Practice questions
CISM (ISACA): Practice Questions
Ten original concept-check questions on core CISM ideas. Choose an answer to reveal the explanation. Answer as a risk-focused security manager, not a technician.
-
Compared with CISSP, CISM is most focused on:
Correct answer: B. CISM is a management certification centred on governance, risk and running a security programme, even more than CISSP. -
The primary goal of information security governance is to:
Correct answer: B. Governance exists to ensure security supports and aligns with the organisation's business goals and risk appetite. -
'Risk appetite' is best described as:
Correct answer: A. Risk appetite is how much risk the organisation is willing to take on; tolerance is the acceptable variation around it. -
When an identified risk exceeds the organisation's risk appetite, the security manager should FIRST:
Correct answer: B. The manager assesses options and escalates a recommended response through the governance process rather than acting unilaterally. -
The primary purpose of a Business Impact Analysis (BIA) is to:
Correct answer: B. A BIA identifies critical business functions and the impact of disruption, informing recovery priorities (RTO/RPO). -
A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:
Correct answer: B. A KRI is a forward-looking signal of increasing risk; a KPI measures how well something is performing. -
'Residual risk' is the risk that remains:
Correct answer: B. Residual risk is what is left after controls reduce inherent risk; management decides whether to accept it. -
When establishing a new security programme, the BEST first step is to:
Correct answer: B. An effective programme starts from business alignment and management commitment, which direct everything that follows. -
During a serious incident, the security manager's priority is to:
Correct answer: B. Incident management follows a plan: contain, eradicate and recover, with communication and lessons learned afterwards. -
Third-party (vendor) risk should be managed by:
Correct answer: B. Vendors extend your attack surface, so their security must be assessed and managed through due diligence and contracts.