{"id":22219,"date":"2026-09-25T11:42:25","date_gmt":"2026-09-25T11:42:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22219"},"modified":"2026-09-25T11:42:25","modified_gmt":"2026-09-25T11:42:25","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>What should guide information security strategy priorities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information security strategy priorities should be guided by business objectives, organizational risks, regulatory requirements, and the protection needs of critical information assets. Security resources are limited, so organizations should focus investment on areas that support important business processes and reduce significant risks. A strategy based mainly on technology trends or departmental preferences may fail to address the organization\u2019s most important exposures. CISM emphasizes alignment between information security and business strategy. Security leaders should therefore understand organizational goals and risk tolerance before establishing strategic priorities, ensuring that security initiatives provide meaningful support to business operations and objectives.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>Which document establishes management direction for information security?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procedure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guideline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technical manual<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security policy establishes management direction, expectations, and principles for protecting organizational information and technology resources. It provides a foundation for more detailed standards, procedures, and guidelines. An effective policy should be aligned with business objectives, applicable laws, regulatory requirements, and organizational risk. Management sponsorship is important because policies require authority and accountability for implementation. CISM emphasizes governance and management direction rather than relying only on technical controls. Policies should also be periodically reviewed because changes in business operations, technology, threats, and regulations may make existing requirements incomplete or inappropriate.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>What is the primary purpose of a security steering committee?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure firewalls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Align security decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repair computers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security steering committee helps align information security decisions with business priorities and organizational risk. It can provide cross-functional oversight, resolve competing priorities, support resource decisions, and promote coordination between security and business departments. The committee generally should not perform routine technical administration because its value comes from governance and strategic oversight. Membership should represent appropriate business and technology interests so decisions consider organizational requirements rather than a single department\u2019s perspective. CISM emphasizes governance structures that establish accountability and support alignment between security objectives, business goals, risk management, and available organizational resources.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>When should security requirements be considered for a new business process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">After deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">During design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">After an incident<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">During retirement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security requirements should be considered during the design of a new business process so risks can be addressed before implementation. Early involvement allows security controls to become part of the process rather than being added later at greater cost or with operational limitations. Security teams should understand the process objectives, information involved, users, dependencies, regulatory requirements, and potential threats. CISM promotes security integration throughout business and technology lifecycles. Addressing requirements early also improves consistency, reduces the likelihood of expensive redesign, and helps ensure that controls support business objectives while maintaining an appropriate level of risk.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which factor is most important when selecting a security control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product color<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk is a key factor when selecting security controls because controls should address identified threats and vulnerabilities in a manner appropriate to the organization\u2019s risk exposure. Control selection should consider business impact, likelihood, regulatory requirements, cost, effectiveness, operational requirements, and risk tolerance. Choosing controls simply because they are popular or technologically advanced may create unnecessary expense without adequately addressing important risks. CISM emphasizes risk-based security management, meaning controls should be justified by organizational needs. Management should also consider whether the proposed control is practical, sustainable, and capable of reducing risk to an acceptable level.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>What should a security investment business case demonstrate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee satisfaction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office expansion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business value<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor preference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security investment business case should demonstrate business value by explaining the risks being addressed, expected benefits, costs, dependencies, and potential effects on organizational objectives. Management needs sufficient information to determine whether an investment is justified relative to competing priorities. A strong business case may describe expected risk reduction, regulatory requirements, operational benefits, loss avoidance, or support for strategic initiatives. CISM emphasizes communicating security in business terms rather than relying exclusively on technical arguments. Security leaders should therefore connect proposed investments to measurable organizational outcomes and explain the consequences of not addressing the identified risk.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>What should happen when residual risk exceeds approved tolerance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accept automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Escalate it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the record<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When residual risk exceeds approved risk tolerance, the issue should be escalated to the appropriate risk owner or management authority for a decision. Possible responses may include implementing additional controls, changing the process, transferring risk, avoiding the activity, or formally accepting the remaining exposure if authorized. Automatically accepting excessive risk without appropriate authority weakens governance and accountability. CISM emphasizes that risk decisions should be made at the appropriate organizational level based on established criteria. Security professionals should provide clear information about the exposure, treatment options, costs, and potential business consequences to support informed management decisions.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which activity helps determine whether security resources are sufficient?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capability assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sales analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A capability assessment helps determine whether the organization has sufficient people, skills, processes, technology, and resources to meet its information security objectives. The assessment can compare current capabilities with required capabilities based on business strategy, risk exposure, regulatory obligations, and expected security services. Identifying gaps allows management to prioritize investments and determine whether training, recruitment, outsourcing, technology, or process changes are necessary. CISM emphasizes aligning resources with organizational requirements rather than assuming that existing capabilities are adequate. Capability assessments should be periodically repeated because business priorities, threats, technologies, and regulatory requirements change over time.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>What is the main purpose of data classification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine protection needs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce staffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improve advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data classification determines the level of protection information requires based on factors such as sensitivity, confidentiality, business value, regulatory requirements, and potential impact if compromised. Classification allows organizations to apply appropriate controls rather than treating every information asset identically. Highly sensitive information may require stronger access restrictions, encryption, monitoring, retention controls, or handling procedures. Classification should be supported by clear ownership and defined handling requirements. CISM emphasizes protecting information according to business value and risk. Effective classification therefore helps organizations prioritize security resources and apply controls proportionate to the consequences associated with unauthorized disclosure, alteration, or loss.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Who should generally be accountable for an information asset?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security analyst<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network technician<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Help desk agent<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The information asset owner should generally be accountable for determining appropriate protection requirements and ensuring that the asset is managed according to organizational policies and business needs. Security personnel can provide expertise and implement controls, but ownership should remain connected to the business function responsible for the information. The owner may determine classification, access requirements, retention needs, and acceptable use conditions. CISM emphasizes clear accountability because unclear ownership can result in unmanaged risks and conflicting decisions. Assigning ownership also helps ensure that security requirements reflect the actual business value and consequences associated with the information asset.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>What should security metrics primarily help management understand?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee hobbies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product design<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security metrics should help management understand security performance, business risk, control effectiveness, trends, and areas requiring decisions. Technical counts alone may have limited value if they cannot be connected to organizational consequences. For example, reporting the number of vulnerabilities may be less useful than showing how critical vulnerabilities affect important business services and whether remediation is progressing within acceptable timeframes. CISM emphasizes meaningful metrics that support management decision-making. Effective metrics should have clear objectives, reliable data, appropriate context, and understandable reporting. They should help management determine whether security investments and activities are producing the expected results.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which metric is most useful for senior management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk trend<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch commands<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business risk trend is generally more useful to senior management because it connects security information with organizational exposure and decision-making. Senior leaders typically need to understand whether significant risks are increasing, decreasing, or remaining stable and whether current investments are addressing important exposures. Highly technical measures can still be useful to security teams, but they should often be translated into business implications for executive audiences. CISM emphasizes audience-appropriate reporting and communication. Effective executive metrics should highlight material risks, trends, control effectiveness, resource requirements, and decisions that management may need to make.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>What should be done when a security metric no longer supports decisions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep it unchanged<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redesign it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hide the results<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security metric that no longer supports meaningful decisions should be redesigned or replaced. Metrics should remain aligned with security objectives, business requirements, risk indicators, and management information needs. Changes in technology, threats, organizational priorities, or reporting requirements may make previously useful metrics less relevant. Keeping ineffective measures simply because they have been used historically can consume resources without improving decision-making. CISM emphasizes continuous improvement, including periodic evaluation of security measurement practices. Organizations should determine whether each metric provides reliable and actionable information and modify measures when they no longer provide sufficient insight into performance or risk.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>What should guide the frequency of third-party security assessments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supplier preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk level<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office distance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk level should guide the frequency and depth of third-party security assessments. Suppliers handling sensitive information, supporting critical services, or creating significant operational dependencies may require more frequent or comprehensive assessments. Lower-risk suppliers may be assessed less frequently if justified by organizational criteria. A risk-based approach helps focus limited security resources where weaknesses could have the greatest business consequences. CISM emphasizes continuous third-party risk management rather than treating supplier assessment as a one-time procurement activity. Assessment frequency should therefore consider business criticality, data sensitivity, threat exposure, regulatory requirements, previous findings, and changes in the supplier relationship.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>What should be included in third-party security requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office decorations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Personal preferences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security obligations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sales forecasts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party agreements should include appropriate security obligations that define the supplier\u2019s responsibilities for protecting organizational information and services. Requirements may address access control, confidentiality, incident notification, data handling, security assessments, compliance, business continuity, and termination procedures. Specific requirements should reflect the risk and criticality of the relationship. Clearly documented obligations provide a basis for accountability and allow the organization to verify whether expected controls are being maintained. CISM emphasizes managing third-party risk throughout the relationship, so security requirements should be established before significant information or services are entrusted to the supplier and reviewed when circumstances change.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>What is the primary purpose of security awareness programs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expand offices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The primary purpose of security awareness programs is to influence behavior so employees and other users understand their security responsibilities and make safer decisions. Awareness should help users recognize threats, follow policies, protect information, report suspicious activity, and understand the consequences of unsafe behavior. Simply delivering training does not guarantee effectiveness, so organizations should evaluate whether awareness activities produce measurable behavioral improvements. CISM emphasizes aligning awareness programs with organizational risks and audience needs. Content should be relevant to actual threats and job responsibilities, while program effectiveness should be measured through indicators such as reporting behavior, policy compliance, and observed security practices.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>How should security training differ for privileged administrators?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use no training<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide role-based content<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use identical content<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Focus only on policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged administrators should receive role-based security training that reflects the elevated risks and responsibilities associated with administrative access. Their training may address privileged account protection, secure configuration, credential handling, logging, change management, incident reporting, and the consequences of misuse. Generic awareness content may not provide sufficient practical guidance for high-risk roles. CISM emphasizes tailoring security education to the audience, responsibilities, and risks involved. Organizations should periodically update role-based training as technologies, threats, policies, and responsibilities change. Effectiveness should also be evaluated to determine whether administrators demonstrate the expected security behaviors in practice.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>What should be done when a policy exception creates significant risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evaluate compensating controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a policy exception creates significant risk, the organization should evaluate whether compensating controls can reduce the exposure to an acceptable level. The exception should follow a formal approval process involving the appropriate risk owner and should include a documented business justification, duration, affected assets, and risk assessment. Compensating controls may provide alternative protection when the standard requirement cannot be implemented. CISM emphasizes controlled exception management because informal or permanent exceptions can weaken security governance. Exceptions should be periodically reviewed to determine whether the original business justification remains valid and whether the organization can eventually comply with the standard requirement.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>What should trigger reassessment of a security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office repainting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">New business risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee birthdays<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Furniture changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New business risks should trigger reassessment of the information security strategy because changes in organizational objectives, markets, technology, regulations, acquisitions, or threats can alter the security requirements of the enterprise. A strategy that was appropriate under previous conditions may no longer address current risks or priorities. Security leaders should evaluate whether objectives, resources, architecture, policies, and investments remain aligned with the organization. CISM emphasizes strategic alignment and continuous improvement, so security strategy should not be treated as a static document. Significant changes should lead to appropriate review and adjustment based on current business needs and risk conditions.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>What should management review to evaluate security program effectiveness?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office furniture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee schedules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product packaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management should review security objectives and related performance measures to evaluate whether the security program is achieving its intended outcomes. Evaluation should consider risk reduction, control effectiveness, business alignment, regulatory requirements, resource utilization, and progress against established objectives. Merely completing security activities does not prove that the program is effective if important risks remain unmanaged. CISM emphasizes outcome-based security management, where performance is assessed against organizational needs rather than activity volume alone. Regular management reviews can identify gaps, emerging risks, resource requirements, and opportunities for improvement, helping ensure that the security program continues to support business objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 321 What should guide information security strategy priorities? Business objectives Office capacity Employee preference Vendor location Correct Answer: 1 Explanation Information security strategy priorities should be guided by business objectives, organizational risks, regulatory requirements, and the protection needs of critical information assets. Security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22219"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22219"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22219\/revisions"}],"predecessor-version":[{"id":22220,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22219\/revisions\/22220"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}