CISM Exam Questions & Answers
Certified Information Security Manager • Isaca
100% money-back guarantee
Sample CISM Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Which of the following service offerings in a typical Infrastructure as a Service (laaS) model will BEST enable a cloud service provider to assist customers when recovering from a security incident?
A snapshot is a point-in-time copy of the state of a virtual machine (VM) that can be used to restore the VM to a previous state in case of a security incident or a disaster. A snapshot can capture the VM's disk, memory, and device configuration, allowing for a quick and easy recovery of the VM's data and functionality. Snapshots can also be used to create backups, clones, or replicas of VMs for testing, analysis, or migration purposes. Snapshots are a common service offering in Infrastructure as a Service (IaaS) models, where customers can provision and manage VMs on demand from a cloud service provider (CSP).A CSP that offers the capability to take snapshots of VMs can assist customers when recovering from a security incident by providing them with the following benefits12:
Faster recovery time: Snapshots can reduce the downtime and data loss caused by a security incident by allowing customers to quickly revert their VMs to a known good state. Snapshots can also help customers avoid the need to reinstall or reconfigure their VMs after an incident, saving time and resources.
Easier incident analysis: Snapshots can enable customers to perform online or offline analysis of their VMs after an incident, without affecting the production environment. Customers can use snapshots to examine the VM's disk, memory, and logs for evidence of compromise, root cause analysis, or forensic investigation. Customers can also use snapshots to test and validate their incident response plans or remediation actions before applying them to the production VMs.
Enhanced security posture: Snapshots can improve the security posture of customers by enabling them to implement best practices such as backup and restore, disaster recovery, and business continuity. Snapshots can help customers protect their VMs from accidental or malicious deletion, corruption, or modification, as well as from environmental or technical disruptions. Snapshots can also help customers comply with regulatory or contractual requirements for data retention, availability, or integrity.References=What is Disaster Recovery as a Service? | CSA - Cloud Security Alliance,What Is Cloud Incident Response (IR)? CrowdStrike
An organization is in the process of acquiring a new company. Which of the following is the FIRST step to determine how to protect newly acquired data assets prior to integration?
The correct answer is A because the organization must first identify and inventory the newly acquired information assets before determining how to protect them. Without knowing what data assets exist, where they are located, who owns them, how they are used, and what sensitivity or criticality they have, the organization cannot select appropriate controls. Including security requirements in the contract is important during acquisition planning, but the question asks how to protect newly acquired data assets prior to integration. Assessing controls is necessary, but it should be based on a clear understanding of the assets being protected. Reviewing data architecture is useful, but it is also dependent on first identifying the assets and their locations. CISM risk management emphasizes asset identification, ownership, classification, and risk assessment as foundational steps in protecting information. An asset inventory enables classification, impact analysis, access review, control selection, and integration planning. Therefore, inventorying information assets is the correct first step.
An employee who is a remote user has copied financial data from the corporate server to a laptop using virtual private network (VPN) connectivity. Which of the following is the MOST important factor to determine if it should be classified as a data leakage incident?
Due to changes in an organization's environment, security controls may no longer be adequate. What is the information security manager's BEST course of action?
According to the CISM Review Manual, the information security manager's best course of action when security controls may no longer be adequate due to changes in the organization's environment is to perform a new risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the risks that affect the organization's information assets and business processes. A risk assessment should be performed periodically or whenever there are significant changes in the organization's environment, such as new threats, vulnerabilities, technologies, regulations, or business objectives. A risk assessment helps to determine the current level of risk exposure and the adequacy of existing security controls. A risk assessment also provides the basis for developing or updating the risk treatment plan, which defines the appropriate risk responses, such as implementing new or enhanced security controls, transferring the risk to a third party, accepting the risk, or avoiding the risk.
The other options are not the best course of action in this scenario. Reviewing the previous risk assessment and countermeasures may not reflect the current state of the organization's environment and may not identify new or emerging risks. Evaluating countermeasures to mitigate new risks may be premature without performing a new risk assessment to identify and prioritize the risks. Transferring the new risk to a third party may not be feasible or cost-effective without performing a new risk assessment to evaluate the risk level and the available risk transfer options.
References= CISM Review Manual, 16th Edition, Chapter 2, Section 1, pages 43-45.
Which of the following BEST encourages staff to report issues related to information security?
The correct answer is C because staff are more likely to report information security issues when leadership establishes a positive security culture. A positive culture encourages openness, trust, accountability, and timely reporting without fear of unfair blame. In CISM governance, information security is not only a technical function; it depends heavily on behavior, communication, leadership support, and organizational values. Tabletop exercises are useful for testing incident response readiness, but they do not necessarily encourage everyday reporting by all staff. Incentives for security skills training may improve participation in learning activities, but they do not directly create a reporting culture. Formal incident response processes are important because they define how incidents are handled, but processes alone may not motivate employees to report concerns if the culture is negative or punitive. Leadership behavior is critical because employees follow the tone set by management. Therefore, leaders setting a positive security culture is the best way to encourage staff to report information security issues.
Get access to all 1191 verified questions with detailed answers.
Unlock All CISM Questions