{"id":22193,"date":"2026-09-25T11:36:06","date_gmt":"2026-09-25T11:36:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22193"},"modified":"2026-09-25T11:36:06","modified_gmt":"2026-09-25T11:36:06","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>Which activity is MOST important when developing an information security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecting security products before identifying business requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Understanding business objectives, risks, and stakeholder expectations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replacing all existing security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establishing technical standards without management input<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An effective information security strategy should begin with an understanding of organizational objectives, business priorities, risk exposure, stakeholder expectations, and applicable requirements. This information allows the security manager to develop security goals that directly support the organization. Selecting products before understanding requirements can result in unnecessary spending or inadequate protection. Replacing all existing controls is also inappropriate because current controls may remain effective. Technical standards are important, but they should support an approved strategy rather than independently determine it. A business-aligned strategy provides direction for security investments, priorities, resources, and risk treatment.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>What should be the PRIMARY consideration when aligning an information security strategy with business strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The organization&#8217;s most expensive security technology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The organization&#8217;s business objectives and risk tolerance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security employees available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The preferred security framework of the IT department<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The information security strategy should align with the organization&#8217;s business objectives and risk tolerance. Security exists to enable and protect business activities, so security priorities should reflect what the organization is trying to accomplish and the risks management is willing to accept. Technology, staffing, and frameworks can support implementation, but they should not independently determine strategic direction. Understanding business goals helps the CISM identify which information and processes are most important, what risks could affect them, and what security capabilities are necessary. This alignment also helps justify security investments to senior management.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>A business strategy changes significantly after an acquisition. What should the CISM do regarding the information security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep the existing strategy unchanged<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess and update the security strategy based on the new business environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediately discontinue all security initiatives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow the acquired organization to establish security requirements independently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A major business change such as an acquisition can alter organizational structure, assets, technology, regulatory obligations, third-party relationships, and risk exposure. The CISM should therefore reassess the information security strategy to determine whether its objectives and priorities remain appropriate. Keeping the strategy unchanged could leave important risks unaddressed or create unnecessary controls. Discontinuing all initiatives is also unjustified, while allowing a newly acquired organization to operate independently can create inconsistent security requirements. A strategic reassessment allows security leadership to integrate appropriate requirements while supporting the organization&#8217;s new business direction.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>Which factor should have the GREATEST influence on security strategy priorities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The availability of new security products<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The organization&#8217;s most significant business risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security conferences attended by employees<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The preferences of individual system administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security strategy priorities should be driven primarily by significant business risks and the organization&#8217;s objectives. This ensures that security resources are directed toward protecting assets and processes where compromise could have meaningful consequences. New security products may offer useful capabilities, but technology should be selected based on identified needs rather than novelty. Conference participation can improve knowledge but does not determine strategic priorities. Individual administrators may provide technical recommendations, but strategic decisions should consider enterprise-wide risk and business requirements. A risk-based strategy helps management make informed decisions about investments, capabilities, and resource allocation.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>A security manager is preparing a strategic plan with several proposed security initiatives. What should be used to evaluate each initiative?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Its expected contribution to business objectives and risk reduction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of configuration options it provides<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Its popularity on social media<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The size of its implementation team<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security initiatives should be evaluated according to their contribution to business objectives, risk reduction, compliance requirements, operational needs, and available resources. An initiative that provides meaningful protection for critical business processes may have greater strategic value than a technically sophisticated project with limited organizational benefit. Configuration options, social media popularity, and team size do not reliably demonstrate strategic value. A structured evaluation helps management compare proposed initiatives using consistent criteria and understand the expected outcomes. This also supports transparent prioritization when resources are limited and multiple security projects compete for funding.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of defining security architecture principles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide consistent direction for designing and implementing security capabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To document every employee&#8217;s daily tasks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate all technology changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace organizational security policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture principles provide consistent guidance for designing security capabilities, technologies, processes, and solutions across the organization. They can establish expectations such as defense in depth, least privilege, secure design, appropriate segregation, and integration with business requirements. Architecture principles do not replace policies because policies define management expectations and requirements at a broader level. They also do not eliminate technology changes or document individual employee tasks. Consistent principles help prevent fragmented security decisions and ensure that new solutions are developed or acquired in a manner that supports the organization&#8217;s overall security strategy.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>A security manager is evaluating whether an existing security architecture supports a newly introduced business application. What should be assessed FIRST?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the application introduces new business risks and security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the application uses the newest technology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether another company uses the same application<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the application&#8217;s interface is visually attractive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The first consideration should be whether the new application introduces risks, security requirements, compliance obligations, or changes to the existing security architecture. The manager should understand what information the application processes, who will access it, how it integrates with other systems, and what business processes depend on it. Technology novelty and external adoption do not determine whether the application fits the organization&#8217;s security needs. User interface design may affect usability but is not the primary security architecture concern. Early risk assessment helps identify required controls before the application becomes deeply integrated into business operations.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>Which approach BEST supports security by design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adding security controls only after deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incorporating security requirements throughout the solution development lifecycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing developers to decide security requirements without business input<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Testing security only when an incident occurs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security by design means incorporating security requirements and considerations throughout the lifecycle of a solution rather than treating security as a final activity. Requirements should be identified during planning and design, implemented appropriately, tested before deployment, and monitored throughout operation. Adding controls after deployment can increase costs and may leave weaknesses unresolved. Developers provide important technical expertise, but security and business stakeholders should also contribute to requirements. Waiting for an incident to test security is reactive. Integrating security throughout the lifecycle supports more consistent protection and reduces the likelihood of costly redesign.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>A security manager is reviewing a proposed architecture that relies on a single security control to protect a critical application. What principle should raise concern?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized reporting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth is the principle of using multiple complementary layers of protection so that failure of one control does not automatically result in complete compromise. Relying on a single security control for a critical application creates a potential single point of failure. The appropriate architecture should consider multiple preventive, detective, and corrective measures based on the application&#8217;s risks and business requirements. Centralized reporting, asset classification, and risk acceptance are important security concepts but do not directly address the concern created by dependence on one control. Layered protection can improve resilience against control failure.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>Which statement BEST describes the relationship between security architecture and security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture implements strategic security requirements through structured designs and capabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture determines business objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security strategy is limited to firewall configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture eliminates the need for risk management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security strategy establishes direction, objectives, priorities, and desired security outcomes, while security architecture helps translate those strategic requirements into structured designs, capabilities, and technology or process patterns. Architecture should therefore support the approved strategy rather than independently determine business objectives. Security strategy is broader than technical configuration and encompasses governance, risk, people, processes, and technology. Risk management also remains necessary because architecture cannot eliminate uncertainty or all security exposure. A well-aligned architecture provides a practical foundation for implementing security capabilities consistently across the organization&#8217;s systems and business processes.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>An organization is adopting a new technology that creates previously unidentified risks. What should the CISM recommend?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the risks until an incident occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update the risk assessment and determine appropriate treatment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reject every new technology automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transfer all responsibility to the technology vendor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New technology can introduce unfamiliar threats, vulnerabilities, dependencies, privacy concerns, and operational risks. The CISM should ensure that the risk assessment is updated so management can understand the new exposure and determine appropriate treatment. Automatically rejecting new technology may unnecessarily restrict business opportunities, while ignoring the risks is inconsistent with effective governance. Vendors can have important responsibilities, but outsourcing technology does not automatically transfer all organizational risk. Updated risk analysis allows management to evaluate controls, contractual requirements, residual risk, and business benefits before making an informed decision.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>What is the MOST appropriate role of the CISM in enterprise risk management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Make every business risk decision independently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide security risk expertise and support informed risk decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assume ownership of every organizational asset<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve all business investments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CISM contributes security risk expertise to enterprise risk management by identifying information security risks, evaluating potential impacts, recommending treatment options, and communicating security issues to appropriate decision makers. The CISM should support management rather than independently make every business risk decision. Business and asset ownership should remain with the appropriate organizational stakeholders, and the CISM does not normally approve every investment. Effective enterprise risk management depends on collaboration between business leaders, risk owners, security professionals, legal teams, and other relevant functions. The CISM helps ensure that security risks are properly represented in organizational decisions.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>A risk owner chooses to accept a risk that exceeds the organization&#8217;s established tolerance. What should the CISM do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the decision because the risk owner is accountable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Escalate the issue through the organization&#8217;s established governance process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically shut down the affected business process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the risk from the risk register<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If a risk exceeds established organizational tolerance, the CISM should ensure that the matter is escalated through the appropriate governance process. Risk owners have accountability for risks within their authority, but they should not accept exposure beyond established limits without appropriate authorization. The CISM should provide relevant analysis and recommendations while ensuring that management understands the potential consequences. Automatically shutting down the business process may be disproportionate, while deleting the risk would reduce visibility. Governance escalation allows authorized decision makers to determine whether additional treatment, formal exception, or another response is appropriate.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>Which factor is MOST important when determining an organization&#8217;s information security resource requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The organization&#8217;s risk profile and security objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security products advertised in the market<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of employees in the IT department alone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The preferences of the security manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information security resource requirements should be based on the organization&#8217;s risk profile, security objectives, business needs, regulatory obligations, current capabilities, and planned initiatives. Resource planning should identify the people, processes, technology, and funding required to achieve approved security objectives. Market availability of security products does not determine how many resources are needed. The overall IT headcount may provide context but does not reflect security workload or risk. Individual preferences should not drive resource allocation. A risk-based approach provides management with a defensible basis for determining appropriate staffing, investment, and capability requirements.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>A security manager is requesting additional security personnel. Which evidence would BEST support the request?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A documented workload and risk analysis showing gaps against required security objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The personal preference of the security manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The fact that another company employs more security staff<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A list of recently released security products<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A documented workload and risk analysis provides objective support for additional staffing. The analysis can demonstrate existing responsibilities, required security capabilities, current resource capacity, workload trends, regulatory requirements, identified gaps, and the potential consequences of insufficient resources. Comparing staffing levels with another company may be useful for context but does not demonstrate that the same staffing model is appropriate. New security products are also unrelated to staffing justification unless they create specific operational requirements. Evidence-based resource requests help senior management understand why additional personnel are needed and how they will contribute to security objectives.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>Which activity is MOST important for ensuring that security policies remain aligned with organizational requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Periodic review and approval by appropriate stakeholders<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing policies to remain unchanged indefinitely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Updating policies only after major incidents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricting policy review to technical administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Periodic policy review ensures that security requirements remain aligned with changes in business objectives, technology, threats, laws, regulations, and organizational responsibilities. Appropriate stakeholders should participate so that policies remain practical and reflect management expectations. Waiting until a major incident occurs is reactive and may leave important requirements outdated. Technical administrators can provide valuable input, but policy approval and governance should involve appropriate business and management stakeholders. Policies should also be communicated and enforced after approval. Regular review helps ensure that security requirements continue to provide relevant direction to employees and business units.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>A business unit requests an exception to a mandatory security policy. What should be required before approval?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A documented business justification and appropriate risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Verbal approval from any employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate removal of the policy requirement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic approval when the business unit is profitable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A policy exception should be supported by a documented business justification, assessment of associated risks, compensating controls where appropriate, defined duration, and approval from an authorized authority. This ensures that exceptions are deliberate and traceable rather than becoming informal workarounds. Verbal approval from an arbitrary employee does not establish appropriate accountability. Removing the policy requirement for everyone is unnecessary, and profitability does not justify accepting uncontrolled security exposure. A formal exception process allows management to balance business needs with security requirements while ensuring that deviations remain visible and periodically reviewed.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of compensating controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide an alternative means of achieving a required security objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate the need for risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To permanently exempt an organization from security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To reduce the number of security policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Compensating controls are alternative measures used when the original required control cannot be implemented as intended or is not practical in a particular situation. The alternative should provide an appropriate level of protection or satisfy the underlying security objective. Compensating controls do not eliminate the need for risk assessment or create permanent exemptions from requirements. They also do not exist primarily to reduce the number of policies. Their use should be documented, justified, approved by appropriate authority, and periodically reviewed to confirm that the alternative remains effective and appropriate for the associated risk.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>An organization wants to improve its security program after identifying repeated control failures. Which approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Focus only on employee mistakes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perform root cause analysis and address underlying process or control weaknesses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase penalties without examining the control design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore failures that do not cause incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated control failures should prompt an examination of their underlying causes rather than focusing only on individual mistakes. Root cause analysis can identify weaknesses in processes, control design, ownership, training, technology, resources, or management oversight. Increasing penalties without understanding why failures occur may not address the actual problem. Ignoring failures because they have not yet caused incidents allows weaknesses to persist and potentially worsen. Addressing root causes can improve control reliability and reduce recurring problems. The security manager should use findings to determine corrective actions and monitor whether those actions produce sustained improvement.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>Which activity BEST demonstrates continuous improvement of an information security program?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repeating the same security activities without measuring results<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using performance and risk information to identify gaps and improve controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replacing all security controls every year<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing security spending regardless of outcomes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous improvement requires the organization to use performance information, risk assessments, incidents, audits, testing results, and stakeholder feedback to identify weaknesses and improve security processes and controls. Simply repeating activities does not demonstrate that the program is becoming more effective. Replacing controls annually can create unnecessary disruption and cost, while increasing spending without measuring outcomes provides no assurance that risk is being reduced. A mature security program uses evidence to identify gaps, implement corrective actions, measure results, and adjust priorities as organizational needs and risks change. This creates a repeatable improvement cycle.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 61 Which activity is MOST important when developing an information security strategy? Selecting security products before identifying business requirements Understanding business objectives, risks, and stakeholder expectations Replacing all existing security controls Establishing technical standards without management input Correct Answer: 2 Explanation An effective [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22193"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22193"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22193\/revisions"}],"predecessor-version":[{"id":22194,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22193\/revisions\/22194"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}