Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 59 pages
Exam (elaborations)

ISC2 CISSP-ISSMP CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 59 pages

ISC2 CISSP-ISSMP CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF ISC2 CISSP-ISSMP CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

ISC2 CISSP-ISSMP CERTIFICATION EXAM
WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A multinational organization has recently appointed a new Information
Security Management Professional (ISSMP) to coordinate security
governance across business units. The organization has an enterprise risk
management framework, but individual business units have historically
implemented security controls independently. Senior management wants
the ISSMP to establish a consistent security direction without
unnecessarily centralizing operational decision-making.
Which action should the ISSMP take FIRST?
A. Require every business unit to implement an identical set of technical
controls
B. Establish enterprise-wide security governance principles, objectives,
roles, and accountability while allowing risk-based implementation
flexibility
C. Centralize all security operations under the ISSMP
D. Replace the existing enterprise risk management framework with a
cybersecurity-specific framework
Answer: B.
Rationale: Effective security management begins with governance, not
technology standardization. The ISSMP should establish consistent
enterprise security objectives, accountability, policies, and decision
rights while allowing business units to implement controls according

1

,to their specific risk profiles. Option A is overly prescriptive, C
confuses governance with operations, and D unnecessarily discards an
existing enterprise capability.


2.
The board asks the ISSMP to explain why information security should
be considered a business issue rather than solely an IT responsibility.
Which response BEST demonstrates executive-level security
management?
A. Security is primarily an IT responsibility because most cyberattacks
target computer systems
B. Security is a business issue because security risks can affect strategic
objectives, financial performance, regulatory obligations, reputation, and
operational resilience
C. Security is a business issue only when personally identifiable
information is processed
D. Security becomes a business issue only after a major breach occurs
Answer: B.
Rationale: Senior security management must translate cyber risk into
business consequences. Security can influence revenue, operations,
customer trust, legal exposure, strategic initiatives, and organizational
resilience regardless of whether a specific incident has occurred.


3.
An ISSMP is developing an enterprise information security strategy.
Several executives recommend purchasing advanced security
technologies immediately because competitors have recently
experienced ransomware attacks.

2

,What should the ISSMP do FIRST?
A. Purchase endpoint detection and response technology
B. Conduct a threat, risk, business-impact, and organizational-context
assessment
C. Increase the cybersecurity budget by 50 percent
D. Deploy security technologies used by the affected competitors
Answer: B.
Rationale: A mature security strategy is risk-driven rather than
technology-driven. The ISSMP should first understand business
objectives, critical assets, threats, vulnerabilities, existing capabilities,
risk appetite, regulatory requirements, and potential impacts.
Technology selection should follow this assessment.


4.
The chief executive officer asks the ISSMP to define the organization's
security risk appetite. Which statement BEST describes risk appetite?
A. The maximum number of vulnerabilities permitted on production
systems
B. The amount and type of risk an organization is willing to pursue,
retain, or accept in achieving its objectives
C. The number of security incidents that can occur before management
becomes concerned
D. The percentage of systems that must pass vulnerability scans
Answer: B.
Rationale: Risk appetite is an enterprise-level expression of how much
risk the organization is willing to accept in pursuit of its objectives. It
is broader than individual vulnerabilities, incidents, or technical
compliance measurements.

3

, 5.
An organization has established a risk appetite stating that it has very
low tolerance for unauthorized disclosure of sensitive customer
information. A business unit proposes deploying a new cloud service
that significantly improves productivity but introduces additional data-
exposure risks.
What should the ISSMP recommend?
A. Reject every cloud service automatically
B. Evaluate the proposed service against the organization's risk appetite
and determine whether additional safeguards can reduce residual risk to
an acceptable level
C. Allow the business unit to decide independently
D. Approve the service because productivity benefits always outweigh
security concerns
Answer: B.
Rationale: Security management requires balancing business value
and risk. A proposed service should be evaluated against established
risk appetite, with controls, contractual requirements, architectural
safeguards, and monitoring used to reduce risk where appropriate.


6.
An ISSMP notices that the organization's security policy states that all
critical systems must use multifactor authentication, but several senior
executives have been exempted informally.
Which governance problem is MOST significant?
A. The organization lacks vulnerability scanning
B. Security requirements are not being applied consistently and
4

Document information

Uploaded on
August 28, 2026
Number of pages
59
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
profwhite
4.3
(20)
Sold
120
Followers
76
Items
4660
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions