NEWEST CERTIFIED INFORMATION
SECURITY MANAGER (CISM) EXAM |
Q&A WITH RATIONALES
1. What is the primary purpose of the Certified
Information Security Manager (CISM)
certification?
A) To validate entry-level technical security
skills
B) To validate expertise in managing, designing,
and overseeing an enterprise's information
security program
C) To certify expertise in network routing and
switching
D) To validate secure software development
skills
Correct answer: B
Rationale: CISM is a management-focused
certification that affirms an individual's ability to
manage and govern an enterprise's information
security program effectively.
,2. Which organization administers the CISM
certification?
A) CompTIA
B) (ISC)²
C) ISACA
D) GIAC
Correct answer: C
Rationale: The Certified Information Security
Manager (CISM) certification is granted by
ISACA, a globally recognized professional
organization known for its rigorous standards in
information security and governance.
3. How many questions are on the CISM exam
and what is the time limit?
A) 100 questions, 2 hours
B) 125 questions, 3 hours
C) 150 questions, 4 hours
D) 200 questions, 5 hours
,Correct answer: C
Rationale: The CISM exam consists of 150
multiple-choice questions that must be
completed within a 4-hour (240 minutes)
timeframe.
4. What is the minimum work experience
requirement for full CISM certification?
A) 2 years
B) 3 years
C) 5 years total, with 3 years in a management
role
D) 10 years
Correct answer: C
Rationale: Candidates must have at least five
years of information security work experience,
with a minimum of three years in a management
role across at least three of the four CISM
domains.
, 5. Which of the following is NOT one of the four
domains covered by the CISM exam?
A) Information Security Governance
B) Information Security Risk Management
C) Security Architecture and Engineering
D) Incident Management
Correct answer: C
Rationale: The four CISM domains are
Information Security Governance, Information
Security Risk Management, Information
Security Program, and Incident Management.
6. Which domain has the highest weight on the
CISM exam?
A) Information Security Governance
B) Information Security Risk Management
C) Information Security Program
D) Incident Management
Correct answer: C
SECURITY MANAGER (CISM) EXAM |
Q&A WITH RATIONALES
1. What is the primary purpose of the Certified
Information Security Manager (CISM)
certification?
A) To validate entry-level technical security
skills
B) To validate expertise in managing, designing,
and overseeing an enterprise's information
security program
C) To certify expertise in network routing and
switching
D) To validate secure software development
skills
Correct answer: B
Rationale: CISM is a management-focused
certification that affirms an individual's ability to
manage and govern an enterprise's information
security program effectively.
,2. Which organization administers the CISM
certification?
A) CompTIA
B) (ISC)²
C) ISACA
D) GIAC
Correct answer: C
Rationale: The Certified Information Security
Manager (CISM) certification is granted by
ISACA, a globally recognized professional
organization known for its rigorous standards in
information security and governance.
3. How many questions are on the CISM exam
and what is the time limit?
A) 100 questions, 2 hours
B) 125 questions, 3 hours
C) 150 questions, 4 hours
D) 200 questions, 5 hours
,Correct answer: C
Rationale: The CISM exam consists of 150
multiple-choice questions that must be
completed within a 4-hour (240 minutes)
timeframe.
4. What is the minimum work experience
requirement for full CISM certification?
A) 2 years
B) 3 years
C) 5 years total, with 3 years in a management
role
D) 10 years
Correct answer: C
Rationale: Candidates must have at least five
years of information security work experience,
with a minimum of three years in a management
role across at least three of the four CISM
domains.
, 5. Which of the following is NOT one of the four
domains covered by the CISM exam?
A) Information Security Governance
B) Information Security Risk Management
C) Security Architecture and Engineering
D) Incident Management
Correct answer: C
Rationale: The four CISM domains are
Information Security Governance, Information
Security Risk Management, Information
Security Program, and Incident Management.
6. Which domain has the highest weight on the
CISM exam?
A) Information Security Governance
B) Information Security Risk Management
C) Information Security Program
D) Incident Management
Correct answer: C