• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

CISM Advanced Practice Examination v2.0 a well detailed practice exam 2025/2026 graded A+ well written !!! Comprehensive 150 Question Multiple-Choice Practice Exam

Document preview thumbnail
Preview 4 out of 48 pages

CISM Advanced Practice Examination v2.0 a well detailed practice exam 2025/2026 graded A+ well written !!! Comprehensive 150 Question Multiple-Choice Practice Exam

Content preview

CISM Advanced Practice Examination v2.0 a
well detailed practice exam 2025/2026 graded
A+ well written !!! Comprehensive 150-
Question Multiple-Choice Practice Exam




Exam Format: 150 multiple-choice questions | 4 hours (240 minutes) | Passing score: 450/800

Domain Weighting: Domain 1 – Information Security Governance (17%) | Domain 2 –
Information Security Risk Management (20%) | Domain 3 – Information Security Program
Development and Management (33%) | Domain 4 – Incident Management (30%)

Target Audience: Experienced information security professionals preparing for the ISACA CISM
certification exam

Instructions: Select the single best answer for each question. Questions are designed to test
managerial-level decision-making, strategic thinking, and the application of information security
management principles from a risk-based, business-aligned perspective.



DOMAIN 1: INFORMATION SECURITY GOVERNANCE (25 Questions)

Questions 1-25

1. An organization's information security governance framework is being reviewed by external
auditors. Which of the following findings would represent the MOST significant governance
deficiency?

A. Security policies have not been updated in 18 months
B. The information security steering committee lacks representation from business units
C. Security awareness training completion rates are below 80%
D. The security budget has remained flat for three consecutive years

,Correct Answer: B
Rationale: Lack of business unit representation on the steering committee indicates that
security governance is not integrated with business operations, undermining the fundamental
purpose of governance—aligning security with business objectives. Policy updates (A), training
rates (C), and budget stagnation (D) are operational concerns that can be addressed within a
governance framework, but the framework itself is deficient without business stakeholder
participation.

2. Which of the following BEST describes the relationship between information security
governance and enterprise governance?

A. Information security governance operates independently of enterprise governance
B. Information security governance is a subset of enterprise governance
C. Enterprise governance is a subset of information security governance
D. They are parallel but unrelated governance structures

Correct Answer: B
Rationale: Information security governance is a subset of enterprise governance, operating
within the broader framework of how the organization is directed and controlled. Security
governance must align with and support the overall corporate governance structure, not
operate independently or in parallel.

3. A newly appointed CISO discovers that the organization has no formal information security
strategy. What should be the CISO's FIRST action?

A. Conduct a comprehensive risk assessment
B. Develop an information security strategy aligned with business objectives
C. Implement immediate technical controls to address critical vulnerabilities
D. Hire additional security staff to build the program

Correct Answer: B
Rationale: The first action should be to develop an information security strategy aligned with
business objectives, as the strategy provides the vision and direction for all subsequent security
activities. Risk assessment (A) and technical controls (C) should follow the strategy, and staffing
(D) should be based on strategic needs.

4. Which of the following would be the BEST indicator that information security governance is
effective within an organization?

A. Zero security incidents in the past year
B. Security is integrated into strategic business decisions

,C. All employees have completed security awareness training
D. The security budget has increased year over year

Correct Answer: B
Rationale: Integration of security into strategic business decisions is the strongest indicator of
effective governance—it demonstrates that security considerations are embedded in how the
organization operates. Zero incidents (A) may indicate luck or under-reporting, training
completion (C) is an operational metric, and budget increases (D) are resource inputs, not
governance outcomes.

5. Who bears ultimate accountability for the organization's information security program?

A. The Chief Information Security Officer
B. The Chief Information Officer
C. The Board of Directors
D. The Information Security Steering Committee

Correct Answer: C
Rationale: The board of directors bears ultimate accountability for information security as part
of their fiduciary duty to oversee the organization's risk management. While the CISO (A), CIO
(B), and steering committee (D) have important roles in implementation and oversight,
accountability ultimately rests with the board.

6. Which of the following is the PRIMARY reason for establishing an information security
governance framework?

A. To ensure regulatory compliance
B. To align security investments with business strategy
C. To reduce the number of security incidents
D. To implement technical security controls

Correct Answer: B
Rationale: The primary purpose of an information security governance framework is to align
security investments and activities with business strategy. Compliance (A) is a component,
incident reduction (C) is an outcome, and technical controls (D) are implementation details—
governance ensures security supports business objectives.

7. An organization is considering a significant investment in a new security technology. Which
of the following should be the PRIMARY factor in the decision?

A. The technology's effectiveness in peer organizations
B. The technology's alignment with business risk priorities

, C. The technology's total cost of ownership
D. The technology's compliance with industry standards

Correct Answer: B
Rationale: Alignment with business risk priorities should be the primary factor—security
investments must address the risks that matter most to the organization. Peer effectiveness (A),
cost (C), and standards compliance (D) are important considerations but secondary to business
alignment.

8. Which of the following is the MOST appropriate reporting structure for the information
security function?

A. Reporting to the Chief Information Officer
B. Reporting to the Chief Financial Officer
C. Reporting to the Chief Operating Officer
D. Reporting directly to the Board of Directors

Correct Answer: A
Rationale: Reporting to the Chief Information Officer (CIO) provides appropriate organizational
stature and enterprise-wide perspective while maintaining separation from operational
conflicts. Reporting to the CFO (B) or COO (C) may not provide the necessary IT context, and
direct board reporting (D) is typically impractical.

9. Which of the following situations represents the GREATEST threat to effective information
security governance?

A. The security team lacks sufficient technical expertise
B. The security budget is reviewed annually
C. Executive management views security as a technical function
D. The organization uses multiple security frameworks

Correct Answer: C
Rationale: When executive management views security as a technical function rather than a
business risk management function, governance is fundamentally compromised. Technical
expertise gaps (A), annual budget reviews (B), and multiple frameworks (D) are challenges that
can be addressed within a governance framework, but executive misperception undermines
governance itself.

10. An information security manager is developing a security strategy. Which of the following
should be the PRIMARY input to this strategy?

A. Industry best practices and frameworks
B. Organizational risk appetite and business objectives

Document information

Uploaded on
July 19, 2026
Number of pages
48
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$27.29

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopMarkStudyHub
2.5
(2)
Sold
19
Followers
0
Items
2363
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions