View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 341
What should determine security program priorities?
- Office size
- Business risk
- Vendor preference
- Employee requests
Correct Answer: 2
Explanation
Business risk should determine security program priorities because security resources should be directed toward risks that could significantly affect organizational objectives. Prioritization should consider business impact, likelihood, regulatory requirements, critical information assets, and organizational risk tolerance. Security teams should avoid selecting initiatives simply because they are technologically attractive or requested by a particular department. A risk-based approach allows management to make informed decisions about competing security investments. CISM emphasizes alignment between security programs and business objectives, ensuring that security activities address meaningful organizational exposures while supporting important operational and strategic requirements.
Question 342
Which activity helps identify gaps between current and required security capabilities?
- Gap analysis
- Sales review
- Office survey
- Product testing
Correct Answer: 1
Explanation
A gap analysis compares the organization’s current security capabilities with the capabilities required to meet business objectives, regulatory obligations, and risk management expectations. It can identify weaknesses in personnel, processes, technology, governance, controls, or security services. The results help management determine which gaps require immediate attention and which can be addressed through longer-term planning. CISM emphasizes capability assessment as part of effective security program management. A well-conducted gap analysis should be based on defined requirements and organizational priorities rather than assumptions. It can also support budgeting, resource planning, and development of a security improvement roadmap.
Question 343
What is the main purpose of a security program roadmap?
- Track office moves
- Schedule vacations
- Prioritize improvements
- Manage sales
Correct Answer: 3
Explanation
A security program roadmap provides a structured view of planned security initiatives, priorities, dependencies, resources, and expected outcomes over time. It helps management understand how the security program will progress from its current state toward desired capabilities. Initiatives should be prioritized according to business risk, regulatory requirements, organizational objectives, and available resources. A roadmap also helps coordinate activities that depend on one another and prevents disconnected security investments. CISM emphasizes strategic planning and alignment, making the roadmap a useful management tool for communicating priorities and ensuring that security improvements are implemented in a logical and sustainable manner.
Question 344
When resources are limited, which initiative should receive greater consideration?
- Low-impact project
- High-risk exposure
- Optional upgrade
- Cosmetic change
Correct Answer: 2
Explanation
A high-risk exposure should generally receive greater consideration when resources are limited because it may create significant consequences for critical business objectives. Prioritization should consider the likelihood and impact of the risk, regulatory requirements, business criticality, existing controls, and available treatment options. This does not mean every high-risk issue must immediately receive the same treatment; management should compare competing risks and expected benefits. CISM emphasizes risk-based resource allocation, allowing organizations to direct limited security resources toward areas where they can provide meaningful risk reduction and support organizational objectives.
Question 345
What should a security budget primarily reflect?
- Business priorities
- Employee preferences
- Office location
- Vendor popularity
Correct Answer: 1
Explanation
A security budget should reflect business priorities, organizational risks, regulatory obligations, and the resources required to achieve security objectives. Budget decisions should be connected to the organization’s security strategy and should explain how proposed investments support important business outcomes. A budget based primarily on historical spending or technology popularity may fail to address current risks. CISM emphasizes demonstrating business value when requesting security resources. Security leaders should therefore communicate expected benefits, risks addressed, resource requirements, and consequences of insufficient funding. This allows management to compare security investments with other organizational priorities and make informed resource decisions.
Question 346
What should be reviewed before approving a major security initiative?
- Office furniture
- Business case
- Employee birthdays
- Product packaging
Correct Answer: 2
Explanation
A business case should be reviewed before approving a major security initiative because management needs to understand the justification, expected benefits, costs, risks, dependencies, and resource requirements. The business case should explain how the initiative supports organizational objectives and what risks or regulatory requirements it addresses. It should also consider alternatives and the consequences of not proceeding. CISM emphasizes that security investments should be justified in business terms rather than solely through technical arguments. A clear business case enables management to compare initiatives consistently and determine whether the expected value and risk reduction justify the required investment.
Question 347
Which approach helps maintain accountability for security responsibilities?
- Shared ambiguity
- Informal assignments
- Undefined ownership
- Clear responsibility
Correct Answer: 4
Explanation
Clear responsibility helps maintain accountability because individuals and functions need to understand who is responsible for specific security decisions and activities. Responsibilities should be documented and aligned with organizational authority, job functions, and business requirements. Ambiguous ownership can lead to missed tasks, delayed decisions, duplicated effort, or unmanaged risks. CISM emphasizes governance structures that establish clear accountability across security and business functions. Responsibility should also include appropriate authority and resources so assigned individuals can fulfill their roles effectively. Periodic reviews are useful because organizational changes may require responsibilities to be reassigned or updated.
Question 348
Why is segregation of duties important in security management?
- Reduce accountability
- Prevent conflicts
- Increase privileges
- Remove oversight
Correct Answer: 2
Explanation
Segregation of duties reduces the risk that one individual can perform conflicting activities without adequate oversight. For example, the person requesting a privileged access change should not necessarily be the same person who independently approves and implements it. Separating responsibilities creates checks and balances that can reduce fraud, misuse, unauthorized changes, and errors. The exact separation should reflect the organization’s risk and operational structure. CISM emphasizes governance and accountability, meaning security responsibilities should be designed so that critical actions receive appropriate review. Where complete separation is impractical, compensating controls may provide additional oversight.
Question 349
What should happen when an employee changes roles?
- Review access
- Keep all access
- Add privileges
- Disable monitoring
Correct Answer: 1
Explanation
When an employee changes roles, their access should be reviewed to ensure permissions remain appropriate for the new responsibilities. Access that was necessary for the previous role may no longer be required and could create unnecessary risk if retained. The review should consider least privilege, segregation of duties, sensitive information, and privileged access. Appropriate permissions should be removed or modified according to organizational procedures. CISM emphasizes lifecycle management of access because security risks can arise when permissions do not reflect current responsibilities. Role changes should therefore trigger timely access reviews rather than relying on users to request changes themselves.
Question 350
Which principle limits access to only what a user needs?
- Defense in depth
- Risk transfer
- Least privilege
- Separation of networks
Correct Answer: 3
Explanation
Least privilege limits users, applications, and processes to the minimum access necessary to perform authorized responsibilities. This reduces the potential impact of compromised accounts, insider misuse, accidental changes, and unauthorized access. Privileges should be based on job requirements and reviewed periodically because responsibilities change over time. Highly privileged access should receive additional controls such as stronger authentication, monitoring, approval, and logging. CISM emphasizes risk-based access management, meaning permissions should support legitimate business needs without creating unnecessary exposure. Least privilege is therefore an important principle for protecting sensitive information and limiting the potential consequences of security incidents.
Question 351
What should be required for sensitive privileged access?
- Informal approval
- Business justification
- Permanent access
- Shared credentials
Correct Answer: 2
Explanation
Sensitive privileged access should have a documented business justification and appropriate authorization because privileged accounts can make significant changes to systems, data, and security controls. Access should be limited to legitimate responsibilities and granted according to established policies. Organizations should also consider stronger authentication, monitoring, logging, periodic review, and time-limited access where appropriate. Shared credentials reduce accountability and should generally be avoided when individual identities can be used. CISM emphasizes controlling high-risk access through governance and accountability. Proper authorization ensures that privileged permissions are necessary, traceable, and consistent with organizational risk requirements.
Question 352
What should security leaders consider when adopting a new technology?
- Business risk
- Product color
- Office furniture
- Employee hobbies
Correct Answer: 1
Explanation
Business risk should be considered when adopting new technology because new technologies can introduce changes to architecture, data flows, access requirements, third-party dependencies, compliance obligations, and threat exposure. Security leaders should evaluate how the technology supports business objectives and what risks may result from its implementation. The assessment should consider security requirements, control effectiveness, integration issues, data protection, operational impact, and regulatory considerations. CISM emphasizes that security should enable business objectives while managing risk. Technology adoption should therefore involve appropriate security and risk assessment rather than being based solely on features, cost, or market popularity.
Question 353
Which factor should influence security architecture decisions?
- Office decoration
- Vendor advertising
- Business requirements
- Employee preference
Correct Answer: 3
Explanation
Business requirements should influence security architecture decisions because architecture must support organizational processes while providing appropriate protection for information and technology assets. Security architecture decisions should consider business objectives, risk tolerance, regulatory obligations, information flows, system dependencies, and required security controls. A technically sophisticated architecture may not provide appropriate value if it prevents essential business activities or fails to address significant risks. CISM emphasizes alignment between security strategy and enterprise requirements. Security architecture should therefore translate strategic objectives and risk decisions into practical design principles and controls that can be implemented and maintained throughout the technology lifecycle.
Question 354
What is the main benefit of defense in depth?
- Multiple protections
- Fewer controls
- Single protection
- Reduced monitoring
Correct Answer: 1
Explanation
Defense in depth uses multiple layers of security controls so that failure or bypass of one control does not automatically result in complete compromise. Layers may include preventive, detective, corrective, administrative, physical, and technical controls. The approach can reduce the likelihood and impact of successful attacks by creating multiple opportunities to detect or stop malicious activity. Controls should still be selected according to risk and business requirements rather than added without justification. CISM emphasizes layered protection as part of effective security architecture, particularly for critical assets and processes where reliance on a single control would create unacceptable exposure.
Question 355
What should happen when controls overlap unnecessarily?
- Ignore the overlap
- Add more controls
- Assess rationalization
- Remove all controls
Correct Answer: 3
Explanation
Unnecessary control overlap should be assessed through control rationalization to determine whether duplicated controls provide meaningful additional protection or create avoidable complexity and cost. Some overlap may be intentional as part of defense in depth, while other duplication may result from disconnected initiatives or legacy requirements. Organizations should evaluate control effectiveness, risk reduction, operational burden, and compliance requirements before deciding whether controls should be combined, retained, modified, or removed. CISM emphasizes efficient use of security resources, so rationalization can help simplify security architecture while preserving appropriate protection and meeting organizational and regulatory requirements.
Question 356
What should happen after a major business acquisition?
- Ignore existing strategy
- Reassess security strategy
- Remove all policies
- Stop monitoring
Correct Answer: 2
Explanation
A major business acquisition should trigger reassessment of the security strategy because the organization may inherit new systems, information assets, users, suppliers, technologies, regulations, and security risks. Existing security policies, architecture, controls, and resources may not adequately address the combined environment. Management should evaluate differences in risk tolerance, governance, regulatory requirements, security capabilities, and business priorities. CISM emphasizes strategic alignment and continuous reassessment when significant organizational changes occur. The objective is not simply to integrate technologies but to establish a security approach that supports the expanded organization while maintaining appropriate governance, risk management, and protection.
Question 357
What should guide security program maturity improvement?
- Risk and objectives
- Office size
- Staff preference
- Vendor popularity
Correct Answer: 1
Explanation
Risk and organizational objectives should guide security program maturity improvement because maturity should reflect what the organization needs to achieve and the level of risk it must manage. Not every organization requires the same security capabilities or maturity level. Management should identify current capabilities, desired outcomes, significant gaps, and the resources needed to close those gaps. Improvements should be prioritized according to business impact, risk tolerance, regulatory obligations, and strategic requirements. CISM emphasizes a business-aligned approach to security management, ensuring that maturity investments provide practical value instead of pursuing maturity for its own sake.
Question 358
What is an important characteristic of an effective security policy?
- Technical complexity
- Frequent exceptions
- Clear requirements
- Informal wording
Correct Answer: 3
Explanation
Clear requirements are an important characteristic of an effective security policy because employees and management need to understand expected security behaviors, responsibilities, and boundaries. A policy should provide authoritative direction without becoming so technically detailed that it becomes difficult to maintain. Supporting standards, procedures, and guidelines can provide implementation details. Policies should be approved by appropriate management authority and reviewed periodically to ensure continued alignment with business objectives, laws, regulations, and risks. CISM emphasizes management direction and accountability, so security policies should be understandable, enforceable, and supported by appropriate governance mechanisms.
Question 359
What should determine how often a security policy is reviewed?
- Risk and change
- Office schedule
- Staff birthdays
- Vendor preference
Correct Answer: 1
Explanation
Risk and organizational change should influence the frequency of security policy reviews. Significant changes in business processes, technology, regulations, threats, organizational structure, or risk tolerance may make existing policy requirements outdated. Policies should also be reviewed according to established governance requirements even when no major change occurs. The review should determine whether responsibilities, requirements, exceptions, and enforcement mechanisms remain appropriate. CISM emphasizes continuous alignment between security governance and organizational needs. Regular policy review helps ensure that management direction remains relevant and that employees are operating under requirements that accurately reflect current risks and business conditions.
Question 360
What should a security program do when business objectives change significantly?
- Continue unchanged
- Reduce oversight
- Reassess alignment
- Remove controls
Correct Answer: 3
Explanation
When business objectives change significantly, the security program should reassess its alignment with the organization’s new direction. Changes such as entering new markets, launching digital services, acquiring businesses, or modifying operating models can create new information security requirements and risks. Security leaders should evaluate whether existing strategy, policies, architecture, resources, controls, and metrics remain appropriate. CISM emphasizes that security should support business objectives rather than operate independently from them. Reassessment allows management to identify new priorities, address emerging exposures, and redirect resources where necessary while maintaining an appropriate balance between business enablement, security, compliance, and risk management.