Certified Information Security Manager (CISM) practice questions

286 free questions with answers and explanations.

Practice test
  1. 101.During a disaster recovery exercise, an organization successfully restores its primary applications and data to an alternate site. However, several business units report that they cannot access critical functionalities due to misconfigured network settings at the recovery site. Which aspect of disaster recovery planning was MOST likely overlooked or inadequately tested?Incident Management
  2. 102.A CISO is developing a disaster recovery plan (DRP) for a cloud-native application. The application relies on managed services from the cloud provider, including serverless functions and managed databases. Which of the following is the MOST important consideration for ensuring the DRP's effectiveness for this architecture?Incident Management
  3. 103.A global enterprise with diverse business units is developing its incident response strategy. The CISO wants to ensure that each business unit can manage localized incidents efficiently while maintaining overall corporate oversight and consistency. Which incident response model BEST supports this requirement?Incident Management
  4. 104.A CISO is reviewing the organization's business continuity plan (BCP) and identifies that while critical IT systems have robust recovery strategies, there is a significant gap in addressing the availability of specialized personnel required to operate these systems in a disaster. Which of the following is the MOST effective strategy to mitigate this risk?Incident Management
  5. 105.A large enterprise is struggling to manage its vast and complex IT environment, which includes on-premise, cloud, and hybrid systems. The security team receives thousands of security alerts daily, leading to alert fatigue and missed critical incidents. The CISO wants to improve the efficiency and effectiveness of security operations. Which solution would BEST address these challenges by automating routine tasks and orchestrating complex workflows?Information Security Risk Management
  6. 106.A financial institution is implementing a new online banking platform. During the risk assessment process, the information security manager identifies a potential vulnerability related to cross-site scripting (XSS) that could allow attackers to inject malicious scripts into trusted websites. Based on the risk assessment, which of the following is the MOST appropriate next step for the information security manager?Information Security Risk Management
  7. 107.A Chief Information Security Officer (CISO) is presenting the current state of information security to the board of directors. The board is primarily concerned with the financial implications of cyber risks and the return on security investments. Which of the following metrics would be MOST effective for the CISO to present?Information Security Risk Management
  8. 108.A manufacturing company is integrating its operational technology (OT) network with its information technology (IT) network to improve efficiency and data analytics. The information security manager recognizes the unique security challenges presented by OT environments. What is the PRIMARY concern when securing this converged IT/OT environment?Information Security Risk Management
  9. 109.A CISO is developing a disaster recovery plan (DRP) for a cloud-native application hosted across multiple regions. The application leverages microservices, serverless functions, and managed databases. Which of the following strategies is MOST aligned with a cloud-native approach to disaster recovery?Incident Management
  10. 110.A large multinational corporation uses a complex array of security tools, generating millions of logs daily. The security operations center (SOC) analysts are overwhelmed by the volume of alerts, leading to potential missed incidents. The CISO wants to improve the efficiency and effectiveness of threat detection and response. Which of the following solutions would provide the MOST immediate and impactful improvement?Information Security Risk Management
  11. 111.A software development company is adopting a DevSecOps model to integrate security into every stage of the software development lifecycle (SDLC). The information security manager is tasked with ensuring that security vulnerabilities are identified and addressed as early as possible. Which of the following practices is MOST effective in achieving this goal within a DevSecOps environment?Information Security Risk Management
  12. 112.During a significant cyber incident, the CISO observes that the incident response team (IRT) is overwhelmed with manual tasks such as log aggregation from disparate systems, manual threat intelligence lookups, and uncoordinated communication across multiple platforms. This significantly delays containment and recovery. To address this, which capability should the CISO prioritize implementing to improve the IRT's efficiency?Incident Management
  13. 113.An organization has identified a critical vulnerability in a legacy system that cannot be patched without significant operational disruption. The information security manager proposes implementing a firewall rule to restrict access to the system only from specific, hardened jump servers. Which risk treatment strategy is being applied?Information Security Risk Management
  14. 114.A large enterprise is struggling with a high volume of false positives from its Security Information and Event Management (SIEM) system, leading to alert fatigue among security analysts and delaying response to legitimate threats. The information security manager wants to improve the efficiency of threat detection and response. Which of the following actions should the manager prioritize?Information Security Risk Management
  15. 115.An organization is conducting a disaster recovery (DR) exercise. The scenario involves the complete loss of their primary data center. The exercise reveals that while data backups are successfully restored, the applications fail to start correctly due to incompatible configurations in the recovery environment. The CISO needs to address this issue to ensure future DR success. Which of the following actions is MOST effective in preventing this type of application recovery failure?Incident Management
  16. 116.A financial institution is updating its incident response plan. The CISO wants to ensure that the organization continuously learns from past incidents and improves its incident response capabilities over time. Which of the following processes should the CISO emphasize to achieve this objective?Incident Management
  17. 117.A software development company is adopting a DevSecOps model. The information security manager is tasked with integrating security controls throughout the software development lifecycle (SDLC). Which of the following is the MOST effective way to ensure security is 'shifted left' in this new model?Information Security Risk Management
  18. 118.A CISO is developing an incident response capability for a rapidly growing startup with limited resources. The goal is to establish a functional and efficient incident response process quickly. Which of the following principles should the CISO prioritize to achieve this objective?Incident Management
  19. 119.An organization is conducting a disaster recovery (DR) exercise. During the exercise, it is discovered that several critical applications, while technically restored at the DR site, are unable to communicate with their backend databases due to incorrect network configurations. Which of the following aspects of DR planning was MOST likely overlooked?Incident Management
  20. 120.A global organization is implementing a new customer relationship management (CRM) system that will store sensitive personal data across multiple jurisdictions. The information security manager is tasked with ensuring compliance with various data protection regulations, including GDPR and CCPA. Which of the following is the MOST critical initial step in managing the information security risks associated with this new system?Information Security Risk Management
  21. 121.A CISO is establishing an incident response program for a mid-sized financial institution. Which of the following is the MOST critical initial step to ensure the program aligns with organizational objectives and regulatory requirements?Incident Management
  22. 122.A CISO is reviewing the organization's disaster recovery plan (DRP) and notes that while individual application recovery procedures are well-documented, there is no formal process to verify that the recovered applications will collectively support critical business functions end-to-end. This leads to uncertainty about achieving the overall Recovery Time Objective (RTO). Which of the following activities should the CISO prioritize?Incident Management
  23. 123.A CISO is reviewing the organization's incident response metrics. The metrics currently track the number of incidents, average containment time, and cost per incident. To improve the overall effectiveness of the IR program, which additional metric would be MOST valuable for identifying systemic weaknesses and areas for strategic improvement?Incident Management
  24. 124.A CISO is tasked with implementing a new incident response playbooks system. The goal is to ensure that incident responders can quickly and accurately follow procedures for common incident types. Which of the following design principles for playbooks is MOST crucial to achieve this goal?Incident Management
  25. 125.A global manufacturing company experiences a cyber-physical incident where ransomware encrypts critical production control systems, halting operations across several plants. The CISO needs to prioritize recovery efforts. Which of the following is the MOST critical initial step to inform recovery prioritization?Incident Management
  26. 126.A CISO is reviewing the organization's business continuity plan (BCP) and identifies a critical business process that relies on a single, highly specialized vendor for a key component. The CISO is concerned about the potential impact if this vendor experiences a disruption. Which of the following strategies would MOST effectively mitigate this single point of failure in the BCP?Incident Management
  27. 127.A CISO is developing a business continuity plan (BCP) for a critical supply chain that involves multiple third-party vendors. The CISO identifies that a disruption at a single key vendor could halt production. To enhance resilience and minimize the impact of such a disruption, which of the following strategies is MOST effective?Incident Management
  28. 128.A financial institution is implementing a new online banking platform. During the risk assessment, the information security manager identifies a high-risk vulnerability related to unpatched legacy components within the platform's infrastructure. The cost to patch these components immediately is significant and will delay the platform's launch. The business leadership is unwilling to accept the delay. What is the MOST appropriate information security management response?Information Security Risk Management
  29. 129.A CISO is developing a business continuity plan (BCP) for an organization that relies heavily on a single, highly specialized vendor for a critical component of its supply chain. The CISO identifies the potential for this vendor's failure to cause significant business disruption. Which of the following is the MOST effective strategy to mitigate this single point of failure in the BCP?Incident Management
  30. 130.An organization is conducting a risk assessment for a new critical business application. The information security manager wants to systematically identify potential threats to the application by focusing on its design and functionality. Which of the following methodologies is BEST suited for this purpose?Information Security Risk Management
  31. 131.A global e-commerce company experiences a data breach involving customer credit card information. The incident response team successfully contained the breach and eradicated the threat. According to best practices for incident response, which of the following is the MOST critical next step for the information security manager?Information Security Risk Management
  32. 132.An organization is evaluating the effectiveness of its information security awareness training program. Post-training phishing simulations show a 15% click-through rate, which is higher than the industry average of 10%. The information security manager needs to report this to senior management and recommend improvements. Which of the following metrics would be MOST useful to present alongside the click-through rate to provide a comprehensive view of the program's impact?Information Security Risk Management
  33. 133.A CISO is presenting to the executive leadership on the organization's information security program. The executives are concerned about aligning security investments with the overall business strategy. Which of the following actions demonstrates the BEST alignment of information security with business objectives?Information Security Risk Management
  34. 134.A financial institution is developing a new mobile banking application. The project manager is focused on rapid deployment and feature delivery. The information security manager emphasizes the need to integrate security requirements early in the development lifecycle. Which of the following BEST describes the security manager's recommended approach?Information Security Risk Management
  35. 135.A global manufacturing company experiences a significant cyber-physical incident that affects its operational technology (OT) systems, leading to production downtime across multiple facilities. The CISO is tasked with ensuring a comprehensive recovery. Beyond restoring IT systems, which of the following is the MOST critical consideration for incident recovery in this OT environment?Incident Management
  36. 136.A CISO is reviewing the organization's disaster recovery plan (DRP) and notes that while it outlines detailed procedures for restoring IT systems, it lacks specific guidance for the business units to validate the functionality and data integrity of their applications after recovery. Which critical aspect of disaster recovery is missing?Incident Management
  37. 137.During a strategic planning session, the board expresses concern about the organization's ability to adapt its information security program to rapidly evolving cyber threats and new regulatory mandates. Which of the following information security governance principles should the CISO emphasize to address this concern MOST effectively?Information Security Governance
  38. 138.A CISO is tasked with fostering a stronger security-aware culture within an organization where security is often viewed as an impediment to innovation and speed. The organization has a strong, fast-paced 'move fast and break things' culture. Which of the following approaches is MOST likely to successfully integrate security into this organizational culture?Information Security Governance
  39. 139.A CISO is presenting the annual information security strategy to the board of directors. A board member questions the return on investment (ROI) of recent security expenditures, asking for clearer evidence of their financial benefits. Which of the following actions should the CISO prioritize to address this concern effectively?Information Security Governance
  40. 140.An organization discovers that a critical financial system, developed years ago, does not fully comply with a recently enacted industry-specific data protection regulation. The CISO needs to present a remediation plan to senior management. Which of the following actions should the CISO prioritize to demonstrate due care and due diligence in this situation?Information Security Governance
  41. 141.A CISO is presenting the annual information security strategy to the board of directors. During the presentation, a board member asks how information security investments contribute to the organization's overall profitability and competitive advantage. Which metric would be MOST effective for the CISO to use in demonstrating the value of security in business terms?Information Security Governance
  42. 142.A CISO is reviewing the organization's information security policies. The organization has recently acquired several smaller companies, each with its own legacy systems and unique operational requirements. The CISO wants to ensure that the current policy framework is flexible enough to accommodate these diverse environments without compromising overall security objectives. Which characteristic of the policy framework is MOST crucial in this scenario?Information Security Governance
  43. 143.An organization is updating its information security policy framework. To ensure the framework remains adaptable to future technological changes and evolving business needs, which characteristic is MOST important for its design?Information Security Governance
  44. 144.A CISO is developing an information security strategy for a manufacturing company that emphasizes operational efficiency and cost reduction. Which of the following approaches BEST ensures that the security strategy supports these organizational objectives?Information Security Governance
  45. 145.A CISO is establishing an information security governance framework for a newly formed organization. Which of the following is the MOST critical initial step to ensure the framework effectively supports business objectives?Information Security Governance
  46. 146.A multinational corporation is acquiring a smaller technology startup. The CISO of the acquiring company is conducting due diligence. Which of the following security aspects of the startup should the CISO prioritize to assess for potential integration risks and liabilities?Information Security Governance
  47. 147.An organization relies heavily on its supply chain for critical components. A recent audit highlighted significant information security risks originating from third-party vendors. To address this, the CISO proposes establishing a formal vendor risk management (VRM) program. Which of the following is the MOST important element to include in the VRM program's initial design?Information Security Governance
  48. 148.A CISO is reviewing the organization's approach to information security awareness. Despite regular training, employees frequently bypass security controls for convenience, indicating a gap between policy and practice. To address this, the CISO wants to embed security more deeply into the organizational culture and daily operations. Which initiative would be MOST effective in achieving this cultural shift?Information Security Governance
  49. 149.An organization relies heavily on a third-party cloud provider for its critical data processing and storage. The CISO is tasked with ensuring the third-party provider's adherence to the organization's information security policies and regulatory obligations. Which of the following is the MOST effective governance mechanism to achieve this?Information Security Governance
  50. 150.An organization is considering a significant investment in a new cloud-based data analytics platform. The CISO needs to ensure that security considerations are integrated into the decision-making process from the outset. Which of the following BEST describes the CISO's primary role in this scenario?Information Security Governance