovery (DR) event?
- A. An incident always requires invoking the full DR plan
- B. An incident is a security-relevant event requiring investigation and response, while DR specifically addresses recovery of IT services after significant disruption
- C. There is no meaningful difference between the two terms
- D. DR events are always caused by malicious actors, while incidents are always accidental
Show answer & explanation
Answer: B
An information security incident is any event that threatens confidentiality, integrity, or availability requiring investigation and response, whereas disaster recovery specifically addresses restoring IT services after a significant disruption, which may or may not stem from a security incident. Not every incident requires full DR invocation (A); many are handled without disrupting service. The terms are not interchangeable (C). DR events are not always malicious, nor are incidents always accidental (D); both can stem from a range of causes.31. An information security manager is defining recovery time objectives (RTOs) for critical systems as part of incident and continuity planning. What should PRIMARILY determine the RTO for a given system?
- A. The preference of the system administrator
- B. The maximum tolerable downtime the business can withstand before unacceptable impact occurs
- C. The age of the hardware supporting the system
- D. The number of support tickets filed for the system last year
Show answer & explanation
Answer: B
RTO should be derived from a business impact analysis reflecting the maximum period the business can tolerate the system being unavailable before harm becomes unacceptable, ensuring recovery planning matches actual business need. Administrator preference (A) is subjective and not risk-based. Hardware age (C) may affect feasibility of recovery but does not define the acceptable downtime threshold. Historical ticket volume (D) reflects support demand, not business criticality.32. An organization is evaluating whether to launch a new product feature that would require processing highly sensitive data in a jurisdiction with weak data protection enforcement and no feasible compensating controls. Which risk treatment option is the organization applying if it decides not to launch the feature at all?
- A. Risk mitigation.
- B. Risk acceptance.
- C. Risk avoidance.
- D. Risk transfer.
Show answer & explanation
Answer: C
Choosing not to proceed with an activity because the associated risk cannot be adequately reduced or offset is the definition of risk avoidance, which eliminates the risk by eliminating the activity itself rather than reducing its likelihood or impact, shifting it to another party, or knowingly retaining it. This differs from mitigation, which would involve implementing controls to reduce the risk while still launching the feature.33. Two independent risk assessments of the same critical system, conducted using different methodologies, produce materially different risk ratings: one rates the system as high risk and the other as moderate risk. Executive leadership is preparing to make a funding decision based on these results. What should the information security manager do FIRST?
- A. Present both ratings to leadership and let them choose which one to believe.
- B. Reconcile the differences by examining the underlying assumptions, scope, and data of each assessment before presenting a unified recommendation.
- C. Discard both assessments and postpone the funding decision indefinitely.
- D. Adopt the higher rating automatically, since it represents the more conservative outcome.
Show answer & explanation
Answer: B
When two assessments of the same system disagree, the underlying cause is almost always a difference in scope, assumptions, threat data, or methodology, and understanding that discrepancy is essential before presenting leadership with a reliable, unified view; simply picking the higher rating by default, letting leadership arbitrate a methodological dispute, or postponing the decision indefinitely all avoid the analytical work needed to produce a defensible, accurate recommendation for a critical funding decision.34. A new employee is granted access rights matching only the specific systems and data needed to perform their job duties, rather than broad administrative access. This reflects which security principle?
- A. Least privilege.
- B. Defense in depth.
- C. Non-repudiation.
- D. Separation of environments.
Show answer & explanation
Answer: A
Granting access limited strictly to what is necessary to perform a specific role is the definition of the least privilege principle, which reduces the potential impact of a compromised account or insider misuse by minimizing the scope of access any single user holds, unlike defense in depth, which concerns layered controls, or non-repudiation, which concerns the ability to prove an action occurred.35. A security monitoring tool generates a very high volume of alerts, the vast majority of which analysts determine are false positives after investigation. What is the MOST significant operational risk this creates?
- A. The organization will need to purchase additional monitoring licenses.
- B. Alert fatigue may cause analysts to overlook or delay response to a genuine security event among the noise.
- C. The tool will automatically be disabled by the vendor.
- D. False positives always indicate the tool is fundamentally unsuitable for use.
Show answer & explanation
Answer: B
A high volume of false positives creates alert fatigue, where analysts become desensitized to the constant noise and may delay, deprioritize, or entirely miss a genuine security event buried among the false alarms, which is a significant operational risk to the program's actual detection capability. This calls for tuning the tool's rules and thresholds rather than assuming it is unusable or expecting the vendor to disable it.36. A candidate is planning their CISM certification timeline after passing the exam. Which statement about the certification application process is accurate?
- A. Candidates must apply for certification within 5 years of passing the exam
- B. Candidates must apply for certification within 30 days of passing the exam
- C. There is no time limit to apply for certification after passing
- D. Certification is granted automatically the moment the exam is passed
Show answer & explanation
Answer: A
Candidates have a five-year window from their exam pass date to submit their certification application, which is separate from the exam-eligibility registration window. A 30-day limit (B) is incorrect and far too short. There is in fact a defined limit, so it is not unlimited (C). Certification is not automatic (D); candidates must submit an application, including verified work experience, before being certified.37. An organization allows the same individual to both request and approve their own changes to a production firewall configuration. What control principle does this violate?
- A. Data classification.
- B. Segregation of duties, since a single individual should not both initiate and approve a sensitive change without independent oversight.
- C. Least privilege.
- D. Defense in depth.
Show answer & explanation
Answer: B
Segregation of duties requires that critical actions, such as requesting and approving a sensitive production change, be divided between different individuals so that no single person can both initiate and authorize an action without independent review, reducing the risk of unauthorized or erroneous changes going unchecked. While related to least privilege, this scenario specifically concerns the separation of initiating and approving roles rather than the scope of access granted.38. An information security strategy is being developed. What should it be aligned to first?
- A. The organization's business objectives and strategy, so security investment supports what the organization is trying to achieve
- B. The security manager's professional certification syllabus
- C. The controls implemented by industry peers
- D. The latest available security technologies
Show answer & explanation
Answer: A
Alignment to business objectives is what makes a security programme defensible and fundable, because it connects each control to something the organization cares about. Technology-led or peer-led programmes produce capability that may address risks the organization does not have while leaving its actual exposures unaddressed.39. Who should own an information security policy and approve it?
- A. Senior management or the board, since a policy sets organization-wide direction that only that level can mandate
- B. The security operations team that will enforce it
- C. The internal audit function
- D. The external security consultant who drafted it
Show answer & explanation
Answer: A
A policy directs behaviour across the organization, so its authority comes from the level able to require compliance and allocate resources to it. Security operations translates policy into standards and procedures, and audit assesses compliance, so neither can own the policy without conflating direction with execution or assurance.40. How do a policy, a standard, a procedure and a guideline differ in a security documentation hierarchy?
- A. A policy states mandatory direction, a standard specifies mandatory requirements meeting it, a procedure gives step-by-step instructions, and a guideline offers recommended but optional practice
- B. All four are mandatory and differ only in length
- C. A guideline is mandatory and a standard is optional
- D. A procedure sets direction and a policy implements it
Show answer & explanation
Answer: A
The hierarchy separates enduring direction from technology-specific requirements and from the operational steps that change frequently, which is why a policy can survive a technology refresh that rewrites every standard beneath it. Mislabelling a guideline as a standard creates unenforceable expectations, and the reverse creates unnoticed non-compliance.41. A security manager must report programme status to the board. What reporting approach is most effective?
- A. Expressing status in terms of risk to business objectives, trends and decisions required, rather than technical control counts
- B. Providing the raw output of vulnerability scanning tools
- C. Reporting the number of blocked firewall connections
- D. Listing every security incident with full technical detail
Show answer & explanation
Answer: A
A board allocates resources and accepts risk, so it needs exposure relative to appetite, direction of travel and the decisions being asked of it. Volume metrics such as blocked connections measure activity rather than risk and can move in either direction without any change in the organization's actual exposure.42. What does information security governance establish that a security programme alone does not?
- A. The accountability structure, decision rights and oversight that direct the programme and hold it to account
- B. The technical configuration of security tooling
- C. The daily operational response to security alerts
- D. The vendor selection for security products
Show answer & explanation
Answer: A
Governance answers who decides, who is accountable and how performance is overseen, while the programme is the set of activities carried out within that structure. A well-run programme without governance depends on the individuals running it and lacks the mandate to resolve conflicts with business units.43. An organization defines its risk appetite. What role does it play in security decisions?
- A. It sets the threshold above which risk must be treated rather than accepted, making treatment decisions consistent across the organization
- B. It specifies which security products must be purchased
- C. It determines the security team's headcount
- D. It eliminates the need for individual risk assessments
Show answer & explanation
Answer: A
Without a stated appetite, each treatment decision is made on the judgment of whoever is present, producing inconsistency that is invisible until an accepted risk materializes. Appetite gives a common reference point, while tolerance expresses the acceptable variation around it for a specific risk or objective.44. A risk assessment produces an inherent risk rating and a residual risk rating. What is the difference?
- A. Inherent risk is the exposure before considering controls, while residual risk is what remains after existing controls operate as designed
- B. Inherent risk is the risk after treatment and residual is before
- C. Inherent risk applies to external threats and residual to internal ones
- D. The two are the same measure at different points in time
Show answer & explanation
Answer: A
The pairing shows how much protection existing controls actually provide, which is what justifies their cost and identifies where further treatment is needed. Reporting only residual risk hides the dependency on controls whose failure would restore the inherent exposure, which matters when a control is being decommissioned.45. Which risk treatment option is being applied when an organization buys cyber insurance?
- A. Transfer or sharing, since the financial consequence moves to another party while the operational risk remains
- B. Mitigation, since the likelihood of an incident falls
- C. Acceptance, since no action was taken
- D. Avoidance, since the risk no longer applies
Show answer & explanation
Answer: A
Insurance moves financial consequence but leaves likelihood, operational disruption and reputational harm entirely with the organization, which is why it complements rather than replaces controls. The four options are avoid, mitigate, transfer and accept, and clarity about which is being used prevents an insured organization from believing it is protected.46. A quantitative risk analysis estimates annualized loss expectancy. What does that figure represent?
- A. The expected loss per year from a risk, combining the loss per occurrence with how often occurrences are expected
- B. The worst-case loss from a single occurrence
- C. The cost of the controls addressing the risk
- D. The insurance premium for the exposure
Show answer & explanation
Answer: A
Annualized loss expectancy is single loss expectancy multiplied by annualized rate of occurrence, which converts a severity figure and a frequency estimate into a comparable annual number. Comparing it to the annual cost of a control gives a defensible basis for investment, though the frequency estimate is usually the weakest input.47. A control costs more per year than the annualized loss expectancy of the risk it addresses. What does this suggest?
- A. The control is not cost-justified on that risk alone, though qualitative factors such as regulatory obligation or reputational harm may still justify it
- B. The control should always be implemented regardless of cost
- C. The risk assessment must be wrong
- D. The risk should be transferred automatically
Show answer & explanation
Answer: A
Spending more than the expected loss destroys value on a purely financial basis, which is why the comparison is a useful discipline against controls justified by discomfort alone. The qualification matters because regulatory penalties, safety consequences and reputational harm are frequently underrepresented in the loss figure.48. A risk register entry has no named owner. Why is this a significant weakness?
- A. Because without an accountable owner no one is responsible for treating the risk or for the consequences of accepting it, so the entry documents rather than manages it
- B. Because a register cannot be maintained without owners
- C. Because owners are required by all security standards
- D. Because unowned risks are automatically the security manager's
Show answer & explanation
Answer: A
Ownership converts a documented observation into a managed item with someone answerable for the decision taken. The last option is the common failure mode in practice: risks default to the security function, which usually lacks the authority or budget to treat risks arising in business processes it does not control.49. A newly identified threat is added to the risk assessment. What should trigger reassessment of existing risks?
- A. Material change in the threat landscape, business processes, technology or regulation, in addition to a periodic cycle
- B. Only the annual review date
- C. Only a security incident
- D. Only a request from internal audit
Show answer & explanation
Answer: A
A purely calendar-driven assessment is stale by the time it is used in a fast-moving environment, so event-driven triggers must supplement the cycle. Waiting for an incident makes the process reactive by definition, since the incident is the materialization of the risk the assessment was supposed to surface in advance.50. A security programme is being built. What should determine the controls selected?
- A. The risk assessment results and the organization's risk appetite, so controls address assessed exposures at proportionate cost
- B. A complete implementation of every control in a chosen framework
- C. The controls the previous security manager preferred
- D. The products the organization already owns licences for
Show answer & explanation
Answer: A
Frameworks provide a catalogue and a common language, but implementing them exhaustively without reference to assessed risk spends the budget uniformly rather than where exposure is greatest. Existing licences legitimately influence how a control is implemented but should not determine which risks get addressed.51. How do preventive, detective and corrective controls differ in function?
- A. Corrective controls operate before an event
- B. Preventive controls are technical and detective controls are administrative
- C. Detective controls are always stronger than preventive ones
- D. Preventive controls stop an event occurring, detective controls identify that it occurred, and corrective controls restore the state afterward
Show answer & explanation
Answer: D
The three form a defensive sequence, and a programme relying only on prevention has no way of knowing when prevention failed, which is how compromises persist undetected for long periods. Each type appears in technical, administrative and physical forms, so the functional classification is independent of the implementation category.52. A security awareness programme is measured by completion rates. What is the limitation of that metric?
- A. It measures participation rather than behaviour change, so it can be high while susceptibility to social engineering remains unchanged
- B. It cannot be collected reliably
- C. It is prohibited by privacy regulation
- D. It applies only to technical staff
Show answer & explanation
Answer: A
Completion is an input metric and the outcome the programme exists to change is behaviour, which is better approximated by simulated phishing susceptibility, reporting rates and incidents attributable to user action. Measuring only completion produces a programme optimized for attendance.53. A security manager wants to reduce the risk of insider data theft. Which combination addresses it most completely?
- A. Least privilege and segregation of duties, monitoring of sensitive data access, and defined joiner-mover-leaver processes
- B. Perimeter firewall rules and intrusion prevention alone
- C. Antivirus deployment across all endpoints
- D. Annual penetration testing of external systems
Show answer & explanation
Answer: A
Insider risk originates inside the perimeter with legitimate credentials, so perimeter and malware controls are largely irrelevant to it. The effective measures constrain what an insider can reach, detect abnormal access to sensitive data and remove access promptly when roles change or employment ends.54. A security manager introduces a control that materially slows a revenue-generating process. What is the appropriate course?
- A. Quantify the risk reduction against the business impact and present the trade-off to the accountable business owner for a decision
- B. Implement the control regardless, since security takes precedence
- C. Abandon the control, since business operations take precedence
- D. Implement the control without informing the business
Show answer & explanation
Answer: A
Neither function unilaterally outranks the other, and the accountable owner of the business objective is the party positioned to weigh the trade-off. A security manager who imposes controls without that conversation loses influence over the decisions where it matters most, while one who abandons controls at the first objection provides no assurance at all.55. A third-party supplier will process sensitive data. What should the security manager ensure before onboarding?
- A. Due diligence proportionate to the risk, contractual security requirements including breach notification and audit rights, and defined ongoing monitoring
- B. That the supplier holds any security certification, without reviewing its scope
- C. That the supplier is larger than the organization
- D. That procurement has obtained the lowest price
Show answer & explanation
Answer: A
Supplier risk is managed across the lifecycle rather than at a single gate, so pre-contract diligence, contractual obligations and ongoing monitoring all have a part. A certification with a scope excluding the service being purchased provides no relevant assurance, which is why reading the scope statement matters more than noting the certificate exists.56. A security programme reports a declining number of detected incidents. How should this be interpreted?
- A. Cautiously, since it may indicate improved prevention or degraded detection, and the two require different responses
- B. As unambiguous evidence that security has improved
- C. As evidence that the security budget should be reduced
- D. As evidence that reporting should be discontinued
Show answer & explanation
Answer: A
Detected incident counts measure detection capability as much as underlying incidence, so a fall is ambiguous without corroborating measures such as detection coverage, mean time to detect and external notifications. Treating the decline as success and reducing investment can accelerate the degradation that produced it.57. An incident response plan defines phases. What is the purpose of the containment phase?
- A. To notify regulators of the breach
- B. To limit the incident's spread and damage while preserving evidence, before eradication of the cause begins
- C. To identify the root cause of the incident
- D. To restore all systems to normal operation
Show answer & explanation
Answer: B
Containment stops the bleeding while retaining the forensic material that eradication and later analysis depend on, which is why hasty rebuilding of a compromised host can destroy the evidence needed to find the other compromised hosts. Eradication removes the cause and recovery restores service, each after containment has bounded the damage.58. During an incident, a responder wants to reboot a compromised server immediately. What is the concern?
- A. Rebooting would alert the attacker
- B. There is no concern, since disk evidence is sufficient
- C. Volatile evidence in memory and active connections would be lost, potentially destroying the only record of how the compromise occurred and what else it reached
- D. The server would take too long to restart
Show answer & explanation
Answer: C
Memory contains running processes, injected code, network connections and often credentials or keys that exist nowhere on disk, and it is lost on power cycle. Order of volatility guides collection, taking the most perishable evidence first, and premature rebuilding is one of the most common ways an investigation loses the ability to scope the compromise.59. An incident response plan requires a communication protocol. Why is this a distinct element?
- A. Because regulatory notification is never time-bound
- B. Because who says what to regulators, customers, staff and media, and when, must be decided in advance rather than improvised under pressure
- C. Because communication is optional in most incidents
- D. Because technical responders should handle all external communication
Show answer & explanation
Answer: B
Communication failures during an incident cause damage independent of the technical event, through contradictory statements, premature assurances later retracted or missed notification deadlines. Predefined spokespeople, approval paths and holding statements are what make coherent communication possible while the facts are still uncertain.60. After an incident is resolved, a post-incident review is held. What is its principal purpose?
- A. To identify what allowed the incident and what impeded the response, producing improvements to controls and to the plan itself
- B. To determine which individual was at fault
- C. To calculate the exact financial loss for accounting
- D. To formally close the incident ticket
Show answer & explanation
Answer: A
The review's value lies in feeding both control improvements and response improvements back into the programme, and a review that stops at the technical cause misses the response friction that determined how bad the incident became. A blame-focused review reliably suppresses the candid information the process depends on.61. How do incident response and business continuity planning relate?
- A. They are alternative names for the same plan
- B. Incident response replaces business continuity for cyber events
- C. Business continuity applies only to natural disasters
- D. Incident response addresses the security event itself while business continuity maintains critical operations, and a severe incident invokes both
Show answer & explanation
Answer: D
The two answer different questions, one about handling the attack and one about continuing to operate while it is handled, and a ransomware event demonstrates why both are needed simultaneously. Plans that are not cross-referenced produce conflicting instructions at exactly the moment coordination matters most.62. An organization measures mean time to detect and mean time to respond. What do these indicate?
- A. The number of incidents occurring per month
- B. How long an adversary operates undetected and how quickly the organization acts once aware, both of which bound the damage an incident causes
- C. The cost of the security operations function
- D. The technical severity of each incident
Show answer & explanation
Answer: B
Dwell time and response latency determine how far an intrusion progresses, which is why they are more actionable than incident counts that reflect threat activity outside the organization's control. Improving them is within the organization's power, making them appropriate programme performance measures.63. An incident may involve criminal activity and potential litigation. What does this require of evidence handling?
- A. A documented chain of custody and forensically sound acquisition, so the evidence remains admissible and its integrity demonstrable
- B. Immediate deletion of affected data to prevent further exposure
- C. Analysis performed only on the original media
- D. Restricting all documentation to verbal briefings
Show answer & explanation
Answer: A
Admissibility depends on demonstrating that evidence was not altered, which requires documented custody and analysis performed on verified copies rather than originals. Involving legal counsel early also matters because privilege and preservation obligations attach before the technical investigation concludes.64. A security manager is asked whether an incident constitutes a reportable breach. What primarily determines this?
- A. The applicable legal and regulatory definitions against the facts established, including the data involved and the jurisdictions of affected individuals
- B. The organization's internal severity rating alone
- C. Whether the media has reported the incident
- D. Whether the attacker has been identified
Show answer & explanation
Answer: A
Reportability is a legal determination made against statutory definitions, which differ in what triggers notification, the deadline and to whom, and multiple regimes can apply where affected individuals span jurisdictions. Internal severity ratings inform response prioritization but have no bearing on statutory obligations.65. A tabletop exercise is run for the incident response team. What does it validate that a technical drill does not?
- A. Decision-making, escalation paths and coordination between technical, legal, communications and executive participants under scenario pressure
- B. The throughput of the detection tooling
- C. The patch level of production systems
- D. The accuracy of the asset inventory
Show answer & explanation
Answer: A
Most incident response failures are decision and coordination failures rather than technical ones, and a tabletop is the only cheap way to surface unclear authority, missing escalation paths and conflicting assumptions between functions. Technical drills validate capability but involve a narrower set of participants.66. A security manager inherits a programme with no asset inventory. Why is this the priority to address?
- A. Because controls, risk assessment, vulnerability management and incident scoping all depend on knowing what exists and who owns it
- B. Because inventories are required for software licensing compliance
- C. Because it determines the security team's budget
- D. Because it is the easiest deliverable to complete quickly
Show answer & explanation
Answer: A
Every downstream security activity is bounded by the inventory, since an unknown asset is not patched, monitored, assessed or included in incident scoping. It is also rarely the easiest deliverable, because building and maintaining it requires cooperation from across the organization rather than effort within the security function.67. A vulnerability management programme reports thousands of open findings. How should remediation be prioritized?
- A. By risk to the organization, combining severity with exploitability, exposure and the criticality of the affected asset
- B. By the technical severity score alone, highest first
- C. By the age of the finding, oldest first
- D. By the ease of remediation, simplest first
Show answer & explanation
Answer: A
A high-severity vulnerability on an isolated non-critical system can matter less than a moderate one on an internet-facing system holding sensitive data, so severity scores are an input rather than the ranking. Prioritizing by ease produces a falling count while the genuinely dangerous findings remain open.68. An organization must comply with multiple overlapping regulatory regimes. What approach reduces duplicated effort?
- A. A common control framework mapped to each regime's requirements, so one control implementation satisfies several obligations and is tested once
- B. A separate security programme for each regime
- C. Complying with only the strictest regime and ignoring the others
- D. Delegating all compliance to the internal audit function
Show answer & explanation
Answer: A
Requirements across regimes overlap substantially, so a mapped common control set removes duplicated implementation and testing while making coverage gaps visible. Assuming the strictest regime subsumes the others fails because regimes differ in kind rather than only in degree, with distinct notification, residency and consent requirements.69. A security manager proposes a maturity model assessment of the programme. What does it provide that a control gap analysis does not?
- A. A view of how consistently and repeatably processes operate, distinguishing a control performed ad hoc from one that is managed and measured
- B. A list of missing controls
- C. The financial cost of remediation
- D. The technical configuration of each system
Show answer & explanation
Answer: A
A gap analysis answers whether a control exists while maturity answers how dependably it operates, and a control performed inconsistently by one knowledgeable individual passes existence testing while carrying substantial key-person risk. Maturity also gives a defensible trajectory for multi-year investment rather than a binary compliance statement.70. What criteria should PRIMARILY determine when an information security incident can formally be closed?
- A. When exactly 30 days have passed since detection, regardless of remediation status.
- B. When the incident response team simply runs out of available time to continue working it.
- C. When the affected business unit stops asking for status updates.
- D. When containment, eradication, and recovery actions are verified complete, the root cause is addressed, and any required documentation and notifications are finished.
Show answer & explanation
Answer: D
An incident should be formally closed only once containment, eradication, and recovery have been verified as complete, the underlying root cause has been addressed to prevent recurrence, and any required documentation or regulatory and stakeholder notifications have been completed, rather than being closed based on an arbitrary elapsed time period, waning attention from the business, or the response team simply moving on to other priorities.71. The CISO in an organization reports administratively to the Chief Information Officer (CIO), who is also responsible for IT operations and system implementation. What is the PRIMARY governance concern with this reporting structure?
- A. Security incidents will not be reported to executive management in a timely manner.
- B. The CIO may deprioritize security initiatives that conflict with IT delivery timelines and budgets, creating a conflict of interest.
- C. The CISO may lack sufficient technical knowledge of the systems being secured.
- D. The CIO cannot approve funding for information security initiatives without board approval.
Show answer & explanation
Answer: B
Because the CIO is accountable for IT delivery, cost, and schedule, having security report through that same chain creates an inherent conflict of interest: security decisions that slow releases or add cost may be deprioritized to protect operational metrics the CIO is measured on. Independent or dual reporting lines mitigate this by preserving the objectivity needed to challenge IT priorities when warranted.72. An information security manager is preparing a business case to secure funding for a new security initiative. Which approach is MOST likely to gain executive support?
- A. Frame the initiative in terms of business risk reduction and alignment with strategic objectives.
- B. Emphasize the technical sophistication of the proposed controls.
- C. Highlight the number of vulnerabilities the initiative will remediate.
- D. Compare the initiative's cost to typical industry security budgets.
Show answer & explanation
Answer: A
Executives allocate resources based on business impact rather than technical detail. Presenting the initiative as a reduction of business risk that supports strategic goals speaks the language decision-makers use to evaluate competing investments, whereas technical depth, budget benchmarking, or raw vulnerability counts do not by themselves demonstrate value to the organization.73. An organization is selecting a governance framework (such as COBIT) to structure its information security program. What is the PRIMARY benefit of adopting a recognized framework?
- A. It provides a structured set of processes and controls that can be consistently measured and audited over time.
- B. It eliminates the need for a dedicated information security manager.
- C. It guarantees compliance with all applicable laws and regulations.
- D. It removes the need for board-level oversight of the security program.
Show answer & explanation
Answer: A
A recognized governance framework gives the organization a common, well-tested structure of processes, roles, and controls that can be applied consistently and assessed for maturity or audited over time, rather than relying on an ad hoc approach. It does not replace dedicated security leadership, guarantee legal compliance on its own, or reduce the need for oversight, since frameworks still require capable people and governance to be effective.74. Senior executives visibly comply with security policies and reference security priorities in company communications. What is this PRIMARILY an example of?
- A. Establishing a security-conscious organizational culture through tone at the top.
- B. Regulatory compliance enforcement.
- C. Risk transfer.
- D. Segregation of duties.
Show answer & explanation
Answer: A
When senior leaders visibly model compliance and communicate security as a priority, they set the 'tone at the top,' which is one of the most influential factors in shaping an organization's security culture because employees tend to mirror the behaviors and priorities they see modeled by leadership, more so than policy documents alone can achieve.75. A new data protection regulation in the organization's operating jurisdiction introduces mandatory breach notification requirements. What should the information security manager do FIRST?
- A. Immediately notify all customers of the new regulatory requirement.
- B. Purchase additional cyber insurance to cover potential fines.
- C. Wait until a breach occurs before determining notification obligations.
- D. Assess current incident response and governance processes against the new requirement to identify gaps.
Show answer & explanation
Answer: D
Before any specific incident occurs, the security manager needs to understand how the organization's existing governance and incident response processes measure up against the new legal obligation so that gaps in roles, timelines, and documentation can be closed proactively. Waiting for a breach to occur, or reacting only through insurance or premature customer notice, does not address the underlying gap between current practice and the new legal requirement.76. An information security manager wants to add leading indicators to a governance dashboard that currently only reports incident counts and audit findings. Which metric BEST serves as a leading indicator?
- A. Percentage of critical systems with overdue vulnerability patches.
- B. Total financial loss attributed to past breaches.
- C. Number of audit findings closed in the prior year.
- D. Number of security incidents reported last quarter.
Show answer & explanation
Answer: A
Leading indicators measure conditions that predict future risk before an adverse event occurs, such as the backlog of unpatched vulnerabilities on critical systems, which signals exposure that could lead to an incident. Incident counts, historical losses, and closed audit findings all describe events that have already happened and therefore function as lagging indicators rather than predictive ones.77. A global organization with autonomous regional business units is deciding between a centralized and a federated information security governance model. Which factor MOST strongly favors a federated approach?
- A. Significant differences in regulatory requirements and risk profiles across regions.
- B. A desire to minimize the total number of security staff employed.
- C. A preference for uniform security metrics across all regions.
- D. The need to reduce the overall cost of the security program.
Show answer & explanation
Answer: A
A federated governance model allows regional units to tailor policies and controls to local regulatory and risk conditions while still operating under a shared overarching framework, which is most valuable when regions differ significantly in legal requirements or threat exposure. Cost reduction, staffing minimization, and metric uniformity are generally better served by a centralized model, since federation typically increases coordination overhead rather than reducing it.78. A business unit requests a formal exception to a mandatory security policy due to a legacy application that cannot support required controls. What should the information security manager ensure is part of the exception process?
- A. The exception is granted permanently once approved to avoid repeated requests.
- B. The business unit is exempted from all related policies going forward.
- C. The exception includes documented compensating controls, an owner, and a defined expiration or review date.
- D. The exception is kept informal to expedite business operations.
Show answer & explanation
Answer: C
A properly governed exception process requires documented compensating controls to offset the unmet requirement, a clearly assigned owner accountable for the residual risk, and a review or expiration date so the exception does not become a permanent, unmonitored gap. Granting an open-ended or informal exception removes accountability and allows risk to persist unchecked over time.79. An organization is establishing an enterprise architecture function. What is the PRIMARY reason information security governance should have formal input into this function?
- A. To eliminate the need for separate security reviews of new technology projects.
- B. To ensure the enterprise architecture team reports directly to the information security manager.
- C. To reduce the overall headcount required for the architecture function.
- D. To ensure security requirements are embedded into technology decisions from the earliest design stages.
Show answer & explanation
Answer: D
When security governance has formal input into enterprise architecture, security requirements can be built into standards, reference architectures, and technology roadmaps from the outset rather than being bolted on after systems are already designed or deployed, which is both more effective and less costly. This input does not remove the need for security review of individual projects nor does it require organizational reporting changes.80. A business unit leader overrules a security control recommendation from the information security manager, citing operational impact, and proceeds without documented risk acceptance. What is the MOST appropriate governance response?
- A. Accept the business unit leader's decision without further action since they own the operational risk.
- B. Escalate the unresolved risk to the appropriate governance body, such as a steering committee, for formal risk acceptance.
- C. Implement the control unilaterally despite the business unit's objection.
- D. Document the disagreement informally and take no further action.
Show answer & explanation
Answer: B
When a business decision-maker overrides a security recommendation without going through a formal risk acceptance process, governance structures exist precisely to resolve this kind of impasse by escalating the decision to a body with the authority and accountability to formally accept or reject the residual risk on behalf of the organization. Simply deferring, documenting informally, or unilaterally imposing the control bypasses the governance mechanism designed for this situation.81. An information security manager is documenting who is Responsible, Accountable, Consulted, and Informed for a new access review process. What is the PRIMARY value of this exercise?
- A. It clarifies ownership and prevents gaps or overlaps in responsibility for the process.
- B. It replaces the need for a written procedure.
- C. It guarantees that the access review will detect all inappropriate access.
- D. It eliminates the need for periodic audits of the process.
Show answer & explanation
Answer: A
A RACI exercise clarifies exactly who performs a task, who is ultimately accountable for its outcome, who must be consulted, and who simply needs to stay informed, which prevents the common problem of tasks falling through the cracks because multiple people assumed someone else was responsible. It does not substitute for documented procedures, guarantee detection effectiveness, or remove the need for independent audit.82. Within an information security governance structure, which activity is MOST appropriately reserved for the board of directors rather than delegated to security management?
- A. Configuring firewall rule sets for the perimeter network.
- B. Selecting a specific vulnerability scanning tool.
- C. Assigning incident response duties during a live security event.
- D. Approving the organization's overall risk appetite for information security.
Show answer & explanation
Answer: D
Setting the organization's risk appetite is a strategic governance decision that defines how much risk the organization is willing to accept in pursuit of its objectives, and it properly belongs at the board level because it shapes decisions across the entire enterprise, not just information security. Operational activities such as tool selection, configuration, and incident duty assignment are management-level responsibilities delegated to security staff.83. A governance committee is reviewing two competing security investments with similar cost but different expected outcomes: one reduces the likelihood of a low-impact, high-frequency risk, and the other reduces the impact of a low-frequency, catastrophic risk. Absent other constraints, which consideration should MOST influence the committee's prioritization?
- A. The investment that is easiest to implement technically.
- B. The organization's documented risk appetite and tolerance for catastrophic versus recurring losses.
- C. The investment that has been requested most recently by staff.
- D. The investment with the shorter vendor contract term.
Show answer & explanation
Answer: B
Because both investments cost roughly the same but address fundamentally different risk profiles, the governance committee should prioritize based on how the organization has defined its appetite for catastrophic, low-frequency events versus recurring, lower-impact ones, since this appetite reflects the organization's strategic tolerance for different loss patterns. Ease of implementation, recency of request, or contract term are operational or administrative factors that do not reflect the organization's actual risk priorities.84. An information security strategy was approved eighteen months ago. The organization has since undergone a merger and entered new markets. What should trigger a formal review of the security strategy?
- A. The passage of exactly twelve months since the last review.
- B. A request from the IT help desk for additional staffing.
- C. The renewal date of the cyber insurance policy.
- D. Material changes to the business, such as a merger or new market entry, that alter the risk and threat landscape.
Show answer & explanation
Answer: D
Security strategy should be reviewed whenever significant business changes occur that alter the organization's risk profile, threat landscape, or objectives, such as a merger or expansion into new markets, because the existing strategy may no longer reflect the assets, regulatory exposure, or priorities that need protecting. A fixed calendar interval, staffing requests, or insurance renewal dates are not reliable triggers for reassessing whether the strategy still fits the business.85. An organization's governance framework requires that critical third-party service providers be subject to periodic security oversight. What is the PRIMARY reason this oversight should be governed at the enterprise level rather than left to individual business units?
- A. It ensures consistent risk criteria and accountability are applied across all vendor relationships regardless of which unit engages them.
- B. It eliminates the need for contractual security clauses.
- C. It reduces the total number of vendors the organization can use.
- D. It transfers all security liability to the third party.
Show answer & explanation
Answer: A
Enterprise-level governance of third-party oversight ensures that every business unit applies the same risk assessment criteria and accountability standards when engaging vendors, preventing inconsistent or weaker practices in units that manage their own vendor relationships without central oversight. It does not reduce vendor options, shift legal liability entirely to the third party, or remove the need for security clauses in contracts.86. A parent company with a conservative risk appetite acquires a subsidiary operating in a jurisdiction where local competitors normally accept far higher levels of cyber risk to remain price-competitive. The subsidiary's leadership resists adopting the parent's security requirements, citing competitive disadvantage. What is the MOST appropriate governance approach for the information security manager to recommend?
- A. Allow the subsidiary to define its own independent risk appetite separate from the parent company.
- B. Mandate immediate, uniform application of all parent company controls regardless of local business impact.
- C. Engage subsidiary and parent governance stakeholders to reconcile risk appetite differences through a documented, risk-based exception and phased-adoption plan.
- D. Defer the decision entirely to the subsidiary's local IT department.
Show answer & explanation
Answer: C
Reconciling a genuine conflict between an acquired subsidiary's competitive realities and the parent organization's risk appetite requires structured governance engagement that documents where controls must be phased in and where formal, time-bound exceptions with compensating measures are appropriate, rather than either abandoning parent oversight entirely or imposing controls without regard to legitimate business impact. Leaving the decision to local IT or letting the subsidiary set an entirely independent risk appetite undermines the enterprise governance structure the parent company is accountable for.87. An information security manager conducts a maturity assessment and finds the organization's security processes are performed but not consistently documented or repeatable across teams. According to common maturity models, this level is BEST characterized as which stage?
- A. Nonexistent, where no processes are performed at all.
- B. Optimized, where processes are continuously improved using metrics.
- C. Managed and measured, where processes are quantitatively controlled.
- D. Repeatable but informal, where processes are performed and produce results but are not consistently documented or standardized across teams.
Show answer & explanation
Answer: D
Maturity models generally describe a stage where activities are being performed and produce results, but without consistent documentation or repeatability across teams — a repeatable-but-informal stage, distinct from both the earliest stage where nothing is done at all and the higher stages where processes are formally defined, measured, or continuously optimized. Recognizing this stage accurately helps the security manager target standardization and documentation as the next improvement priority rather than jumping to advanced metrics-driven optimization.88. An organization has passed all required regulatory compliance audits for the past three years but has experienced two significant security incidents caused by control gaps that fell outside the scope of the audited requirements. What does this scenario BEST illustrate?
- A. The compliance audits were performed incorrectly.
- B. Compliance with regulatory requirements is necessary but not sufficient for effective security governance, which must address risk beyond the minimum mandated baseline.
- C. Regulatory requirements are always sufficient to prevent security incidents.
- D. The organization should discontinue compliance audits since they did not prevent incidents.
Show answer & explanation
Answer: B
Regulatory compliance establishes a minimum legally required baseline, but effective security governance must identify and address risks beyond that baseline based on the organization's actual threat landscape, since compliance frameworks are not designed to cover every possible risk an organization faces. The incidents in this scenario demonstrate exactly this gap, not that the audits were flawed or should be abandoned, since compliance remains necessary even though it is insufficient alone.89. An organization needs to assess risk for a new initiative but lacks reliable historical loss data and cannot easily estimate financial impact in dollar terms. Which risk assessment approach is MOST appropriate?
- A. A purely quantitative approach using annualized loss expectancy calculations.
- B. No formal risk assessment is needed since data is unavailable.
- C. A qualitative approach using risk ratings such as high, medium, and low based on expert judgment.
- D. A purely statistical approach based on industry-wide breach cost averages.
Show answer & explanation
Answer: C
When reliable historical loss data is unavailable, a qualitative approach that relies on structured expert judgment to rate likelihood and impact allows the organization to prioritize risks meaningfully without requiring precise financial inputs that do not exist. Forcing a quantitative calculation without valid data produces false precision, while skipping assessment altogether or relying solely on generic industry averages ignores the organization's specific context.90. An information security manager wants to improve the accuracy of likelihood estimates used in the organization's risk assessments. Which action would MOST directly improve this?
- A. Incorporating current threat intelligence relevant to the organization's industry and technology environment.
- B. Increasing the frequency of employee security awareness training.
- C. Reducing the number of risk categories tracked in the risk register.
- D. Outsourcing the entire risk assessment process to a single vendor.
Show answer & explanation
Answer: A
Likelihood estimates are strengthened when they are grounded in current, relevant threat intelligence about the actors, techniques, and campaigns actually targeting the organization's industry and technology stack, rather than relying on generic or outdated assumptions. Awareness training, reducing risk categories, or full outsourcing may have other benefits but do not directly sharpen the accuracy of likelihood estimation the way relevant threat data does.91. After implementing a set of security controls, the residual risk for a critical system remains above the organization's documented risk appetite. What is the MOST appropriate next step for the information security manager?
- A. Consider the risk treatment complete since controls were implemented.
- B. Identify and implement additional controls, or escalate the residual risk for formal acceptance by an authorized party.
- C. Remove the risk from the risk register since it has already been treated.
- D. Transfer full responsibility for the residual risk to the system's end users.
Show answer & explanation
Answer: B
When residual risk remains above the organization's stated appetite even after treatment, the security manager must either pursue further risk reduction through additional controls or formally escalate the gap so an authorized party can knowingly accept the excess risk with documented accountability; simply considering the matter closed or removing it from tracking leaves an unmanaged exposure that exceeds what the organization has said it is willing to tolerate.92. How does a business impact analysis (BIA) relate to an information security risk assessment?
- A. A BIA replaces the need for a risk assessment entirely.
- B. A BIA is only relevant to physical security, not information security.
- C. A BIA identifies the criticality and impact of business processes, informing which assets and risks the risk assessment should prioritize.
- D. A BIA and a risk assessment measure identical variables and produce redundant results.
Show answer & explanation
Answer: C
A business impact analysis identifies which business processes and supporting assets are most critical to the organization and quantifies the impact of their disruption, and this information feeds directly into a risk assessment by helping prioritize which assets and scenarios warrant the closest scrutiny. The two are complementary rather than redundant or interchangeable, and a BIA does not eliminate the need for a separate risk assessment covering threats and vulnerabilities.93. Individually, ten systems each carry a 'low' risk rating, but they share a common underlying vulnerability in a widely used software component. What risk consideration does this scenario illustrate?
- A. Low individual risk ratings can always be safely ignored regardless of scale.
- B. Risk ratings for individual systems should never be compared to one another.
- C. Aggregated risk across multiple assets can be significantly higher than any single asset's individual rating suggests.
- D. Shared vulnerabilities only matter if the systems are physically co-located.
Show answer & explanation
Answer: C
When many assets share a common vulnerability, an exploit affecting that shared component can compromise all of them simultaneously, meaning the true organizational exposure is better represented by the aggregate or portfolio risk than by looking at any single system's rating in isolation, since a single low individual score can mask a much larger cumulative exposure. This illustrates why risk assessments should consider cross-asset dependencies rather than evaluating systems purely in isolation.94. An organization is rapidly adopting generative AI tools across business units without a formal risk assessment process for new technology adoption. What is the GREATEST concern with this approach?
- A. Generative AI tools cannot be used for legitimate business purposes.
- B. Employees will become overly reliant on AI for routine tasks.
- C. Sensitive data may be exposed to external AI providers or embedded in outputs without appropriate risk evaluation and controls.
- D. AI tools are inherently more expensive than traditional software.
Show answer & explanation
Answer: C
Adopting new technology such as generative AI without a formal risk assessment process means data handling, third-party exposure, and output-related risks are not evaluated before sensitive information is potentially shared with external providers or surfaced inappropriately in generated outputs, leaving the organization exposed to risks it has not consciously assessed or accepted. Concerns about cost or overreliance are secondary business considerations rather than the primary security risk in this scenario.95. An information security manager facilitates risk assessments and maintains the risk register, but a specific risk in the register concerns a business application owned by a department director. Who should be assigned as the risk owner for that item?
- A. The department director, since they have the authority and accountability to make decisions about that application's risk.
- B. The information security manager, since they maintain the risk register.
- C. The organization's external auditor.
- D. No owner is required as long as the risk is documented.
Show answer & explanation
Answer: A
Risk ownership belongs with the individual who has the authority and business context to make decisions about accepting, treating, or escalating a specific risk, which in this case is the department director accountable for the application, not the security manager who facilitates the risk process or an external party with no operational authority. Leaving a risk without an assigned owner undermines accountability regardless of how well it is documented.96. Before onboarding a new cloud service provider that will store regulated customer data, the information security manager is designing a vendor risk assessment approach. Which approach BEST ensures resources are focused appropriately?
- A. Skip formal assessment for vendors offering the lowest contract price.
- B. Tier vendors by the sensitivity of data and level of system access involved, applying deeper scrutiny to higher-tier vendors.
- C. Rely exclusively on the vendor's self-attestation without independent verification for any vendor.
- D. Apply the identical, most rigorous assessment to every vendor regardless of the data or access involved.
Show answer & explanation
Answer: B
Tiering vendors based on the sensitivity of the data they will handle and the level of access they require allows the organization to apply deeper, more resource-intensive scrutiny where the potential impact is greatest, while using lighter-touch review for lower-risk engagements, which is a more sustainable and defensible use of limited assessment resources than treating every vendor identically or skipping assessment based on price. Relying solely on unverified self-attestation for any vendor, regardless of risk tier, leaves material gaps in assurance.97. A project team plans to launch a new customer-facing application in eight weeks and requests that the risk assessment be skipped to meet the deadline, citing that a similar application was assessed two years ago. What is the MOST appropriate response from the information security manager?
- A. Perform a scoped risk assessment for the new application, since the threat landscape and application design may have changed materially since the prior assessment.
- B. Approve skipping the assessment since a similar application was already assessed previously.
- C. Delay the launch indefinitely until a full enterprise-wide risk assessment is completed.
- D. Allow the project team to self-certify that no significant risks exist.
Show answer & explanation
Answer: A
A prior assessment of a different, similar application two years ago does not account for changes in the threat landscape, the specific design and data flows of the new application, or new vulnerabilities that may have emerged since then, so a scoped, timely risk assessment focused on this application is warranted rather than skipping the step entirely, delaying the launch indefinitely, or relying on the project team's self-certification, which lacks independent verification.98. An organization has limited resources to perform risk assessments. How should the information security manager PRIMARILY determine the frequency of reassessment for different systems?
- A. Assess every system on the same fixed annual schedule regardless of criticality.
- B. Assess systems in alphabetical order as time permits.
- C. Assess higher-risk and more critical systems more frequently than lower-risk, less critical systems.
- D. Assess only systems that have experienced a prior security incident.
Show answer & explanation
Answer: C
With limited assessment resources, prioritizing more frequent reassessment of systems that carry higher risk or greater business criticality ensures that the areas of greatest potential impact receive the closest and most current scrutiny, which is a more effective use of resources than a uniform schedule, incident-triggered-only approach, or an arbitrary ordering that ignores actual risk levels.99. An information security manager needs to explain a complex technical vulnerability to a group of business executives with no technical background. What is the MOST effective communication approach?
- A. Present the full technical details, including exploit mechanics, to ensure completeness.
- B. Translate the vulnerability into business terms, describing potential business impact and recommended decisions needed.
- C. Delegate the explanation entirely to a third-party consultant.
- D. Postpone the discussion until the executives acquire technical training.
Show answer & explanation
Answer: B
Executives are best equipped to make decisions when technical risk is translated into business terms, such as potential financial, operational, or reputational impact and the specific decision or resource commitment being requested, rather than being given exploit-level technical detail they are not positioned to evaluate. Postponing the conversation or fully outsourcing it to a consultant does not serve the immediate need for informed executive decision-making.100. How does risk tolerance differ from risk appetite in the context of an information security risk management program?
- A. Risk appetite is set by IT staff, while risk tolerance is set by external auditors.
- B. Risk tolerance and risk appetite are interchangeable terms with no meaningful distinction.
- C. Risk tolerance applies only to financial risk, while risk appetite applies only to security risk.
- D. Risk appetite is the broad level of risk the organization is willing to pursue, while risk tolerance is the acceptable variation around that level for specific objectives.
Show answer & explanation
Answer: D
Risk appetite describes the overall amount and type of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance defines the acceptable range of variation around specific targets or metrics within that broader appetite, giving more granular boundaries for day-to-day decisions. Treating the two terms as identical, or misattributing who sets each, obscures this useful distinction between strategic-level and operational-level risk boundaries.101. A risk analysis estimates that a successful ransomware attack on a specific server would result in a single-occurrence financial loss of $200,000. This figure represents which quantitative risk metric?
- A. Annualized rate of occurrence.
- B. Annualized loss expectancy.
- C. Single loss expectancy.
- D. Total cost of ownership.
Show answer & explanation
Answer: C
Single loss expectancy represents the estimated monetary loss expected from one occurrence of a specific risk event, which is distinct from annualized loss expectancy that multiplies this figure by the expected frequency of occurrence per year, and distinct from the annualized rate of occurrence, which measures frequency rather than dollar loss. Total cost of ownership is an unrelated concept describing the lifetime cost of an asset.102. In quantitative risk analysis, the exposure factor represents which of the following?
- A. The total financial value of an asset.
- B. The annual frequency of a threat event occurring.
- C. The total number of threats facing an asset.
- D. The percentage of an asset's value that would be lost if a specific threat event occurred.
Show answer & explanation
Answer: D
The exposure factor is expressed as a percentage representing the proportion of an asset's value that would be lost or destroyed if a given threat materialized, and it is multiplied by the asset's value to derive the single loss expectancy. It is distinct from the count of threats, the frequency of occurrence used in annualized calculations, or the raw asset value itself.103. An organization formally accepts a risk associated with an outdated authentication mechanism on a legacy system because replacement is not feasible in the near term. What should accompany this risk acceptance?
- A. Documented compensating controls, such as enhanced monitoring, that reduce exposure while the underlying risk remains.
- B. Transfer of the risk to the software vendor.
- C. No further action, since acceptance means the risk requires no additional attention.
- D. Removal of the system from the risk register to simplify reporting.
Show answer & explanation
Answer: A
Even when a risk is formally accepted rather than remediated, sound practice is to identify and document compensating controls, such as increased monitoring, network segmentation, or access restrictions, that reduce the practical exposure while the underlying weakness persists, rather than treating acceptance as license to ignore the risk entirely. Removing the item from tracking or assuming the vendor bears responsibility for an internally accepted risk are both inappropriate.104. A proposed control would reduce a risk's annualized loss expectancy from $500,000 to $150,000, at an annual cost of $200,000 to operate. Based purely on this cost-benefit comparison, what should the information security manager conclude?
- A. The annualized cost of $200,000 is less than the $350,000 reduction in annualized loss expectancy the control provides, indicating a positive net benefit that supports adoption.
- B. The control should be rejected because its annual cost of $200,000 is a significant expense.
- C. The organization should discontinue risk analysis since a single control produced an unfavorable result.
- D. The control's cost is irrelevant as long as any risk is reduced.
Show answer & explanation
Answer: A
Comparing the control's $200,000 annual cost against the $350,000 reduction in annualized loss expectancy it achieves, from $500,000 down to $150,000, shows a net positive benefit of $150,000 per year, which supports adoption on a purely cost-benefit basis, though the manager should still confirm that no lower-cost alternative achieves comparable risk reduction. Rejecting the control based on its cost alone, discontinuing risk analysis after one result, or ignoring cost entirely all reflect flawed reasoning about cost-benefit trade-offs.105. A risk register contains several risks with similar likelihood ratings but significantly different potential business impact. When resources for treatment are limited, which risks should generally be prioritized FIRST?
- A. Risks that are least costly to remediate, regardless of impact.
- B. Risks that were most recently added to the register.
- C. Risks with the greatest combination of likelihood and potential business impact.
- D. Risks that were identified by external auditors rather than internal staff.
Show answer & explanation
Answer: C
Prioritization of limited treatment resources should be driven by the combined effect of likelihood and impact, since this reflects the actual magnitude of risk exposure to the organization, rather than by remediation cost alone, recency of identification, or the source that identified the risk, none of which reliably indicate which risks pose the greatest threat to the organization if left untreated.106. An organization purchases a cyber insurance policy to cover the financial costs of a potential data breach. What is an important LIMITATION of this risk transfer strategy that the information security manager should communicate to leadership?
- A. Cyber insurance eliminates the need for any technical security controls.
- B. Cyber insurance transfers full legal accountability for the breach to the insurer.
- C. Cyber insurance automatically prevents breaches from occurring.
- D. Cyber insurance may not cover reputational damage, regulatory penalties, or losses from failure to meet policy security requirements.
Show answer & explanation
Answer: D
Cyber insurance can offset certain financial costs of an incident, but it typically does not cover intangible losses such as reputational harm, may exclude or limit coverage for regulatory fines, and can be voided or reduced if the organization failed to maintain security controls required by the policy, so it should never be treated as a substitute for underlying security controls or as eliminating legal accountability, which remains with the organization.107. An organization is planning a merger with another company that will integrate the acquired company's IT environment into its own network. At what point should a risk assessment of the acquired environment BEST be initiated?
- A. Only after the networks have been fully integrated and are operating as one environment.
- B. After the first annual audit following the merger.
- C. Only if a security incident occurs after integration.
- D. As early as possible during due diligence, before systems and networks are integrated.
Show answer & explanation
Answer: D
Assessing the acquired environment's security posture as early as possible during due diligence allows the organization to identify risks, unknown vulnerabilities, and control gaps before systems are connected to the broader network, preventing the acquiring organization from inheriting undiscovered exposure at the point of integration. Waiting until after integration, until an incident occurs, or until the next scheduled audit needlessly extends the window during which the organization is exposed to unassessed risk.108. An information security program relies on a single perimeter firewall as its primary control against external threats, with minimal internal network controls. What principle is this program failing to apply?
- A. Risk transfer.
- B. Segregation of duties.
- C. Least privilege.
- D. Defense in depth, using multiple layered controls so that failure of one does not compromise the entire environment.
Show answer & explanation
Answer: D
Relying on a single perimeter control means that once an attacker bypasses that one barrier, there is little standing between them and internal assets, which is precisely the weakness that defense in depth addresses by layering multiple, complementary controls such as network segmentation, endpoint protection, and monitoring so that no single point of failure compromises the whole environment. Least privilege and segregation of duties address different concerns around access and accountability, not layered protection.109. How does patch management relate to a broader vulnerability management program?
- A. Patch management is one remediation mechanism within the broader vulnerability management program, which also includes identification, prioritization, and verification.
- B. Patch management and vulnerability management are unrelated disciplines.
- C. Vulnerability management applies only to network devices, while patch management applies only to servers.
- D. Patch management replaces the need for vulnerability scanning.
Show answer & explanation
Answer: A
Vulnerability management is the broader, ongoing process of identifying, assessing, prioritizing, and verifying the remediation of weaknesses, and patch management is one of the primary mechanisms used to remediate a significant share of those vulnerabilities, but it is not the entire process since some vulnerabilities require configuration changes or compensating controls rather than a patch. Treating them as unrelated or scoped only to specific device types misrepresents how the two fit together.110. A development team wants to identify security flaws in application source code before it is deployed to production. Which practice BEST supports this goal within the SDLC?
- A. Conducting user acceptance testing after deployment.
- B. Relying solely on production monitoring to detect issues.
- C. Performing a post-incident review after a breach occurs.
- D. Integrating static application security testing and secure code review into the development pipeline.
Show answer & explanation
Answer: D
Static application security testing and secure code review analyze source code for known flaw patterns before the application is deployed, allowing issues to be found and fixed while they are still inexpensive to address, rather than relying on production monitoring or post-incident reviews that only surface problems after they may have already been exploited. User acceptance testing focuses on functional correctness rather than security flaws in the code itself.111. An organization's IT administrators use their standard, always-on privileged accounts for both daily email and browsing as well as system administration tasks. What is the PRIMARY risk this practice introduces?
- A. Administrators will be unable to complete their job duties efficiently.
- B. A compromise of the administrator's everyday activity, such as a phishing click, could directly expose highly privileged credentials to an attacker.
- C. The organization will incur higher software licensing costs.
- D. Administrators will be unable to receive email notifications about system alerts.
Show answer & explanation
Answer: B
Using a single always-on privileged account for routine activities like browsing and email means that a common compromise vector, such as a phishing email or malicious webpage, can directly expose credentials with elevated system access, dramatically increasing the potential impact of an everyday security lapse. Best practice is to use separate, non-privileged accounts for routine tasks and time-limited or just-in-time privileged access for administrative work, which this practice fails to do.112. What is the PRIMARY function of a security operations center (SOC) within an information security program?
- A. Drafting the organization's information security policies.
- B. Conducting the organization's financial audits.
- C. Continuously monitoring, detecting, and initially responding to security events across the environment.
- D. Approving the organization's annual security budget.
Show answer & explanation
Answer: C
A security operations center is primarily responsible for continuous, real-time monitoring of the environment to detect security events and coordinate initial response actions, functioning as the operational nerve center for day-to-day threat detection, whereas policy drafting, financial audits, and budget approval are governance or management functions performed elsewhere in the organization.113. An organization frequently experiences security incidents traced back to unauthorized or undocumented changes to production systems. Which program improvement would MOST directly address this root cause?
- A. Strengthening the change management process to require documented approval and security review before production changes are implemented.
- B. Expanding the security awareness training curriculum.
- C. Purchasing additional endpoint detection tools.
- D. Increasing the frequency of penetration testing.
Show answer & explanation
Answer: A
Since the incidents are specifically traced to unauthorized or undocumented changes, the root cause lies in a weak or bypassed change management process, and directly strengthening that process, requiring documented approval and security review prior to implementation, addresses the actual gap. Additional detection tools, more frequent penetration testing, or expanded awareness training may have general value but do not directly close the specific process gap identified.114. An information security program establishes a standardized, hardened configuration baseline that all new servers must be built from. What is the PRIMARY security benefit of this practice?
- A. It reduces the attack surface and ensures a consistent, known-secure starting state across the environment.
- B. It eliminates the need for future vulnerability scanning.
- C. It guarantees compliance with all data protection regulations.
- D. It removes the need for a change management process.
Show answer & explanation
Answer: A
A standardized, hardened configuration baseline ensures that every new system starts from a consistent, minimized, and known-secure state, reducing unnecessary services and settings that would otherwise expand the attack surface and create inconsistency across the environment. It does not eliminate the ongoing need for vulnerability scanning, does not by itself guarantee regulatory compliance, and does not remove the need for change management around subsequent modifications.115. An organization encrypts sensitive data at rest but stores the encryption keys on the same server as the encrypted data, with no separate access controls on the keys. What is the PRIMARY weakness in this approach?
- A. Encryption at rest is not an effective control under any circumstances.
- B. Encrypted data cannot be backed up if keys are stored locally.
- C. An attacker who compromises the server gains access to both the encrypted data and the means to decrypt it, undermining the protection encryption is meant to provide.
- D. Local key storage always violates data protection regulations.
Show answer & explanation
Answer: C
Effective encryption depends on keeping the encryption keys separately protected and access-controlled from the data they protect; storing them together on the same server means that a single compromise gives an attacker everything needed to both access and decrypt the sensitive data, which defeats much of the purpose of encrypting it in the first place. This is a key management weakness rather than a flaw in encryption as a control generally, a backup limitation, or an automatic regulatory violation.116. An organization implements a data loss prevention (DLP) solution as part of its information security program. What is the PRIMARY purpose of this control?
- A. To manage user authentication across applications.
- B. To detect and remediate software vulnerabilities.
- C. To encrypt all data at rest automatically.
- D. To detect and prevent unauthorized transmission or exfiltration of sensitive data.
Show answer & explanation
Answer: D
Data loss prevention tools are designed to monitor, detect, and block the unauthorized movement of sensitive data, such as attempts to email, upload, or copy protected information outside approved channels, which is a distinct function from encryption, authentication management, or vulnerability remediation, even though DLP may work alongside those other controls within a broader program.117. An organization currently relies solely on an annual penetration test to identify security weaknesses. What is the PRIMARY limitation of this approach compared to continuous monitoring?
- A. Annual testing eliminates the need for a vulnerability management program.
- B. Annual testing is always more expensive than continuous monitoring.
- C. Annual testing cannot be performed by external parties.
- D. Vulnerabilities or misconfigurations introduced between annual tests may go undetected for extended periods.
Show answer & explanation
Answer: D
Because an annual penetration test provides only a point-in-time snapshot, any new vulnerabilities, misconfigurations, or changes introduced in the months between tests can remain undetected and unaddressed for a significant period, which is the gap that continuous monitoring is designed to close by providing ongoing visibility rather than periodic snapshots. Cost comparisons and the involvement of external testers are secondary considerations that do not describe this core limitation.118. An information security manager wants independent assurance that implemented controls are actually operating as designed, beyond the team's own self-assessment. What is the MOST appropriate approach?
- A. Rely on the control owners' self-reported completion status.
- B. Engage internal audit or an independent third party to test control effectiveness.
- C. Review the original control design documentation only.
- D. Assume controls are effective if no incidents have occurred recently.
Show answer & explanation
Answer: B
Independent testing by internal audit or a qualified third party provides objective assurance that controls are functioning as intended, free from the bias that can affect self-assessment by the same team responsible for implementing them. The absence of recent incidents does not prove control effectiveness, and reviewing only the original design documentation does not confirm the control is actually operating correctly in practice today.119. An organization establishes a 'security champions' program, designating volunteers within each development team to receive additional security training and serve as a liaison to the security team. What is the PRIMARY benefit of this approach?
- A. It transfers all security responsibility from the security team to developers.
- B. It eliminates the need for formal secure coding standards.
- C. It removes the need for the security team to review any code.
- D. It embeds security awareness and a point of contact directly within development teams, improving early identification of security concerns.
Show answer & explanation
Answer: D
A security champions program extends the security team's reach by placing a trained advocate directly within each development team, which improves early identification of security concerns during design and development and creates a more efficient communication channel back to the central security function. It does not transfer ultimate security accountability away from the security team, nor does it remove the need for standards or independent code review.120. An organization migrates a workload to a public cloud infrastructure-as-a-service (IaaS) provider. Under the typical shared responsibility model, which security responsibility generally REMAINS with the customer?
- A. Maintaining the physical network hardware.
- B. Securing the physical data center facility.
- C. Patching the underlying virtualization hypervisor.
- D. Securing the guest operating system, applications, and data configurations within the cloud environment.
Show answer & explanation
Answer: D
Under a typical infrastructure-as-a-service shared responsibility model, the cloud provider is responsible for securing the underlying physical infrastructure, hypervisor, and facility, while the customer remains responsible for securing what they configure and deploy on top of that infrastructure, including the guest operating system, applications, and data. Confusing this division is a common cause of cloud misconfiguration incidents when customers assume the provider covers responsibilities that are actually still theirs.121. An organization permits employees to access corporate email and data on personally owned mobile devices (BYOD) without any mobile device management (MDM) enrollment requirement. What is the GREATEST security gap this creates?
- A. The organization will be unable to issue any devices to employees in the future.
- B. Personal devices will automatically be slower than corporate-issued devices.
- C. The organization has no ability to enforce security configurations or remotely wipe corporate data if a device is lost, stolen, or compromised.
- D. Employees will be unable to access corporate resources from their devices.
Show answer & explanation
Answer: C
Without MDM enrollment, the organization has no mechanism to enforce baseline security configurations such as encryption or screen locks, nor the ability to remotely wipe corporate data from a device that is lost, stolen, or found to be compromised, leaving corporate data exposed on devices the organization does not control. This is the core security gap, distinct from unrelated concerns about device performance or future issuance policy.122. When defining the scope of an information security program, what is the MOST important factor to establish at the outset?
- A. The color scheme for security awareness training materials.
- B. The exact number of full-time security staff to be hired.
- C. Which assets, systems, and organizational units the program's policies and controls apply to.
- D. The specific vendor products that will be purchased.
Show answer & explanation
Answer: C
Clearly establishing which assets, systems, and organizational units fall within the program's scope is foundational, because every subsequent decision about policy applicability, control selection, and resource allocation depends on knowing what the program is actually meant to protect and govern. Vendor selection, staffing levels, and training material design are downstream implementation details that follow from, rather than precede, a clearly defined scope.123. Over three consecutive annual penetration tests, the number of critical findings has steadily decreased, while the overall scope and complexity of the tested environment has grown. How should the information security manager MOST reasonably interpret this trend?
- A. The security program's controls are likely improving in effectiveness, since findings decreased despite increased environmental complexity.
- B. The penetration testers are becoming less thorough each year.
- C. The organization no longer needs to conduct future penetration tests.
- D. The decreasing findings indicate the environment has become simpler to defend.
Show answer & explanation
Answer: A
A steady decline in critical findings despite the tested environment growing in scope and complexity is a reasonably positive signal that the security program's controls are becoming more effective at preventing and catching issues, since one would expect findings to increase, not decrease, if complexity grew and defenses stayed static or worsened. This trend does not eliminate the ongoing need for future testing, nor does it necessarily reflect reduced tester diligence, which would be an unsupported assumption without further evidence.124. An organization is redesigning its network architecture around the principle that no user or device should be inherently trusted, regardless of whether it is inside or outside the traditional network perimeter. This describes which architectural approach?
- A. Perimeter-based security.
- B. Segregation of duties.
- C. Zero trust architecture, which requires continuous verification of identity and context for every access request.
- D. Defense in depth.
Show answer & explanation
Answer: C
Zero trust architecture is built on the premise that trust should never be assumed based solely on network location, whether inside or outside a traditional perimeter, and instead requires continuous verification of identity, device posture, and context for every access request. This differs from traditional perimeter-based security, which assumes traffic inside the network boundary is inherently more trustworthy, and it is a distinct concept from defense in depth or segregation of duties.125. Two vulnerabilities have identical severity scores, but one has a publicly available exploit actively being used in attacks, while the other has no known exploit. How should the information security manager prioritize remediation?
- A. Treat both vulnerabilities with equal priority since their severity scores are identical.
- B. Prioritize the vulnerability with the known, actively exploited attack, since real-world exploitability increases the actual likelihood of compromise.
- C. Prioritize the vulnerability without a known exploit, since it is less understood by defenders.
- D. Defer both vulnerabilities until the next scheduled patch cycle regardless of exploit status.
Show answer & explanation
Answer: B
A severity score alone reflects potential impact but not the actual likelihood of exploitation; when a vulnerability has a known exploit actively used in the wild, the real-world risk of compromise is substantially higher than an equally severe vulnerability with no known exploit, so remediation resources should be directed there first. Treating both equally or deferring both regardless of exploit status ignores this critical difference in actual threat activity.126. An organization requires users to provide both a password and a one-time code from a mobile authenticator app to log into sensitive systems. This is an example of which security practice?
- A. Single sign-on.
- B. Data classification.
- C. Role-based access control.
- D. Multi-factor authentication, combining something the user knows with something the user has.
Show answer & explanation
Answer: D
Requiring both a password, which the user knows, and a time-based code from an authenticator app, which the user possesses, is a standard example of multi-factor authentication, which significantly reduces the risk of unauthorized access compared to a password alone, since compromising both factors is substantially more difficult for an attacker than obtaining a single credential.127. As part of an acquisition, the information security program must integrate the acquired company's systems and staff into the parent organization's security policies and controls. Which factor is MOST important for the information security manager to address EARLY in this integration?
- A. Postponing any security assessment until the acquired company's staff have completed a full year of employment.
- B. Immediately terminating all of the acquired company's existing security contracts.
- C. Identifying gaps between the acquired company's control environment and the parent's required baseline, and prioritizing remediation of the highest-risk gaps.
- D. Rebranding all acquired company assets with the parent company's logo.
Show answer & explanation
Answer: C
Early in an integration, the priority is understanding where the acquired company's control environment falls short of the parent organization's required security baseline and addressing the highest-risk gaps first, since connecting a weaker environment to the broader network without this understanding can introduce significant unmanaged risk. Rebranding, wholesale contract termination, or delaying assessment for a year all fail to address the actual security exposure introduced by the integration.128. An employee resigns and their last day is in two weeks. What is the BEST practice for managing their system access during the notice period and upon departure?
- A. Leave all access unchanged until the employee's final day, then review access at a convenient time afterward.
- B. Immediately revoke all access the moment resignation is announced, regardless of ongoing job duties.
- C. Rely on the employee to self-report which systems should be deactivated.
- D. Review and restrict access to only what is needed during the notice period, and ensure all access is revoked promptly at the effective termination time.
Show answer & explanation
Answer: D
Best practice during a notice period is to review the departing employee's access and restrict anything not needed for their remaining duties, while ensuring full and prompt revocation occurs at the actual termination time, balancing operational continuity against the elevated risk a departing employee can pose. Leaving access fully unchanged until after departure, revoking everything immediately regardless of remaining duties, or relying on the employee's own self-reporting all create either operational or security gaps.129. A security program relies exclusively on static application security testing (SAST) of source code and performs no testing of the running application. What type of vulnerability is this approach MOST likely to miss?
- A. Hardcoded credentials embedded directly in the source code.
- B. Runtime configuration and environment-specific vulnerabilities that only manifest when the application is executing, such as certain authentication or session-handling flaws.
- C. Vulnerabilities involving unsafe use of a known-insecure coding pattern.
- D. Vulnerable open-source library versions referenced directly in the code.
Show answer & explanation
Answer: B
Static testing analyzes source code without executing the application, so it is generally effective at catching insecure coding patterns, hardcoded secrets, and known-vulnerable library references, but it cannot observe how the application actually behaves at runtime, meaning issues that only manifest during execution, such as certain authentication flows or session-handling weaknesses, require dynamic application security testing of the running application to detect. Relying on static testing alone leaves this class of runtime vulnerabilities largely unaddressed.130. An organization segments its network so that point-of-sale systems are isolated on a separate network segment from general corporate workstations, with tightly controlled traffic between them. What is the PRIMARY security benefit of this design?
- A. It guarantees compliance with all payment card industry requirements.
- B. It eliminates the need for endpoint protection software on either segment.
- C. It removes the need for monitoring traffic within the payment segment.
- D. It limits the ability of an attacker who compromises the general corporate network to move laterally into the more sensitive payment environment.
Show answer & explanation
Answer: D
Network segmentation contains the blast radius of a compromise by restricting communication paths between segments, so that an attacker who gains a foothold in the general corporate network faces significant additional barriers before reaching the more sensitive point-of-sale environment, rather than being able to move freely across a flat network. Segmentation is one control among several needed for a compliant, secure environment, not a substitute for endpoint protection, monitoring, or the broader set of required controls.131. An organization performs nightly backups of critical systems but has never tested restoring from those backups. What is the GREATEST risk this practice creates?
- A. Backup storage costs will be higher than necessary.
- B. Nightly backups will interfere with normal business operations during the day.
- C. The backups will automatically expire after a fixed period.
- D. The organization may discover during an actual recovery event that the backups are incomplete, corrupted, or unusable, when it is too late to correct the problem.
Show answer & explanation
Answer: D
Backups that are never tested for restoration provide only an illusion of resilience, since corruption, incomplete data, or process errors can go undetected indefinitely, and the worst possible time to discover such a problem is during an actual incident when the organization urgently needs to recover and has no time to correct the deficiency. Cost, retention scheduling, and operational timing are secondary concerns compared to the risk that the backups may simply not work when actually needed.132. An information security manager wants a metric that reflects how consistently systems adhere to the organization's hardened configuration standard over time. Which metric BEST serves this purpose?
- A. The total number of servers owned by the organization.
- B. The average age of the organization's hardware inventory.
- C. The number of help desk tickets submitted per month.
- D. The percentage of systems found compliant with the configuration baseline during periodic scans.
Show answer & explanation
Answer: D
Tracking the percentage of systems that are actually found compliant with the defined configuration baseline during periodic scans directly measures how consistently the standard is being maintained across the environment over time, giving a meaningful trend the security manager can act on. Total server count, hardware age, and unrelated help desk ticket volume do not measure configuration compliance at all.133. After a compromised system has been contained, the incident response team removes the malware, disables the attacker's persistence mechanisms, and closes the exploited vulnerability. Which incident response phase does this describe?
- A. Eradication.
- B. Preparation.
- C. Detection.
- D. Containment.
Show answer & explanation
Answer: A
Eradication is the phase focused on removing the root cause of the incident from the environment, including malware, attacker persistence mechanisms such as backdoors, and the underlying vulnerability that was exploited, which comes after containment has limited the spread but before systems are restored to normal operation in the recovery phase. Containment focuses on limiting damage, while preparation and detection occur earlier in the lifecycle.134. Before returning a previously compromised system to production, what should the incident response team verify FIRST?
- A. That end users have been notified of a new password policy.
- B. That the system's hardware has been physically relocated.
- C. That the system's warranty is still valid.
- D. That the root cause has been eradicated and the system is free of any remaining indicators of compromise.
Show answer & explanation
Answer: D
Returning a system to production before confirming that the root cause has been fully eradicated and no indicators of compromise remain risks reintroducing a compromised system into the live environment, potentially allowing the attacker to regain access or the incident to recur. Warranty status, physical relocation, and password policy notification are unrelated administrative matters that do not verify the system is actually safe to restore.135. An organization develops documented runbooks that specify step-by-step actions for responding to common incident types, such as ransomware or phishing, before any incident occurs. Which incident response phase does this activity belong to?
- A. Preparation.
- B. Recovery.
- C. Containment.
- D. Eradication.
Show answer & explanation
Answer: A
Developing documented runbooks and playbooks in advance of any actual incident is a core activity of the preparation phase, which establishes the tools, procedures, and readiness the response team will rely on once an incident does occur, rather than being an activity performed during the later phases of containment, eradication, or recovery that respond to an incident already in progress.136. A security operations center simultaneously receives alerts for a suspected phishing email reported by one employee and unusual outbound data transfer from a database server containing regulated customer records. With limited immediate analyst capacity, which should be triaged FIRST?
- A. The phishing email, since email-based threats are always the most common attack vector.
- B. Both should be assigned equal priority and worked in the order received.
- C. Neither should be treated as urgent until a formal incident is declared by management.
- D. The unusual outbound data transfer from the regulated database server, given its higher potential impact and evidence of active data movement.
Show answer & explanation
Answer: D
Triage prioritization should weigh potential impact and the evidence available; an unusual outbound transfer from a server holding regulated customer records suggests active data exfiltration in progress with severe potential consequences, which warrants more urgent attention than a reported phishing email that has not yet been confirmed as a successful compromise. Treating both as equal priority or waiting for a formal declaration before acting risks losing critical time on the higher-impact event.137. An organization's incident response plan defines specific criteria, such as data type affected and number of systems involved, that determine when an event must be escalated to senior management. What is the PRIMARY purpose of having these predefined escalation criteria?
- A. To reduce the total number of incidents the organization experiences.
- B. To ensure all incidents, regardless of severity, are escalated to the board of directors.
- C. To eliminate the need for a formal incident response plan.
- D. To ensure incidents of sufficient severity reach decision-makers consistently and promptly, rather than relying on ad hoc judgment calls during a stressful event.
Show answer & explanation
Answer: D
Predefined escalation criteria remove the burden of making a high-stakes severity judgment in the heat of a stressful, time-sensitive event, ensuring that incidents meeting objective thresholds are consistently and promptly routed to the appropriate decision-makers rather than depending on whoever happens to be handling the incident at the time. These criteria do not reduce the number of incidents that occur, replace the broader incident response plan, or mean every incident regardless of severity goes to the board.138. During evidence collection for a security incident that may result in legal action, an analyst images a hard drive and documents who handled it, when, and for what purpose at each step. What is the PRIMARY reason this documentation is maintained?
- A. To reduce the storage space required for the evidence.
- B. To satisfy the organization's data retention policy.
- C. To allow the evidence to be deleted more quickly after the investigation.
- D. To establish a defensible chain of custody demonstrating the evidence was not altered or tampered with between collection and use.
Show answer & explanation
Answer: D
Recording who handled a piece of evidence, when, and for what purpose at every step establishes a chain of custody that can be used to demonstrate the evidence was properly controlled and not altered or tampered with from the moment of collection through its eventual use, which is essential if the evidence is later challenged in legal proceedings. This documentation serves evidentiary integrity, not retention policy compliance, storage efficiency, or faster deletion.139. During an active incident on a critical production server, the team is deciding between isolating the server from the network while keeping it running, versus immediately powering it off. What is the PRIMARY trade-off between these two containment approaches?
- A. Isolating the server always causes greater business disruption than powering it off.
- B. Isolating while running can preserve volatile evidence such as memory contents and active connections, while powering off may cause the loss of that volatile data but definitively stops any ongoing malicious activity.
- C. There is no meaningful difference between the two approaches for containment purposes.
- D. Powering off the server always preserves more forensic evidence than isolating it.
Show answer & explanation
Answer: B
Keeping a compromised server running but isolated from the network can preserve volatile forensic evidence such as memory contents, running processes, and active network connections that would otherwise be lost, whereas immediately powering the system off guarantees that any ongoing malicious activity stops but destroys that volatile evidence in the process. The choice involves weighing evidentiary value against the certainty of halting active compromise, and neither approach is universally less disruptive to the business.140. An alert indicating potential malware on an endpoint is investigated and determined to be a false positive triggered by legitimate administrative software. What is the MOST appropriate next step?
- A. Immediately isolate the endpoint from the network regardless of the finding.
- B. Escalate the alert to senior management as a confirmed incident.
- C. Take no further action or documentation since the alert was a false positive.
- D. Document the finding and, if appropriate, tune the detection rule to reduce recurrence of similar false positives.
Show answer & explanation
Answer: D
Once an alert is confirmed to be a false positive caused by legitimate software, the appropriate response is to document the finding for the record and consider tuning the detection rule so that the same legitimate activity does not continue generating unnecessary alerts, which helps preserve analyst attention for genuine threats. Isolating the endpoint or escalating as a confirmed incident would be an overreaction once the false positive is confirmed, while taking no action at all wastes the opportunity to improve detection accuracy going forward.141. Following an incident, the response team determines that the initial point of entry was a misconfigured remote access service left exposed to the internet. What activity does identifying this specific finding represent?
- A. Business impact analysis.
- B. Risk transfer.
- C. Root cause analysis, which identifies the underlying condition that allowed the incident to occur.
- D. Chain of custody documentation.
Show answer & explanation
Answer: C
Identifying the specific underlying condition, in this case a misconfigured, internet-exposed remote access service, that allowed the incident to occur is the purpose of root cause analysis, which digs beneath the immediate symptoms of an incident to find the actual enabling weakness so it can be corrected. This is distinct from chain of custody documentation, which concerns evidence handling, business impact analysis, which concerns process criticality, or risk transfer, which is a treatment option unrelated to identifying causation.142. During a major incident involving multiple technical teams, legal, and communications staff, who is generally responsible for coordinating overall response activities and making key operational decisions?
- A. Whichever team member first detected the incident.
- B. A designated incident commander with the authority to coordinate across teams and make timely decisions.
- C. The organization's external auditor.
- D. The most senior executive available, regardless of incident response training.
Show answer & explanation
Answer: B
Effective incident response depends on a designated incident commander role, filled by someone trained and authorized to coordinate activities across the various technical and business teams involved and make timely operational decisions, rather than defaulting to whoever happened to detect the issue or to a senior executive without specific incident response training and authority. This role is defined in advance as part of preparation, not assigned reactively during the event.143. During an incident involving a suspected nation-state actor, legal counsel recommends engaging law enforcement. What is an important consideration the information security manager should raise regarding this decision?
- A. Law enforcement engagement is never appropriate for security incidents.
- B. Law enforcement involvement will guarantee full recovery of any stolen data.
- C. Engaging law enforcement eliminates the need to continue technical remediation efforts.
- D. Law enforcement involvement may affect the timeline and handling of evidence, systems, and public disclosure, and should be coordinated with the ongoing technical response.
Show answer & explanation
Answer: D
Involving law enforcement can affect how evidence must be handled, may influence the timing of system remediation or public disclosure to avoid compromising an investigation, and should be carefully coordinated with the technical response so that neither effort undermines the other. It does not guarantee data recovery, does not remove the need for continued technical remediation, and is a legitimate consideration in many serious incidents rather than something to be avoided entirely.144. During a significant incident that may require public disclosure, why is it important for the information security manager to coordinate closely with legal and communications teams before any public statement is released?
- A. To delay the incident response process until a statement is fully drafted.
- B. To ensure the statement uses the most technical language possible for accuracy.
- C. To transfer full responsibility for the incident response to the communications team.
- D. To ensure the statement is factually accurate, legally sound, and does not disclose information that could aid attackers or violate notification obligations.
Show answer & explanation
Answer: D
Coordinating with legal and communications teams before any public statement helps ensure the disclosure is factually accurate based on what is actually known, complies with applicable legal and regulatory obligations, and avoids revealing operational details that could help the attacker or other threat actors, none of which is achieved by prioritizing technical language, delaying the broader response, or handing off full incident ownership to communications staff.145. An incident response plan has been drafted by the security operations team. Who should formally approve the plan to ensure organizational commitment and authority?
- A. Senior management or an appropriate governance body with the authority to commit organizational resources and roles during an incident.
- B. Only the security operations team that authored it.
- C. The organization's external penetration testing vendor.
- D. No formal approval is necessary as long as the plan is technically sound.
Show answer & explanation
Answer: A
Because an incident response plan commits people across multiple functions, including legal, communications, and business units, to specific roles and actions during a crisis, it requires formal approval by senior management or an appropriate governance body with the authority to commit those resources and enforce the plan across the organization, not just sign-off from the team that drafted it. Relying only on the authoring team's approval or skipping formal approval altogether undermines the plan's organizational authority when it is needed most.146. An organization has only ever tested its incident response plan through tabletop discussions where participants talk through hypothetical scenarios. What additional value would a full technical simulation exercise, involving actual systems in a test environment, provide beyond the tabletop format?
- A. It would replace the need for documented runbooks.
- B. It would validate the technical execution of response actions, such as actual tool usage and system isolation steps, which a discussion-based exercise cannot verify.
- C. It would eliminate the need for any future tabletop exercises.
- D. It guarantees that no future incident will occur.
Show answer & explanation
Answer: B
A tabletop exercise validates decision-making, communication, and coordination through discussion, but it does not verify whether the actual technical steps, such as running specific tools or executing isolation procedures on real systems, work as expected under realistic conditions; a full technical simulation closes that gap by testing the hands-on execution of the plan. Neither exercise type replaces the other, and no form of testing can guarantee incidents will never occur.147. An organization discovers that a security incident originated at a third-party vendor with system access to its environment, rather than within its own systems. What should the information security manager do regarding this vendor relationship as part of the response?
- A. Immediately terminate the vendor contract without further investigation.
- B. Wait for the vendor to voluntarily disclose details with no formal engagement.
- C. Take no action regarding the vendor since the incident occurred on the organization's own systems ultimately.
- D. Engage the vendor per any contractual incident notification and cooperation obligations, and assess the vendor's access and controls as part of the response.
Show answer & explanation
Answer: D
When an incident traces back to a third-party vendor with access to the organization's environment, the appropriate response includes engaging the vendor under any contractual notification and cooperation terms, and assessing the scope of the vendor's access and the adequacy of their controls as part of understanding and containing the incident, rather than either ignoring the vendor's role, terminating the relationship reflexively before investigation, or passively waiting for the vendor to volunteer information.148. An investigation reveals that a current employee intentionally exfiltrated confidential data. Compared to responding to an external attacker, what additional consideration does this insider incident MOST require?
- A. Close coordination with human resources and legal counsel regarding employment action, evidence standards, and potential legal proceedings against the individual.
- B. Technical containment steps become unnecessary once an insider is identified.
- C. The incident does not need to be documented since no external party was involved.
- D. No additional considerations are needed since the response process is identical.
Show answer & explanation
Answer: A
An insider incident introduces employment law, human resources, and potential criminal or civil legal considerations that an external attacker incident typically does not involve in the same way, requiring close coordination with HR and legal counsel to ensure evidence is handled to a standard that supports possible employment action or legal proceedings, in addition to the standard technical containment and eradication steps that remain necessary. Treating the response as identical to an external incident, skipping documentation, or dropping technical containment would all be inappropriate.149. An information security manager wants to report the total organizational cost of a recent incident to executive leadership. Which set of factors should this figure PRIMARILY include?
- A. Direct costs such as remediation, legal fees, and regulatory fines, along with reasonably estimable indirect costs such as business disruption.
- B. Only the cost of new security tools purchased after the incident.
- C. Only the salary of the incident response team members involved.
- D. Only the cost of the cyber insurance premium for the following year.
Show answer & explanation
Answer: A
A meaningful total cost figure for an incident should capture direct costs, such as remediation efforts, legal fees, and any regulatory fines, along with indirect costs that can be reasonably estimated, such as lost business or productivity from disruption, since focusing narrowly on just one cost category, like new tools, staff salaries, or a future insurance premium, would significantly understate the incident's true organizational impact.150. An organization's public-facing web application becomes unavailable due to a large-scale distributed denial-of-service (DDoS) attack. Which response action is MOST directly relevant to this specific type of incident, compared to a typical malware-based incident?
- A. Performing forensic imaging of the affected web server's hard drive.
- B. Engaging DDoS mitigation services or traffic-scrubbing capabilities to absorb and filter malicious traffic while preserving legitimate access.
- C. Disabling the affected employee's user account credentials.
- D. Reviewing email gateway logs for phishing indicators.
Show answer & explanation
Answer: B
A DDoS attack is fundamentally a volumetric or protocol-based attack aimed at overwhelming availability, so the most directly relevant response involves engaging DDoS mitigation or traffic-scrubbing capabilities that can absorb and filter the malicious traffic while allowing legitimate users through, which is distinct from the forensic imaging, account disabling, or phishing log review actions more typically associated with a malware or account-compromise incident.151. An organization discovers that an attacker compromised an executive's email account and used it to instruct the finance department to wire funds to a fraudulent account, a portion of which was transferred before detection. In addition to securing the compromised account, what should the incident response include?
- A. Notification to the marketing department to update the company website.
- B. A review of the physical security badge access logs for the building.
- C. Prompt engagement with the organization's bank and, where applicable, law enforcement to attempt to recall or trace the fraudulent transfer, alongside a review of financial approval controls.
- D. A mandatory password reset for all customers of the organization.
Show answer & explanation
Answer: C
In a business email compromise resulting in a fraudulent wire transfer, time is critical for engaging the bank to attempt to recall the funds and involving law enforcement to assist in tracing the transfer, while also reviewing the financial approval controls, such as verification requirements for wire instructions, that allowed the fraudulent request to succeed. Notifying marketing, reviewing physical badge logs, or resetting customer passwords do not address the actual financial fraud or its enabling control gap in this scenario.152. An organization learns that a software vendor whose product is widely deployed across the organization's environment has suffered a supply chain compromise, potentially distributing malicious code through a legitimate software update. What should the information security manager's response PRIMARILY focus on FIRST?
- A. Identifying all instances of the affected product and update version within the environment and assessing whether indicators of compromise associated with the malicious update are present.
- B. Waiting for the vendor to issue a public statement before taking any internal action.
- C. Immediately uninstalling all software from every vendor the organization uses, as a precaution.
- D. Filing a lawsuit against the vendor before assessing internal exposure.
Show answer & explanation
Answer: A
The immediate priority in a supply chain compromise is determining the organization's actual exposure, specifically which systems have the affected product and update version installed, and then checking those systems for indicators of compromise associated with the malicious update, so that containment and remediation can be scoped correctly and quickly. Broadly uninstalling unrelated software, waiting passively for vendor communication, or pursuing legal action before understanding internal exposure would all delay or misdirect the necessary response.153. An analyst isolates an infected workstation from the network to prevent malware from spreading further, but has not yet removed the malware from the system. What has been accomplished at this point?
- A. Recovery, since the system is now considered safe to use.
- B. Preparation, since the response plan is now being followed for the first time.
- C. Containment, since the spread of the threat has been limited, though the underlying malware has not yet been eradicated.
- D. Eradication, since the malware can no longer communicate externally.
Show answer & explanation
Answer: C
Isolating the infected workstation limits the malware's ability to spread to other systems, which is the definition of containment, but the malicious code itself remains present on the machine until it is actively removed, meaning eradication has not yet occurred and the system is not yet safe to consider recovered. Preparation refers to readiness activities performed before an incident, not actions taken during an active response.154. An organization's incident response process requires a formal 'incident' to be declared before certain response resources and communication protocols are activated. What is the PRIMARY benefit of having clearly defined criteria for when an event qualifies as a formal incident?
- A. It guarantees that declared incidents will always be resolved within a fixed time period.
- B. It reduces the total number of security events the organization experiences.
- C. It ensures response resources and protocols are activated consistently for events that meet the threshold, avoiding both under-response to serious events and unnecessary activation for minor ones.
- D. It eliminates the need to investigate events that do not meet the incident threshold.
Show answer & explanation
Answer: C
Clear criteria for declaring a formal incident ensure that the organization consistently activates its more intensive response resources and communication protocols when an event genuinely warrants it, while avoiding the cost and disruption of activating those same resources for every minor event that does not meet the threshold. It does not reduce the underlying number of security events, does not remove the need to still investigate lower-threshold events at an appropriate level, and does not guarantee any particular resolution timeframe.155. An information security manager is preparing a post-incident report for two audiences: the technical response team and executive leadership. How should the content of these two versions MOST appropriately differ?
- A. Both versions should be identical to avoid any inconsistency in reporting.
- B. The executive version should focus on business impact, root cause at a high level, and recommended actions, while the technical version includes detailed forensic findings and remediation steps.
- C. The executive version should include the full technical exploit details for completeness.
- D. The technical version should omit the timeline of events entirely.
Show answer & explanation
Answer: B
Different audiences need different levels of detail to act effectively: executives are best served by a summary of business impact, a high-level explanation of root cause, and clear recommended actions or decisions needed, while the technical team needs the detailed forensic findings, indicators of compromise, and specific remediation steps to do their work, so tailoring content to each audience serves the report's purpose better than either omitting the timeline or forcing identical, overly technical content on both groups.156. A severe incident begins to affect not only IT systems but also physical facility operations and requires coordination with corporate crisis management processes. What does this scenario illustrate about incident response planning?
- A. Incident response plans should never address scenarios beyond pure IT systems.
- B. Crisis management and incident response are entirely separate processes that should never interact.
- C. Physical facility issues should always be handled independently of the security incident response team.
- D. Incident response plans should be integrated with broader organizational crisis management processes to handle incidents with impacts beyond IT systems alone.
Show answer & explanation
Answer: D
When a security incident's effects extend beyond IT systems into physical operations or broader business continuity concerns, it demonstrates the need for the incident response plan to be integrated with, rather than isolated from, the organization's broader crisis management processes, so that response efforts across different domains are coordinated rather than conducted in silos that could work at cross purposes or duplicate effort.157. An organization with a small internal security team is evaluating whether to establish a retainer agreement with an external incident response firm before any incident occurs. What is the PRIMARY benefit of establishing this retainer in advance, rather than seeking external help only after an incident begins?
- A. It transfers full legal liability for any incident to the external firm.
- B. It guarantees the organization will never need to declare a major incident.
- C. It eliminates the need for the internal security team to have any incident response capability.
- D. It secures predefined response times, contractual terms, and familiarity with the environment, avoiding delays that would occur if vendor selection and contracting started only after an incident is already underway.
Show answer & explanation
Answer: D
Establishing a retainer in advance means response times, contractual terms, and often prior familiarity with the environment are already negotiated and in place, so the organization can engage expert help immediately when an incident occurs rather than losing critical time to vendor selection, contract negotiation, and onboarding during an active crisis. It does not guarantee incidents won't occur, does not eliminate the need for baseline internal capability, and does not shift legal liability to the external firm.158. During an investigation into a suspected compromise, the response team discovers that critical system logs were only retained for seven days and the initial intrusion is believed to have occurred three weeks earlier. What is the PRIMARY impact of this finding?
- A. The investigation can proceed with no meaningful loss of capability.
- B. The organization will be unable to declare a formal incident.
- C. The team's ability to reconstruct the full timeline and initial entry point of the attack is significantly impaired due to the missing historical log data.
- D. The compromised systems can no longer be patched.
Show answer & explanation
Answer: C
Because the retained logs do not extend back far enough to cover the believed initial intrusion date, the response team's ability to reconstruct exactly how, when, and where the attacker first gained access is significantly impaired, which can hinder both the technical investigation and any subsequent legal or regulatory reporting that depends on an accurate timeline. This gap does not prevent declaring an incident, patching systems, or otherwise continuing the response, but it does meaningfully limit what can be conclusively determined about the attack's origin.159. An organization is simultaneously handling two active incidents: a low-severity malware infection on a single non-critical workstation, and a suspected unauthorized access attempt against the organization's core financial database. With limited response staff available, how should resources be allocated?
- A. Prioritize the suspected unauthorized access to the core financial database, given its significantly higher potential business impact.
- B. Postpone both incidents until additional staff can be hired.
- C. Prioritize the malware infection because it was detected first.
- D. Equally split resources between both incidents regardless of severity or potential impact.
Show answer & explanation
Answer: A
When response capacity is limited, resources should be allocated based on potential business impact and severity rather than order of detection or an arbitrary equal split; a suspected unauthorized access attempt against a core financial database carries substantially greater potential impact than a low-severity infection on a single non-critical workstation, and postponing response to either incident while waiting to hire additional staff would leave a serious, active threat unaddressed.
More in this family
Explore more Technology & IT Certifications
In the same family
More in this category
- ISC2 Certified in Cybersecurity (CC)Practice questions →
- Project Management Professional (PMP)Practice questions →
- Microsoft Certified: Power BI Data Analyst Associate (Exam PL-300)Practice questions →
- Salesforce Certified Platform AdministratorPractice questions →
- HashiCorp Certified: Terraform Associate (004)Practice questions →
- AWS Certified AI PractitionerPractice questions →
- AWS Certified Cloud PractitionerPractice questions →
- AWS Certified Developer - AssociatePractice questions →
- AWS Certified Solutions Architect – AssociatePractice questions →
- Microsoft Certified: Azure Administrator Associate (Exam AZ-104)Practice questions →
- Microsoft Azure AI FundamentalsPractice questions →
2026 statistics
Key facts: CISM exam
Every free resource for this exam
Get a free CISM study plan
A week-by-week plan plus new practice questions, straight to your inbox.
Official sources
Primary documents used to verify the exam details shown on this page.
- ISACA Certification Exam Candidate GuideISACAisaca.org
- CISM Exam Content OutlineISACAisaca.org
- CISM Certification OverviewISACAisaca.org
- ISACA (CISA/CRISC/CISM/CGEIT) Scheduling GuidePSIproctor2.psionline.com
- CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling GuideISACAisaca.org
Last verified against the official exam content outline:
Frequently asked questions
What is the passing score for the CISM exam, and how is it scored?
The CISM exam is not scored as a simple percentage of questions answered correctly. Instead, ISACA reports a scaled score on a common scale from 200 to 800, where 800 is a perfect score. You must receive a scaled score of 450 or higher to pass. Because the score is scaled rather than raw, you cannot simply count correct answers to know if you passed — the scaling accounts for the relative difficulty of the specific question set you receive.
How many questions are on the CISM exam and how much time do I get?
The CISM exam contains 150 multiple-choice questions and you are given 240 minutes (4 hours) to complete it. That works out to an average of about 1.6 minutes per question, so pacing matters — practice answering under timed conditions so you do not run short at the end. Every question has a stem and four answer options, and you are asked to select the single best answer, which means more than one option may be partially correct.
Which CISM domains should I focus my study time on?
The exam covers four job practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. They are not weighted equally. Domain 3, Information Security Program, is the largest at 33%, and Domain 4, Incident Management, is next at 30% — together these two account for 63% of the exam. Domain 2, Information Security Risk Management, is 20% and Domain 1, Information Security Governance, is 17%. A smart study plan weights your effort toward Domains 3 and 4, since nearly two-thirds of your score comes from them.
How do I register and schedule the CISM exam, and what does it cost?
You register and pay first: the registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Only after you have registered and paid does ISACA email you that you are eligible to schedule your appointment on the PSI platform — PSI is ISACA's exam delivery vendor. When scheduling, you choose a delivery mode of either an in-person test center or an online remote-proctored exam. Note two deadlines: any rescheduling or cancelling must be done at least 48 hours before your appointment, and once you pass, you have 5 years to apply for the CISM certification.