WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A multinational organization has recently appointed a new Information
Security Management Professional (ISSMP) to coordinate security
governance across business units. The organization has an enterprise risk
management framework, but individual business units have historically
implemented security controls independently. Senior management wants
the ISSMP to establish a consistent security direction without
unnecessarily centralizing operational decision-making.
Which action should the ISSMP take FIRST?
A. Require every business unit to implement an identical set of technical
controls
B. Establish enterprise-wide security governance principles, objectives,
roles, and accountability while allowing risk-based implementation
flexibility
C. Centralize all security operations under the ISSMP
D. Replace the existing enterprise risk management framework with a
cybersecurity-specific framework
Answer: B.
Rationale: Effective security management begins with governance, not
technology standardization. The ISSMP should establish consistent
enterprise security objectives, accountability, policies, and decision
rights while allowing business units to implement controls according
1
,to their specific risk profiles. Option A is overly prescriptive, C
confuses governance with operations, and D unnecessarily discards an
existing enterprise capability.
2.
The board asks the ISSMP to explain why information security should
be considered a business issue rather than solely an IT responsibility.
Which response BEST demonstrates executive-level security
management?
A. Security is primarily an IT responsibility because most cyberattacks
target computer systems
B. Security is a business issue because security risks can affect strategic
objectives, financial performance, regulatory obligations, reputation, and
operational resilience
C. Security is a business issue only when personally identifiable
information is processed
D. Security becomes a business issue only after a major breach occurs
Answer: B.
Rationale: Senior security management must translate cyber risk into
business consequences. Security can influence revenue, operations,
customer trust, legal exposure, strategic initiatives, and organizational
resilience regardless of whether a specific incident has occurred.
3.
An ISSMP is developing an enterprise information security strategy.
Several executives recommend purchasing advanced security
technologies immediately because competitors have recently
experienced ransomware attacks.
2
,What should the ISSMP do FIRST?
A. Purchase endpoint detection and response technology
B. Conduct a threat, risk, business-impact, and organizational-context
assessment
C. Increase the cybersecurity budget by 50 percent
D. Deploy security technologies used by the affected competitors
Answer: B.
Rationale: A mature security strategy is risk-driven rather than
technology-driven. The ISSMP should first understand business
objectives, critical assets, threats, vulnerabilities, existing capabilities,
risk appetite, regulatory requirements, and potential impacts.
Technology selection should follow this assessment.
4.
The chief executive officer asks the ISSMP to define the organization's
security risk appetite. Which statement BEST describes risk appetite?
A. The maximum number of vulnerabilities permitted on production
systems
B. The amount and type of risk an organization is willing to pursue,
retain, or accept in achieving its objectives
C. The number of security incidents that can occur before management
becomes concerned
D. The percentage of systems that must pass vulnerability scans
Answer: B.
Rationale: Risk appetite is an enterprise-level expression of how much
risk the organization is willing to accept in pursuit of its objectives. It
is broader than individual vulnerabilities, incidents, or technical
compliance measurements.
3
, 5.
An organization has established a risk appetite stating that it has very
low tolerance for unauthorized disclosure of sensitive customer
information. A business unit proposes deploying a new cloud service
that significantly improves productivity but introduces additional data-
exposure risks.
What should the ISSMP recommend?
A. Reject every cloud service automatically
B. Evaluate the proposed service against the organization's risk appetite
and determine whether additional safeguards can reduce residual risk to
an acceptable level
C. Allow the business unit to decide independently
D. Approve the service because productivity benefits always outweigh
security concerns
Answer: B.
Rationale: Security management requires balancing business value
and risk. A proposed service should be evaluated against established
risk appetite, with controls, contractual requirements, architectural
safeguards, and monitoring used to reduce risk where appropriate.
6.
An ISSMP notices that the organization's security policy states that all
critical systems must use multifactor authentication, but several senior
executives have been exempted informally.
Which governance problem is MOST significant?
A. The organization lacks vulnerability scanning
B. Security requirements are not being applied consistently and
4