
[Sep 22, 2025] Today Updated CISM Exam Dumps Actual Questions
CISM exam dumps with real ISACA questions and answers
The CISM certification is ideal for individuals who are responsible for managing the information security programs of their organizations. These individuals may include IT managers, security managers, security consultants, and security auditors. Certified Information Security Manager certification is also beneficial for individuals who are looking to advance their career in the field of information security.
NEW QUESTION # 16
The value of information assets relative to the organization is BEST determined by:
- A. a threat assessment.
- B. an impact analysis.
- C. a risk assessment.
- D. an asset classification.
Answer: C
NEW QUESTION # 17
Which of the following should be the FIRST step of incident response procedures?
- A. Evaluate the cause of the control failure
- B. Perform a risk assessment to determine the business impact
- C. Classify the event depending on severity and type
- D. Identify if there is a need for additional technical assistance
Answer: C
NEW QUESTION # 18
Which of the following is the MOST effective way to protect the authenticity of data in transit?
- A. Hash value
- B. Private key
- C. Digital signature
- D. Public key
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION # 19
When a user employs a client-side digital certificate to authenticate to a web server through Secure Socket Layer (SSL), confidentiality is MOST vulnerable to which of the following?
- A. IP spoofing
- B. Man-in-the-middle attack
- C. Trojan
- D. Repudiation
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation:
A Trojan is a program that gives the attacker full control over the infected computer, thus allowing the attacker to hijack, copy or alter information after authentication by the user. IP spoofing will not work because IP is not used as an authentication mechanism. Man-in-the-middle attacks are not possible if using SSL with client-side certificates. Repudiation is unlikely because client-side certificates authenticate the user.
NEW QUESTION # 20
At what stage of the applications development process would encryption key management initially be addressed?
- A. Code reviews
- B. Requirements development
- C. Deployment
- D. Systems testing
Answer: B
Explanation:
Explanation
Encryption key management has to be integrated into the requirements of the application's design. During systems testing and deployment would be too late since the requirements have already been agreed upon. Code reviews are part of the final quality assurance (QA) process and would also be too late in the process.
NEW QUESTION # 21
Which of the following is MOST important in determining whether a disaster recovery test is successful?
- A. Only business data files from offsite storage are used
- B. Critical business processes are duplicated
- C. IT staff fully recovers the processing infrastructure
- D. All systems are restored within recovery time objectives (RTOs)
Answer: B
Explanation:
Explanation/Reference:
Explanation:
To ensure that a disaster recovery test is successful, it is most important to determine whether all critical business functions were successfully recovered and duplicated. Although ensuring that only materials taken from offsite storage are used in the test is important, this is not as critical in determining a test's success. While full recovery of the processing infrastructure is a key recovery milestone, it does not ensure the success of a test. Achieving the RTOs is another important milestone, but does not necessarily prove that the critical business functions can be conducted, due to interdependencies with other applications and key elements such as data, staff, manual processes, materials and accessories, etc.
NEW QUESTION # 22
Which of the following is the FIRST step to establishing an effective information security program?
- A. Conduct a compliance review.
- B. Create a business case.
- C. Perform a business impact analysis (BIA).
- D. Assign accountability.
Answer: B
Explanation:
According to the CISM Review Manual, the first step to establishing an effective information security program is to create a business case that aligns the program objectives with the organization's goals and strategies. A business case provides the rationale and justification for the information security program and helps to secure the necessary resources and support from senior management and other stakeholders. A business case should include the following elements:
* The scope and objectives of the information security program
* The current state of information security in the organization and the gap analysis
* The benefits and value proposition of the information security program
* The risks and challenges of the information security program
* The estimated costs and resources of the information security program
* The expected outcomes and performance indicators of the information security program
* The implementation plan and timeline of the information security program References = CISM Review Manual, 16th Edition, Chapter 3, Section 2, pages 97-99.
NEW QUESTION # 23
Which of the following is the BEST way to measure the effectiveness of a newly implemented social engineering training program?
- A. Administer quizzes upon completion of training.
- B. Test end user response to simulated scenarios
- C. Track the trending of malware infections.
- D. Track the trending of reported security incidents
Answer: B
NEW QUESTION # 24
To help ensure that contract personnel do not obtain unauthorized access to sensitive information, an information security manager should PRIMARILY:
- A. ensure they successfully pass background checks.
- B. set their accounts to expire in six months or less.
- C. avoid granting system administration roles.
- D. ensure their access is approved by the data owner.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Contract personnel should not be given job duties that provide them with power user or other administrative roles that they could then use to grant themselves access to sensitive files. Setting expiration dates, requiring background checks and having the data owner assign access are all positive elements, but these will not prevent contract personnel from obtaining access to sensitive information.
NEW QUESTION # 25
Which of the following has The GREATEST positive impact on The ability to execute a disaster recovery plan (DRP)?
- A. Conducting a walk-through of the plan
- B. Updating the plan periodically
- C. Communicating the plan to all stakeholders
- D. Storing the plan at an offsite location
Answer: A
Explanation:
Explanation
A walk-through of the disaster recovery plan (DRP) is a method of testing the plan by simulating a disaster scenario and having the participants review their roles and responsibilities, as well as the procedures and resources required to execute the plan. A walk-through has the greatest positive impact on the ability to execute the DRP, as it helps to identify and resolve any gaps, errors, or inconsistencies in the plan, as well as to enhance the awareness and readiness of the stakeholders involved in the recovery process. References = CISM Review Manual, 16th Edition, Chapter 5, Section 5.3.2.21
NEW QUESTION # 26
A multinational organization's information security manager has been advised that the city in which a contracted regional data center is located is experiencing civil unrest. The information security manager should FIRST:
- A. engage another service provider at a safer location
- B. verify the provider's ability to protect the organization's data
- C. evaluate options to recover if the data center becomes unreachable
- D. delete the organization's sensitive data at the provider's location
Answer: B
NEW QUESTION # 27
To ensure appropriate control of information processed in IT systems, security safeguards should be based PRIMARILY on:
- A. overall IT capacity and operational constraints
- B. criteria consistent with classification levels
- C. established guidelines
- D. efficient technical processing considerations
Answer: C
NEW QUESTION # 28
Data owners are PRIMARILY responsible for establishing risk mitigation methods to address which of the following areas?
- A. Entitlement changes
- B. Platform security
- C. Antivirus controls
- D. Intrusion detection
Answer: A
Explanation:
Data owners are responsible for assigning user entitlements and approving access to the systems for which they are responsible. Platform security, intrusion detection and antivirus controls are all within the responsibility of the information security manager.
NEW QUESTION # 29
An outsourced vendor handles an organization's business-critical data. Which of the following is the MOST effective way for the client organization to obtain assurance of the vendor's security practices?
- A. Requiring business continuity plans (BCPs) from the vendor
- B. Verifying security certifications held by the vendor
- C. Requiring periodic independent third-party reviews
- D. Reviewing the vendor's security audit reports
Answer: D
NEW QUESTION # 30
Which of the following is the BEST indication that an organization has a mature information security culture?
- A. Information security training is mandatory for all staff.
- B. The chief information security officer (CISO) regularly interacts with the board.
- C. The organization's information security policy is documented and communicated.
- D. Staff consistently consider risk in making decisions.
Answer: D
Explanation:
Explanation
The BEST indication that an organization has a mature information security culture is when its staff consistently consider risk in making decisions. When an organization's staff understands the risks associated with their actions and are empowered to make risk-informed decisions, it indicates that the organization has a mature information security culture.
According to the Certified Information Security Manager (CISM) Study Manual, "A mature information security culture exists when the people within the organization understand and appreciate the risks associated with information and technology and when they take steps to manage those risks on a daily basis." While information security training, documented information security policies, and regular interaction between the chief information security officer (CISO) and the board are all important components of a mature information security culture, they are not sufficient on their own. It is only when staff consistently consider risk in making decisions that an organization's information security culture can be considered mature.
NEW QUESTION # 31
An information security manager is assisting in the development of the request for proposal (RFP) for a new outsourced service. This will require the third party to have access to critical business information. The security manager should focus PRIMARILY on defining:
- A. security metrics
- B. service level agreements (SLAs)
- C. risk-reporting methodologies.
- D. security requirements for the process being outsourced.
Answer: D
Explanation:
Explanation
An information security manager is assisting in the development of the request for proposal (RFP) for a new outsourced service. This will require the third party to have access to critical business information. The security manager should focus primarily on defining security requirements for the process being outsourced.
Security requirements are the specifications of what needs to be done to protect the information assets from unauthorized access, use, disclosure, modification, or destruction. Security requirements should be aligned with the organization's risk appetite and business objectives, and should cover both technical and organizational aspects of the service delivery. Security requirements should also be clear, concise, measurable, achievable, realistic, and testable. References = CISM Review Manual (Digital Version), Chapter 3:
Information Security Risk Management, Section 3.1: Risk Identification, p. 115-1161. CISM Review Manual (Print Version), Chapter 3: Information Security Risk Management, Section 3.1: Risk Identification, p. 115-1162. CISM ITEM DEVELOPMENT GUIDE, Domain 3: Information Security Program Development and Management, Task Statement 3.1, p. 193.
Security requirements for the process being outsourced are the specifications and standards that the third party must comply with to ensure the confidentiality, integrity and availability of the critical business information.
They define the roles and responsi-bilities of both parties, the security controls and measures to be implemented, the se-curity objectives and expectations, the security risks and mitigation strategies, and the security monitoring and reporting mechanisms. Security requirements are essential to protect the information assets of the organization and to establish a clear and en-forceable contractual relationship with the third party.
References:
*1 Outsourcing Strategies for Information Security: Correlated Losses and Security Exter-nalities - SpringerLink
*2 What requirements must outsourcing services comply with for the European market? - CBI
*3 Outsourcing cybersecurity: What services to outsource, what to keep in house - Infosec Institute
*4 BCFSA outsourcing and information security guidelines - BLG
NEW QUESTION # 32
An effective way of protecting applications against Structured Query Language (SQL) injection vulnerability is to:
- A. ensure that the security patches are updated on operating systems.
- B. harden the database listener component.
- C. validate and sanitize client side inputs.
- D. normalize the database schema to the third normal form.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
SQL injection vulnerability arises when crafted or malformed user inputs are substituted directly in SQL queries, resulting into information leakage. Hardening the database listener does enhance the security of the database; however, it is unrelated to the SQL injection vulnerability. Normalization is related to the effectiveness and efficiency of the database but not to SQL injection vulnerability. SQL injections may also be observed in normalized databases. SQL injection vulnerability exploits the SQL query design, not the operating system.
NEW QUESTION # 33
Which of the following would be MOST effective in reducing the impact of a distributed denial of service (DDoS) attack?
- A. Spread a site across multiple ISPs.
- B. Harden network security.
- C. Block the attack at the source.
- D. Impose state limits on servers.
Answer: A
Explanation:
Explanation
The answer to the question is B. Spread a site across multiple ISPs. This is because spreading a site across multiple Internet service providers (ISPs) can help to reduce the impact of a distributed denial of service (DDoS) attack by increasing the bandwidth and redundancy of the site, and making it harder for the attacker to target and overwhelm a single point of failure. Spreading a site across multiple ISPs can also help to distribute the traffic load and balance the performance of the site, and to mitigate the effects of regional or network-specific outages or disruptions. Spreading a site across multiple ISPs can be done by using various techniques, such as anycast routing, content delivery networks (CDNs), or cloud-based services12.
Spreading a site across multiple ISPs can help to reduce the impact of a DDoS attack by increasing the bandwidth and redundancy of the site, and making it harder for the attacker to target and overwhelm a single point of failure. (From CISM Manual or related resources) References = CISM Review Manual 15th Edition, Chapter 4, Section 4.2.1, page 2091; DDoS Attacks-A Cyberthreat and Possible Solutions2
NEW QUESTION # 34
Which of the following BEST facilitates effective strategic alignment of security initiatives?
- A. Organizational units contribute to and agree on priorities
- B. Periodic security audits are conducted by a third-party.
- C. Procedures and standards are approved by department heads.
- D. The business strategy is periodically updated
Answer: A
Explanation:
Organizational units contribute to and agree on priorities is the best way to facilitate effective strategic alignment of security initiatives because it ensures that the security initiatives are aligned with the business goals and objectives, supported by relevant stakeholders, and prioritized based on risk and value. The business strategy is periodically updated is not sufficient to facilitate effective strategic alignment of security initiatives because it does not involve collaboration or communication between different organizational units.
Procedures and standards are approved by department heads is not sufficient to facilitate effective strategic alignment of security initiatives because it does not reflect the strategic direction or vision of the organization.
Periodic security audits are conducted by a third-party is not sufficient to facilitate effective strategic alignment of security initiatives because it does not address the planning or implementation of security initiatives. References: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/how-to-align- security-initiatives-with-business-goals-and-objectives https://www.isaca.org/resources/isaca-journal/issues
/2015/volume-1/how-to-measure-the-effectiveness-of-information-security-governance
NEW QUESTION # 35
Which of the following should be the PRIMARY objective of an information security governance framework?
- A. Provide a baseline for optimizing the security profile of the organization.
- B. Demonstrate senior management commitment.
- C. Ensure that users comply with the organization's information security policies.
- D. Demonstrate compliance with industry best practices to external stakeholders.
Answer: A
Explanation:
According to the Certified Information Security Manager (CISM) Study Manual, "The primary objective of information security governance is to provide a framework for managing and controlling information security practices and technologies at an enterprise level. Its goal is to manage and reduce risk through a process of identification, assessment, and management of those risks." While demonstrating senior management commitment, compliance with industry best practices, and ensuring user compliance with policies are all important aspects of information security governance, they are not the primary objective. The primary objective is to manage and reduce risk by establishing a framework for managing and controlling information security practices and technologies at an enterprise level.
Reference:
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 60.
NEW QUESTION # 36
Who is responsible for ensuring that information is classified?
- A. Senior management
- B. Custodian
- C. Security manager
- D. Data owner
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The data owner is responsible for applying the proper classification to the data. Senior management is ultimately responsible for the organization. The security officer is responsible for applying security protection relative to the level of classification specified by the owner. The technology group is delegated the custody of the data by the data owner, but the group does not classify the information.
NEW QUESTION # 37
Failure to include information security requirements within the build/buy decision would MOST likely result in the need for:
- A. compensating controls in the operational environment.
- B. security scanning of operational platforms.
- C. more stringent source programming standards.
- D. commercial product compliance with corporate standards.
Answer: A
NEW QUESTION # 38
A finance department director has decided to outsource the organization's budget application and has identified potential providers. Which of the following actions should be initiated FIRST by IN information security manager?
- A. Determine the required security controls for the new solution
- B. Obtain audit reports on the service providers' hosting environment
- C. Align the roles of the organization's and the service providers' stats.
- D. Review the disaster recovery plans (DRPs) of the providers
Answer: A
Explanation:
Before outsourcing any application or service, an information security manager should first determine the required security controls for the new solution, based on the organization's risk appetite, security policies and standards, and regulatory requirements. This will help to evaluate and select the most suitable provider, as well as to define the security roles and responsibilities, service level agreements (SLAs), and audit requirements. References: https://www.isaca.org/credentialing/cism https://www.wiley.com/en-us
/CISM+Certified+Information+Security+Manager+Study+Guide-p-9781119801948
NEW QUESTION # 39
Which of the following is the BEST indication ofa successful information security culture?
- A. The budget allocated for information security is sufficient.
- B. Penetration testing is done regularly and findings remediated.
- C. Individuals are given roles based on job functions.
- D. End users know how to identify and report incidents.
Answer: D
Explanation:
The best indication of a successful information security culture is that end users know how to identify and report incidents. This shows that the end users are aware of the information security policies, procedures, and practices of the organization, and that they understand their roles and responsibilities in protecting the information assets and resources. It also shows that the end users are engaged and committed to the information security goals and objectives of the organization, and that they are willing to cooperate and collaborate with the information security team and other stakeholders in preventing, detecting, and responding to information security incidents. A successful information security culture is one that fosters a positive attitude and behavior toward information security among all members of the organization, and that aligns the information security strategy with the business strategy and the organizational culture1.
References = CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section:
Information Security Culture, page 281.
NEW QUESTION # 40
Which of the following is the MOST important risk associated with middleware in a client-server environment?
- A. System backups may be incomplete
- B. Server patching may be prevented
- C. System integrity may be affected
- D. End-user sessions may be hijacked
Answer: C
Explanation:
Explanation/Reference:
Explanation:
The major risk associated with middleware in a client-server environment is that system integrity may be adversely affected because of the very purpose of middleware, which is intended to support multiple operating environments interacting concurrently. Lack of proper software to control portability of data or programs across multiple platforms could result in a loss of data or program integrity. All other choices are less likely to occur.
NEW QUESTION # 41
......
Exam Sure Pass ISACA Certification with CISM exam questions: https://passleader.examtorrent.com/CISM-prep4sure-dumps.html
