Certified Information Security Manager (CISM)
Practice Test Exam
1. What is the primary focus of the CISM certification?
A. Information security governance and management
B. Hands-on technical hacking
C. Network routing and switching
D. Database administration
Answer: A
Rationale: CISM focuses on information security governance,
risk management, program development, and incident
management from a managerial perspective.
2. Which of the following is the most important responsibility of
an information security manager?
A. Aligning security strategy with business objectives
B. Configuring firewalls
C. Writing malware signatures
D. Managing server hardware
Answer: A
,Rationale: The information security manager must align security
strategy with business goals to ensure security supports
organizational objectives.
3. What is the primary purpose of information security
governance?
A. To provide strategic direction and oversight for security
B. To install antivirus software
C. To configure routers
D. To manage help desk tickets
Answer: A
Rationale: Information security governance provides strategic
direction, oversight, and accountability for security across the
organization.
4. Which framework is commonly used for information security
governance?
A. COBIT
B. HTTP
C. SMTP
D. FTP
,Answer: A
Rationale: COBIT is a widely used framework for IT governance
and management, including information security governance.
5. What is the purpose of a security steering committee?
A. To provide strategic oversight and direction
B. To configure firewalls
C. To write code
D. To manage backups
Answer: A
Rationale: A security steering committee provides strategic
oversight and direction for the security program.
6. Which of the following best describes risk management?
A. The process of identifying, assessing, and treating risks
B. The process of installing patches
C. The process of configuring routers
D. The process of managing help desk tickets
Answer: A
, Rationale: Risk management involves identifying, assessing, and
treating risks to reduce their impact on the organization.
7. What is the purpose of a risk assessment?
A. To identify and evaluate risks to assets
B. To install antivirus software
C. To configure firewalls
D. To manage backups
Answer: A
Rationale: A risk assessment identifies and evaluates risks to
organizational assets.
8. Which of the following is a qualitative risk assessment
method?
A. Delphi technique
B. Annualized loss expectancy
C. Single loss expectancy
D. Exposure factor
Answer: A
Practice Test Exam
1. What is the primary focus of the CISM certification?
A. Information security governance and management
B. Hands-on technical hacking
C. Network routing and switching
D. Database administration
Answer: A
Rationale: CISM focuses on information security governance,
risk management, program development, and incident
management from a managerial perspective.
2. Which of the following is the most important responsibility of
an information security manager?
A. Aligning security strategy with business objectives
B. Configuring firewalls
C. Writing malware signatures
D. Managing server hardware
Answer: A
,Rationale: The information security manager must align security
strategy with business goals to ensure security supports
organizational objectives.
3. What is the primary purpose of information security
governance?
A. To provide strategic direction and oversight for security
B. To install antivirus software
C. To configure routers
D. To manage help desk tickets
Answer: A
Rationale: Information security governance provides strategic
direction, oversight, and accountability for security across the
organization.
4. Which framework is commonly used for information security
governance?
A. COBIT
B. HTTP
C. SMTP
D. FTP
,Answer: A
Rationale: COBIT is a widely used framework for IT governance
and management, including information security governance.
5. What is the purpose of a security steering committee?
A. To provide strategic oversight and direction
B. To configure firewalls
C. To write code
D. To manage backups
Answer: A
Rationale: A security steering committee provides strategic
oversight and direction for the security program.
6. Which of the following best describes risk management?
A. The process of identifying, assessing, and treating risks
B. The process of installing patches
C. The process of configuring routers
D. The process of managing help desk tickets
Answer: A
, Rationale: Risk management involves identifying, assessing, and
treating risks to reduce their impact on the organization.
7. What is the purpose of a risk assessment?
A. To identify and evaluate risks to assets
B. To install antivirus software
C. To configure firewalls
D. To manage backups
Answer: A
Rationale: A risk assessment identifies and evaluates risks to
organizational assets.
8. Which of the following is a qualitative risk assessment
method?
A. Delphi technique
B. Annualized loss expectancy
C. Single loss expectancy
D. Exposure factor
Answer: A