Certified Information Security Manager · every answer carries the reasoning, and why each
other option fails.
1,312 questions
8 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
Which of the following steps should be FIRST in developing an information security plan?
APerform a technical vulnerabilities assessmentA technical vulnerability assessment produces a list of vulnerabilities; without the business strategy there is no way to judge which vulnerabilities truly threaten the organization's objectives. It belongs to the risk-identification stage and only has a basis for prioritization once the business direction is clear.
BAnalyze the current business strategy
CPerform a business impact analysisA business impact analysis is a precursor step within business continuity planning, focused on losses from availability disruption; using it as the first step of the whole security plan would narrow the scope. Its own judgment of criticality also depends on objectives supplied by the business strategy.
DAssess the current levels of security awarenessAssessing the current state of security awareness is part of a gap analysis, but for awareness to be effective staff need to understand the organization's business context and threats. Without knowing the business strategy, even the baseline of "what level of awareness should exist" cannot be set.
Why B is correct
The starting point of a security plan is the business, not technology. ISACA's fixed rule: for any FIRST-step planning question, ask first "what are the business objectives we are protecting" — only after understanding the current business strategy and direction can you know which assets are critical, which risks are worth managing, and where the subsequent vulnerability assessment and business impact analysis (BIA) should focus. Technical actions are not wrong actions, just later in sequence: their output only has meaning once it is hung on business objectives. The trap candidates fall into most often is treating the business impact analysis as an all-purpose first step — it is the first step on the business continuity planning track and covers only the availability dimension; placing it at the start of a security plan would miss confidentiality and integrity.
Question 2 of 10
A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:
Aan increased threat profile.Threats come from outside; they do not increase because we failed to patch.
Ba vulnerability management failure.Calling it a vulnerability management failure assigns blame to the process, whereas the question asks what this situation itself is.
Can increased risk profile.
Da security control failure.A control failure describes a control that did not work, whereas here the control simply was not executed, and the outcome is still elevated risk.
Why C is correct
Unpatched systems in violation of patching policy means known vulnerabilities remain open, and the organization's risk level rises as a result. No harm has occurred yet, so it is not an incident; it is a state that needs to enter the risk process for handling.
Question 3 of 10
Which of the following is the BEST approach for data owners to use when defining access privileges for users?
AImplement an identity and access management (IDM) tool.An IDM tool is an implementation mechanism; the tool alone does not resolve what privileges should be granted.
BAdopt user account settings recommended by the vendor.Adopting vendor-recommended default settings is usually too permissive and does not match the business.
CPerform a risk assessment of the users' access privileges.Performing a risk assessment for each individual's privileges is extremely costly and not sustainable.
DDefine access privileges based on user roles.
Why D is correct
Defining access privileges by role (RBAC) maps authorization to business function — when personnel change, only the role needs to change — which both enforces least privilege and remains maintainable. Defining privileges person by person quickly spirals out of control.
Question 4 of 10
Which of the following should be the MOST important consideration when prioritizing risk remediation?
AEvaluation of riskRisk evaluation is an input to prioritization; it does not itself provide a threshold.
BDuration of exposureDuration of exposure is one factor, not the primary criterion.
CComparison to risk appetite
DImpact of complianceImpact of compliance is a consideration specific to certain categories.
Why C is correct
Prioritization has to answer "which items must be addressed now." Comparing each risk against the organization's risk appetite lets items that exceed the appetite be remediated first while items within the appetite can wait — this is the only criterion with a clear threshold.
Question 5 of 10
The MOST important information for influencing management's support of information security is:
Aa report of a successful attack on a competitor.A report of a competitor being attacked can raise momentary alarm.
Ba demonstration of alignment with the business strategy.
Can identification of the overall threat landscape.Identifying the overall threat landscape is technical background.
Dan identification of organizational risks.Identifying organizational risks is a necessary input, but it still needs to be translated into business language.
Why B is correct
Whether management supports security or not depends on whether they believe security is helping the business. Demonstrating alignment between security and business strategy — turning security from a cost item into a business enabler — is the most effective way to persuade them.
Question 6 of 10
A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?
ATo gain an understanding of the current business direction
BTo update in accordance with the best business practicesUpdating according to best business practices lacks this organization's context.
CTo perform a risk assessment of the current IT environmentPerforming a risk assessment of the IT environment covers only the technical side.
DTo assess corporate cultureAssessing corporate culture is a factor that affects how execution happens.
Why A is correct
Policies that haven't been touched in five years likely no longer match a business that has very probably changed. Understanding the current business direction first is what tells you which direction the policies should be updated in; updating straight to best practice would leave them disconnected from the business.
Question 7 of 10
Which of the following is the PRIMARY purpose of implementing information security standards?
ATo provide a basis for developing information security policiesPolicies precede standards; they are not derived from standards.
BTo provide step-by-step instructions for performing security-related tasksStep-by-step instructions belong to procedures.
CTo provide management direction with a specific security objectiveProviding management direction is the function of policies.
DTo establish a minimum acceptable security baseline
Why D is correct
Standards translate policy intent into concrete requirements that must be met, establishing the minimum acceptable level of security. Policies set direction, procedures give steps, and guidelines offer recommendations—each has its own role.
Question 8 of 10
Which of the following BEST enables an information security manager to determine the comprehensiveness of an organization's information security strategy?
AInternal security auditAn internal security audit checks compliance with execution.
DBusiness impact analysis (BIA)A business impact analysis covers only the category of business-disruption risk.
Why B is correct
Whether a strategy is comprehensive depends on whether it covers the full range of risk the organization is willing and unwilling to accept. Risk appetite defines that range and so serves as the benchmark for measuring coverage.
Question 9 of 10
An organization's main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated risk?
AThe data ownerThe data owner is responsible for data classification and authorization.
BThe information security managerThe information security manager is responsible for assessment and driving action.
CThe security engineerThe security engineer is responsible for discovery and technical analysis.
DThe application owner
Why D is correct
The vulnerability sits with the cloud provider, but the risk falls on the business that depends on this application. The application owner bears the business consequences and has the authority to decide whether to keep using it or take it offline, which makes them the accountable party.
Question 10 of 10
The MOST useful technique for maintaining management support for the information security program is:
Ainforming management about the security of business operations.
Bidentifying the risks and consequences of failure to comply with standards.Emphasizing the risks and consequences of noncompliance applies pressure.
Cbenchmarking the security programs of comparable organizations.Benchmarking against comparable organizations' programs is an external reference.
Dimplementing a comprehensive security awareness and training program.Implementing an awareness and training program is aimed at the whole workforce.
Why A is correct
Keeping management continuously informed about the current security state of business operations — what is stable, where the risks are, and what the investment has bought — is the most effective way to maintain support.
These 10 are a sample
✓1,312 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓8 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal