Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 82 pages
Exam (elaborations)

ISACA Certified Information Security Manager (CISM) Exam | Latest Verified Questions and Detailed Answers

Document preview thumbnail
Preview 4 out of 82 pages

OVERVIEW DESCRIPTION: The ISACA Certified Information Security Manager (CISM) exam is a rigorous, four-hour, 150-question assessment designed for individuals transitioning from technical roles to management positions. It evaluates a candidate's expertise across four key domains: Information Security Governance, Information Risk Management, Information Security Program Development and Management, and Incident Management. The exam emphasizes a managerial mindset, testing the ability to align security initiatives with business goals, manage risk from a strategic perspective, and oversee the entire security lifecycle rather than focusing on hands-on technical execution.

Content preview

1|Page




ISACA Certified Information Security Manager
(CISM) Exam | Latest Verified Questions and
Detailed Answers

OVERVIEW DESCRIPTION:
The ISACA Certified Information Security Manager (CISM) exam is a rigorous, four-hour,
150-question assessment designed for individuals transitioning from technical roles to
management positions. It evaluates a candidate's expertise across four key domains:
Information Security Governance, Information Risk Management, Information Security
Program Development and Management, and Incident Management. The exam emphasizes
a managerial mindset, testing the ability to align security initiatives with business goals,
manage risk from a strategic perspective, and oversee the entire security lifecycle rather
than focusing on hands-on technical execution.

QUESTION 1

An information security risk analysis is MOST helpful for an organization to ensure that:


A. The infrastructure has the right level of access control.
B. Cost-effective decisions are made about which assets need protection.

C. The right amount of funding goes to security processes.
D. The organization puts appropriate security technologies in place.


CORRECT ANSWER: B

EXPERT RATIONALE: Risk analysis is fundamentally a business tool designed to identify

and prioritize risks so that resources are allocated efficiently and effectively. It ensures
protection decisions are based on a cost-benefit analysis relative to asset value and

threat impact, which is the core of management thinking.

QUESTION 2

,2|Page


In a company that operates in multiple countries, local security regulations should be

followed over the global security policy because:

A. Business goals are set by the managers of the local business units.

B. Teaching employees about local rules is easier than teaching them about a global
policy.

C. Global security policies often have unnecessary controls for local branches.
D. The requirements of local laws have higher authority.


CORRECT ANSWER: D

EXPERT RATIONALE: From a governance and legal standpoint, local laws and regulations

always supersede internal company policies. The organization must comply with the law
in any jurisdiction where it operates, making regulatory requirements the primary driver.


QUESTION 3

To get a clear picture of how a new regulation will affect the organization's security

controls, the information security manager should FIRST:

A. Perform a cost-benefit analysis.

B. Carry out a risk assessment.
C. Talk to senior management.

D. Conduct a gap analysis.

CORRECT ANSWER: D


EXPERT RATIONALE: A gap analysis is the initial step to compare current security
controls against the specific requirements of the new regulation. This identifies the

specific areas of non-compliance, which is essential before any further action, like a risk
assessment or cost analysis, can be taken.

,3|Page


QUESTION 4


When management changes the overall business strategy, which process should be
used to review existing security controls and choose new ones?


A. Access control management
B. Change management

C. Configuration management
D. Risk management


CORRECT ANSWER: D

EXPERT RATIONALE: A change in business strategy alters the organization's risk profile

and objectives. Risk management is the ongoing process of identifying, assessing, and
responding to risk, making it the correct framework for evaluating and selecting controls

aligned with the new strategic direction .

QUESTION 5


What is the MOST effective method to build a culture where employees are aware of
and proactive about risk?


A. Change the risk awareness messages from time to time.
B. Make sure threats are communicated to everyone in the organization quickly.

C. Regularly check if security controls are being followed and share the results.
D. Set up rewards and a way for staff to report risks.


CORRECT ANSWER: D

EXPERT RATIONALE: A risk-aware culture is built on engagement and empowerment.
Establishing incentives encourages proactive identification of risks, while creating a safe

, 4|Page


channel for reporting ensures that issues are raised and addressed, fostering a sense of

shared responsibility .

QUESTION 6


An information security manager discovers an existing third-party contract lacks clear
data protection requirements. What is the BEST recommendation?


A. End the outsourcing agreement.
B. Transfer the risk to the provider.

C. Create an addendum to the current contract.
D. Start an external audit of the provider's data center.


CORRECT ANSWER: C

EXPERT RATIONALE: Creating a contract addendum is the most practical and immediate

solution to remedy the gap. It formally establishes the necessary security obligations
and safeguards for the organization's data within the existing business relationship .


QUESTION 7

An organization has bought a Security Information and Event Management (SIEM) tool.

What is MOST important to decide before putting it in place?

A. Which controls will be monitored

B. The reporting features
C. The contract with the SIEM vendor

D. The technical support available

CORRECT ANSWER: A

Document information

Uploaded on
March 29, 2026
Number of pages
82
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$70.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
VerifiedSets
3.7
(7)
Sold
31
Followers
1
Items
1400
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions