CISM Sample Questions & Answers
Developing and managing the security program carries the most weight, closely followed by incident management readiness and day-to-day operations, assessing and responding to risk, and setting enterprise security strategy and governance.
Launch the full CISM simulator →Showing 10 of 20 free samples.
- Question 1
Which of the following represents the MAJOR focus of privacy regulations?
Show answer & explanation
Correct answer: D
Explanation: Protection of identifiable personal data is the major focus of recent privacy regulations such as the Health Insurance Portability and Accountability Act (HIPAA). Data mining is an accepted tool for ad hoc reporting; it could pose a threat to privacy only if it violates regulatory provisions. Identity theft is a potential consequence of privacy violations but not the main focus of many regulations. Human rights addresses privacy issues but is not the main focus of regulations.
- Question 2
Investments in information security technologies should be based on:
Show answer & explanation
Correct answer: B
Explanation: Investments in security technologies should be based on a value analysis and a sound business case. Demonstrated value takes precedence over the current business climate because it is ever changing. Basing decisions on audit recommendations would be reactive in nature and might not address the key business needs comprehensively. Vulnerability assessments are useful, but they do not determine whether the cost is justified.
- Question 3
Retention of business records should PRIMARILY be based on:
Show answer & explanation
Correct answer: B
Explanation: Retention of business records is generally driven by legal and regulatory requirements. Business strategy and direction would not normally apply nor would they override legal and regulatory requirements. Storage capacity and longevity are important but secondary issues. Business case and value analysis would be secondary to complying with legal and regulatory requirements.
- Question 4
Which of the following is characteristic of centralized information security management?
Show answer & explanation
Correct answer: B
Explanation: Centralization of information security management results in greater uniformity and better adherence to security policies. It is generally less expensive to administer due to the economics of scale. However, turnaround can be slower due to the lack of alignment with business units.
- Question 5
Successful implementation of information security governance will FIRST require:
Show answer & explanation
Correct answer: B
Explanation: Updated security policies are required to align management objectives with security procedures; management objectives translate into policy; policy translates into procedures. Security procedures will necessitate specialized teams such as the computer incident response and management group as well as specialized tools such as the security mechanisms that comprise the security architecture. Security awareness will promote the policies, procedures and appropriate use of the security mechanisms.
- Question 6
Which of the following individuals would be in the BEST position to sponsor the creation of an information security steering group?
Show answer & explanation
Correct answer: B
Explanation: The chief operating officer (COO) is highly-placed within an organization and has the most knowledge of business operations and objectives. The chief internal auditor and chief legal counsel are appropriate members of such a steering group. However, sponsoring the creation of the steering committee should be initiated by someone versed in the strategy and direction of the business. Since a security manager is looking to this group for direction, they are not in the best position to oversee formation of this group.
- Question 7
The MOST important component of a privacy policy is:
Show answer & explanation
Correct answer: A
Explanation: Privacy policies must contain notifications and opt-out provisions: they are a high-level management statement of direction. They do not necessarily address warranties, liabilities or geographic coverage, which are more specific.
- Question 8
The cost of implementing a security control should not exceed the:
Show answer & explanation
Correct answer: C
Explanation: The cost of implementing security controls should not exceed the worth of the asset. Annualized loss expectancy represents the losses drat are expected to happen during a single calendar year. A security mechanism may cost more than this amount (or the cost of a single incident) and still be considered cost effective. Opportunity costs relate to revenue lost by forgoing the acquisition of an item or the making of a business decision.
- Question 9
When a security standard conflicts with a business objective, the situation should be resolved by:
Show answer & explanation
Correct answer: C
Explanation: Conflicts of this type should be based on a risk analysis of the costs and benefits of allowing or disallowing an exception to the standard. It is highly improbable that a business objective could be changed to accommodate a security standard, while risk acceptance* is a process that derives from the risk analysis.
- Question 10
Minimum standards for securing the technical infrastructure should be defined in a security:
Show answer & explanation
Correct answer: D
Explanation: Minimum standards for securing the technical infrastructure should be defined in a security architecture document. This document defines how components are secured and the security services that should be in place. A strategy is a broad, high-level document. A guideline is advisory in nature, while a security model shows the relationships between components.
Ready for the real thing?
The full CISM simulator has every exam-style question, timed mode, and instant scoring.