Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 65 pages

ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

ISACA CERTIFIED INFORMATION
SECURITY MANAGER (CISM) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1.
A multinational organization is developing its annual information
security strategy. The board has identified aggressive digital-
transformation objectives, including migration of critical business
applications to the cloud and expansion into new international markets.
The CISO wants to increase security spending substantially, but the CFO
requests evidence that the proposed investments directly support
business objectives. What should the information security manager do
FIRST?
A. Conduct a technical vulnerability assessment of all existing systems
B. Align the information security strategy with organizational objectives
and risk appetite
C. Purchase additional security technologies to address emerging threats
D. Benchmark the organization's security budget against industry
competitors
Answer: B. Align the information security strategy with
organizational objectives and risk appetite
Rationale: The CISM perspective emphasizes business alignment
before selecting controls or technologies. The information security
manager should first understand organizational objectives, risk
appetite, regulatory requirements and business priorities, then develop

1

,a security strategy that supports those objectives. A vulnerability
assessment may identify technical weaknesses, but it does not establish
whether proposed security investments support business goals.
Purchasing technology before establishing strategic requirements can
result in unnecessary expenditure. Industry benchmarking may
provide useful context, but it should not replace alignment with the
organization's own risk profile.


2.
An organization has established a risk appetite stating that it has very
low tolerance for interruption of its payment-processing platform.
During a risk assessment, the information security manager determines
that a ransomware incident could cause several days of disruption.
Which action BEST demonstrates alignment with the organization's risk
appetite?
A. Accept the ransomware risk because no security control can eliminate
it completely
B. Implement controls that reduce the likelihood and impact of
ransomware to an acceptable level
C. Transfer all ransomware risk to the organization's cyber insurance
provider
D. Require employees to complete annual cybersecurity awareness
training
Answer: B. Implement controls that reduce the likelihood and
impact of ransomware to an acceptable level
Rationale: Risk appetite defines the amount and type of risk an
organization is willing to pursue or retain. Because the organization
has very low tolerance for payment-processing disruption, the
manager should prioritize controls that reduce both the probability
and business impact of ransomware. Insurance can transfer certain
2

,financial consequences but does not eliminate operational risk.
Awareness training is useful but insufficient by itself. Simply
accepting the risk would conflict with the stated risk appetite unless
formally justified and approved by the appropriate risk owner.


3.
A security manager is asked to create an information security
governance framework. Which component is MOST important to
establish before defining detailed security procedures?
A. Technical configuration standards
B. Security awareness training schedules
C. Roles, responsibilities, authority and accountability
D. Vulnerability scanning frequencies
Answer: C. Roles, responsibilities, authority and accountability
Rationale: Effective governance requires clear ownership and
accountability. Establishing who has authority to make decisions, who
owns risks, who approves policies and who is accountable for security
outcomes provides the foundation for subsequent policies, procedures
and controls. Technical standards, awareness programs and scanning
frequencies are operational mechanisms and should be derived from
governance requirements rather than established before
organizational accountability is defined.


4.
A board member asks the information security manager why
cybersecurity metrics should be reported in business terms rather than as
purely technical statistics. Which response is BEST?



3

, A. Business metrics eliminate the need for technical security metrics
B. Business-oriented metrics allow executives to understand security
performance and risk in relation to organizational objectives
C. Technical metrics are inappropriate for information security
management
D. Business metrics are required only when the organization is publicly
traded
Answer: B. Business-oriented metrics allow executives to
understand security performance and risk in relation to
organizational objectives
Rationale: Senior management and boards generally need information
that supports business decisions. Metrics such as patching percentages
or alert counts can be valuable, but their significance becomes clearer
when translated into business impact, risk exposure, trends and
performance against objectives. Technical metrics remain important
for operational teams; they are not eliminated. Business-oriented
reporting is useful regardless of whether an organization is publicly
traded.


5.
An organization is considering outsourcing a critical security monitoring
function to a managed security service provider. Which action should
the information security manager perform FIRST?
A. Negotiate the provider's service-level agreement
B. Determine the organization's requirements, risks and expected
outcomes
C. Review the provider's marketing materials
D. Require the provider to use the organization's existing SIEM
technology


4

Document information

Uploaded on
August 28, 2026
Number of pages
65
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
profwhite
4.3
(20)
Sold
120
Followers
76
Items
4660
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions