Maryland Information Security
Manager Certification Exam Practice
Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which framework is most commonly used to establish an enterprise-
wide information security management system?
A. COBIT
B. ISO/IEC 27001
C. ITIL
D. TOGAF
B
ISO/IEC 27001 provides a structured framework for establishing,
implementing, maintaining, and continuously improving an
information security management system across an organization.
2. What is the primary purpose of a risk assessment in information
security management?
A. To eliminate all system vulnerabilities
B. To identify, analyze, and evaluate risks to information assets
C. To encrypt organizational data
D. To design physical security controls only
, B
Risk assessment focuses on identifying threats, analyzing
vulnerabilities, and evaluating the potential impact on organizational
assets to support informed decision-making.
3. Which control type is primarily focused on detecting security
incidents?
A. Preventive
B. Corrective
C. Detective
D. Deterrent
C
Detective controls are designed to identify and alert on security
events or incidents after they occur.
4. What does the principle of least privilege ensure?
A. Users have maximum system access
B. Users are granted only the access necessary to perform their job
functions
C. All users share administrative privileges
D. Systems operate without authentication
B
The principle of least privilege minimizes risk by restricting user
access rights to only what is required for their roles.
5. Which document defines how an organization responds to security
incidents?
A. Business Continuity Plan
B. Incident Response Plan
C. Risk Register
D. Audit Report
B
, An incident response plan outlines procedures for detecting,
responding to, and recovering from security incidents.
6. What is the main goal of business continuity planning?
A. To prevent all cyberattacks
B. To ensure critical business functions continue during disruptions
C. To eliminate the need for backups
D. To monitor network traffic only
B
Business continuity planning ensures essential operations can
continue during and after a disruptive event.
7. Which security principle ensures data is not altered in an unauthorized
manner?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
B
Integrity ensures that data remains accurate, consistent, and
unaltered except by authorized actions.
8. What is a vulnerability in information security?
A. A malicious software program
B. A weakness that could be exploited by a threat
C. A firewall configuration rule
D. A type of encryption algorithm
B
A vulnerability is a weakness in a system that could be exploited to
compromise security.
9. Which role is primarily responsible for approving security policies at
the organizational level?
Manager Certification Exam Practice
Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which framework is most commonly used to establish an enterprise-
wide information security management system?
A. COBIT
B. ISO/IEC 27001
C. ITIL
D. TOGAF
B
ISO/IEC 27001 provides a structured framework for establishing,
implementing, maintaining, and continuously improving an
information security management system across an organization.
2. What is the primary purpose of a risk assessment in information
security management?
A. To eliminate all system vulnerabilities
B. To identify, analyze, and evaluate risks to information assets
C. To encrypt organizational data
D. To design physical security controls only
, B
Risk assessment focuses on identifying threats, analyzing
vulnerabilities, and evaluating the potential impact on organizational
assets to support informed decision-making.
3. Which control type is primarily focused on detecting security
incidents?
A. Preventive
B. Corrective
C. Detective
D. Deterrent
C
Detective controls are designed to identify and alert on security
events or incidents after they occur.
4. What does the principle of least privilege ensure?
A. Users have maximum system access
B. Users are granted only the access necessary to perform their job
functions
C. All users share administrative privileges
D. Systems operate without authentication
B
The principle of least privilege minimizes risk by restricting user
access rights to only what is required for their roles.
5. Which document defines how an organization responds to security
incidents?
A. Business Continuity Plan
B. Incident Response Plan
C. Risk Register
D. Audit Report
B
, An incident response plan outlines procedures for detecting,
responding to, and recovering from security incidents.
6. What is the main goal of business continuity planning?
A. To prevent all cyberattacks
B. To ensure critical business functions continue during disruptions
C. To eliminate the need for backups
D. To monitor network traffic only
B
Business continuity planning ensures essential operations can
continue during and after a disruptive event.
7. Which security principle ensures data is not altered in an unauthorized
manner?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
B
Integrity ensures that data remains accurate, consistent, and
unaltered except by authorized actions.
8. What is a vulnerability in information security?
A. A malicious software program
B. A weakness that could be exploited by a threat
C. A firewall configuration rule
D. A type of encryption algorithm
B
A vulnerability is a weakness in a system that could be exploited to
compromise security.
9. Which role is primarily responsible for approving security policies at
the organizational level?