Leads4pass > Isaca > Isaca Certifications > CISM > CISM Online Practice Questions and Answers

CISM Online Practice Questions and Answers

Questions 4

Which of the following would BEST ensure the success of information security governance within an organization?

A. Steering committees approve security projects

B. Security policy training provided to all managers

C. Security training available to all employees on the intranet

D. Steering committees enforce compliance with laws and regulations

Buy Now
Questions 5

Acceptable risk is achieved when:

A. residual risk is minimized.

B. transferred risk is minimized.

C. control risk is minimized.

D. inherent risk is minimized.

Buy Now
Questions 6

Which of the following is MOST important to the success of an information security program?

A. Security' awareness training

B. Achievable goals and objectives

C. Senior management sponsorship

D. Adequate start-up budget and staffing

Buy Now
Questions 7

A message* that has been encrypted by the sender's private key and again by the receiver's public key achieves:

A. authentication and authorization.

B. confidentiality and integrity.

C. confidentiality and nonrepudiation.

D. authentication and nonrepudiation.

Buy Now
Questions 8

Management has announced the acquisition of a new company. The information security manager of parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies.

To BEST address this concern, the information security manager should:

A. escalate concern for conflicting access rights to management.

B. implement consistent access control standards.

C. review access rights as the acquisition integration occurs.

D. perform a risk assessment of the access rights.

Buy Now
Questions 9

Which of the following needs to be established between an IT service provider and its clients to the BEST enable adequate continuity of service in preparation for an outage?

A. Data retention policies

B. Server maintenance plans

C. Recovery time objectives

D. Reciprocal site agreement

Buy Now
Questions 10

The BEST way to ensure that security settings on each platform are in compliance with information security policies and procedures is to:

A. perform penetration testing.

B. establish security baselines.

C. implement vendor default settings.

D. link policies to an independent standard.

Buy Now
Questions 11

Which of the following is a PRIMARY security responsibility of an information owner?

A. Deciding what level of classification the information requires

B. Testing information classification controls

C. Maintaining the integrity of data in the information system

D. Determining the controls associated with information classification

Buy Now
Questions 12

Which of the following should be the information security manager's NEXT step following senior management approval of the information security strategy?

A. Develop a security policy.

B. Develop a budget.

C. Perform a gap analysis.

D. Form a steering committee.

Buy Now
Questions 13

An organization's security policy is to disable access to USB storage devices on laptops and desktops.

Which of the following is the STRONGEST justification for granting an exception to the policy?

A. The benefit is greater than the potential risk.

B. USB storage devices are enabled based on user roles.

C. Users accept the risk of noncompliance.

D. Access is restricted to read-only.

Buy Now
Exam Code: CISM
Exam Name: Certified Information Security Manager
Last Update: Jun 07, 2026
Questions: 1583
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99