ISACA Certified Information Security Manager
(CISM) Exam | Latest Verified Questions and
Detailed Answers
OVERVIEW DESCRIPTION:
The ISACA Certified Information Security Manager (CISM) exam is a rigorous, four-hour,
150-question assessment designed for individuals transitioning from technical roles to
management positions. It evaluates a candidate's expertise across four key domains:
Information Security Governance, Information Risk Management, Information Security
Program Development and Management, and Incident Management. The exam emphasizes
a managerial mindset, testing the ability to align security initiatives with business goals,
manage risk from a strategic perspective, and oversee the entire security lifecycle rather
than focusing on hands-on technical execution.
QUESTION 1
An information security risk analysis is MOST helpful for an organization to ensure that:
A. The infrastructure has the right level of access control.
B. Cost-effective decisions are made about which assets need protection.
C. The right amount of funding goes to security processes.
D. The organization puts appropriate security technologies in place.
CORRECT ANSWER: B
EXPERT RATIONALE: Risk analysis is fundamentally a business tool designed to identify
and prioritize risks so that resources are allocated efficiently and effectively. It ensures
protection decisions are based on a cost-benefit analysis relative to asset value and
threat impact, which is the core of management thinking.
QUESTION 2
,2|Page
In a company that operates in multiple countries, local security regulations should be
followed over the global security policy because:
A. Business goals are set by the managers of the local business units.
B. Teaching employees about local rules is easier than teaching them about a global
policy.
C. Global security policies often have unnecessary controls for local branches.
D. The requirements of local laws have higher authority.
CORRECT ANSWER: D
EXPERT RATIONALE: From a governance and legal standpoint, local laws and regulations
always supersede internal company policies. The organization must comply with the law
in any jurisdiction where it operates, making regulatory requirements the primary driver.
QUESTION 3
To get a clear picture of how a new regulation will affect the organization's security
controls, the information security manager should FIRST:
A. Perform a cost-benefit analysis.
B. Carry out a risk assessment.
C. Talk to senior management.
D. Conduct a gap analysis.
CORRECT ANSWER: D
EXPERT RATIONALE: A gap analysis is the initial step to compare current security
controls against the specific requirements of the new regulation. This identifies the
specific areas of non-compliance, which is essential before any further action, like a risk
assessment or cost analysis, can be taken.
,3|Page
QUESTION 4
When management changes the overall business strategy, which process should be
used to review existing security controls and choose new ones?
A. Access control management
B. Change management
C. Configuration management
D. Risk management
CORRECT ANSWER: D
EXPERT RATIONALE: A change in business strategy alters the organization's risk profile
and objectives. Risk management is the ongoing process of identifying, assessing, and
responding to risk, making it the correct framework for evaluating and selecting controls
aligned with the new strategic direction .
QUESTION 5
What is the MOST effective method to build a culture where employees are aware of
and proactive about risk?
A. Change the risk awareness messages from time to time.
B. Make sure threats are communicated to everyone in the organization quickly.
C. Regularly check if security controls are being followed and share the results.
D. Set up rewards and a way for staff to report risks.
CORRECT ANSWER: D
EXPERT RATIONALE: A risk-aware culture is built on engagement and empowerment.
Establishing incentives encourages proactive identification of risks, while creating a safe
, 4|Page
channel for reporting ensures that issues are raised and addressed, fostering a sense of
shared responsibility .
QUESTION 6
An information security manager discovers an existing third-party contract lacks clear
data protection requirements. What is the BEST recommendation?
A. End the outsourcing agreement.
B. Transfer the risk to the provider.
C. Create an addendum to the current contract.
D. Start an external audit of the provider's data center.
CORRECT ANSWER: C
EXPERT RATIONALE: Creating a contract addendum is the most practical and immediate
solution to remedy the gap. It formally establishes the necessary security obligations
and safeguards for the organization's data within the existing business relationship .
QUESTION 7
An organization has bought a Security Information and Event Management (SIEM) tool.
What is MOST important to decide before putting it in place?
A. Which controls will be monitored
B. The reporting features
C. The contract with the SIEM vendor
D. The technical support available
CORRECT ANSWER: A