(Grade A+)
The foundation of an information security program is: -
correct answer ✅Alignment with the goals and objectives of the
organization
The core principles of an information security program are: -
correct answer ✅Confidentiality, Integrity and Availability
The key factor in a successful information security program is: -
correct answer ✅Senior Management support
A threat can be described as: -
correct answer ✅Any event or action that could cause harm to the
organization
True/False: Threats can be either intentional or accidental -
correct answer ✅True
Personnel Security requires trained personnel to manage systems
and networks. When does personnel security begin? -
correct answer ✅Through pre-employment checks
,CISM Exam Questions & Answers
(Grade A+)
Who plays the most important role in information security? -
correct answer ✅Upper management
The advantage of an IPS (intrusion prevention system) over an IDS
(intrusion detection system) is that: -
correct answer ✅The IPS can block suspicious activity in real time
True/False: Physical security is an important part of an Information
Security program -
correct answer ✅True
The Sherwood Applied Business Security Architecture (SABSA) is
primarily concerned with: -
correct answer ✅An enterprise=wide approach to security
architecture
A centralized approach to security has the primary advantage of: -
correct answer ✅Uniform enforcement of security policies
The greatest advantage to a decentralized approach to security is: -
correct answer ✅More adjustable to local laws and requirements
, CISM Exam Questions & Answers
(Grade A+)
A primary objective of an information security strategy is to: -
correct answer ✅Identify and protect information assets
The first step in an information security strategy is to: -
correct answer ✅Determine the desired state of security
Effective information security governance is based on: -
correct answer ✅implementing security policies and procedures
The use of a standard such as ISO27001 is useful to: -
correct answer ✅Ensure that all relevant security needs have been
addressed
Three main factors in a business case are resource usage, regulatory
compliance and: -
correct answer ✅Return on investment
What is a primary method for justifying investments in information
security? -
correct answer ✅development of a business case