Skip to main content

CISM Real Exam Questions

Certified Information Security Manager

1,659 questions available · Page 1 of 166

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Senior management has requested a budget cut for the information security program in the coming fiscal year.

Which of the following should be the information security manager's FIRST course of action?

  1. A

    Analyze the impact to the information security program.

  2. B

    Advise business unit heads of potential changes to the information security program.

  3. C

    Evaluate cost savings within existing implementations.

  4. D

    Re-prioritize information security implementation and operations.

Show answer and explanation

Correct answer: A

Explanation

Before changing priorities or seeking savings, the information security manager must analyze how the proposed budget cut would affect the program. This establishes the resulting impact on risk, controls, operations, and commitments and supports informed tradeoffs. Reprioritization and communication should follow only after the consequences are understood.

Question 2 Single choice

An information security manager has determined that the mean time to prioritize information security incidents has increased to an unacceptable level.

Which of the following processes would BEST enable the information security manager to address this concern?

  1. A

    Incident classification

  2. B

    Incident response

  3. C

    Forensic analysis

  4. D

    Vulnerability assessment

Show answer and explanation

Correct answer: A

Explanation

Prioritization depends on quickly assigning incidents consistent categories and severity levels. A defined incident classification process applies common criteria to impact and urgency, enabling faster routing and response priority decisions. Incident response acts after prioritization, forensic analysis examines causes and evidence, and vulnerability assessment evaluates weaknesses rather than classifying active incidents.

Question 3 Single choice

Which of the following is the GREATEST concern resulting from the lack of severity criteria in incident classification?

  1. A

    Statistical reports will be incorrect.

  2. B

    The service desk will be staffed incorrectly.

  3. C

    Escalation procedures will be ineffective.

  4. D

    Timely detection of attacks will be impossible.

Show answer and explanation

Correct answer: C

Explanation

Severity criteria determine how urgently an incident must be handled and which level of authority or expertise must become involved. Without consistent severity classification, escalation thresholds cannot reliably route serious incidents to the appropriate responders and decision-makers. Detection can still occur, but the resulting response path may be ineffective.

Question 4 Single choice

An organization has experienced multiple instances of privileged users misusing their access.

Which of the following processes would be MOST helpful in identifying such violations?

  1. A

    Policy exception review

  2. B

    Review of access controls

  3. C

    Security assessment

  4. D

    Log review

Show answer and explanation

Correct answer: D

Explanation

Privileged misuse is identified by examining records of what elevated accounts actually did. Log review can reveal account activity, access times, affected resources, and actions that conflict with authorized duties. Reviewing access controls shows what users are permitted to do, but it does not by itself establish whether granted privileges were abused.

Question 5 Single choice

The ULTIMATE responsibility for ensuring the objectives of an information security framework are being met belongs to:

  1. A

    the internal audit manager.

  2. B

    the information security officer.

  3. C

    the steering committee.

  4. D

    the board of directors.

Show answer and explanation

Correct answer: D

Explanation

The board of directors holds ultimate accountability for organizational governance, including assurance that the information security framework achieves its objectives. Management and the security officer implement and monitor the framework, while internal audit provides independent assurance. These functions support the board but do not transfer its final oversight responsibility.

Question 6 Single choice

Which of the following is the GREATEST benefit of effective information security governance?

  1. A

    Treatment priorities are based on risk exposure.

  2. B

    Information security standards are communicated to primary stakeholders.

  3. C

    The information security budget is aligned to the organization.

  4. D

    Executive management's strategy is aligned to the information security strategy.

Show answer and explanation

Correct answer: D

Explanation

Effective governance connects information security direction to executive management's strategy and the organization's objectives. This alignment ensures security decisions support business priorities and that risk is addressed in the context of enterprise goals. Budgets, standards communication, and treatment priorities are useful governance results, but strategic alignment is the broader benefit.

Question 7 Single choice

An information security manager has identified that security risks are not being treated in a timely manner.

Which of the following is the BEST way to address this situation?

  1. A

    Provide regular updates about the current state of the risks.

  2. B

    Re-perform risk analysis at regular intervals.

  3. C

    Assign a risk owner to each risk

  4. D

    Create mitigating controls to manage the risks.

Show answer and explanation

Correct answer: C

Explanation

Assigning an owner to each risk creates clear accountability for selecting, funding, tracking, and completing treatment within an appropriate time. Without ownership, updates and repeated analysis can document delays without resolving them. The risk owner coordinates treatment decisions, while control implementation follows from those authorized decisions.

Question 8 Single choice

During a post-incident review, the sequence and correlation of actions must be analyzed PRIMARILY based on:

  1. A

    a consolidated event timeline.

  2. B

    logs from systems involved.

  3. C

    interviews with personnel.

  4. D

    documents created during the incident.

Show answer and explanation

Correct answer: A

Explanation

A consolidated event timeline places evidence from different systems, documents, and people into a single chronological sequence. That structure makes it possible to analyze order, dependencies, and correlation among actions during the incident. Individual logs, interviews, and incident documents are inputs, but each provides only a partial view until the events are normalized and combined by time.

Question 9 Single choice

An incident response team has been alerted to suspicious communications between an end user's workstation and a possibly infected external server.

Which of the following should be done NEXT?

  1. A

    Reinstall the operating system of the end user's workstation

  2. B

    Analyze and validate the event

  3. C

    Request an IP address block

  4. D

    Isolate the end user's workstation and the external server

Show answer and explanation

Correct answer: B

Explanation

Suspicious communication is an alert that still requires confirmation and classification. Analyzing and validating the event determines whether an incident exists, what systems and traffic are involved, and what containment action is justified. Reinstallation, blocking, or isolation before validation could disrupt operations or destroy useful information without addressing an accurately established incident.

Question 10 Single choice

IT projects have gone over budget with too many security controls being added post-production.

Which of the following would MOST help to ensure that relevant controls are applied to a project?

  1. A

    Involving information security at each stage of project management

  2. B

    Identifying responsibilities during the project business case analysis

  3. C

    Creating a data classification framework and providing it to stakeholders

  4. D

    Providing stakeholders with minimum information security requirements

Show answer and explanation

Correct answer: A

Explanation

Involving information security at every project management stage allows requirements and relevant controls to be identified as the design, implementation, testing, and release decisions are made. Security issues can then be addressed before they become costly production changes. A one-time list of minimum requirements cannot adapt controls to decisions and risks arising throughout the project.