Isaca CISM Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Isaca CISM Exam Dumps and Practice Test Dumps.

 

Question 181

What is the PRIMARY purpose of an information security program roadmap?

  1. To document employee attendance
  2. To define the sequence and timing of major security initiatives
  3. To replace the organization’s security policy
  4. To list every technical vulnerability

Correct Answer: 2

Explanation

An information security program roadmap provides a structured view of planned security initiatives, priorities, dependencies, and expected timing. It helps management understand how the program will progress toward strategic objectives and how resources should be allocated over time. A roadmap does not replace security policies or function as a vulnerability inventory. It should reflect business priorities, risk exposure, regulatory requirements, available resources, and organizational capabilities. By establishing a coordinated sequence of initiatives, the roadmap helps prevent fragmented investments and allows management to track progress toward the desired security program state.

Question 182

Which factor should MOST influence the prioritization of security initiatives?

  1. Business risk and strategic objectives
  2. The newest available technology
  3. The number of vendors promoting a solution
  4. The personal preference of the security administrator

Correct Answer: 1

Explanation

Security initiatives should be prioritized according to their contribution to business objectives, reduction of significant risks, regulatory requirements, and organizational priorities. New technology may provide useful capabilities, but novelty alone does not establish business value. Vendor marketing and individual preferences should not determine enterprise priorities. A risk-based prioritization approach considers potential impact, likelihood, urgency, dependencies, available resources, and expected benefits. This helps management direct funding and personnel toward initiatives that address important exposures or enable strategic objectives. It also provides a defensible basis for explaining why some security projects should be completed before others.

Question 183

A security program has more initiatives than available resources. What should the CISM do?

  1. Start every initiative with minimal resources
  2. Prioritize initiatives according to risk, business value, and strategic requirements
  3. Select projects randomly
  4. Delay all initiatives until additional funding appears

Correct Answer: 2

Explanation

When resources are limited, the CISM should use a structured prioritization process based on business risk, strategic objectives, regulatory obligations, dependencies, urgency, and expected security benefits. Starting every project with insufficient resources can result in delays, weak implementation, and ineffective controls. Random selection provides no defensible basis for investment decisions. Waiting for unlimited funding may also leave important risks untreated. Prioritization allows management to identify which initiatives are most important, determine what can be deferred, and communicate resource constraints clearly. This approach supports realistic planning and keeps the security program aligned with organizational needs.

Question 184

Which activity BEST supports effective security program governance?

  1. Periodic review of program performance against approved objectives
  2. Allowing each security team to define unrelated objectives
  3. Avoiding management reporting
  4. Changing objectives whenever a minor incident occurs

Correct Answer: 1

Explanation

Periodic review of program performance against approved objectives helps management determine whether the security program is delivering its intended outcomes. Reviews can examine risk trends, control effectiveness, resource use, strategic progress, incidents, compliance, and performance measures. Allowing teams to establish unrelated objectives can create fragmentation, while avoiding management reporting reduces oversight. Security objectives should not be changed simply because of every minor incident; meaningful changes should be based on evidence, risk analysis, business priorities, and changes in the operating environment. Governance reviews provide an opportunity to identify gaps and make informed adjustments to the program.

Question 185

What should a security program charter primarily establish?

  1. The authority, scope, responsibilities, and objectives of the program
  2. The password of every employee
  3. The configuration of every firewall
  4. The source code of security applications

Correct Answer: 1

Explanation

A security program charter formally establishes the program’s purpose, scope, authority, responsibilities, objectives, and relationship with other organizational functions. It provides a governance foundation for determining what the program is expected to accomplish and who is accountable for major activities. Detailed passwords, firewall configurations, and application source code belong in operational or technical documentation and should not be part of a program charter. A clear charter can also help establish management sponsorship and clarify decision-making authority. This reduces ambiguity and provides a reference point for evaluating whether program activities remain aligned with organizational expectations.

Question 186

Which approach is MOST appropriate when defining security program objectives?

  1. Make them measurable and aligned with business and risk requirements
  2. Keep them intentionally vague
  3. Base them only on security technology capabilities
  4. Change them every month without management approval

Correct Answer: 1

Explanation

Security program objectives should be clearly defined, measurable where practical, and aligned with organizational business objectives, risk requirements, compliance obligations, and security strategy. Measurable objectives allow management to determine whether desired outcomes are being achieved and whether resources are being used effectively. Vague objectives make performance difficult to evaluate and can create inconsistent expectations. Technology capabilities may support objectives but should not define them independently of business requirements. Objectives should also remain stable enough to provide direction while being reviewed and adjusted through appropriate governance when significant changes occur.

Question 187

A security program objective cannot be measured with the current data. What should the CISM do?

  1. Define an appropriate measurement method and data source
  2. Remove the objective immediately
  3. Report that the objective has been achieved
  4. Use an unrelated metric because data is available

Correct Answer: 1

Explanation

If an objective is important but cannot currently be measured, the CISM should identify an appropriate measurement method and determine what data is required to support it. This may involve improving data collection, defining new metrics, establishing baselines, or modifying processes so that meaningful evidence becomes available. Removing the objective simply because measurement is difficult may weaken the program. Reporting achievement without evidence is misleading, while using an unrelated metric can create a false impression of performance. Effective measurement should provide reliable information about progress and outcomes and should remain aligned with the original security objective.

Question 188

Which practice BEST helps maintain security knowledge when key personnel leave the organization?

  1. Knowledge transfer and documented procedures
  2. Restricting all information to one administrator
  3. Avoiding documentation to save time
  4. Removing backup personnel

Correct Answer: 1

Explanation

Knowledge transfer and appropriate documentation reduce dependence on individual employees and help maintain operational continuity when personnel leave or change roles. Important knowledge can include procedures, system dependencies, security processes, contacts, escalation paths, configurations, and decision criteria. Concentrating knowledge in one administrator creates a single point of failure and can make recovery difficult. Documentation should be supplemented by cross-training and practical knowledge transfer because documents alone may not capture all operational expertise. Succession planning and backup responsibilities further strengthen resilience by ensuring that critical security activities can continue when key personnel are unavailable.

Question 189

An organization depends heavily on one security specialist for a critical process. What should the CISM address?

  1. Key-person dependency and continuity risk
  2. The specialist’s preferred software brand
  3. The office location of the specialist
  4. The number of meetings attended by the specialist

Correct Answer: 1

Explanation

Heavy dependence on one individual creates key-person risk because the organization may be unable to perform critical activities if that person becomes unavailable. The CISM should assess the dependency and establish appropriate continuity measures such as cross-training, documented procedures, backup responsibilities, succession planning, and knowledge transfer. The goal is not to eliminate the specialist’s role but to ensure that critical security capabilities remain available. Key-person dependencies should be considered as part of operational resilience and resource planning. Addressing them also reduces the risk that security processes will be delayed or disrupted during unexpected personnel changes.

Question 190

What is the PRIMARY purpose of segregation of duties?

  1. To prevent one individual from controlling incompatible activities
  2. To increase the number of administrative accounts
  3. To eliminate all security monitoring
  4. To give managers unrestricted access

Correct Answer: 1

Explanation

Segregation of duties reduces the risk of fraud, misuse, and unauthorized activity by ensuring that incompatible responsibilities are divided among different individuals or functions. For example, the person who approves a sensitive transaction should not necessarily be the same person who executes and independently verifies it. Segregation does not eliminate the need for monitoring and should not be confused with simply increasing the number of accounts. Organizations should identify conflicting duties based on business processes and risk. Where staffing limitations prevent complete separation, compensating controls such as independent review or enhanced monitoring may be appropriate.

Question 191

Which situation represents a segregation-of-duties concern?

  1. The same employee requests, approves, and implements a high-risk access change
  2. An employee submits a support ticket
  3. A manager reviews a security report
  4. A user changes a permitted application setting

Correct Answer: 1

Explanation

Allowing one individual to request, approve, and implement a high-risk access change concentrates incompatible responsibilities and can enable unauthorized activity without independent oversight. Separating these functions provides checks and balances and makes inappropriate changes more difficult to conceal. The appropriate separation depends on the organization’s processes and risk level. Where complete separation is impractical, compensating controls such as independent approval, detailed logging, or periodic review may reduce the risk. Segregation of duties should be incorporated into role design and access governance rather than addressed only after an incident or audit finding occurs.

Question 192

What is the PRIMARY purpose of security awareness training?

  1. To help personnel understand and apply required secure behaviors
  2. To replace technical security controls
  3. To make employees responsible for all security decisions
  4. To eliminate the need for security policies

Correct Answer: 1

Explanation

Security awareness training helps personnel understand security expectations and apply appropriate behaviors in their daily activities. It can address topics such as phishing, data handling, authentication, reporting procedures, acceptable use, social engineering, and organizational policies. Training does not replace technical controls or transfer all security responsibility to employees. It should complement governance, processes, technology, and management practices. Effective awareness programs should be tailored to different audiences and evaluated using appropriate outcome measures. The objective is not merely to confirm attendance but to improve understanding, decision-making, reporting, and adherence to required security practices.

Question 193

Which approach is MOST appropriate for training employees with different security responsibilities?

  1. Use identical content for every role
  2. Tailor training to job responsibilities and associated risks
  3. Train only technical employees
  4. Provide training only after incidents occur

Correct Answer: 2

Explanation

Security training should be tailored to the responsibilities and risks associated with different roles. Executives may need training focused on governance and decision-making, privileged administrators may require stronger technical and access-management guidance, and employees handling sensitive information may need detailed data protection requirements. Identical content for every audience can reduce relevance and effectiveness. Training only technical staff ignores significant human and business risks. Waiting for incidents is also reactive. Role-based awareness improves the likelihood that employees will recognize relevant threats, follow appropriate procedures, and understand how their specific responsibilities contribute to organizational security.

Question 194

A phishing simulation shows that many employees still enter credentials into fraudulent pages. What should the CISM evaluate?

  1. The awareness program’s effectiveness and underlying behavioral causes
  2. Whether phishing should be ignored
  3. Whether all email should be permanently disabled
  4. Whether employees should be punished automatically

Correct Answer: 4

Explanation

A high failure rate in a phishing simulation indicates that the organization should evaluate the effectiveness of its awareness program and understand why employees are still engaging in risky behavior. The CISM may review training content, message relevance, role-specific risks, reporting processes, technical protections, management support, and repeated behavioral patterns. The objective should be measurable improvement rather than simply increasing training volume. Technical controls such as email filtering can complement awareness efforts. Corrective actions should be proportionate and supported by organizational policies. Simulation results can provide valuable evidence for improving both human and technical defenses.

Question 195

Which control MOST directly reduces the risk of unauthorized administrative access?

  1. Privileged access management
  2. Public website advertising
  3. Data archiving
  4. Employee satisfaction surveys

Correct Answer: 1

Explanation

Privileged access management helps control, monitor, and govern accounts with elevated permissions. Depending on the implementation, it may support approval workflows, credential protection, session monitoring, time-limited access, password rotation, and detailed logging. These capabilities reduce the risk associated with powerful administrative accounts. Data archiving and employee surveys do not directly control privileged access, while advertising has no meaningful access-management function. Privileged access should also follow least privilege and segregation-of-duties principles. Periodic reviews should verify that elevated permissions remain necessary and that administrative activity can be appropriately attributed and investigated.

Question 196

A privileged user requests permanent administrator access for convenience. What should the CISM recommend?

  1. Grant permanent access because the user is experienced
  2. Evaluate the business need and apply least privilege with appropriate approval
  3. Grant access without logging
  4. Give the same privilege to all employees

Correct Answer: 2

Explanation

Permanent privileged access should not be granted simply for convenience. The CISM should ensure that the business need is understood and that access is limited according to least privilege and established authorization requirements. Where practical, temporary or just-in-time privileged access may reduce exposure while still allowing administrators to perform necessary tasks. Appropriate monitoring and logging should also be applied. Experience or seniority does not automatically justify unrestricted privileges. The objective is to balance operational requirements with security risk by ensuring that elevated access is necessary, authorized, appropriately controlled, and periodically reviewed.

Question 197

Which activity BEST supports secure disposal of sensitive information?

  1. Following approved disposal procedures appropriate to the information and storage medium
  2. Allowing employees to discard information informally
  3. Keeping all information forever
  4. Moving sensitive data to an unknown personal device

Correct Answer: 3

Explanation

Sensitive information should be disposed of according to approved procedures that consider its classification, legal and regulatory requirements, retention obligations, and the characteristics of the storage medium. Appropriate methods may include secure deletion, cryptographic erasure, physical destruction, or other approved techniques depending on the circumstances. Informal disposal can expose information to unauthorized parties, while retaining everything indefinitely can increase security, privacy, and compliance risks. Moving information to an unknown personal device does not constitute secure disposal. Effective information lifecycle management ensures that data is retained when required and securely disposed of when the retention period ends.

Question 198

A security program has strong technical controls but employees frequently bypass them to complete work faster. What should the CISM examine?

  1. The relationship between security controls, business processes, usability, and organizational culture
  2. Only the employees’ technical skills
  3. Whether additional controls should always be added
  4. Whether all business processes should be stopped

Correct Answer: 1

Explanation

Repeated control bypasses may indicate that security requirements are poorly integrated with business processes or that controls create unnecessary operational friction. The CISM should examine usability, process design, incentives, management expectations, awareness, control effectiveness, and whether the security requirement is appropriately designed for the business context. Adding more controls without understanding the cause may increase complexity and encourage further circumvention. Stopping business processes is generally disproportionate. Effective security should support business objectives while managing risk. Understanding why employees bypass controls can reveal opportunities for automation, process improvement, better training, or control redesign.

Question 199

Which factor is MOST important when selecting security awareness content?

  1. The risks and behaviors relevant to the target audience
  2. The number of slides available
  3. The vendor’s preferred presentation format
  4. The length of the employee handbook

Correct Answer: 1

Explanation

Awareness content should focus on risks and behaviors that are relevant to the audience receiving the training. Employees are more likely to apply guidance when they understand how security requirements relate to their actual responsibilities and common threats. For example, administrators may need specialized guidance about privileged access, while general employees may require stronger emphasis on phishing, data handling, and reporting suspicious activity. Slide count and presentation format may affect delivery but do not determine content relevance. Awareness programs should also use performance and behavioral results to refine content and address areas where employees continue to demonstrate weaknesses.

Question 200

A security program review shows that several objectives are being met, but risk exposure remains above management’s tolerance. What should the CISM do?

  1. Report the remaining exposure and reassess whether additional treatment is required
  2. Declare the program completely successful
  3. Remove the affected risks from the risk register
  4. Stop measuring security objectives

Correct Answer: 1

Explanation

Meeting defined security objectives does not automatically mean that all organizational risks are within acceptable limits. If significant residual exposure remains above management’s tolerance, the CISM should communicate the situation clearly and reassess whether additional treatment, resources, control changes, risk transfer, avoidance, or formally authorized acceptance is appropriate. Removing the risks from the register would obscure the actual exposure, while stopping measurement would weaken governance. Management should understand both program performance and remaining risk because these are related but distinct concepts. Effective security governance ensures that achievement of program activities does not substitute for appropriate management of residual business risk.