Certified Information Security Manager (CISM) practice questions

286 free questions with answers and explanations.

Practice test
  1. 1.A critical system outage at a large logistics company has been declared a major incident impacting global operations. The CISO, acting as the Incident Commander, has assembled the incident response team. During the initial phase of the response, which of the following actions should the Incident Commander prioritize to ensure an effective and coordinated effort?Incident Management
  2. 2.A CISO is tasked with improving the organization's information security posture. They observe that security incidents are often discovered reactively, leading to significant disruption and recovery costs. Which of the following approaches would BEST help the CISO shift from a reactive to a proactive security stance?Information Security Risk Management
  3. 3.During a routine security audit, several critical vulnerabilities are identified in a legacy application that is essential for core business operations. Due to the application's age and complexity, immediate patching would require extensive re-engineering, which is not feasible within the acceptable timeframe. The information security manager needs to implement a temporary solution to reduce the risk while a long-term fix is developed. Which of the following is the MOST appropriate immediate risk treatment strategy?Information Security Risk Management
  4. 4.A CISO is developing an incident response plan for a rapidly growing startup with limited resources. The CISO needs to ensure the plan focuses on quick containment and recovery for the most critical assets, without investing heavily in complex forensic tools or extensive long-term analysis capabilities initially. Which incident response strategy BEST aligns with this approach?Incident Management
  5. 5.A global e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that overwhelms its public-facing web servers, making the website inaccessible for several hours. The incident response team successfully mitigates the attack, but the CISO is concerned about the financial impact. When calculating the cost of the incident (COI), which of the following components would be MOST challenging to accurately quantify?Incident Management
  6. 6.A CISO is evaluating the current incident response capabilities and discovers that while the technical team is proficient, there is a significant delay in communicating incident status and impact to executive management and external stakeholders. This delay often leads to misunderstandings and reputational damage. Which of the following should the CISO prioritize to resolve this issue?Incident Management
  7. 7.A new Chief Information Security Officer (CISO) is establishing an information security program for a rapidly growing startup. The CISO recognizes the need to align security investments with business objectives. What is the MOST crucial initial step in developing an effective information security program?Information Security Risk Management
  8. 8.A CISO is reviewing the organization's incident response metrics. The metrics currently track the total time from incident detection to full resolution. To improve the effectiveness of the detection phase and identify potential weaknesses in monitoring systems, which of the following metrics should the CISO additionally prioritize?Incident Management
  9. 9.A CISO is establishing a new incident response team. To ensure the team can effectively manage incidents of varying severity and complexity, from minor alerts to major breaches, which organizational structure design principle is MOST critical?Incident Management
  10. 10.A CISO is tasked with developing an incident response capability for a rapidly growing startup. The startup has limited budget and personnel. Which of the following approaches should the CISO prioritize to establish a foundational incident response capability MOST effectively under these constraints?Incident Management
  11. 11.A manufacturing company is deploying a new Industrial Control System (ICS) that will manage critical production lines. The information security manager is concerned about the potential for cyber-physical attacks. Which of the following is the MOST important consideration when implementing security controls for this ICS environment?Information Security Risk Management
  12. 12.A Chief Information Security Officer (CISO) is presenting the information security program's annual budget request to the executive board. The board is primarily concerned with the financial impact and return on investment (ROI) of security expenditures. Which of the following metrics would BEST articulate the value of the security program in terms that resonate with the executive board?Information Security Risk Management
  13. 13.A CISO is developing a disaster recovery plan (DRP) for an organization that operates in a highly regulated industry. During the DRP development, it is identified that a key third-party cloud provider, hosting critical customer relations management (CRM) data, has an RTO of 24 hours, while the organization's RTO for the CRM system is 4 hours. Which of the following is the BEST initial action for the CISO to address this discrepancy?Incident Management
  14. 14.An organization is conducting a disaster recovery (DR) exercise. During the exercise, it is discovered that while primary applications are restored, critical inter-application dependencies are not correctly re-established, leading to downstream system failures and an extended recovery time. Which of the following activities should the CISO prioritize to prevent this issue in future DR scenarios?Incident Management
  15. 15.A healthcare organization is developing its Disaster Recovery Plan (DRP). The CISO is debating the inclusion of a comprehensive communication plan with external stakeholders (e.g., regulators, media, patients). What is the MOST compelling reason to integrate such a communication plan into the DRP?Incident Management
  16. 16.A CISO is developing an information security program for a newly established FinTech startup. The startup operates in a highly regulated industry and aims for rapid growth. Which of the following should be the CISO's PRIMARY focus when initially structuring the program?Information Security Risk Management
  17. 17.A CISO is developing a business continuity plan (BCP) for a critical business process that relies heavily on specialized personnel. The CISO recognizes that the sudden unavailability of these key individuals could severely impact the organization's ability to recover. Which of the following actions is MOST effective in mitigating this human factor risk?Incident Management
  18. 18.A company's CISO is reviewing the Business Continuity Plan (BCP) and discovers that several critical business functions lack a defined Recovery Point Objective (RPO). What is the MOST significant risk associated with an undefined RPO for a critical business function?Incident Management
  19. 19.A global enterprise with diverse business units is developing its incident response strategy. The CISO is evaluating models to balance centralized control with local responsiveness. Which incident response model is BEST suited for an organization that requires a strong central oversight but also empowers local teams to handle routine incidents independently?Incident Management
  20. 20.A CISO is developing a disaster recovery plan (DRP) for an organization that relies heavily on a critical legacy application. This application has highly specialized hardware requirements and is incompatible with modern virtualization platforms and cloud environments. The organization has a limited budget for DR, making a hot site financially unfeasible. Which of the following recovery strategies is MOST appropriate for this specific legacy application?Incident Management
  21. 21.A CISO is tasked with developing an incident response capability for a rapidly growing startup with limited resources and a small IT team. The startup primarily uses SaaS applications and cloud infrastructure. The CISO needs an approach that is agile, cost-effective, and focuses on quick recovery. Which incident response methodology is BEST suited for this scenario?Incident Management
  22. 22.A global e-commerce company experiences a data breach involving customer credit card information. The incident response team has contained the breach and is now in the recovery phase. Which of the following is the MOST critical activity during the recovery phase to prevent recurrence and restore normal operations?Information Security Risk Management
  23. 23.A global manufacturing company is expanding its operations into a new region with strict data residency and privacy laws. The existing enterprise architecture, which relies on centralized data processing in a different continent, is not compliant with these new regulations. The information security manager is tasked with addressing this compliance gap. Which of the following approaches represents the MOST effective long-term strategy?Information Security Risk Management
  24. 24.An organization is evaluating its information security program's maturity and effectiveness. The CISO wants to ensure that security controls are not only implemented but also continuously monitored and regularly reviewed to adapt to evolving threats and business changes. Which concept BEST describes this ongoing process of verification and adaptation?Information Security Risk Management
  25. 25.A healthcare organization is conducting a business impact analysis (BIA) as part of its business continuity planning. During the BIA, several critical business processes are identified, each supported by multiple IT systems. The CISO needs to prioritize recovery efforts for these systems. Which of the following factors should be the PRIMARY consideration when assigning recovery priorities to IT systems based on BIA results?Incident Management
  26. 26.A multinational corporation is developing a global incident response strategy. The CISO proposes implementing a centralized incident response team to handle all incidents across all regions. However, regional business leaders express concerns about local autonomy and unique regulatory landscapes. Which of the following is the MOST appropriate strategy for the CISO to address these concerns while maintaining overall control and consistency?Incident Management
  27. 27.A financial institution is developing its incident response plan. The CISO is reviewing the objectives and wants to ensure that the plan effectively addresses the organization's regulatory obligations and minimizes financial impact. Which of the following incident response objectives is MOST crucial for achieving these goals?Incident Management
  28. 28.An organization is developing a new critical business application. The information security manager wants to proactively identify and categorize potential threats to the application during its design phase to ensure appropriate security controls are embedded early. Which threat modeling methodology would be MOST effective for systematically identifying and categorizing threats based on common attack types?Information Security Risk Management
  29. 29.A global organization is developing a new cloud-based application that will process sensitive customer data across multiple jurisdictions. The information security manager is tasked with ensuring compliance with various data protection regulations (e.g., GDPR, CCPA). Which of the following is the MOST effective approach to manage this complex regulatory landscape?Information Security Risk Management
  30. 30.A software development company is experiencing an increase in security-related defects being discovered late in the development lifecycle, leading to costly rework and project delays. The CISO wants to embed security more effectively into the software development process. Which of the following approaches is MOST effective in addressing this issue?Information Security Risk Management
  31. 31.An organization is evaluating its current threat landscape. The information security manager is analyzing recent attack patterns, including zero-day exploits and advanced persistent threats (APTs). To effectively manage these evolving threats, which of the following actions should be prioritized?Information Security Risk Management
  32. 32.A CISO is tasked with implementing a new incident response playbooks system. The goal is to ensure that playbooks are actionable, consistent, and easily updated, allowing the incident response team (IRT) to respond effectively to a wide range of incidents. Which of the following approaches is MOST effective for designing and maintaining these playbooks?Incident Management
  33. 33.An organization is developing its information security program. The information security manager is tasked with ensuring that the program aligns with business objectives. Which of the following actions is MOST crucial to achieve this alignment?Information Security Risk Management
  34. 34.An organization is considering deploying a new cloud-based application that will process highly sensitive customer data. The information security manager is conducting a risk assessment and identifies that the cloud provider's data encryption at rest uses a key management system (KMS) where the encryption keys are managed solely by the provider. Which of the following risk responses is MOST appropriate in this scenario?Information Security Risk Management
  35. 35.A Chief Information Security Officer (CISO) is presenting the information security program's progress and effectiveness to the board of directors. The board is primarily interested in understanding the financial impact of security investments and how they contribute to the organization's bottom line. Which metric would be MOST effective for the CISO to use to demonstrate the financial value of security initiatives?Information Security Risk Management
  36. 36.An organization is conducting a disaster recovery (DR) exercise. The scenario involves the complete loss of its primary data center. During the exercise, it is discovered that while individual applications can be restored, the interdependencies between critical business applications are not correctly accounted for, leading to functional failures and extended recovery times. Which of the following actions should the CISO prioritize to address this deficiency?Incident Management
  37. 37.A CISO is reviewing the organization's business continuity plan (BCP) and identifies a critical dependency on a single third-party vendor for a key communication platform. A disruption to this vendor could severely impact the organization's ability to communicate with customers and employees during a crisis. Which of the following is the MOST effective strategy to mitigate this single point of failure within the BCP?Incident Management
  38. 38.A CISO is establishing an incident response program for a mid-sized financial institution. The CISO wants to ensure that the program can adapt to emerging threats and technologies while maintaining core principles. Which of the following components is MOST crucial for achieving this adaptability?Incident Management
  39. 39.A large e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that disrupts its online sales for several hours. The incident response team successfully mitigates the attack, but the CISO is asked to quantify the total impact. Beyond direct revenue loss and mitigation costs, which of the following 'intangible' costs is MOST challenging to accurately quantify but can have a profound long-term impact?Incident Management
  40. 40.A CISO is reviewing the organization's disaster recovery plan (DRP) and identifies that while technical recovery procedures are well-documented, there is no clear process for managing the transition of business operations back to the primary site after a disaster. Which of the following is the MOST significant risk uncovered by this finding?Incident Management
  41. 41.A CISO is establishing a new incident response program for a mid-sized financial institution. The CISO wants to ensure that the program can effectively address various types of incidents while maintaining operational efficiency. Which of the following is the MOST critical first step in developing a robust incident response capability?Incident Management
  42. 42.During a review of an organization's vulnerability management program, the CISO notes that while many vulnerabilities are identified, the mean time to remediate (MTTR) critical findings is consistently high. Which of the following actions should the CISO prioritize to improve this situation?Information Security Risk Management
  43. 43.An organization relies on a critical legacy system that processes sensitive data but lacks modern security features and cannot be easily patched. Replacing the system is prohibitively expensive and time-consuming. Which of the following risk treatment strategies is MOST appropriate for the CISO to recommend in this situation?Information Security Risk Management
  44. 44.A CISO is establishing an incident response team for a medium-sized enterprise. Which of the following roles is MOST critical to ensure effective coordination and decision-making during a major security incident?Incident Management
  45. 45.A CISO is reviewing the organization's current incident response plan. The plan details steps for technical containment and eradication but lacks specific guidance on preserving potential evidence for legal or forensic purposes. What is the MOST significant risk posed by this oversight?Incident Management
  46. 46.An organization experiences a significant data breach due to a zero-day vulnerability. Following the incident, the CISO is tasked with improving the organization's ability to anticipate and defend against future advanced threats. Which of the following would be the MOST effective long-term strategy?Information Security Risk Management
  47. 47.A critical system outage at a large e-commerce company is identified as a major incident. The CISO mandates the establishment of an Incident Command Structure (ICS) to manage the response. Which of the following is the PRIMARY benefit of implementing an ICS in this scenario?Incident Management
  48. 48.A manufacturing company is implementing a new Supervisory Control and Data Acquisition (SCADA) system for its critical production line. The Chief Information Security Officer (CISO) is concerned about potential cyber-physical risks. Which of the following risk management strategies is MOST appropriate for mitigating the unique threats associated with operational technology (OT) systems like SCADA?Information Security Risk Management
  49. 49.An organization is conducting a risk assessment for a new critical business application. The information security manager is evaluating various threat actors and their potential capabilities. Which of the following threat modeling approaches would BEST help in proactively identifying and prioritizing potential threats from these actors against the application?Information Security Risk Management
  50. 50.A CISO is developing a business continuity plan (BCP) for an organization that relies heavily on a critical supply chain that involves multiple international partners. A disruption at any point in this supply chain could severely impact the organization's ability to deliver products. Which of the following strategies is MOST effective in enhancing the resilience of this complex supply chain?Incident Management