• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

Certified Information Security Manager (CISM) Advanced Practice Examination Comprehensive 150-Question Multiple Choice Practice Exam a well detailed practice exam 2025/2026 graded A+ well written !!!

Document preview thumbnail
Preview 4 out of 48 pages

Certified Information Security Manager (CISM) Advanced Practice Examination Comprehensive 150-Question Multiple Choice Practice Exam a well detailed practice exam 2025/2026 graded A+ well written !!!

Content preview

Certified Information Security Manager
(CISM) Advanced Practice Examination
Comprehensive 150-Question Multiple-
Choice Practice Exam a well detailed
practice exam 2025/2026 graded A+ well
written !!!




Exam Format: 150 multiple-choice questions | 4 hours (240 minutes) | Passing score: 450/800

Domain Weighting: Domain 1 – Information Security Governance (17%) | Domain 2 –
Information Security Risk Management (20%) | Domain 3 – Information Security Program
Development and Management (33%) | Domain 4 – Incident Management (30%)

Target Audience: Experienced information security professionals preparing for the ISACA CISM
certification exam

Instructions: Select the single best answer for each question. Questions are designed to test
managerial-level decision-making, strategic thinking, and the application of information security
management principles from a risk-based, business-aligned perspective.



DOMAIN 1: INFORMATION SECURITY GOVERNANCE (25 Questions)

Questions 1-25

1. Which of the following would BEST ensure the success of information security governance
within an organization?

,A. The steering committee approves all security projects
B. The security policy manual is distributed to all managers
C. Security procedures are accessible on the company intranet
D. The corporate network utilizes multiple screened subnets

Correct Answer: A
Rationale: Success of information security governance requires active oversight and approval
from a steering committee with appropriate authority. While distributing policies (B) and
making procedures accessible (C) are important implementation activities, and network
segmentation (D) is a technical control, governance success depends on executive-level
commitment and decision-making authority. A steering committee with approval authority
ensures security initiatives are properly prioritized and resourced.

2. Information security governance is PRIMARILY driven by:

A. Technology constraints
B. Regulatory requirements
C. Litigation potential
D. Business strategy

Correct Answer: D
Rationale: Information security governance must align with and support business strategy.
While regulatory requirements (B) and litigation concerns (C) are important drivers, and
technology constraints (A) influence implementation, governance exists to enable business
objectives. Security is a business enabler, and governance frameworks must be established to
support organizational strategy and direction.

3. Which of the following individuals would be in the BEST position to sponsor the creation of
an information security steering group?

A. Chief security officer
B. Chief operating officer
C. Chief internal auditor
D. Chief legal counsel

Correct Answer: B
Rationale: The Chief Operating Officer (COO) has enterprise-wide operational oversight and the
authority to establish cross-functional governance structures. While the Chief Security Officer
(A) is the security expert, sponsorship requires someone with broader organizational authority.
The Chief Internal Auditor (C) and Chief Legal Counsel (D) have specific functional focuses that
may not represent the full organizational perspective required for governance sponsorship.

,4. Which of the following is MOST indicative of the failure of information security governance
within an organization?

A. The information security department has difficulty filling vacancies
B. The CIO approves changes to the security policy
C. The information security oversight committee only meets quarterly
D. The data center manager has final sign-off on all security projects

Correct Answer: D
Rationale: When the data center manager (an operational role) has final sign-off on all security
projects, it indicates a fundamental governance failure—security decisions are being made at an
inappropriate level without proper executive oversight. Staffing difficulties (A) indicate
operational challenges, CIO approval of policy (B) is appropriate, and quarterly committee
meetings (C) may be sufficient depending on organizational needs.

5. Information security governance must be integrated into all business functions and
activities PRIMARILY to:

A. Maximize security efficiency
B. Standardize operational activities
C. Ensure security is embedded in business processes
D. Reduce the cost of security controls

Correct Answer: C
Rationale: The primary purpose of integrating security governance into all business functions is
to ensure security is embedded in business processes rather than treated as an add-on. While
efficiency (A), standardization (B), and cost reduction (D) may be secondary benefits, the
fundamental goal is to make security an integral part of how the organization operates.

6. What is the PRIMARY purpose of establishing an information security governance
framework?

A. To ensure regulatory compliance
B. To reduce the number of security incidents
C. To align security strategy with business objectives
D. To implement technical security controls

Correct Answer: C
Rationale: The primary purpose of an information security governance framework is to align
security strategy with business objectives. Compliance (A) is a component but not the primary
driver, incident reduction (B) is a security program outcome, and technical controls (D) are

, implementation details. Governance provides the strategic direction that ensures security
investments support organizational goals.

7. Which of the following should be developed FIRST in establishing an information security
program?

A. Standards
B. Procedures
C. Policies
D. Guidelines

Correct Answer: C
Rationale: Policies establish the foundational direction and principles for information security
and must be developed first. Standards (A) and procedures (B) are derived from policies, and
guidelines (D) provide flexibility within the policy framework. Without policies, there is no
authoritative basis for developing lower-level documents.

8. Which of the following is the MOST appropriate task for a Chief Information Security
Officer (CISO) to perform?

A. Update platform-level security settings
B. Conduct disaster recovery test exercises
C. Approve access to critical financial systems
D. Develop an information security strategy paper

Correct Answer: D
Rationale: The CISO's role is strategic and managerial. Developing an information security
strategy paper aligns with this responsibility. Updating platform settings (A), conducting DR
exercises (B), and approving access to financial systems (C) are operational or tactical activities
that should be delegated to appropriate staff.

9. Which of the following is characteristic of decentralized information security management
across a geographically dispersed organization?

A. More uniformity in quality of service
B. Better adherence to policies
C. More aligned to business unit needs
D. Less total cost of ownership

Correct Answer: C
Rationale: Decentralized security management allows business units to tailor security to their
specific needs and operational contexts. Uniformity (A) and better policy adherence (B) are
characteristics of centralized models. Cost (D) is variable and not a defining characteristic.

Document information

Uploaded on
July 19, 2026
Number of pages
48
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$28.16

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopMarkStudyHub
2.5
(2)
Sold
19
Followers
0
Items
2363
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions