Certified Information Security Manager (CISM)
Examination: 100 Practice Questions with Answers
and Detailed Rationales
DOMAIN 1: INFORMATION SECURITY GOVERNANCE
Question 1
Which of the following is the PRIMARY responsibility of an information security
manager regarding corporate governance?
A) Implementing technical controls to prevent data breaches
B) Ensuring information security strategy aligns with business objectives
C) Managing the day-to-day operations of the security team
D) Approving all user access requests
Answer: B
Rationale: Information security governance is about aligning security strategy with
business strategy to ensure that security investments support organizational goals.
While implementation (A) and operations (C) are tasks, they are not governance
responsibilities. Approval of access (D) is an operational control, not a governance
function .
Question 2
Who has ULTIMATE accountability for an organization's information security
program?
A) Chief Information Security Officer (CISO)
B) Board of Directors and senior management
,C) IT Director
D) External auditors
Answer: B
Rationale: According to governance principles, the board of directors and senior
management hold ultimate accountability for information security. While the CISO
(A) is responsible for implementation and execution, ultimate accountability
cannot be delegated .
Question 3
What is the MOST critical success factor for an information security program?
A) Advanced technical tools
B) Support and commitment from executive management
C) A large security department
D) A detailed incident response plan
Answer: B
Rationale: Without top-level support and commitment (often called "tone from the
top"), a security program lacks authority, resources, and organizational buy-in.
Technical tools (A) and staff (C) are useless without executive backing. The IR plan
(D) is a component, not the overarching success factor .
Question 4
A security manager is developing a business case for a new security initiative.
What is the MOST important element to include?
A) Detailed technical specifications of the solution
B) Alignment of the initiative with business objectives and risk reduction
,C) Names of competitors who have implemented similar solutions
D) Cost breakdown of hardware and software components
Answer: B
Rationale: The board and executives focus on business outcomes, risk reduction,
and strategic alignment. Technical details (A, D) are less relevant to decision-
makers. Competitor information (C) is not primary justification. CISM emphasizes
communicating security in business terms .
Question 5
An organization has no formal information security governance structure. What is
the MOST significant risk?
A) Increased number of security incidents
B) Inability to align security with business objectives
C) Higher cost of security technology
D) Difficulty hiring security staff
Answer: B
Rationale: Without governance, security initiatives may not align with business
objectives, leading to ineffective resource allocation and unmanaged risk.
Incidents (A) and costs (C) are secondary consequences. Governance is the
foundation for strategic alignment .
Question 6
What is the PRIMARY purpose of a security steering committee?
A) To approve individual firewall rule changes
B) To provide strategic direction and ensure business alignment
, C) To conduct forensic investigations after a breach
D) To write security policies and standards
Answer: B
Rationale: A steering committee is typically composed of senior business leaders.
Its primary role is to provide strategic oversight, resolve conflicts, ensure resources
are available, and align security initiatives with business priorities. Day-to-day
operational tasks (A, C, D) are handled by management and technical staff .
Question 7
What is the difference between a policy and a standard?
A) Policies are mandatory; standards are optional
B) Policies are high-level statements of intent; standards are specific mandatory
rules
C) Policies are technical; standards are strategic
D) Policies are written by management; standards are written by legal
Answer: B
Rationale: Policies are high-level, broad statements that define management's
intent and direction. Standards are specific, detailed, mandatory rules that support
the policy by defining specific configurations, technologies, or procedures .
Question 8
Where does ultimate accountability for information security reside when an
organization outsources IT infrastructure to a cloud provider?
A) The cloud service provider
B) The information security manager
Examination: 100 Practice Questions with Answers
and Detailed Rationales
DOMAIN 1: INFORMATION SECURITY GOVERNANCE
Question 1
Which of the following is the PRIMARY responsibility of an information security
manager regarding corporate governance?
A) Implementing technical controls to prevent data breaches
B) Ensuring information security strategy aligns with business objectives
C) Managing the day-to-day operations of the security team
D) Approving all user access requests
Answer: B
Rationale: Information security governance is about aligning security strategy with
business strategy to ensure that security investments support organizational goals.
While implementation (A) and operations (C) are tasks, they are not governance
responsibilities. Approval of access (D) is an operational control, not a governance
function .
Question 2
Who has ULTIMATE accountability for an organization's information security
program?
A) Chief Information Security Officer (CISO)
B) Board of Directors and senior management
,C) IT Director
D) External auditors
Answer: B
Rationale: According to governance principles, the board of directors and senior
management hold ultimate accountability for information security. While the CISO
(A) is responsible for implementation and execution, ultimate accountability
cannot be delegated .
Question 3
What is the MOST critical success factor for an information security program?
A) Advanced technical tools
B) Support and commitment from executive management
C) A large security department
D) A detailed incident response plan
Answer: B
Rationale: Without top-level support and commitment (often called "tone from the
top"), a security program lacks authority, resources, and organizational buy-in.
Technical tools (A) and staff (C) are useless without executive backing. The IR plan
(D) is a component, not the overarching success factor .
Question 4
A security manager is developing a business case for a new security initiative.
What is the MOST important element to include?
A) Detailed technical specifications of the solution
B) Alignment of the initiative with business objectives and risk reduction
,C) Names of competitors who have implemented similar solutions
D) Cost breakdown of hardware and software components
Answer: B
Rationale: The board and executives focus on business outcomes, risk reduction,
and strategic alignment. Technical details (A, D) are less relevant to decision-
makers. Competitor information (C) is not primary justification. CISM emphasizes
communicating security in business terms .
Question 5
An organization has no formal information security governance structure. What is
the MOST significant risk?
A) Increased number of security incidents
B) Inability to align security with business objectives
C) Higher cost of security technology
D) Difficulty hiring security staff
Answer: B
Rationale: Without governance, security initiatives may not align with business
objectives, leading to ineffective resource allocation and unmanaged risk.
Incidents (A) and costs (C) are secondary consequences. Governance is the
foundation for strategic alignment .
Question 6
What is the PRIMARY purpose of a security steering committee?
A) To approve individual firewall rule changes
B) To provide strategic direction and ensure business alignment
, C) To conduct forensic investigations after a breach
D) To write security policies and standards
Answer: B
Rationale: A steering committee is typically composed of senior business leaders.
Its primary role is to provide strategic oversight, resolve conflicts, ensure resources
are available, and align security initiatives with business priorities. Day-to-day
operational tasks (A, C, D) are handled by management and technical staff .
Question 7
What is the difference between a policy and a standard?
A) Policies are mandatory; standards are optional
B) Policies are high-level statements of intent; standards are specific mandatory
rules
C) Policies are technical; standards are strategic
D) Policies are written by management; standards are written by legal
Answer: B
Rationale: Policies are high-level, broad statements that define management's
intent and direction. Standards are specific, detailed, mandatory rules that support
the policy by defining specific configurations, technologies, or procedures .
Question 8
Where does ultimate accountability for information security reside when an
organization outsources IT infrastructure to a cloud provider?
A) The cloud service provider
B) The information security manager