Home > General Studies (Hindi) > Quizzes > Certified Information Security Manager (CISM) Test Prep Questions
Certified Information Security Manager (CISM) Test Prep Questions
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 38% Most missed: “A control for protecting an information technology (IT) asset, such as a laptop …”

ISACA CISM Exam syllabus in brief:

Information Security Governance    
A. Enterprise Governance
B. Information Security Strategy

Information Security Risk Management    
A. Information Security Risk Assessment
B. Information Security Risk Response

Information Security Program    
A. Information Security Program Development
B. Information Security Program Management

Incident Management    
A. Incident Management Readiness
B. Incident Management Operations

Certified Information Security Manager (CISM) Test Prep Questions
Time left 00:00
25 Questions

1. Which of the following is MOST likely to be discretionary?
2. The FIRST step to create an internal culture that embraces information security is to:
3. The FIRST step in developing an information security management program is to:
4. An organization has identified a major threat to which it is vulnerable. Which of the following choices is the BEST reason why information security management would not be concerned with preventive remediation under these circumstances?
5. Which of the following attributes would be MOST essential to developing effective metrics?
6. The PRIMARY objective of asset classification is to:
7. Which of the following would be MOST useful in developing a series of recovery time objectives?
8. Highly integrated enterprise IT systems pose a challenge to the information security manager when attempting to set security baselines PRIMARILY from the perspective of:
9. The output of the risk management process is an input for making:
10. What is the initial step that an information security manager would take during the requirements gathering phase of an IT project to avoid project failure?
11. Which of the following choices BEST helps determine appropriate levels of information resource protection?
12. From an information security perspective, which of the following will have the GREATEST impact on a financial enterprise with offices in various countries and involved in transborder transactions?
13. Which of the following choices would be the BEST measure of the effectiveness of a risk assessment?
14. Which of the following items determines the acceptable level of residual risk in an organization?
15. Who should generally determine the classification of an information asset?
16. The PRIMARY goal of a corporate risk management program is to ensure that an organization's:
17. When recommending a control to protect corporate applications against structured query language injection, the information security manager is MOST likely to suggest:
18. Which of the following is characteristic of decentralized information security management across a geographically dispersed organization?
19. Controls are effective when:
20. Laws and regulations should be addressed by the information security manager:
21. The information classification scheme should:
22. The aspect of governance that is MOST relevant to setting security baselines is:
23. Who is responsible for raising awareness of the need for adequate funding to support risk mitigation plans?
24. Of the following, what does a network vulnerability assessment expect to identify?
25. What is the PRIMARY purpose of segregation of duties?