Certified Information Security Manager (CISM) practice questions
286 free questions with answers and explanations.
- 51.An organization relies heavily on a third-party cloud provider for its critical data storage and processing. Recent news reports indicate a significant data breach at a similar cloud provider. The information security manager needs to assess the potential impact of this external event on the organization's risk posture. Which of the following is the MOST appropriate next step?Information Security Risk Management
- 52.An organization relies on a third-party cloud provider for its critical customer relationship management (CRM) system. The CISO is reviewing the disaster recovery capabilities for this system. Which of the following is the MOST effective way to ensure the cloud provider's disaster recovery plan (DRP) aligns with the organization's specific recovery time objectives (RTOs) and recovery point objectives (RPOs)?Incident Management
- 53.A multinational corporation operates in various jurisdictions, each with its own set of privacy regulations. The information security manager is developing a global information security program. Which of the following principles should be MOST heavily emphasized to ensure compliance across all regions while maintaining operational efficiency?Information Security Risk Management
- 54.A multinational corporation uses a federated incident response model, where local business units manage their own initial incident response. However, the CISO notes a lack of consistent reporting and insufficient aggregation of threat intelligence across regions, hindering the ability to identify widespread attacks. To improve this, which action should the CISO prioritize?Incident Management
- 55.A CISO is reviewing the organization's incident response plan and observes that while technical steps for containment and eradication are well-defined, there is no clear process for ensuring that forensic evidence is properly collected, preserved, and admissible in legal proceedings. Which of the following roles or functions should the CISO establish or reinforce to address this gap?Incident Management
- 56.A global e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that overwhelms its online sales platform. The incident response team successfully mitigates the attack after several hours. During the post-incident analysis, the CISO wants to understand the total cost incurred due to the incident, including lost revenue, mitigation efforts, and reputational damage. Which of the following metrics is MOST appropriate for this assessment?Incident Management
- 57.A manufacturing company's operational technology (OT) network, which controls critical production machinery, experiences a cyberattack. The CISO is informed that the attack has moved from the IT network into the OT environment, potentially causing physical damage and production halts. Given the potential for significant physical and business impact, which of the following is the MOST critical immediate action to take?Incident Management
- 58.A multinational corporation is developing a new cloud-based application that will process sensitive customer data across various geographical regions. The CISO needs to ensure that the application's security architecture is robust and compliant with diverse regulations. Which framework provides a comprehensive, integrated approach to manage governance, risk, and compliance (GRC) across the organization's IT environment?Information Security Risk Management
- 59.A company is experiencing a significant increase in phishing attacks targeting its employees. The information security manager has implemented email filtering, security awareness training, and multi-factor authentication (MFA). However, the attacks persist. To determine the MOST effective additional control, the manager decides to calculate the Annualized Loss Expectancy (ALE) for phishing attacks. Given the following data: Single Loss Expectancy (SLE) = $50,000, Annualized Rate of Occurrence (ARO) = 0.5. What is the ALE?Information Security Risk Management
- 60.A financial institution is developing its incident response capabilities. The CISO wants to ensure that the incident response plan (IRP) clearly defines the thresholds at which an event escalates to a major incident requiring executive notification and activation of the incident command structure. Which of the following elements of the IRP is MOST critical for this purpose?Incident Management
- 61.A manufacturing company is integrating its operational technology (OT) network with its information technology (IT) network to gain efficiencies through data analytics. The CISO is concerned about the increased risk to critical production systems. Which of the following risk management strategies is MOST appropriate to address the unique challenges of OT security in this converged environment?Information Security Risk Management
- 62.A managed security service provider (MSSP) detects anomalous outbound network traffic from a client's server, indicating potential data exfiltration. The client's incident response plan states that the incident coordinator must be notified within 15 minutes. What is this 15-minute timeframe an example of?Incident Management
- 63.An organization is conducting a disaster recovery (DR) exercise. The scenario involves the complete loss of a primary data center. After successfully restoring applications and data to the alternate site, the CISO observes that end-users are having difficulty performing their daily tasks due to unfamiliarity with the recovered system's interface and workflow changes. Which critical aspect of DR planning was MOST likely neglected?Incident Management
- 64.An organization is developing its information security program. The information security manager is tasked with ensuring that security initiatives are aligned with the overall business strategy and objectives. Which of the following activities is MOST crucial for achieving this business-security alignment?Information Security Risk Management
- 65.A CISO is evaluating the effectiveness of the organization's information security program. The CISO wants to ensure that security controls remain effective against new and emerging threats without requiring constant manual review. Which of the following practices BEST supports this objective?Information Security Risk Management
- 66.A CISO is developing a disaster recovery plan (DRP) for an organization that operates in a highly regulated industry. The organization relies heavily on several third-party cloud providers for critical services. The CISO is concerned that the DR capabilities of these providers may not align with the organization's specific RTO/RPO requirements and regulatory obligations. Which of the following is the MOST effective approach for the CISO to ensure alignment?Incident Management
- 67.During a disaster recovery exercise, an organization successfully restores its core financial systems at a warm site. However, the CISO observes that the critical personnel required to operate these systems are not familiar with the specific configurations and procedures of the warm site, leading to significant delays. Which of the following is the MOST effective way to prevent this human-factor related delay in a real disaster?Incident Management
- 68.During a significant cyber incident, the CISO observes that the incident response team (IRT) is overwhelmed with manual tasks, leading to delays in containment and reporting. The CISO wants to improve the efficiency and speed of future incident response activities. Which of the following capabilities should the CISO prioritize for implementation?Incident Management
- 69.A CISO is reviewing the organization's current vulnerability management program. They notice that while vulnerabilities are identified regularly, the time taken to fix critical issues (Mean Time To Remediate - MTTR) is consistently high. Which of the following initiatives would MOST effectively reduce the MTTR for critical vulnerabilities?Information Security Risk Management
- 70.A global technology company is planning to launch a new product that involves collecting and processing a large volume of customer personal data. The information security manager is tasked with ensuring compliance with various international data protection regulations. Which approach BEST integrates privacy considerations into the product development lifecycle from its earliest stages?Information Security Risk Management
- 71.A global manufacturing company relies heavily on its Enterprise Resource Planning (ERP) system for daily operations. A recent business impact analysis (BIA) determined that the maximum tolerable downtime (MTD) for the ERP system is 4 hours. Which of the following recovery strategies would BEST support meeting this MTD, assuming a significant system failure?Incident Management
- 72.A financial services organization is assessing its information security posture. The Chief Information Security Officer (CISO) needs to prioritize remediation efforts based on the potential impact of identified vulnerabilities. Which of the following risk assessment approaches BEST facilitates this prioritization?Information Security Risk Management
- 73.An organization is conducting a quantitative risk assessment for a critical business application. The Annualized Rate of Occurrence (ARO) for a specific type of cyberattack is estimated to be 0.5 (meaning it's expected to occur once every two years). The Single Loss Expectancy (SLE) for this attack is calculated as $200,000. What is the Annualized Loss Expectancy (ALE) for this cyberattack?Information Security Risk Management
- 74.An organization relies heavily on a third-party cloud provider for its critical data storage and processing. During a recent audit, it was discovered that the cloud provider's incident response plan does not explicitly address data breach notification requirements specific to the organization's industry (healthcare). Which of the following is the MOST critical action for the information security manager to take?Information Security Risk Management
- 75.A critical system outage at a large e-commerce company is identified as a major incident. The incident response team is struggling to contain the issue due to a lack of clear authority and decision-making processes. Which of the following is the MOST crucial element missing from their incident response plan that would address this challenge?Incident Management
- 76.A global organization is implementing a new enterprise resource planning (ERP) system that will process sensitive financial and customer data across multiple jurisdictions. Which of the following is the MOST critical consideration for the information security manager in this scenario?Information Security Risk Management
- 77.A multinational corporation uses a federated incident response model, where local business units handle initial incident triage and response, escalating to a central team only for major incidents. A CISO is reviewing this model. What is the MOST significant challenge this model may introduce compared to a fully centralized model?Incident Management
- 78.A software development company is experiencing an increase in security-related defects being discovered late in the development cycle, leading to costly rework and project delays. The CISO wants to implement a security testing methodology that integrates security checks earlier in the Software Development Life Cycle (SDLC). Which of the following would be the MOST effective approach to identify code vulnerabilities during the coding phase, before runtime?Information Security Risk Management
- 79.An organization is evaluating its information security risk appetite. The board of directors expresses concern over potential reputational damage from a data breach, while the IT department emphasizes the cost of implementing extensive security controls. What is the CISO's PRIMARY role in aligning these perspectives?Information Security Risk Management
- 80.A Chief Information Security Officer (CISO) is presenting the current state of information security to the executive management. To justify ongoing and future security investments, the CISO wants to demonstrate the financial benefits of the security program. Which of the following approaches BEST illustrates the economic value of security to the business?Information Security Risk Management
- 81.An organization is conducting a disaster recovery (DR) exercise. The scenario involves the loss of its primary data center. During the exercise, the CISO observes that while all systems are technically restored at the recovery site, several key business applications fail to communicate with each other due to incorrect network configurations and outdated firewall rules at the new location. Which aspect of the DR exercise was inadequately tested?Incident Management
- 82.A CISO is evaluating the current incident response capabilities and discovers that while the team is proficient in technical remediation, there is a lack of structured processes for effective internal and external stakeholder communication during incidents. Which of the following is the MOST significant consequence of this deficiency?Incident Management
- 83.A financial institution is updating its incident response plan. The CISO wants to ensure that the plan effectively addresses emerging threats while remaining agile. Which of the following approaches BEST supports continuous improvement and adaptation of the incident response plan?Incident Management
- 84.During a security audit, it is discovered that several critical vulnerabilities exist in an organization's internal applications. The development team argues that patching these vulnerabilities would disrupt current project timelines and require significant refactoring. What is the CISO's MOST appropriate immediate action?Information Security Risk Management
- 85.A global manufacturing company experiences a cyber-physical incident where ransomware encrypts critical production control systems (OT network), halting operations. The CISO, working with the OT security team, needs to prioritize recovery efforts to minimize production downtime. Which of the following should be the PRIMARY consideration when prioritizing the recovery of OT systems?Incident Management
- 86.An organization is considering the implementation of a new security control that will cost $50,000 annually. This control is expected to reduce the likelihood of a specific incident, which currently has an Annualized Loss Expectancy (ALE) of $200,000, by 75%. What is the Annualized Savings of this new control?Information Security Risk Management
- 87.A global e-commerce company recently experienced a significant data breach. Following the incident containment and eradication, the CISO initiates a 'lessons learned' review. What is the PRIMARY objective of this post-incident activity?Information Security Risk Management
- 88.During an ongoing major cyber incident, the CISO is informed that the primary incident response team is overwhelmed, and external experts need to be onboarded rapidly. Which of the following is the MOST important consideration for the CISO regarding these external resources?Incident Management
- 89.A CISO is presenting to the board about the organization's information security program effectiveness. The board asks for a clear metric that demonstrates the financial benefit of security investments. Which of the following metrics would BEST address the board's request?Information Security Risk Management
- 90.A CISO is developing a business continuity plan (BCP) for a critical business process that involves sensitive customer data. The BCP includes provisions for activating an alternate processing site. Which of the following is the MOST critical aspect to ensure during the activation of the alternate site, beyond technical functionality?Incident Management
- 91.A CISO is evaluating the effectiveness of the organization's information security program. Recent internal audits indicate a high rate of compliance with security policies, but there is still concern about the overall security posture due to emerging threats. Which of the following actions would BEST help the CISO assess the true effectiveness of the program against real-world threats?Information Security Risk Management
- 92.During a simulated disaster recovery exercise, a critical step in the business continuity plan (BCP) fails: the remote access VPN infrastructure for key personnel cannot be brought online, preventing them from accessing recovery systems. The CISO notes this failure. What is the MOST appropriate immediate action for the CISO to take regarding this specific failure?Incident Management
- 93.A CISO is reviewing the organization's business continuity plan (BCP) and identifies a critical single point of failure: a proprietary manufacturing system that lacks redundancy and has a very long lead time for replacement parts. To mitigate this risk, which of the following strategies is MOST effective in enhancing the system's resilience within the BCP context?Incident Management
- 94.During a routine vulnerability scan, the information security manager identifies several critical vulnerabilities on a legacy system that supports a non-critical, internal business function. The vendor no longer provides security patches for this system, and replacement is budgeted for next year. Which of the following is the MOST appropriate interim control strategy?Information Security Risk Management
- 95.A large multinational corporation uses a complex array of security tools, generating millions of alerts daily. The security operations center (SOC) team is overwhelmed by the volume and struggles to prioritize and respond effectively. The information security manager is looking for a solution to improve the efficiency and effectiveness of the SOC. Which of the following solutions would be MOST beneficial?Information Security Risk Management
- 96.A retail company experiences a data breach involving customer credit card information. The incident response team has identified the root cause and implemented corrective actions. Before declaring the incident closed, what critical step should the CISO ensure is completed to prevent recurrence and improve future response?Incident Management
- 97.A CISO is developing a disaster recovery plan (DRP) for an organization that relies heavily on a single, aging data center. The CISO identifies the data center as a significant single point of failure. Which of the following strategies BEST mitigates this risk while ensuring business continuity?Incident Management
- 98.A global e-commerce platform experiences a major data breach affecting millions of customer records. The CISO must prioritize actions to mitigate harm and control the incident. According to the NIST Incident Response Lifecycle, which phase is MOST critical immediately AFTER detection and analysis, to prevent further compromise and reduce damage?Incident Management
- 99.A CISO is establishing a new incident response team. To ensure the team can effectively manage incidents of varying severity and complexity, which of the following is the MOST important organizational structure principle to implement?Incident Management
- 100.An organization experiences a ransomware attack that encrypts critical servers. The incident response team successfully contains the spread and eradicates the malware. What is the NEXT logical step according to the typical incident response lifecycle?Incident Management