Isaca CISM Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Isaca CISM Exam Dumps and Practice Test Dumps.

 

Question 161

What is a key purpose of security metrics?

  1. Increase the number of security tools
  2. Measure progress and performance against defined objectives
  3. Replace risk assessments
  4. Eliminate security incidents

Correct Answer: 2

Explanation

Security metrics provide measurable information about whether security activities and controls are achieving their intended objectives. Useful metrics can help management understand performance, trends, control effectiveness, risk exposure, and progress toward strategic goals. Metrics should be relevant to the audience and connected to meaningful outcomes rather than simply counting security activities. They do not replace risk assessments or guarantee that incidents will not occur. The CISM should ensure that metrics support informed decisions and provide evidence about whether security investments and activities are contributing to organizational objectives and reducing significant risks.

Question 162

Which metric is MOST useful for senior management?

  1. Number of firewall rules
  2. Number of malware signatures updated
  3. Trend in significant security risks exceeding tolerance
  4. Number of administrator logins

Correct Answer: 3

Explanation

Senior management generally benefits most from metrics that communicate significant business risks, trends, and progress against organizational objectives. A trend showing risks that exceed established tolerance can help executives understand whether exposure is increasing and whether management action is required. Technical activity counts such as firewall rules, malware signatures, or administrator logins may be useful to operational teams but often lack sufficient business context for executive decision-making. Effective management reporting should focus on information that supports resource allocation, prioritization, risk treatment, and strategic decisions rather than overwhelming executives with low-level technical measurements.

Question 163

A security metric shows a 30% reduction in vulnerabilities but no change in business risk. What should the CISM conclude?

  1. The metric may not adequately measure the intended security outcome
  2. The security program has automatically failed
  3. All vulnerability management activities should stop
  4. The organization has eliminated residual risk

Correct Answer: 1

Explanation

A reduction in vulnerability counts does not necessarily mean that business risk has decreased. Vulnerabilities vary significantly in severity, exploitability, asset criticality, and potential business impact. If the reported metric improves while meaningful business risk remains unchanged, the metric may be measuring activity rather than the outcome management actually needs to understand. The CISM should review whether the metric aligns with security objectives and consider incorporating risk context such as critical assets, exploitability, exposure, or potential impact. Metrics should help management understand meaningful security outcomes rather than simply demonstrate that security activities occurred.

Question 164

Which factor should guide the selection of security program metrics?

  1. The availability of data only
  2. The number of metrics used by competitors
  3. The organization’s security objectives and information needs
  4. The preference of the security administrator

Correct Answer: 3

Explanation

Security metrics should be selected according to defined security objectives, organizational risks, management information needs, and the decisions the metrics are intended to support. Data availability is important for practical measurement, but a metric should not be selected simply because information is easy to collect. Competitor practices and individual preferences may provide ideas but do not establish organizational relevance. Good metrics should be understandable, reliable, timely, and actionable. They should help demonstrate whether security objectives are being achieved, whether risks are changing, and whether management interventions or resource adjustments may be necessary.

Question 165

What is the PRIMARY purpose of a key risk indicator?

  1. To identify changes in risk exposure
  2. To document employee attendance
  3. To measure software licensing costs
  4. To replace security policies

Correct Answer: 1

Explanation

A key risk indicator, or KRI, provides information about conditions that may indicate changes in risk exposure. KRIs can help management identify increasing or decreasing risk before a significant event occurs and can support timely intervention. They differ from many performance indicators because their primary focus is risk conditions rather than simply measuring activity or achievement. Examples may include increasing privileged access exceptions, growing third-party exposure, or rising unresolved critical weaknesses. KRIs should be selected according to organizational risk objectives and thresholds so that management can recognize meaningful changes and respond appropriately.

Question 166

A KRI exceeds its defined threshold. What should happen NEXT?

  1. Ignore it if no incident has occurred
  2. Investigate the change and determine whether management action is required
  3. Delete the KRI
  4. Automatically terminate the related business process

Correct Answer: 2

Explanation

When a KRI exceeds an established threshold, the organization should investigate the underlying condition and determine whether the associated risk has increased beyond acceptable levels. The threshold should serve as an early warning that may require further analysis, escalation, or treatment. The absence of an incident does not mean the increased exposure can be ignored. Likewise, automatically terminating a business process may be disproportionate. The CISM should evaluate the cause, business impact, risk appetite, existing controls, and available responses. Appropriate action may include additional controls, risk treatment, management escalation, or closer monitoring.

Question 167

Which approach BEST supports meaningful security reporting?

  1. Present every available technical detail
  2. Connect security information to business impact and organizational objectives
  3. Report only successful security activities
  4. Avoid reporting negative trends

Correct Answer: 2

Explanation

Meaningful security reporting connects security information with business impact, organizational objectives, risk exposure, and decisions that management may need to make. Reporting every technical detail can obscure important information, while reporting only positive results can provide an incomplete picture of the organization’s security posture. Negative trends should be communicated objectively with appropriate context and recommended actions. The CISM should tailor reports to the audience, emphasizing significant risks, trends, control effectiveness, resource requirements, and progress against objectives. Effective reporting enables management to understand security as a business risk rather than simply as a collection of technical activities.

Question 168

A security program’s performance metric is consistently green, but serious incidents continue to increase. What should the CISM do?

  1. Review whether the metric is measuring the right outcome
  2. Increase the number of green indicators
  3. Stop reporting incidents
  4. Declare the metric successful without review

Correct Answer: 1

Explanation

A consistently positive metric combined with increasing serious incidents suggests that the metric may not be measuring the security outcome that matters most. The CISM should examine the metric’s definition, data sources, assumptions, thresholds, and relationship to business risk. The metric may measure activity rather than effectiveness or may omit important risk factors. Increasing the number of positive indicators would not address the underlying issue. Incident information should continue to be reported accurately because it provides important evidence about security performance. Metrics should be periodically reviewed to ensure they remain relevant, meaningful, and aligned with organizational objectives.

Question 169

Which activity is MOST important before implementing a major security control?

  1. Define the security requirement and risk the control is intended to address
  2. Select the most expensive available technology
  3. Ask users which vendor they prefer
  4. Install the control before identifying its objective

Correct Answer: 1

Explanation

Before implementing a major security control, the organization should understand the risk, security requirement, and objective the control is intended to address. This provides a basis for evaluating control design, effectiveness, cost, operational impact, and alternatives. Selecting technology before defining the problem can result in unnecessary spending or controls that do not address important risks. User preferences can provide valuable usability information but should not replace risk analysis. Clearly defined objectives also make later control evaluation possible because management can determine whether the implemented measure actually achieved the expected level of protection.

Question 170

Which control is MOST appropriate for reducing excessive user privileges?

  1. Periodic access review
  2. Data backup
  3. Network segmentation
  4. Security awareness posters

Correct Answer: 1

Explanation

Periodic access reviews help identify excessive, inappropriate, or outdated privileges and allow authorized owners to confirm that access remains necessary. Reviews can be especially important when employees change roles, leave the organization, or acquire temporary privileges. Backups protect availability and data recovery, while network segmentation can reduce the scope of certain network exposures but does not directly validate individual access rights. Awareness materials can support secure behavior but do not enforce privilege appropriateness. Access governance should also incorporate defined roles, approval requirements, least privilege, segregation of duties, and timely removal or modification of access.

Question 171

An employee changes departments. What should happen to the employee’s access?

  1. It should be reviewed against the requirements of the new role
  2. All previous access should remain indefinitely
  3. All organizational access should automatically be removed permanently
  4. Access should be based on seniority

Correct Answer: 1

Explanation

A change in job responsibilities can make existing access unnecessary or inappropriate. The employee’s access should therefore be reviewed against the requirements of the new role, with unnecessary privileges removed and required privileges approved according to established procedures. Keeping old access indefinitely can create excessive privileges and increase security risk. Removing every privilege permanently may disrupt legitimate business responsibilities. Seniority should not determine technical access unless it is directly relevant to a documented business requirement. Role-based access management and timely reviews help maintain least privilege while allowing employees to perform their assigned responsibilities effectively.

Question 172

Which principle limits access to only what a user needs to perform assigned duties?

  1. Defense in depth
  2. Least privilege
  3. Risk transfer
  4. Data retention

Correct Answer: 2

Explanation

Least privilege means users, applications, and other entities should receive only the access necessary to perform authorized responsibilities. Limiting privileges reduces the potential impact of compromised accounts, misuse, accidental changes, and unauthorized activity. Defense in depth involves multiple complementary security layers, while risk transfer addresses shifting certain consequences to another party. Data retention concerns how long information is kept. Least privilege should be supported through appropriate role definitions, authorization processes, access reviews, privileged access management, and timely modification of permissions when responsibilities change.

Question 173

A privileged account is shared by several administrators. What is the PRIMARY concern?

  1. Lack of individual accountability
  2. Excessive data backup frequency
  3. Reduced network bandwidth
  4. Increased storage capacity

Correct Answer: 1

Explanation

Shared privileged accounts can make it difficult to determine which individual performed a specific administrative action. This weakens accountability and can complicate investigations, monitoring, and disciplinary or corrective processes. Privileged access should generally be individually attributable wherever practical, with appropriate authentication, authorization, logging, and monitoring. If shared access is unavoidable because of technical limitations, compensating measures should be considered, such as controlled credential management and enhanced logging. The issue is not primarily storage, bandwidth, or backup frequency. Strong privileged access governance helps reduce the risk associated with powerful accounts.

Question 174

Which capability BEST supports accountability for privileged activities?

  1. Individual privileged identities with appropriate logging
  2. A shared administrator password
  3. Anonymous administrative access
  4. Unrestricted generic accounts

Correct Answer: 1

Explanation

Individual privileged identities allow administrative activities to be associated with specific authorized users. Appropriate logging can then provide evidence of who performed actions, when they occurred, and potentially what changes were made. Shared or anonymous administrative accounts weaken accountability and make investigations more difficult. Privileged access should also be protected through strong authentication, authorization, monitoring, and periodic review. Where organizations use privileged access management technologies, these capabilities can further support controlled credential use and session monitoring. The objective is to ensure that powerful access is appropriately authorized, traceable, monitored, and limited to legitimate business requirements.

Question 175

What is the PRIMARY purpose of data classification?

  1. To determine appropriate protection based on information sensitivity and business value
  2. To increase the amount of stored data
  3. To identify the fastest network connection
  4. To determine employee salaries

Correct Answer: 1

Explanation

Data classification categorizes information according to characteristics such as sensitivity, confidentiality, business value, regulatory requirements, or potential impact if improperly disclosed, modified, or lost. Classification enables organizations to apply protection requirements that are appropriate to the information’s importance. Without classification, organizations may overprotect low-value information or underprotect sensitive information. Classification should be supported by defined ownership, handling requirements, access rules, retention expectations, and appropriate security controls. It should also be communicated clearly so that employees and systems can apply the required protections consistently throughout the information lifecycle.

Question 176

A business unit begins using an unapproved cloud application to store company data. What should the CISM do FIRST?

  1. Assess the data, business need, risk, and security implications
  2. Immediately approve the application
  3. Ignore the activity because cloud services are common
  4. Delete all data without investigation

Correct Answer: 1

Explanation

Unapproved cloud services can introduce risks involving data exposure, access management, privacy, compliance, third-party dependencies, data location, retention, and incident response. The CISM should first understand what information is being stored, why the service is being used, who has access, and what risks or contractual requirements apply. Immediate approval without assessment could expose the organization to unacceptable risk, while deleting data without investigation may disrupt legitimate business operations or violate retention requirements. After assessing the situation, management can determine whether to approve the service, implement controls, migrate the data, or discontinue the use.

Question 177

Which procurement requirement is MOST important when acquiring a service that will process sensitive information?

  1. Clearly defined security and contractual requirements
  2. The vendor’s office decoration
  3. The shortest product name
  4. The number of vendor advertisements

Correct Answer: 1

Explanation

When a third party will process sensitive information, security requirements should be defined before contracting and incorporated into appropriate agreements. Requirements may address access control, data protection, incident notification, regulatory obligations, business continuity, audit rights, subcontractors, vulnerability management, data retention, and secure termination. These requirements establish expectations and provide contractual mechanisms for managing third-party risk. Marketing materials alone do not provide sufficient assurance. Procurement and security teams should work with the business to ensure that requirements are proportionate to the sensitivity and criticality of the service and that important risks are addressed before the relationship begins.

Question 178

A critical supplier experiences a security incident. What should the organization consider FIRST?

  1. Whether the incident affects organizational information, services, or contractual obligations
  2. Whether the supplier should immediately be removed from every system
  3. Whether all supplier invoices should be cancelled
  4. Whether the incident should remain undisclosed internally

Correct Answer: 1

Explanation

When a critical supplier experiences a security incident, the organization should first determine whether its information, services, systems, customers, or contractual and regulatory obligations are affected. This requires reviewing available incident information, contractual notification requirements, business dependencies, and relevant security procedures. Immediate termination may be inappropriate if the supplier is essential to operations and the impact has not yet been understood. Financial actions do not address the primary security question. Internal stakeholders should receive appropriate information according to established incident and third-party risk procedures so that business continuity, security, legal, and communication decisions can be coordinated.

Question 179

Which factor should determine the frequency of third-party security assessments?

  1. The risk and criticality of the third-party relationship
  2. The vendor’s advertising budget
  3. The number of pages in the contract
  4. The vendor’s office size

Correct Answer: 1

Explanation

Third-party assessment frequency should be based primarily on the risk and criticality of the relationship. A provider handling highly sensitive information or supporting a critical business process may require more frequent or comprehensive assessments than a low-risk supplier. Other considerations can include regulatory requirements, previous findings, changes in services, incidents, subcontracting arrangements, and changes in the threat environment. Contract length or office size does not directly establish security risk. A risk-based assessment schedule helps organizations focus assurance resources where third-party failures could have the greatest effect on business objectives and organizational resilience.

Question 180

A security assessment identifies a control weakness at a critical third-party provider. What should the CISM evaluate NEXT?

  1. The potential business impact, risk exposure, and appropriate remediation
  2. Whether the weakness can be hidden from management
  3. Whether all third-party services should automatically be terminated
  4. Whether the assessment should be deleted

Correct Answer: 1

Explanation

A control weakness at a critical provider should be evaluated in terms of its potential effect on organizational information, services, business continuity, compliance, and overall risk exposure. The CISM should determine the severity of the weakness, existing compensating controls, remediation options, timelines, and whether escalation is required. Automatic termination may not be practical or necessary, especially if the provider supports critical operations, but the risk should not be concealed or the assessment discarded. Management should have sufficient information to decide whether remediation, additional controls, contractual action, risk acceptance, or alternative arrangements are appropriate.