Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

CISM EXAM OBJECTIVES QUESTIONS AND ANSWERS WITH RATIONALES/GRADED A+/2026 UPDATE/100% CORRECT /INSTANT DOWNLOAD

Beoordeling
-
Verkocht
-
Pagina's
38
Cijfer
A+
Geüpload op
24-06-2026
Geschreven in
2025/2026

This document is a study and exam preparation resource for the Certified Information Security Manager (CISM) certification examination. It contains exam-style questions, answers, and explanatory rationales designed to help candidates review information security management concepts and prepare for professional certification assessments. The content typically covers the four primary CISM domains: information security governance, information risk management, information security program development and management, and information security incident management. Additional topics may include security strategy alignment with business objectives, risk assessment methodologies, security policies and frameworks, regulatory compliance, governance structures, business continuity planning, disaster recovery, incident response processes, and leadership responsibilities within cybersecurity programs. The material is organized in a question-and-answer format to reinforce security management knowledge, strengthen decision-making and governance skills, and support preparation for the CISM certification examination.

Meer zien Lees minder
Instelling
2026
Vak
2026

Voorbeeld van de inhoud

CISM EXAM OBJECTIVES QUESTIONS AND ANSWERS WITH
RATIONALES/GRADED A+/2026 UPDATE/100% CORRECT /INSTANT
DOWNLOAD


DOMAIN 1: INFORMATION SECURITY GOVERNANCE (Questions 1–
17)




Question 1
A security manager is presenting a business case for a new security initiative to the board of
directors. Which of the following is the MOST important element to include?

A) Detailed technical specifications of the solution
B) Alignment of the initiative with business objectives and risk reduction
C) Names of competitors who have implemented similar solutions
D) Cost breakdown of hardware and software components

Correct Answer: B

Rationale: The board focuses on business outcomes, risk reduction, and strategic alignment.
Technical details (A, D) are less relevant to board-level decision-making. Competitor information (C) is not
a primary justification. CISM emphasizes communicating security in business terms to executive
stakeholders.




Question 2
An organization has recently experienced several security incidents. Who has the ULTIMATE
responsibility for the organization's information security program?

A) CISO (Chief Information Security Officer)
B) Board of Directors / Senior Management
C) IT Director
D) External auditors

Correct Answer: B

,Rationale: According to governance principles, the board of directors and senior management hold
ultimate accountability for the organization's information security program. While the CISO (A) develops
and implements the program, they are not ultimately accountable. The IT Director (C) and external
auditors (D) have supporting or advisory roles.




Question 3
Which of the following BEST describes the primary purpose of information security governance?

A) To implement firewalls and intrusion detection systems
B) To ensure that security strategy aligns with business objectives and provides strategic direction
C) To respond to security incidents when they occur
D) To conduct annual penetration tests

Correct Answer: B

Rationale: Information security governance ensures that security strategy aligns with business
objectives, provides strategic direction, and establishes accountability. Implementation of technical
controls (A), incident response (C), and penetration testing (D) are operational activities that support
governance but are not its primary purpose.




Question 4
A security manager is developing security metrics to present to the board. Which type of metric
would be MOST valuable to the board?

A) Number of firewall rules configured
B) Percentage of systems patched within SLA
C) Reduction in risk exposure over the past quarter
D) Number of security alerts generated

Correct Answer: C

Rationale: The board is most interested in risk reduction and business impact. Metrics that
demonstrate how security is reducing risk exposure (C) provide the most strategic value. Technical
metrics like firewall rules (A), patch percentages (B), and alert counts (D) are operational and less
relevant to board-level governance.




Question 5

,Which of the following is the FIRST step in developing an information security strategy?

A) Selecting security controls
B) Understanding the organization's business objectives and risk appetite
C) Purchasing security technology
D) Hiring a CISO

Correct Answer: B

Rationale: The first step in developing an information security strategy is understanding the
organization's business objectives, risk appetite, and risk tolerance. Security controls (A), technology
purchases (C), and hiring (D) should follow after the strategy is defined.




Question 6
A security manager discovers that a new regulatory requirement will impact the organization's
operations. What should the security manager do FIRST?

A) Implement controls to achieve compliance immediately
B) Assess the impact of the requirement on business operations and existing controls
C) Ignore the requirement until the compliance deadline approaches
D) Hire external consultants to manage compliance

Correct Answer: B

Rationale: The first step when encountering a new regulatory requirement is to assess its impact on
business operations and existing controls. This assessment informs the compliance strategy. Immediate
implementation (A) without assessment may be inefficient; ignoring (C) or immediately outsourcing (D)
are not appropriate governance responses.




Question 7
Which of the following is an example of a "top-down" approach to information security
governance?

A) IT staff implementing security patches
B) Senior management defining security policies and direction
C) Security analysts monitoring intrusion detection alerts
D) Network administrators configuring firewall rules

Correct Answer: B

Rationale: A "top-down" approach means senior management defines the security vision, policies, and
strategic direction, which then cascades down through the organization. IT staff implementing patches
(A), monitoring alerts (C), and configuring firewalls (D) are "bottom-up" operational activities.

, Question 8
What is the PRIMARY purpose of a security policy?

A) To provide detailed technical instructions for security staff
B) To communicate management's intent and establish expectations for security behavior
C) To document all security incidents
D) To replace the need for security training

Correct Answer: B

Rationale: A security policy communicates management's intent, establishes expectations for security
behavior, and provides a framework for implementing controls. Policies are not technical instructions (A)
— those are procedures or standards. Policies do not replace training (D) or serve as incident logs (C).




Question 9
Which of the following frameworks is MOST commonly used for IT governance and is often
referenced in CISM exam questions?

A) COBIT
B) ISO 27001
C) NIST Cybersecurity Framework
D) ITIL

Correct Answer: A

Rationale: COBIT (Control Objectives for Information and Related Technologies) is the framework
most commonly associated with IT governance. While ISO 27001 (B) focuses on information security
management systems, NIST CSF (C) on cybersecurity risk management, and ITIL (D) on IT service
management, COBIT is specifically designed for governance and is heavily referenced in CISM materials.




Question 10
A security manager is developing a business case for a security investment. Which of the
following should be the PRIMARY justification?

A) The technology is industry-leading
B) The investment reduces risk to an acceptable level
C) The investment is within budget
D) The CISO approved the investment

Geschreven voor

Instelling
2026
Vak
2026

Documentinformatie

Geüpload op
24 juni 2026
Aantal pagina's
38
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$20.98
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
DoctorDee Teachme2-tutor
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
29
Lid sinds
2 jaar
Aantal volgers
7
Documenten
4829
Laatst verkocht
1 week geleden
Hi wayne1111

3.5

6 beoordelingen

5
3
4
0
3
1
2
1
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen