PassFish

CISM practice questions — 10 free

Certified Information Security Manager · every answer carries the reasoning, and why each other option fails.
1,312 questions
8 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

Which of the following steps should be FIRST in developing an information security plan?

Why B is correct

The starting point of a security plan is the business, not technology. ISACA's fixed rule: for any FIRST-step planning question, ask first "what are the business objectives we are protecting" — only after understanding the current business strategy and direction can you know which assets are critical, which risks are worth managing, and where the subsequent vulnerability assessment and business impact analysis (BIA) should focus. Technical actions are not wrong actions, just later in sequence: their output only has meaning once it is hung on business objectives. The trap candidates fall into most often is treating the business impact analysis as an all-purpose first step — it is the first step on the business continuity planning track and covers only the availability dimension; placing it at the start of a security plan would miss confidentiality and integrity.

Question 2 of 10

A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:

Why C is correct

Unpatched systems in violation of patching policy means known vulnerabilities remain open, and the organization's risk level rises as a result. No harm has occurred yet, so it is not an incident; it is a state that needs to enter the risk process for handling.

Question 3 of 10

Which of the following is the BEST approach for data owners to use when defining access privileges for users?

Why D is correct

Defining access privileges by role (RBAC) maps authorization to business function — when personnel change, only the role needs to change — which both enforces least privilege and remains maintainable. Defining privileges person by person quickly spirals out of control.

Question 4 of 10

Which of the following should be the MOST important consideration when prioritizing risk remediation?

Why C is correct

Prioritization has to answer "which items must be addressed now." Comparing each risk against the organization's risk appetite lets items that exceed the appetite be remediated first while items within the appetite can wait — this is the only criterion with a clear threshold.

Question 5 of 10

The MOST important information for influencing management's support of information security is:

Why B is correct

Whether management supports security or not depends on whether they believe security is helping the business. Demonstrating alignment between security and business strategy — turning security from a cost item into a business enabler — is the most effective way to persuade them.

Question 6 of 10

A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?

Why A is correct

Policies that haven't been touched in five years likely no longer match a business that has very probably changed. Understanding the current business direction first is what tells you which direction the policies should be updated in; updating straight to best practice would leave them disconnected from the business.

Question 7 of 10

Which of the following is the PRIMARY purpose of implementing information security standards?

Why D is correct

Standards translate policy intent into concrete requirements that must be met, establishing the minimum acceptable level of security. Policies set direction, procedures give steps, and guidelines offer recommendations—each has its own role.

Question 8 of 10

Which of the following BEST enables an information security manager to determine the comprehensiveness of an organization's information security strategy?

Why B is correct

Whether a strategy is comprehensive depends on whether it covers the full range of risk the organization is willing and unwilling to accept. Risk appetite defines that range and so serves as the benchmark for measuring coverage.

Question 9 of 10

An organization's main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated risk?

Why D is correct

The vulnerability sits with the cloud provider, but the risk falls on the business that depends on this application. The application owner bears the business consequences and has the authority to decide whether to keep using it or take it offline, which makes them the accountable party.

Question 10 of 10

The MOST useful technique for maintaining management support for the information security program is:

Why A is correct

Keeping management continuously informed about the current security state of business operations — what is stable, where the risks are, and what the investment has bought — is the most effective way to maintain support.

These 10 are a sample

See the full bank