View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 321
What should guide information security strategy priorities?
- Business objectives
- Office capacity
- Employee preference
- Vendor location
Correct Answer: 1
Explanation
Information security strategy priorities should be guided by business objectives, organizational risks, regulatory requirements, and the protection needs of critical information assets. Security resources are limited, so organizations should focus investment on areas that support important business processes and reduce significant risks. A strategy based mainly on technology trends or departmental preferences may fail to address the organization’s most important exposures. CISM emphasizes alignment between information security and business strategy. Security leaders should therefore understand organizational goals and risk tolerance before establishing strategic priorities, ensuring that security initiatives provide meaningful support to business operations and objectives.
Question 322
Which document establishes management direction for information security?
- Procedure
- Guideline
- Security policy
- Technical manual
Correct Answer: 3
Explanation
A security policy establishes management direction, expectations, and principles for protecting organizational information and technology resources. It provides a foundation for more detailed standards, procedures, and guidelines. An effective policy should be aligned with business objectives, applicable laws, regulatory requirements, and organizational risk. Management sponsorship is important because policies require authority and accountability for implementation. CISM emphasizes governance and management direction rather than relying only on technical controls. Policies should also be periodically reviewed because changes in business operations, technology, threats, and regulations may make existing requirements incomplete or inappropriate.
Question 323
What is the primary purpose of a security steering committee?
- Configure firewalls
- Align security decisions
- Repair computers
- Monitor passwords
Correct Answer: 2
Explanation
A security steering committee helps align information security decisions with business priorities and organizational risk. It can provide cross-functional oversight, resolve competing priorities, support resource decisions, and promote coordination between security and business departments. The committee generally should not perform routine technical administration because its value comes from governance and strategic oversight. Membership should represent appropriate business and technology interests so decisions consider organizational requirements rather than a single department’s perspective. CISM emphasizes governance structures that establish accountability and support alignment between security objectives, business goals, risk management, and available organizational resources.
Question 324
When should security requirements be considered for a new business process?
- After deployment
- During design
- After an incident
- During retirement
Correct Answer: 2
Explanation
Security requirements should be considered during the design of a new business process so risks can be addressed before implementation. Early involvement allows security controls to become part of the process rather than being added later at greater cost or with operational limitations. Security teams should understand the process objectives, information involved, users, dependencies, regulatory requirements, and potential threats. CISM promotes security integration throughout business and technology lifecycles. Addressing requirements early also improves consistency, reduces the likelihood of expensive redesign, and helps ensure that controls support business objectives while maintaining an appropriate level of risk.
Question 325
Which factor is most important when selecting a security control?
- Business risk
- Vendor popularity
- Office size
- Product color
Correct Answer: 1
Explanation
Business risk is a key factor when selecting security controls because controls should address identified threats and vulnerabilities in a manner appropriate to the organization’s risk exposure. Control selection should consider business impact, likelihood, regulatory requirements, cost, effectiveness, operational requirements, and risk tolerance. Choosing controls simply because they are popular or technologically advanced may create unnecessary expense without adequately addressing important risks. CISM emphasizes risk-based security management, meaning controls should be justified by organizational needs. Management should also consider whether the proposed control is practical, sustainable, and capable of reducing risk to an acceptable level.
Question 326
What should a security investment business case demonstrate?
- Employee satisfaction
- Office expansion
- Business value
- Vendor preference
Correct Answer: 3
Explanation
A security investment business case should demonstrate business value by explaining the risks being addressed, expected benefits, costs, dependencies, and potential effects on organizational objectives. Management needs sufficient information to determine whether an investment is justified relative to competing priorities. A strong business case may describe expected risk reduction, regulatory requirements, operational benefits, loss avoidance, or support for strategic initiatives. CISM emphasizes communicating security in business terms rather than relying exclusively on technical arguments. Security leaders should therefore connect proposed investments to measurable organizational outcomes and explain the consequences of not addressing the identified risk.
Question 327
What should happen when residual risk exceeds approved tolerance?
- Ignore it
- Accept automatically
- Escalate it
- Delete the record
Correct Answer: 3
Explanation
When residual risk exceeds approved risk tolerance, the issue should be escalated to the appropriate risk owner or management authority for a decision. Possible responses may include implementing additional controls, changing the process, transferring risk, avoiding the activity, or formally accepting the remaining exposure if authorized. Automatically accepting excessive risk without appropriate authority weakens governance and accountability. CISM emphasizes that risk decisions should be made at the appropriate organizational level based on established criteria. Security professionals should provide clear information about the exposure, treatment options, costs, and potential business consequences to support informed management decisions.
Question 328
Which activity helps determine whether security resources are sufficient?
- Capability assessment
- Office inspection
- Sales analysis
- Product testing
Correct Answer: 1
Explanation
A capability assessment helps determine whether the organization has sufficient people, skills, processes, technology, and resources to meet its information security objectives. The assessment can compare current capabilities with required capabilities based on business strategy, risk exposure, regulatory obligations, and expected security services. Identifying gaps allows management to prioritize investments and determine whether training, recruitment, outsourcing, technology, or process changes are necessary. CISM emphasizes aligning resources with organizational requirements rather than assuming that existing capabilities are adequate. Capability assessments should be periodically repeated because business priorities, threats, technologies, and regulatory requirements change over time.
Question 329
What is the main purpose of data classification?
- Increase storage
- Determine protection needs
- Reduce staffing
- Improve advertising
Correct Answer: 2
Explanation
Data classification determines the level of protection information requires based on factors such as sensitivity, confidentiality, business value, regulatory requirements, and potential impact if compromised. Classification allows organizations to apply appropriate controls rather than treating every information asset identically. Highly sensitive information may require stronger access restrictions, encryption, monitoring, retention controls, or handling procedures. Classification should be supported by clear ownership and defined handling requirements. CISM emphasizes protecting information according to business value and risk. Effective classification therefore helps organizations prioritize security resources and apply controls proportionate to the consequences associated with unauthorized disclosure, alteration, or loss.
Question 330
Who should generally be accountable for an information asset?
- Security analyst
- Asset owner
- Network technician
- Help desk agent
Correct Answer: 2
Explanation
The information asset owner should generally be accountable for determining appropriate protection requirements and ensuring that the asset is managed according to organizational policies and business needs. Security personnel can provide expertise and implement controls, but ownership should remain connected to the business function responsible for the information. The owner may determine classification, access requirements, retention needs, and acceptable use conditions. CISM emphasizes clear accountability because unclear ownership can result in unmanaged risks and conflicting decisions. Assigning ownership also helps ensure that security requirements reflect the actual business value and consequences associated with the information asset.
Question 331
What should security metrics primarily help management understand?
- Business risk
- Employee hobbies
- Office capacity
- Product design
Correct Answer: 1
Explanation
Security metrics should help management understand security performance, business risk, control effectiveness, trends, and areas requiring decisions. Technical counts alone may have limited value if they cannot be connected to organizational consequences. For example, reporting the number of vulnerabilities may be less useful than showing how critical vulnerabilities affect important business services and whether remediation is progressing within acceptable timeframes. CISM emphasizes meaningful metrics that support management decision-making. Effective metrics should have clear objectives, reliable data, appropriate context, and understandable reporting. They should help management determine whether security investments and activities are producing the expected results.
Question 332
Which metric is most useful for senior management?
- Firewall rules
- Business risk trend
- Log entries
- Patch commands
Correct Answer: 2
Explanation
A business risk trend is generally more useful to senior management because it connects security information with organizational exposure and decision-making. Senior leaders typically need to understand whether significant risks are increasing, decreasing, or remaining stable and whether current investments are addressing important exposures. Highly technical measures can still be useful to security teams, but they should often be translated into business implications for executive audiences. CISM emphasizes audience-appropriate reporting and communication. Effective executive metrics should highlight material risks, trends, control effectiveness, resource requirements, and decisions that management may need to make.
Question 333
What should be done when a security metric no longer supports decisions?
- Remove all metrics
- Keep it unchanged
- Redesign it
- Hide the results
Correct Answer: 3
Explanation
A security metric that no longer supports meaningful decisions should be redesigned or replaced. Metrics should remain aligned with security objectives, business requirements, risk indicators, and management information needs. Changes in technology, threats, organizational priorities, or reporting requirements may make previously useful metrics less relevant. Keeping ineffective measures simply because they have been used historically can consume resources without improving decision-making. CISM emphasizes continuous improvement, including periodic evaluation of security measurement practices. Organizations should determine whether each metric provides reliable and actionable information and modify measures when they no longer provide sufficient insight into performance or risk.
Question 334
What should guide the frequency of third-party security assessments?
- Supplier preference
- Risk level
- Office distance
- Contract length
Correct Answer: 2
Explanation
Risk level should guide the frequency and depth of third-party security assessments. Suppliers handling sensitive information, supporting critical services, or creating significant operational dependencies may require more frequent or comprehensive assessments. Lower-risk suppliers may be assessed less frequently if justified by organizational criteria. A risk-based approach helps focus limited security resources where weaknesses could have the greatest business consequences. CISM emphasizes continuous third-party risk management rather than treating supplier assessment as a one-time procurement activity. Assessment frequency should therefore consider business criticality, data sensitivity, threat exposure, regulatory requirements, previous findings, and changes in the supplier relationship.
Question 335
What should be included in third-party security requirements?
- Office decorations
- Personal preferences
- Security obligations
- Sales forecasts
Correct Answer: 3
Explanation
Third-party agreements should include appropriate security obligations that define the supplier’s responsibilities for protecting organizational information and services. Requirements may address access control, confidentiality, incident notification, data handling, security assessments, compliance, business continuity, and termination procedures. Specific requirements should reflect the risk and criticality of the relationship. Clearly documented obligations provide a basis for accountability and allow the organization to verify whether expected controls are being maintained. CISM emphasizes managing third-party risk throughout the relationship, so security requirements should be established before significant information or services are entrusted to the supplier and reviewed when circumstances change.
Question 336
What is the primary purpose of security awareness programs?
- Change behavior
- Increase hardware
- Reduce storage
- Expand offices
Correct Answer: 1
Explanation
The primary purpose of security awareness programs is to influence behavior so employees and other users understand their security responsibilities and make safer decisions. Awareness should help users recognize threats, follow policies, protect information, report suspicious activity, and understand the consequences of unsafe behavior. Simply delivering training does not guarantee effectiveness, so organizations should evaluate whether awareness activities produce measurable behavioral improvements. CISM emphasizes aligning awareness programs with organizational risks and audience needs. Content should be relevant to actual threats and job responsibilities, while program effectiveness should be measured through indicators such as reporting behavior, policy compliance, and observed security practices.
Question 337
How should security training differ for privileged administrators?
- Use no training
- Provide role-based content
- Use identical content
- Focus only on policies
Correct Answer: 2
Explanation
Privileged administrators should receive role-based security training that reflects the elevated risks and responsibilities associated with administrative access. Their training may address privileged account protection, secure configuration, credential handling, logging, change management, incident reporting, and the consequences of misuse. Generic awareness content may not provide sufficient practical guidance for high-risk roles. CISM emphasizes tailoring security education to the audience, responsibilities, and risks involved. Organizations should periodically update role-based training as technologies, threats, policies, and responsibilities change. Effectiveness should also be evaluated to determine whether administrators demonstrate the expected security behaviors in practice.
Question 338
What should be done when a policy exception creates significant risk?
- Approve automatically
- Ignore the risk
- Delete the request
- Evaluate compensating controls
Correct Answer: 4
Explanation
When a policy exception creates significant risk, the organization should evaluate whether compensating controls can reduce the exposure to an acceptable level. The exception should follow a formal approval process involving the appropriate risk owner and should include a documented business justification, duration, affected assets, and risk assessment. Compensating controls may provide alternative protection when the standard requirement cannot be implemented. CISM emphasizes controlled exception management because informal or permanent exceptions can weaken security governance. Exceptions should be periodically reviewed to determine whether the original business justification remains valid and whether the organization can eventually comply with the standard requirement.
Question 339
What should trigger reassessment of a security strategy?
- Office repainting
- New business risks
- Employee birthdays
- Furniture changes
Correct Answer: 2
Explanation
New business risks should trigger reassessment of the information security strategy because changes in organizational objectives, markets, technology, regulations, acquisitions, or threats can alter the security requirements of the enterprise. A strategy that was appropriate under previous conditions may no longer address current risks or priorities. Security leaders should evaluate whether objectives, resources, architecture, policies, and investments remain aligned with the organization. CISM emphasizes strategic alignment and continuous improvement, so security strategy should not be treated as a static document. Significant changes should lead to appropriate review and adjustment based on current business needs and risk conditions.
Question 340
What should management review to evaluate security program effectiveness?
- Office furniture
- Employee schedules
- Security objectives
- Product packaging
Correct Answer: 3
Explanation
Management should review security objectives and related performance measures to evaluate whether the security program is achieving its intended outcomes. Evaluation should consider risk reduction, control effectiveness, business alignment, regulatory requirements, resource utilization, and progress against established objectives. Merely completing security activities does not prove that the program is effective if important risks remain unmanaged. CISM emphasizes outcome-based security management, where performance is assessed against organizational needs rather than activity volume alone. Regular management reviews can identify gaps, emerging risks, resource requirements, and opportunities for improvement, helping ensure that the security program continues to support business objectives.