Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CISM Domain 1 Exam Questions & Answers (Grade A+).docx

Rating
-
Sold
-
Pages
60
Grade
A+
Uploaded on
22-05-2026
Written in
2025/2026

CISM Domain 1 Exam Questions & Answers (Grade A+).docx

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Content preview

CISM Domain 1 Exam Questions &
Answers (Grade A+)
Which of the following is the MOST effective way to ensure that
noncompliance to information security standards is resolved?
a. Periodic audits of noncompliant areas
b. An ongoing vulnerability scanning program
c. Annual security awareness training
d. Regular reports to the audit committee - D is the correct answer.
Justification
Periodic audits can be effective but only when combined with
reporting.
Vulnerability scanning has little to do with noncompliance with
standards.
Training can increase management's awareness regarding
information security, but awareness training is generally not as
compelling to management as having individual names highlighted
on a compliance report.
Reporting noncompliance to the audit committee is the most
effective way to have enforcement for concerned parties to take the
proper action in order to comply.


What activity should the information security manager perform
FIRST after finding that compliance with a set of standards is weak?
a. Initiate the exception process.

,CISM Domain 1 Exam Questions &
Answers (Grade A+)
b. Modify policy to address the risk.
c. Increase compliance enforcement.
d. Perform a risk assessment. - D is the correct answer.
Justification
The exception process can be used after assessing the
noncompliance risk and determining whether compensating
controls are required.
Modifying policy is not necessary unless there is no applicable
standard and policy.
It is not appropriate to increase compliance enforcement until the
information security manager has determined the extent of the risk
posed by weak compliance.
The first action after finding noncompliance with particular
standards should be to determine the risk to the enterprise and the
potential impact (for both compliance and security risk).


Management requests that an information security manager
determine which regulations regarding disclosure, reporting and
privacy are the most important for the enterprise to address. The
recommendations for addressing these legal and regulatory
requirements will be MOST useful if based on which of the
following choices?

,CISM Domain 1 Exam Questions &
Answers (Grade A+)
a. The extent of enforcement actions
b. The probability and consequences
c. The sanctions for noncompliance
d. The amount of personal liability - B is the correct answer.
Justification
The extent of enforcement is a measure of probability. Without
knowing the scope of consequences, probability cannot be viewed
in context.
Legal and regulatory requirements should be treated as any other
risk to the enterprise, calculated as the probability of enforcement
and the magnitude of possible sanctions (impact or consequences).
Sanctions or impact must be considered in the context of the
enforcement mechanisms. If sanctions have less probability of
being implemented due to lax enforcement, their severity poses
lower risk to the enterprise than if they are widely enforced.
Except in extreme cases of fraud or other criminal activity, liability
for regulatory sanctions generally lies with senior management and
the board of directors. It is not a driving factor in the evaluation of
regulatory requirements.

, CISM Domain 1 Exam Questions &
Answers (Grade A+)
How should an information security manager balance the
potentially conflicting requirements of an international enterprise's
security standards with local regulation?
a .Give organizational standards preference over local regulations.
b. Follow local regulations only.
c. Make the enterprise aware of those standards where local
regulations cause conflicts.
d .Negotiate a local version of the enterprise standards. - D is the
correct answer.
Justification
Organizational standards must be subordinate to local regulations.
It would be incorrect to follow local regulations only, because there
must be recognition of organizational requirements.
Making an enterprise aware of standards is a sensible step but is
not a complete solution.
Negotiating a local version of the enterprise's standards is the most
effective compromise in this situation. Regulations cannot be
changed by the enterprise, and it must achieve compliance, making
it necessary to develop a local version of its standards in
consultation with the principal office.

Written for

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Document information

Uploaded on
May 22, 2026
Number of pages
60
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$15.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Chloelunar University Of Nevada-Las Vegas
Follow You need to be logged in order to follow users or courses
Sold
96
Member since
2 year
Number of followers
6
Documents
14296
Last sold
3 days ago

Get study materials, exam answer packs, step-by-step assignment solutions, and much more. Learn more effectively and quickly. After acquiring any document, please always provide a review to ensure that our consumers are completely satisfied.Best Wishes!!!!!!

3.5

17 reviews

5
7
4
4
3
1
2
0
1
5

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions