pg. 1
CISM TEST 2025 TEST BANK 2 WITH 250 REAL
EXAM PREP QUESTIONS AND CORRECT
VERIFIED ANSWERS/ CERTIFIED
INFORMATION SECURITY MANAGER EXAM/
ISACA CISM EXAM 2025 (NEW!)
An information security risk analysis BEST assists an organization in ensuring
that:
- The infrastructure has the appropriate level of access control
- Cost-effective decisions are made with regard to which asset need protection
- An appropriate level of funding is applied to security processes
- The organization implements appropriate security technologies
- Controls to be monitored
- Reporting capabilities
- The contract with the SIEM vendor
- Available technical support
- Definitions of responsibilities
- Retention schedules
- System access specifications
- Organizational risk
B An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?
A Which of the following is MOST likely to be included in an enterprise security policy?
A An information security manager has been asked to determine whether an information security initiative has reduced risk to an acceptable level. Which of the following activities would provide the BEST information for the information 1 / 4
pg. 2 security manager to draw a conclusion?
- Initiating a cost-benefit analysis of the implemented controls
- Performing a risk assessment
- Reviewing the risk register
- Conducting a business impact analysis (BIA)
A An organization that uses external cloud services extensively is concerned with risk monitoring and timely response. The BEST way to address this concern is to
ensure:
- The availability of continuous technical support
- Appropriate service level agreements (SLAs) are in place.
- A right-to-audit clause is included in contracts
- Internal security standards are in place
- Obtain annual sign-off from executive management
- Align the policies to the most stringent global regulations
- Send the policies to stakeholders for review
- Outsource the compliance activities
C Which of the following is the BEST way to ensure that the organizational security policies comply with data security regulatory requirements
B The PRIMARY reason for defining the information security roles and
responsibilities of staff throughout an organization is to:
- comply with security policy.
- increase corporate accountability.
- enforce individual accountability.
- reinforce the need for training.
C
Threat and vulnerability assessments are important PRIMARILY because they are:
- used to establish security investments.
- needed to estimate risk.
- the basis for setting control objectives.
- elements of the organization ג€™s security posture. 2 / 4
pg. 3 B Which of the following should be an information security managers PRIMARY focus during the development of a critical system storing highly confidential data?
- Ensuring the amount of residual risk is acceptable
- Reducing the number of vulnerabilities detected
- Avoiding identified system threats
- Complying with regulatory requirements
- Develop metrics for vendor performance.
- Include information security criteria as part of vendor selection.
- Review third-party reports of potential vendors.
- Include information security clauses in the vendor contract.
- File integrity monitoring (FIM) software
- Security information and event management (SIEM) tool
- Intrusion detection system (IDS)
- Antivirus software
- Compliance requirements associated with the regulation
- Criticality of the service to the organization
- Corresponding breaches associated with each vendor
- Compensating controls in place to protect information security
D When evaluating vendors for sensitive data processing, which of the following should be the FIRST step to ensure the correct level of information security is provided?
B An information security team is investigating an alleged breach of an organization's network. Which of the following would be the BEST single source of evidence to review?
B Over the last year, an information security manager has performed risk assessments on multiple third-party vendors. Which of the following criteria would beMOST helpful in determining the associated level of risk applied to each vendor?
B 3 / 4
pg. 4 Which of the following is the MOST important security consideration when developing an incident response strategy with a cloud provider?
- Security audit reports
- Recovery time objective (RTO)
- Technological capabilities
- Escalation processes
- Executive leadership becomes involved in decisions about information security
- Executive leadership views information security governance primarily as a
- Information security staff has little or no experience with the practice of
- Information security management does not fully accept the responsibility for
D Executive leadership has decided to engage a consulting firm to develop and implement a comprehensive security framework for the organization to allow senior management to remain focused on business priorities. Which of the following poses the GREATEST challenge to the successful implementation of the new security governance framework?
governance.
concern of the information security management team
information security governance.
information security governance.B
Risk scenarios simplify the risk assessment process by:
- covering the full range of possible risk.
- ensuring business risk is mitigated.
- reducing the need for subsequent risk evaluation.
- focusing on important and relevant risk.
- They are regularly reassessed and reported to stakeholders
- They are approved by the IT governance function
- They are clear and can be understood by stakeholders
- They are identified using global security frameworks and standards
- / 4
D Which of the following is the MOST important consideration when developing information security objectives?
C