Sign In
Home/ISACA/CISM/Free questions

CISM — Free Practice Questions

10 free sample questions from a bank of 1769, with the correct answers and explanations. No signup required — start practising right now.

1An information security risk analysis BEST assists an organization in ensuring that:
  • the infrastructure has the appropriate level of access control.
  • cost-effective decisions are made with regard to which assets need protection
  • an appropriate level of funding is applied to security processes.
  • the organization implements appropriate security technologies
Answer: B
2Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?
  • Review the third-party contract with the organization's legal department.
  • Communicate security policy with the third-party vendor.
  • Ensure security is involved in the procurement process.
  • Conduct an information security audit on the third-party vendor.
Answer: C
3Which of the following would BEST enable effective decision-making?
  • Annualized loss estimates determined from past security events
  • A universally applied list of generic threats, impacts, and vulnerabilities
  • A consistent process to analyze new and historical information risk
  • Formalized acceptance of risk analysis by business management
Answer: C
4Which of the following is the BEST option to lower the cost to implement application security controls?
  • Include standard application security requirements.
  • Perform security tests in the development environment.
  • Perform a risk analysis after project completion.
  • Integrate security activities within the development process.
Answer: D
5Which of the following is the GREATEST benefit of effective information security governance?
  • Treatment priorities are based on risk exposure.
  • Information security standards are communicated to primary stakeholders.
  • The information security budget is aligned to the organization.
  • Executive management's strategy is aligned to the information security strategy.
Answer: A
6The ability to integrate information security governance into corporate governance is PRIMARILY driven by:
  • the percentage of corporate budget allocated to the information security program.
  • how often information security metrics are presented to senior management.
  • how often the information security steering committee reviews and updates security policies.
  • how well the information security program supports business objectives.
Answer: D
7Which of the following presents the GREATEST challenge for protecting Internet of Things (IoT) devices?
  • IoT vendor reputation
  • IoT architecture diversity
  • IoT-specific training
  • IoT device policies
Answer: B
8Which of the following parameters is MOST helpful when designing a disaster recovery strategy?
  • Maximum tolerable downtime (MTD)
  • Mean time between failures (MTBF)
  • Allowable interruption window (AIW)
  • Recovery point objective (RPO)
Answer: A
9An IT service desk was not adequately prepared for a recent ransomware attack on user workstations. Which of the following should be given HIGHEST priority by the information security team when creating an action plan to improve service desk readiness?
  • Investing in threat intelligence capability
  • Implementing key risk indicators (KRIs) for ransomware attacks
  • Updating the information security incident response manual
  • Strengthening the organization's data backup capability
Answer: C
10After a risk has been identified, analyzed, and evaluated, which of the following should be done NEXT?
  • Monitor the risk.
  • Prioritize the risk for treatment
  • Identify the risk owner.
  • Identify controls for risk mitigation.
Answer: B

Want the full bank of 1769 questions for CISM? See all practice exams.