Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 34 pages
Exam (elaborations)

CISM Test Practice Question Set | Questions & Verified Answers | Comprehensive ISACA Certified Information Security Manager Exam Review Study Guide PDF | 2026

Document preview thumbnail
Preview 4 out of 34 pages

Prepare for your Certified Information Security Manager (CISM) Exam with this comprehensive practice question set featuring exam questions and verified answers designed to strengthen your knowledge of information security management, governance, and risk-based decision-making. This detailed review covers high-yield topics including information security governance, risk management, security program development and management, incident management, cybersecurity frameworks, security policies, compliance requirements, threat management, business continuity, disaster recovery, and effective security leadership practices. Ideal for cybersecurity professionals, information security managers, IT auditors, risk analysts, and ISACA CISM certification candidates, this resource is perfect for preparing for certification exams, practice tests, quizzes, and comprehensive security assessments while improving technical knowledge, enhancing management skills, and maximizing exam readiness.

Content preview

CISM Test Practice
Question Set


(2025-2026)
Question and Answers
Expert Verified
(With A+ Grades Guarantee)

,Administrative controls policies, processes, procedures, standards




Annualized Loss Expectancy ALE = SLExARO




architecture standard defines technology architecture at the database, system, or network level




assessment an examination that determines the effectiveness of a system or process




asset value the value of an IT asset - usually but not always the Replacement Value




Asynchronous Replication writing to data in a remote system is not synchronized with the local system.No
guarantee that remote system is identical to local systemMight be a time lag



Attestation of compliance assertion of compliance to a law, standard or requirement Typically signed by high
ranking official



authentication asserting an identity and providing proof of ittypically requires an ID (assertion) and
a password (proof)



business email compromiseceo fraud perpetrator impersonates a CEO and gets company personnel to transfer large
amounts of money, typically for a "secret merger" or "acquisition"



Business Impact Analysis Study to identify the impact that different disaster scenarios will have on business
operations



Business Recovery Plan activities required to recover and resume critical business processes and activities




capability maturity model measures relative maturity of an organization and its processes




capability maturity model for Development| CMMi-DEV maturity model used to measure software development process maturity




certification practicer statement (CPS) describes practices used by the CA to issue and manage digital certificates




Change Control BoardakaChange Advisory Board stakeholders from IT and Business who propose, discuss, approve changes to the
IT systems

,CIS Controls framework maintained by the Center for Internet Security (CIS)




COBIT published by ISACAcontrol framework for managing information systems and
security



COSO Committee of Sponsoring Organizations of the Treadway CommissionOrganization
providing control frameworks and guidance on enterprise risk management



COOP Continuity of Operations Planactivities required to continue critical and strategic
business functions at alternate site



Control Policy, Process or Procedure created to ensure desired outcomes or to avoid
unwanted outcomes



Control Framework Collection of controls organized in logical categories




Covered Entity any organization that stores or processes information covered by HIPAA




Critical Path Methodology (CPM) Technique used to identify the most critical path in a project to understand which
tasks are most likely to affect the project schedule



Criticality Analysis (CA) Study of each system and process, a consideration of the impact on the
organization if it's incapacitated, the likelihood of incapacitation and the estimated
cost of mitigating the impact (risk)


Digital envelope method of using two layers of encryptionsymmetric key is used to encrypt a
message and a public or private key is used to encrypt the symmetric key



Disaster unexpected and unplanned event that results in the disruption of business
operations



Dwell Time amount of time from the start of an incident to the organization's awareness of the
incident



e-vaulting backing up information to an off-site location, usually a 3rd-party service provider




Exposure Factor financial loss resulting from realization of a threat.expressed as a percentage of the
asset's total value



Facilities Classification methods for assigning risk levels to facilities based based on their operational
criticality or other risk factors

, fiduciary person who has a legal trust relationship with another party




fiduciary duty highest standard of care that a fiduciary renders to a beneficiary




File Activity Monitoring (FAM) monitoring the use of files on a computer as a way to detect indicators of
compromise



File Integrity Monitoring (FIM) periodically scanning file systems to detect changes to file contents or permissions
that may indicate compromise



HITRUST healthcare control framework and certificationservers as external attestation of an
organization's IT controls



Hybrid cryptography cryptosystem that uses two or more iterations of cryptography




Impact actual or expected result from a threat or disaster




incident any event not part of standard operation of a service and that causes or may cause
interruption or reduction in quality of service



Information Risk business risk associated with use, ownership, operation, involvement, influence and
adoption of information in an enterprise



ISMS| Information Security Management System ISO/IEC 27001 - activities for managing information security in an organization




inherent risk the risk that there are material weaknesses in existing business processes and no
compensating controls to detect or prevent them



integrated audit financial and operational audit




intrusion kill chain intrusion model developed by Lockheed Martin```Phases are:
reconnaissanceweaponizationdeliveryexploitationinstallationcommand and
controlactions on objective```


ISAE 3402| International Standard on Assurance external audit of a service providerperformed according to rules from International
Engagement Auditing and Assurance Standards Board



ISO/IEC 20000 standard for IT service management (ITSM)

Document information

Uploaded on
July 27, 2026
Number of pages
34
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$9.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
estudegrades
5.0
(12)
Sold
28
Followers
1
Items
1225
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions