Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 65 páginas
Examen

ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Vista previa 4 fuera de 65 páginas

ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF ISACA CERTIFIED INFORMATION SECURITY MANAGER (CISM) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Vista previa del contenido

ISACA CERTIFIED INFORMATION
SECURITY MANAGER (CISM) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1.
A multinational organization is developing its annual information
security strategy. The board has identified aggressive digital-
transformation objectives, including migration of critical business
applications to the cloud and expansion into new international markets.
The CISO wants to increase security spending substantially, but the CFO
requests evidence that the proposed investments directly support
business objectives. What should the information security manager do
FIRST?
A. Conduct a technical vulnerability assessment of all existing systems
B. Align the information security strategy with organizational objectives
and risk appetite
C. Purchase additional security technologies to address emerging threats
D. Benchmark the organization's security budget against industry
competitors
Answer: B. Align the information security strategy with
organizational objectives and risk appetite
Rationale: The CISM perspective emphasizes business alignment
before selecting controls or technologies. The information security
manager should first understand organizational objectives, risk
appetite, regulatory requirements and business priorities, then develop

1

,a security strategy that supports those objectives. A vulnerability
assessment may identify technical weaknesses, but it does not establish
whether proposed security investments support business goals.
Purchasing technology before establishing strategic requirements can
result in unnecessary expenditure. Industry benchmarking may
provide useful context, but it should not replace alignment with the
organization's own risk profile.


2.
An organization has established a risk appetite stating that it has very
low tolerance for interruption of its payment-processing platform.
During a risk assessment, the information security manager determines
that a ransomware incident could cause several days of disruption.
Which action BEST demonstrates alignment with the organization's risk
appetite?
A. Accept the ransomware risk because no security control can eliminate
it completely
B. Implement controls that reduce the likelihood and impact of
ransomware to an acceptable level
C. Transfer all ransomware risk to the organization's cyber insurance
provider
D. Require employees to complete annual cybersecurity awareness
training
Answer: B. Implement controls that reduce the likelihood and
impact of ransomware to an acceptable level
Rationale: Risk appetite defines the amount and type of risk an
organization is willing to pursue or retain. Because the organization
has very low tolerance for payment-processing disruption, the
manager should prioritize controls that reduce both the probability
and business impact of ransomware. Insurance can transfer certain
2

,financial consequences but does not eliminate operational risk.
Awareness training is useful but insufficient by itself. Simply
accepting the risk would conflict with the stated risk appetite unless
formally justified and approved by the appropriate risk owner.


3.
A security manager is asked to create an information security
governance framework. Which component is MOST important to
establish before defining detailed security procedures?
A. Technical configuration standards
B. Security awareness training schedules
C. Roles, responsibilities, authority and accountability
D. Vulnerability scanning frequencies
Answer: C. Roles, responsibilities, authority and accountability
Rationale: Effective governance requires clear ownership and
accountability. Establishing who has authority to make decisions, who
owns risks, who approves policies and who is accountable for security
outcomes provides the foundation for subsequent policies, procedures
and controls. Technical standards, awareness programs and scanning
frequencies are operational mechanisms and should be derived from
governance requirements rather than established before
organizational accountability is defined.


4.
A board member asks the information security manager why
cybersecurity metrics should be reported in business terms rather than as
purely technical statistics. Which response is BEST?



3

, A. Business metrics eliminate the need for technical security metrics
B. Business-oriented metrics allow executives to understand security
performance and risk in relation to organizational objectives
C. Technical metrics are inappropriate for information security
management
D. Business metrics are required only when the organization is publicly
traded
Answer: B. Business-oriented metrics allow executives to
understand security performance and risk in relation to
organizational objectives
Rationale: Senior management and boards generally need information
that supports business decisions. Metrics such as patching percentages
or alert counts can be valuable, but their significance becomes clearer
when translated into business impact, risk exposure, trends and
performance against objectives. Technical metrics remain important
for operational teams; they are not eliminated. Business-oriented
reporting is useful regardless of whether an organization is publicly
traded.


5.
An organization is considering outsourcing a critical security monitoring
function to a managed security service provider. Which action should
the information security manager perform FIRST?
A. Negotiate the provider's service-level agreement
B. Determine the organization's requirements, risks and expected
outcomes
C. Review the provider's marketing materials
D. Require the provider to use the organization's existing SIEM
technology


4

Información del documento

Subido en
28 de agosto de 2026
Número de páginas
65
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$25.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
profwhite
4.3
(20)
Vendido
120
Seguidores
76
Artículos
4660
Última venta
1 día hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes