Online Access Free CISM Practice Test
| Exam Code: | CISM |
| Exam Name: | Certified Information Security Manager |
| Certification Provider: | ISACA |
| Free Question Number: | 785 |
| Posted: | Feb 21, 2025 |
| # of views: | 9440 |
| # of Questions views: | 7850 |
| Go To CISM Exam Questions | |
Recent Comments (The most recent comments are at the top.)
No.# Correct answer: B. Ensure a nondisclosure agreement (NDA) is signed by both parties' senior management.
Why this is BEST:
Accountability for data leaks requires a legally enforceable mechanism. An NDA explicitly defines confidentiality obligations, liability, remedies, and consequences for unauthorized disclosure of PII. Having it signed by senior management strengthens enforceability and demonstrates organizational commitment.
Why the others are weaker:
A. Acceptable use policy sign-off ❌
An AUP is internal guidance, not a strong legal instrument for third-party liability.
C. Documentation requirements in the SOW ❌
Helpful for governance and oversight, but they don’t directly establish liability for data leaks.
D. RFP with detailed requirements ❌
An RFP is a pre-contract activity and does not create accountability once services begin.
📌 Exam rule of thumb:
When the question is about holding a third party accountable, the BEST answer is almost always a contractual/legal control (e.g., NDA, liability clauses, penalties).
✅ Answer: B...
No.# Correct answer: A. Promote awareness of the policy among employees.
Why:
Once senior management has endorsed the information security policy, it’s officially approved and authoritative. The next logical step is to ensure the policy is communicated and understood across the organization so it can actually be followed and enforced.
Why the others are not next:
B. Seek policy buy-in from business stakeholders – This should happen before or during policy development, not after executive endorsement.
C. Implement an authentication and authorization system – That’s a control implementation step, which comes after policy awareness and procedural alignment.
D. Identify relevant information security frameworks – Framework selection typically informs policy creation, not follows endorsement.
📌 Key exam principle:
Policy lifecycle order → Develop → Approve (endorse) → Communicate (awareness) → Implement controls → Monitor & enforce
So the best NEXT step is A.
No.# Correct Answer: C. Providing a basis for implementing a need-to-know policy ✅
Explanation
The greatest benefit of information asset classification is that it enables the organization to apply appropriate access controls based on sensitivity and criticality of information. Classification answers the question: “Who should be allowed to access this information, and under what conditions?”
By classifying information (e.g., public, internal, confidential, restricted), an organization can:
Enforce need-to-know and least privilege
Protect sensitive data appropriately
Reduce the risk of unauthorized disclosure
Align security controls with business value
This is the core purpose of information classification in information security governance.
Why the other options are less correct
A. Helping to determine the recovery point objective (RPO)
RPO is determined through business impact analysis (BIA), not classification.
B. Supporting segregation of duties
Segregation of duties relates to roles and processes, not information sensitivity.
D. Defining resource ownership
Ownership should already be defined as part of governance; classification may reference owners, but this is not its greatest benefit.
CISM exam takeaway
Information classification primarily exists to support access control decisions—especially need-to-know.
That governance-focused benefit makes C the best answer...
No.# Correct Answer: D. Evaluate the patches in a test environment
Explanation
When security patches are known to potentially cause stability issues, the best practice is to test them in a controlled, non-production environment before deployment.
Here’s why D is the best choice:
Evaluating patches in a test environment allows the organization to:
Identify stability or compatibility issues
Assess impact on business operations
Validate rollback procedures
Reduce the risk of production outages
Why the other options are not optimal:
A. Increase monitoring after patch implementation
Monitoring is reactive and does not prevent outages or disruptions caused by unstable patches.
B. Research compensating security controls
Compensating controls may be useful if patching must be delayed, but they do not address whether the patch itself is safe to deploy.
C. Research alternative software solutions
Replacing software is excessive and impractical for a patch-related concern.
Key Principle
Testing before deployment is the most effective way to balance security and system stability, making D the best recommendation....
No.# The correct answer is A. Integrating security requirements with processes.
Why A is the MOST effective
Embedding security requirements directly into business processes makes compliance automatic and repeatable, rather than optional.
When security is part of normal workflows (e.g., procurement, system development, vendor management), business units comply by design, not by exception.
This approach aligns with governance principles: security is owned by the business, not enforced only by the security team.
Why the other options are less effective
B. Conducting information security awareness training
Raises knowledge, but does not guarantee compliance. Awareness ≠ enforcement.
C. Conducting a business impact analysis (BIA)
Identifies critical processes and impacts, but does not ensure compliance with governance controls.
D. Performing security assessments and gap analyses
Identifies weaknesses after the fact; it is detective, not preventive.
Key exam takeaway
The MOST effective governance mechanisms are preventive and embedded, not reactive or advisory.
✔ Final Answer: A. Integrating security requirements with processes...