Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 185 pages
Exam (elaborations)

CISM-CERTIFIED INFORMATION SECURITY MANAGER EXAM- ISACA CISM EXAM COMPLETE 300 QUESTIONS WITH DETAILED SOLUTIONS JUST RELEASED THIS YEAR.pdf is a comprehensive study resource designed to help candidates prepare for the ISACA Certified Information Security

Document preview thumbnail
Preview 4 out of 185 pages

CISM-CERTIFIED INFORMATION SECURITY MANAGER EXAM- ISACA CISM EXAM COMPLETE 300 QUESTIONS WITH DETAILED SOLUTIONS JUST RELEASED THIS YEAR.pdf is a comprehensive study resource designed to help candidates prepare for the ISACA Certified Information Security Manager (CISM) examination. It includes 300 practice questions with detailed solutions covering information security governance, risk management, security program development, incident management, security operations, business continuity, and leadership. Ideal for exam preparation, self-assessment, and reinforcing essential information security management knowledge and decision-making skills

Content preview

Page 1 of 185



CISM-CERTIFIED INFORMATION SECURITY
MANAGER EXAM/ ISACA CISM EXAM
COMPLETE 300 QUESTIONS WITH DETAILED
SOLUTIONS JUST RELEASED THIS YEAR

Question 1: Which of the following would BEST ensure the success of information security


governance within an organization?


A. The steering committee approves all security projects


B. The security policy manual is distributed to all managers


C. Security procedures are accessible on the company intranet


D. The corporate network utilizes multiple screened subnets


Answer: A


Information security governance success depends on executive-level commitment and oversight.


A steering committee with approval authority ensures security decisions align with business


strategy and receive appropriate resources and attention from senior leadership. Distributing


policies or procedures alone does not establish governance; technical controls address


operational security, not governance.




1
SUCCESS!

,Page 2 of 185




Question 2: Which of the following should be developed FIRST in an information security


program?


A. Standards


B. Procedures


C. Policies


D. Guidelines


Answer: C


Policies represent the highest level of security documentation and establish the organization's


strategic direction and requirements. Standards, procedures, and guidelines derive from policies


and provide detailed implementation guidance. Without policies, lower-level documents lack a


governing framework and may be inconsistent.




Question 3: Which individual would be in the BEST position to sponsor the creation of an


information security steering group?


A. Chief security officer


B. Chief operating officer


2
SUCCESS!

,Page 3 of 185


C. Chief internal auditor


D. Chief legal counsel


Answer: B


The chief operating officer (COO) has broad organizational authority and can provide the cross-


functional sponsorship needed for an effective steering group. A chief security officer may lack


the seniority to secure resources across business units. Internal audit and legal counsel typically


serve as advisors rather than sponsors.




Question 4: What is the MOST appropriate reporting base for the information security


management function?


A. Head of IT


B. Infrastructure director


C. Network manager


D. Chief information officer


Answer: D


Reporting to the chief information officer (CIO) provides sufficient organizational authority while


maintaining appropriate independence. Reporting to the head of IT or infrastructure director


3
SUCCESS!

, Page 4 of 185


creates a conflict of interest as security would be subordinate to operational IT management.


Reporting to the network manager provides insufficient authority for strategic security decisions.




Question 5: Which of the following is MOST indicative of the failure of information security


governance within an organization?


A. The information security department has had difficulty filling vacancies


B. The chief information officer (CIO) approves changes to the security policy


C. The information security oversight committee only meets quarterly


D. The data center manager has final sign-off on all security projects


Answer: D


Governance failure is evident when operational managers (e.g., data center manager) have final


authority over security projects without appropriate oversight. This indicates security decisions


are being made at too low a level without consideration of enterprise-wide risk. The CIO


approving policy changes is appropriate governance; committee meeting frequency and staffing


challenges are operational issues.




4
SUCCESS!

Document information

Uploaded on
August 18, 2026
Number of pages
185
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Ressy
3.4
(39)
Sold
199
Followers
32
Items
3840
Last sold
6 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions