{"id":22201,"date":"2026-09-25T11:37:26","date_gmt":"2026-09-25T11:37:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22201"},"modified":"2026-09-25T11:37:26","modified_gmt":"2026-09-25T11:37:26","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of an information security governance framework?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To establish how security decisions, responsibilities, and oversight are managed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace all security technologies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate the need for risk assessments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To document individual technical configurations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An information security governance framework establishes how security decisions, responsibilities, authority, accountability, and oversight are organized within the enterprise. It helps ensure that security activities support business objectives and are managed consistently. A governance framework does not replace security technologies or eliminate the need for risk assessments. Technical configurations are generally documented through operational procedures and system documentation. Effective governance defines decision rights, reporting relationships, policies, oversight mechanisms, and escalation paths. It also helps management ensure that security investments and activities remain aligned with organizational strategy, risk appetite, legal obligations, and business priorities.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>Which factor should be MOST important when establishing information security governance responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security tools deployed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clear authority and accountability for decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical location of security personnel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security incidents from the previous year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clear authority and accountability are fundamental to effective information security governance. Individuals and committees should understand which decisions they are authorized to make, which responsibilities they hold, and when matters must be escalated. Security tools and historical incident counts can provide useful information but do not establish governance responsibilities. Without clear accountability, important risks may remain unresolved because different functions assume another party is responsible. Governance structures should therefore define decision rights, ownership, reporting relationships, escalation requirements, and oversight responsibilities while ensuring that security decisions remain aligned with broader organizational governance.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>A business executive asks why information security should participate in strategic planning. What is the BEST explanation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security can identify and address risks that may affect strategic objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security should control all business decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security participation eliminates business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security exists primarily to purchase technical products<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information security should participate in strategic planning because business strategies increasingly depend on information, technology, suppliers, digital services, and data. Security involvement helps identify risks that could affect strategic objectives and allows appropriate protections to be incorporated early. Security should support business decision-making rather than control every business decision. No security program can eliminate all organizational risk, and the function should not be defined by technology purchases. Early involvement can help management understand potential exposures, regulatory requirements, dependencies, and control needs before strategic decisions become difficult or expensive to change.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>Which governance activity BEST supports senior management oversight of information security?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing detailed firewall configurations every week<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Receiving regular reports on significant risks, trends, and security objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approving every employee&#8217;s access request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performing all incident investigations personally<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Senior management oversight is most effective when executives receive concise information about significant security risks, trends, business impact, strategic objectives, and decisions requiring attention. Reviewing detailed technical configurations or individual access requests is generally an operational responsibility and does not provide an effective enterprise-level view. Executives should focus on whether the security program is managing material risks and supporting organizational objectives. Appropriate reporting enables leaders to challenge assumptions, approve priorities, allocate resources, and make informed risk decisions. The information presented should therefore be relevant to management responsibilities rather than dominated by technical details.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>What should be the PRIMARY consideration when defining an organization&#8217;s information security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The latest available security technology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business objectives and the organization&#8217;s risk environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Competitor security advertisements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The preferences of individual administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An information security strategy should be driven by business objectives, organizational risk, regulatory obligations, and the requirements needed to protect critical information and processes. Technology can support the strategy, but selecting technology first can result in investments that do not address the organization&#8217;s most important risks. Competitor marketing and individual administrator preferences are also insufficient foundations for strategic planning. A business-aligned strategy establishes priorities, desired outcomes, governance expectations, resource requirements, and security capabilities. It should provide a practical direction for the security program while remaining responsive to changes in business strategy and the external threat environment.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>A major organizational acquisition is completed. What should the CISM assess FIRST regarding the security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the existing strategy still aligns with the combined organization&#8217;s objectives and risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether every security tool should be replaced<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether all acquired employees should receive identical access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether security policies should be permanently frozen<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A major acquisition can significantly change business objectives, information assets, technology environments, regulatory obligations, threat exposure, and organizational risk. The CISM should therefore assess whether the existing information security strategy remains appropriate for the combined organization. This does not automatically require replacing every security technology. Access and policies should also be evaluated according to business roles and risk requirements rather than applied without analysis. Strategy reassessment provides a foundation for identifying capability gaps, harmonizing governance, prioritizing integration activities, and determining where changes to security architecture, controls, resources, and policies are necessary.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which characteristic is MOST important for an effective information security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is based entirely on technical requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is aligned with business priorities and measurable security objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It remains unchanged regardless of business conditions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It focuses only on preventing malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An effective information security strategy connects security activities with business priorities and establishes measurable objectives. It should address the organization&#8217;s significant risks, regulatory obligations, information needs, technology dependencies, and desired security capabilities. A strategy focused entirely on technical requirements may overlook important business considerations. Likewise, a strategy that never changes can become ineffective as the organization&#8217;s objectives and risk environment evolve. Malware prevention may be important but represents only one aspect of information security. Strategic alignment allows management to understand why security investments are needed and how they contribute to protecting organizational objectives.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>A security initiative is proposed without a clearly identified business risk or objective. What should the CISM do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve it because all security initiatives are valuable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Request clarification of the business need, risk, and expected outcome<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reject all future initiatives from the same department<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purchase the proposed technology before evaluation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security initiatives should have a clear relationship to business requirements, identified risks, compliance obligations, or measurable security objectives. If that relationship is unclear, the CISM should request clarification before recommending investment. This helps determine whether the initiative addresses a meaningful exposure and whether its expected benefits justify the required resources. Automatically approving every security initiative can lead to fragmented spending and unnecessary complexity. Immediate technology purchases also bypass appropriate analysis. A clear business case should explain the problem, risk, expected outcome, alternatives, resource requirements, and measures that will demonstrate whether the initiative achieved its intended purpose.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which activity BEST supports continuous improvement of an information security program?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing performance results and using findings to adjust processes and controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Freezing all security procedures permanently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measuring only the number of security products purchased<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding changes after successful audits<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous improvement requires the organization to review performance, identify weaknesses or changing conditions, and use the findings to improve processes, controls, capabilities, and outcomes. Sources of information may include metrics, incidents, audits, assessments, exercises, risk reviews, user feedback, and regulatory changes. Freezing procedures prevents adaptation, while product counts do not demonstrate security effectiveness. Passing an audit also does not mean that improvement should stop because risks and business requirements continue to change. A mature program treats review findings as opportunities to strengthen security while ensuring that improvements remain aligned with business objectives and risk priorities.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>A security manager discovers that a key security objective cannot be achieved with current resources. What should be done FIRST?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hide the gap until the next budget cycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess the capability gap and its effect on business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce the security objective without management approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purchase resources immediately without analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When resources are insufficient to achieve an important security objective, the CISM should assess the capability gap and determine its potential effect on organizational risk. The analysis should identify what resources are missing, which objectives are affected, the consequences of not addressing the gap, and possible alternatives. This information supports informed management decisions about funding, priorities, outsourcing, timelines, or risk acceptance. Hiding the issue or changing strategic objectives without appropriate approval undermines governance. Immediate purchasing without analysis may also result in inefficient spending. A documented gap analysis provides evidence for appropriate escalation and resource planning.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>Which approach BEST supports effective security resource allocation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allocate resources according to business risk, objectives, and required capabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give every department exactly the same security budget<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fund only the department that reports the most incidents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allocate resources based solely on technology prices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security resources should be allocated according to organizational risk, strategic objectives, critical processes, regulatory requirements, and the capabilities needed to manage identified exposures. Equal funding for every department may ignore differences in business criticality and risk. Incident volume alone can also be misleading because a department with fewer incidents may still have significant exposure. Technology prices do not establish business priority. Risk-based resource allocation helps management direct limited funding and personnel toward areas where security improvements can provide meaningful risk reduction and support important organizational objectives.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>A security policy has not been reviewed for several years despite major technology and business changes. What should the CISM recommend?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review the policy against current business, legal, and security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep it unchanged to preserve consistency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the policy and operate without formal requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace it with technical configuration files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security policies should be reviewed periodically and when significant changes occur in business operations, technology, regulations, organizational structure, or risk conditions. An outdated policy may contain requirements that are no longer appropriate or may fail to address new risks and obligations. The review should assess alignment with current business objectives, legal and regulatory requirements, risk appetite, and security practices. Keeping an outdated policy solely for consistency can create governance problems. Policies should remain authoritative and understandable while supporting practical security requirements that can be implemented and monitored across the organization.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of a policy exception process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide a controlled method for handling justified deviations from requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To allow employees to ignore policies without approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate accountability for policy compliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To permanently weaken all security requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A policy exception process provides a controlled and documented mechanism for addressing situations in which a mandatory requirement cannot reasonably be met. It should require appropriate justification, risk assessment, authorization, documentation, and often a defined expiration or review date. This allows the organization to accommodate legitimate business needs without creating uncontrolled deviations. Employees should not be able to bypass requirements informally. Exceptions should remain visible to management so that associated risks can be monitored. A mature exception process balances business practicality with security governance and ensures that deviations receive appropriate accountability.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>Which situation BEST justifies the use of a compensating control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The original control cannot reasonably be implemented, but an alternative can provide comparable risk reduction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The organization wants to remove every security control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A security administrator prefers a different technology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A business unit wants to avoid documenting its risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control may be appropriate when the original control cannot reasonably be implemented because of technical, operational, business, or other constraints, while an alternative control can provide an acceptable level of risk reduction. The alternative should be formally assessed and approved according to the organization&#8217;s governance process. A compensating control should not simply be selected because someone prefers different technology or wants to avoid compliance. Its effectiveness should be evaluated against the relevant risk and requirement. Documentation should identify the original requirement, reason for substitution, alternative control, residual risk, ownership, and approval.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which action is MOST appropriate when a security control repeatedly fails to achieve its intended objective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Investigate the underlying cause and determine whether the control design or implementation needs improvement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continue using it without review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediately purchase an unrelated security product<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the control without assessing the risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated control failure indicates that the organization should investigate why the control is not achieving its intended objective. Root causes may include poor design, incorrect configuration, insufficient resources, inadequate procedures, lack of ownership, inappropriate technology, or changes in the risk environment. Simply continuing the control or removing it without analysis may leave the organization exposed. Purchasing an unrelated product also does not address the underlying issue. Root cause analysis allows the CISM to determine whether the control should be redesigned, replaced, supplemented, automated, or supported by process changes while considering residual risk and business requirements.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>A security architecture review identifies several systems with overlapping protection mechanisms. What should be assessed before removing any control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The risks and security objectives each control addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The purchase price of the newest control only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which administrator installed the controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of employees using the systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Overlapping controls may provide intentional defense in depth or may address different security objectives despite appearing similar. Before removing any control, the CISM should determine which risks, requirements, and security objectives it addresses and evaluate the consequences of removal. Other considerations include control dependencies, effectiveness, regulatory requirements, operational costs, and residual risk. Focusing only on purchase price or administrative ownership can produce an incomplete decision. Control rationalization should preserve necessary protection while eliminating unnecessary complexity. A risk-based analysis ensures that apparent duplication does not result in unexpected security gaps.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of defense in depth?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To ensure that failure of one control does not automatically result in complete compromise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate the need for monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To use the maximum possible number of security products<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To make all security controls identical<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary layers of protection so that the failure or bypass of one control does not automatically result in complete compromise. Layers may include preventive, detective, corrective, administrative, physical, and technical measures. The objective is not simply to maximize the number of products. Excessive or poorly designed controls can increase cost and complexity without providing meaningful benefit. Effective defense in depth is risk-based and considers how controls work together across different stages of an attack or failure. The architecture should provide appropriate resilience while remaining manageable and aligned with business requirements.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A company introduces a new cloud-based business application. Which security activity should occur EARLY in the implementation lifecycle?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess security and privacy requirements based on the application&#8217;s risks and business use<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wait for the provider&#8217;s first security incident<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant broad access to all employees<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable security testing to accelerate deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security and privacy requirements should be assessed early in the application lifecycle so that appropriate controls can be incorporated before deployment. Cloud applications may introduce risks involving access, data location, confidentiality, integration, logging, availability, third parties, and regulatory requirements. Waiting for an incident is reactive and can make remediation more expensive. Broad access without a business need can create unnecessary exposure, while disabling testing undermines assurance. Early security assessment allows the organization to define appropriate requirements, evaluate the provider, design access controls, establish monitoring, and address risks before the application becomes deeply integrated into critical business processes.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which measure BEST indicates whether a security control is operating effectively?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the control achieves its intended security objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the control has the newest available technology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the control was expensive to implement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether users consider the control impressive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control effectiveness should be evaluated against the security objective the control was designed to achieve. A control may use modern technology and have a high implementation cost while still failing to reduce the relevant risk. Conversely, a simpler control may be highly effective if it consistently achieves its intended objective. Evaluation should consider design adequacy, implementation, operation, evidence, and the resulting level of risk reduction. User perception may provide useful feedback about usability but does not independently establish effectiveness. Measuring outcomes against defined objectives provides management with meaningful evidence about whether controls are performing as expected.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A security program has achieved its stated objectives, but the threat environment has changed significantly. What should the CISM recommend?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess the program&#8217;s objectives and risk assumptions against the changed environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Declare the program permanently complete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stop monitoring because previous objectives were achieved<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove controls that have not experienced incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Achieving existing security objectives does not mean that the program should remain unchanged. A significant change in the threat environment can alter risk assumptions, attack methods, vulnerabilities, business exposure, and required capabilities. The CISM should reassess whether current objectives, controls, resources, and risk treatments remain appropriate. This does not mean every control should be replaced or that previous achievements are invalid. Continuous monitoring and periodic reassessment help the organization adapt its security program to changing conditions. Security objectives should remain connected to business priorities and risk while evolving when meaningful changes affect the organization&#8217;s exposure.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 141 What is the PRIMARY purpose of an information security governance framework? To establish how security decisions, responsibilities, and oversight are managed To replace all security technologies To eliminate the need for risk assessments To document individual technical configurations Correct Answer: 1 Explanation [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22201"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22201"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22201\/revisions"}],"predecessor-version":[{"id":22202,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22201\/revisions\/22202"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}