Home > CompTIA Security+ Certification > Quizzes > Certified Information Security Manager (CISM) Test Prep Questions
Certified Information Security Manager (CISM) Test Prep Questions
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 38% Most missed: “A control for protecting an information technology (IT) asset, such as a laptop …”

ISACA CISM Exam syllabus in brief:

Information Security Governance    
A. Enterprise Governance
B. Information Security Strategy

Information Security Risk Management    
A. Information Security Risk Assessment
B. Information Security Risk Response

Information Security Program    
A. Information Security Program Development
B. Information Security Program Management

Incident Management    
A. Incident Management Readiness
B. Incident Management Operations

Certified Information Security Manager (CISM) Test Prep Questions
Time left 00:00
25 Questions

1. What is the initial step that an information security manager would take during the requirements gathering phase of an IT project to avoid project failure?
2. Which of the following is the MOST important action to take when engaging third-party consultants to conduct an attack and penetration test?
3. Assuming that the value of information assets is known, which of the following gives the information security manager the MOST objective basis for determining that the information security program is delivering value?
4. The MOST appropriate role for senior management in supporting information security is the:
5. An organization's information security manager has been asked to hire a consultant to help assess the maturity level of the organization's information security management. What is the MOST important element of the request for proposal?
6. Which of the following roles is MOST responsible for ensuring that information protection policies are consistent with applicable laws and regulations?
7. Which of the following is the MOST important factor to be considered in the loss of mobile equipment with unencrypted data?
8. What is the PRIMARY purpose of segregation of duties?
9. Assuming all options are technically feasible, which of the following would be the MOST effective approach for the information security manager to address excessive exposure of a critical customer-facing server?
10. For which of the following types of controls is notification of a verified network intrusion an indication that the control is working properly?
11. Which of the following is BEST used to define minimum requirements for database security settings?
12. Which of the following project activities is the MAIN activity in developing an information security program?
13. Information security governance is PRIMARILY driven by:
14. Which of the following will require the MOST effort when supporting an operational information security program?
15. An IS manager has decided to implement a security system to monitor access to the Internet and prevent access to numerous sites. Immediately upon installation, employees flood the IT helpdesk with complaints of being unable to perform business functions on Internet sites. This is an example of:
16. A new business application requires deviation from the standard configuration of the operating system (OS). Which of the following steps should the security manager take FIRST?
17. The MOST important aspect in establishing good information security policies is to ensure that they:
18. A control policy is MOST likely to address which of the following implementation requirements?
19. The PRIMARY goal of a corporate risk management program is to ensure that an organization's:
20. The return on investment of information security can BEST be evaluated through which of the following?
21. Which of the following choices would be the MOST useful in determining the possible consequences of a major compromise?
22. The director of auditing has recommended a specific information security monitoring solution to the information security manager. What should the information security manager do FIRST?
23. Abnormal server communication from inside the organization to external parties may be monitored to:
24. When should risk assessments be performed for optimum effectiveness?
25. Which of the following is PRIMARILY related to the emergence of governance, risk and compliance?