CISM Information Security Program: 124 practice questions
12 of the 124 Information Security Program questions in the Certsqill CISM bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISM? Take the free 5-min readiness check →
1. Background checks and clean desk policy are administrative: Which classification CORRECTLY categorizes these c
- All five controls are preventive controls, and the classification into administrative/technical/physical is less important than their preventive function.Incorrect. CCTV is primarily a detective control (it detects/records incidents) rather than a preventive control. Additionally, the classification into administrative/technical/physical is fundamental to security architecture design, defense-in-depth planning, and control gap analysis. Both dimensions (control type and control function) are important.
- Background checks are technical; biometric access, CCTV, and full-disk encryption are physical; clean desk policy is administrative.Incorrect. Background checks are an administrative control (personnel procedure), not a technical control. Full-disk encryption is a technical control, not a physical control. This misclassification reflects a misunderstanding of the control type framework.
- Background checks and clean desk policy are administrative; biometric access and CCTV are physical; full-disk encryption is technical. ✓Correct. Administrative controls are policies, procedures, and people-based controls: background checks (pre-employment screening procedure) and clean desk policy (behavioral policy). Physical controls protect the physical environment: biometric access controls (physical access restriction) and CCTV (physical surveillance). Technical controls use technology to protect information: full-disk encryption (technical data protection mechanism).
- Background checks and clean desk policy are administrative; biometric access, CCTV, and full-disk encryption are all technical controls because they all use technology.Incorrect. Biometric access controls and CCTV are physical controls protecting the physical environment, even though they use technology to do so. The classification is based on what the control protects (the physical environment vs. information systems) not on whether technology is used. Full-disk encryption is correctly classified as technical.
Administrative controls include policies and procedures; physical controls protect the physical environment; technical controls use IT/software mechanisms.
2. The organization's HIPAA Business Associate Agreement: What is the CISM's MOST critical immediate concern?
- The organization's HIPAA Business Associate Agreement (BAA) obligations may have been violated by the vendor's undisclosed subcontracting arrangement without consent. ✓Correct. Under HIPAA, when a covered entity shares PHI with a Business Associate (the SaaS vendor), a Business Associate Agreement (BAA) is required. The BAA must include provisions requiring the Business Associate to ensure that any subcontractors (fourth parties) that access PHI also agree to the same HIPAA protections through a Subcontractor BAA. If the vendor subcontracted PHI processing without a Subcontractor BAA and without the covered entity's awareness, this constitutes a potential HIPAA violation regardless of the original contract's 'reasonable security measures' language. This is the immediate compliance and legal risk that requires urgent attention.
- The vendor's undisclosed subcontractor may have failed to implement encryption for data at rest and in transit, directly creating a PHI data breach exposure.Incorrect. While encryption is an important control, it is a secondary concern to the fundamental HIPAA compliance violation. The primary issue is not whether encryption is present, but whether the PHI transfer and processing arrangement is legally authorized under the BAA framework. An encryption gap can be remediated; a BAA violation may require immediate operational changes and regulatory notification.
- The original contract's vague 'reasonable security measures' clause is legally unenforceable and should be renegotiated to specify concrete technical security standards.Incorrect. While vague contractual language is a genuine procurement weakness that should be addressed in contract renegotiation, it is not the most critical immediate concern. The 'reasonable security measures' clause is a contract risk; the BAA violation is a regulatory compliance risk with potential financial penalties and mandatory notification requirements.
- The fourth party operates in a country lacking data protection laws equivalent to HIPAA, creating cross-border jurisdictional and data sovereignty risk for the organization.Incorrect. Jurisdictional risk and data sovereignty are valid concerns, particularly for GDPR-regulated data. For HIPAA-regulated PHI, the primary immediate concern is the BAA compliance failure, as HIPAA requirements follow the data regardless of geography. Jurisdictional risk is a serious long-term concern but is secondary to the immediate BAA violation.
The most critical immediate concern is that the subcontracting arrangement may violate HIPAA BAA requirements, which mandate that Business Associates ensure subcontractors also execute appropriate agreements before accessing PHI.
3. Present the CMMI maturity gap analysis alongside specific: Which approach provides the STRONGEST business case
- Reference published industry benchmarks showing that comparable financial institutions average one security staff member per 500 users, thereby demonstrating quantitatively that the current four-person team is significantly understaffed.Incorrect. Industry staffing benchmarks provide context but are weak business case justification because they compare headcount ratios without connecting to specific organizational risk outcomes. Regulators and executives are not compelled by benchmarks alone; they need to understand what specific risks will be reduced by the investment.
- Present the CMMI maturity gap analysis alongside specific risk scenarios that Level 2 versus Level 3 capabilities would handle differently, together with the estimated financial impact of each of those scenarios. ✓Correct. The strongest business case connects program investment to specific, measurable risk reduction outcomes. By showing what incidents or regulatory findings are more likely at Level 2 vs. Level 3, and estimating their financial impact (regulatory fines, incident response costs, business disruption), the CISM translates abstract maturity levels into concrete financial risk reduction. This approach speaks the executive team's language and provides a defensible return-on-investment narrative.
- Present the total projected cost of reaching CMMI Level 3 maturity and compare it directly against the average annual security budget at peer institutions to show that the organization is materially underinvesting in security.Incorrect. Comparing absolute budget figures to peers without adjusting for organizational size, risk profile, and threat environment is weak justification. The focus should be on the specific risk reduction achieved by the investment, not on matching peer spending levels.
- Cite several recent high-profile breaches at similar financial institutions and request budget to implement the same set of controls those breached organizations adopted in the aftermath of their own incidents.Incorrect. Citing peer breaches creates fear-based justification rather than risk-based justification. While it may generate short-term executive attention, it does not connect the investment to the organization's specific risk profile or demonstrate that the requested controls address the organization's actual vulnerabilities. This approach also has diminishing returns as breach news fades.
The strongest business case connects maturity improvements to specific risk scenarios and their financial impact, translating abstract program improvement into concrete risk reduction outcomes.
4. Implement role-based: Which approach is MOST effective?
- Purchase a commercial security awareness platform that bundles pre-built phishing simulations and a broad library of training content, then deploy it globally to all employees using a single standardized curriculum.Incorrect. Commercial platforms are useful tools but are not a program design strategy. Deploying standardized content globally from a commercial platform maintains the one-size-fits-all weakness of the previous program. The key improvement needed is role-based customization and behavioral measurement, which requires program design choices beyond tool selection.
- Focus the majority of program investment on the highest-risk roles such as finance and IT with intensive tailored training, while maintaining only the existing basic annual online course for all other employees.Incorrect. While role-based prioritization is valid, reducing awareness investment for 'lower-risk' roles creates weak links in the security chain. Manufacturing floor workers with physical access to IT assets, removable media, and social engineering vulnerability are high-risk vectors even if their roles are not traditionally considered 'high-risk' from a financial perspective.
- Implement role-based, multi-modal security awareness with content tailored to each audience's specific risk exposure, delivered in local languages, and supported by behavioral metrics that measure real program effectiveness. ✓Correct. An effective security awareness program for a large, diverse, global organization requires: (1) Role-based content—manufacturing workers need training on physical security, removable media, and social engineering in physical settings; financial analysts need training on phishing, insider threat, and data handling; (2) Multi-modal delivery—not just online training but simulations, in-person sessions, digital nudges, and job aids; (3) Localization—content in local languages and culturally adapted scenarios; (4) Behavioral metrics—not just completion rates but behavioral indicators like voluntary incident reporting, phishing simulation performance by role, and security behavior in audits.
- Replace the single annual training course with monthly micro-learning modules delivered through the existing LMS, covering a different information security topic each month to keep awareness continuously fresh for the entire global workforce.Incorrect. Increasing training frequency alone does not address the key weakness of the previous program: a one-size-fits-all approach for a diverse workforce. Manufacturing floor workers face different security risks than financial analysts, and a global organization must account for language and cultural differences. Frequency improvement without role-based customization maintains the fundamental design flaw.
Effective security awareness for diverse global organizations requires role-based content, multi-modal delivery, localization, and behavioral metrics rather than a single uniform training approach.
5. The ability to reduce analyst manual workload through: Final selection should be based on which criterion?
- The total cost of ownership calculated across a five-year horizon, since budget efficiency is the primary constraint facing a small three-person security analyst team at this organization.Incorrect. While TCO is an important evaluation criterion, it should not be the primary selection factor when the stated organizational objective is improving detection capability and reducing MTTD. Selecting the cheapest solution that doesn't achieve the MTTD reduction target fails to meet the business requirement.
- The vendor's overall market reputation and competitive position, since well-established leading vendors tend to provide more dependable long-term support and a stronger ongoing feature development roadmap over time.Incorrect. Vendor reputation is a risk management consideration for selection, not the primary selection criterion. Market leaders may not provide the best fit for this organization's specific requirements (hybrid cloud, 3-analyst team, MTTD focus). Selecting based on market position without validating fit to specific requirements often results in over-engineered solutions that increase analyst workload rather than reducing it.
- The ability to reduce analyst manual workload through automated triage and correlation, measured by the analyst time saved and the projected MTTD improvement demonstrated during the proof-of-concept. ✓Correct. The CISM's stated objective is to reduce MTTD by 50% for a 3-analyst team spending 70% of time on manual work. The primary selection criterion should directly measure whether the solution achieves this objective: automated triage and correlation capability that reduces manual work, with evidence from a proof-of-concept showing actual analyst time reduction and MTTD improvement. This aligns the technology selection with the security program objective and provides measurable evidence of outcome achievement.
- Native out-of-the-box integration with both Azure and the on-premises infrastructure, since seamless connectivity is what ultimately guarantees complete log collection and full visibility coverage across the hybrid environment.Incorrect. Native hybrid integration is a prerequisite (table stakes) for any viable solution in this environment, not a differentiating selection criterion. All three vendors have passed the technical evaluation, which presumably includes integration assessment. The differentiating criterion should be what distinguishes the vendors in achieving the stated objective: MTTD reduction and analyst workload reduction.
When multiple vendors pass technical evaluation, the final selection criterion should directly measure achievement of the stated objective: analyst workload reduction and MTTD improvement demonstrated in a proof-of-concept.
6. Implement a three-level scheme that maps: What approach should the CISM recommend?
- Adopt the security team's four-level scheme unchanged and invest in extensive enterprise-wide training so that employees learn to apply all four classification levels correctly.Incorrect. Complex classification schemes have poor adoption rates regardless of training investment. The business units' concern about complexity is valid—data classification effectiveness depends entirely on whether employees actually classify data correctly in daily work. 'Top Secret' and 'Secret' are government-oriented labels that may not resonate in a corporate context.
- Defer classification implementation until each business unit independently develops its own scheme reflecting local needs, then consolidate those separate schemes into a single enterprise classification standard once they mature.Incorrect. Allowing business units to develop independent classification schemes will result in inconsistent standards that are difficult to consolidate and may create compliance gaps. Enterprise data classification requires central design with business input, not decentralized development.
- Adopt the Legal team's five-level scheme with a distinct legally-privileged tier, because regulatory and legal requirements should take precedence over business usability and adoption concerns.Incorrect. Five classification levels will have even worse adoption than four. Legal requirements can be met within a simpler classification framework through handling procedures and labels rather than additional classification levels. Legal risk from poor classification adoption exceeds the risk from handling legally privileged documents within an existing category.
- Implement a three-level scheme (Restricted, Internal, Public) that maps to business-meaningful labels, with a special handling procedure for legally privileged documents embedded in the Restricted category. ✓Correct. Data classification programs succeed when they are: (1) Simple enough for all employees to apply consistently (fewer levels = better adoption), (2) Labeled in business-meaningful terms (Restricted/Confidential/Public is more intuitive than Top Secret/Secret in a corporate context), (3) Designed with handling requirements that are clear and actionable for each level. Legally privileged documents can be addressed through a special handling sub-category within Restricted (e.g., 'Restricted-Legal Privilege: Do not share without Legal approval') rather than a separate classification level, which would add complexity. A simple scheme with high adoption is more effective than a complex scheme with poor adoption.
Data classification programs succeed with simple, business-meaningful labels (typically 3 levels) and high adoption rather than complex schemes with poor compliance.
7. The charter will provide board or executive-level: What is the MOST important reason to establish a formal sec
- The charter will provide board or executive-level authorization for the security program's authority, scope, and requirements—making security requirements binding across all business units rather than optional recommendations. ✓Correct. A security program charter is a formal document approved by executive leadership (ideally the board or CEO) that authorizes the security program to operate, defines its scope, establishes the CISM's authority, and makes compliance with security requirements mandatory. When business units resist security requirements, the charter provides the organizational mandate that transforms security from a suggestion to a requirement. Without executive-level authorization, the CISM's authority depends on informal influence rather than organizational governance.
- The charter will establish the security program's formal budget authority, ensuring the CISM controls and allocates all security-related spending consistently across the organization's separate business units and cost centers.Incorrect. Budget authority is an important operational consideration but is not the primary purpose of a security program charter. The fundamental problem is authority over business unit behavior, not budget control.
- The charter will satisfy regulatory expectations for documented information security governance, protecting the organization from adverse regulatory findings during examinations by its financial services supervisors.Incorrect. While many regulators expect evidence of security governance, regulatory compliance is a secondary benefit of the charter, not its primary purpose in this scenario. The problem is internal authority and compliance, not regulatory documentation.
- The charter will document the security team's technical capabilities and service offerings so that business units understand which security services the program clearly provides.Incorrect. Service catalog documentation is useful but does not address the authority problem. Business units need to understand that security requirements are mandatory, not optional services they can choose to consume.
A security program charter provides board/executive-level authorization that transforms security requirements from optional recommendations into organizational mandates binding on all business units.
8. Extending the perimeter model to Azure creates: What is the PRIMARY architectural risk?
- Azure workloads placed behind the site-to-site VPN will experience higher network latency than internet-facing Azure services would, measurably reducing the performance of latency-sensitive financial applications.Incorrect. Application performance is an operational concern, not a security architectural risk. The question asks about security risk assessment.
- Extending the perimeter model to Azure creates an implicitly trusted network zone that eliminates the security boundaries between workloads, expanding the blast radius of any compromise to both environments simultaneously. ✓Correct. The 'extended data center' VPN model creates a flat trusted network between on-premises and Azure environments. If any workload in either environment is compromised, the attacker has lateral movement access to all systems in both environments without encountering security boundaries. This model negates the security benefits of cloud architecture (isolation, micro-segmentation, identity-based access) and creates a larger blast radius than either environment would have independently. The modern architectural principle is zero-trust, where no network zone is implicitly trusted.
- The edge firewall will be unable to inspect the encrypted traffic traversing the site-to-site VPN tunnel to Azure, creating a persistent monitoring blind spot that materially weakens the organization's threat detection capability.Incorrect. While encrypted traffic inspection is a valid security consideration, it is a detection control gap, not the primary architectural risk of the extended perimeter model. The fundamental architecture problem—implicit trust between environments—creates greater risk than a detection gap.
- The single site-to-site VPN connection introduces a single point of failure that could simultaneously disrupt network connectivity to both the on-premises and the Azure-hosted production workloads.Incorrect. While redundant connectivity is important, availability of the VPN connection is an operational concern, not the primary security architectural risk. The VPN can be made redundant. The architectural security problem is more fundamental.
Extending perimeter security to cloud via VPN creates a flat, implicitly trusted network that expands the blast radius of any compromise to both environments, eliminating security boundaries.
9. The program was implemented without executive-level: What is the ROOT CAUSE of this program failure?
- The central security team relied on champions to generate awareness organically instead of equipping them with the structured monthly communications and support materials they needed.Incorrect. Newsletters and one-way communication tools do not address the governance failures. Champions need organizational authority, management support, and time—not more content to distribute.
- The selected security champions did not receive sufficient technical security training to perform their liaison role effectively in their units.Incorrect. The failure symptoms—lack of management support and time allocation—point to a governance problem, not a training gap. Better training would not give champions the time or management backing they need to perform their role.
- The program was implemented without executive-level sponsorship and formal management accountability, leaving champions without the organizational support required for the program to function. ✓Correct. Security champion programs succeed when they have: (1) Executive-level sponsorship that signals organizational commitment, (2) Formal time allocation from champions' managers (typically 10-15% of work time), (3) Clear role expectations and charter that business unit managers acknowledge, (4) Recognition and career development benefits that make the role desirable, (5) Regular central team support and community of champions. Without these governance elements, champions are volunteers with additional responsibility and no authority or time—a recipe for failure. The symptoms (unsupported champions, no management time allocation) directly indicate missing governance structure.
- With only 85 champions serving a 15,000-person organization, the program lacked sufficient coverage and likely requires at least 150 active champions to become effective.Incorrect. Adding more champions to a program that is failing due to governance gaps will only create more unsupported, ineffective champions. Scale cannot fix a structural design problem.
Security champion programs fail when implemented without executive sponsorship and formal management accountability for champion time allocation—governance, not training or scale, is the critical success factor.
10. Implement a risk-based prioritization model combining CVSS: How should the CISM redesign the prioritization me
- Reduce the remediation backlog by first excluding all vulnerabilities that currently have no vendor patch available, then prioritizing the remaining items strictly by their CVSS base score.Incorrect. Excluding unpatched vulnerabilities removes them from visibility but not from risk. Compensating controls or vendor escalation may still be required. This approach also maintains the CVSS-only prioritization flaw demonstrated by the scenario.
- Maintain CVSS-only prioritization because it provides an objective, vendor-neutral scoring standard that removes subjective judgment from remediation decisions.Incorrect. The scenario directly illustrates CVSS prioritization failure: a CVSS 7.2 vulnerability being actively exploited on a critical public-facing system is more urgent than a CVSS 9.8 vulnerability on an isolated workstation with no network connectivity. CVSS measures technical severity without context; risk-based prioritization requires asset context and threat intelligence.
- Prioritize every internet-facing system above all internal systems and then apply CVSS within each tier, since external exposure raises the likelihood of exploitation.Incorrect. Internet exposure is one relevant factor but insufficient alone. Internal systems with high asset criticality or active lateral movement exploitation may require higher priority than internet-facing systems with low-severity vulnerabilities. Additionally, this approach doesn't incorporate threat intelligence about active exploitation.
- Implement a risk-based prioritization model combining CVSS score, asset criticality (business impact), and threat intelligence (active exploitation status) to determine remediation priority. ✓Correct. Risk-based vulnerability prioritization recognizes that remediation priority = f(vulnerability severity × asset criticality × exploitability). The CVSS 7.2 vulnerability on the public customer portal with active exploitation has: high asset criticality (customer-facing, revenue-generating), confirmed exploitability (active exploitation in the wild, internet-accessible). The CVSS 9.8 vulnerability on the air-gapped development workstation has: low asset criticality (non-production, isolated), near-zero exploitability (no network connectivity). The risk-based model correctly prioritizes the 7.2 vulnerability, which poses actual immediate business risk, over the 9.8 vulnerability that poses minimal risk due to isolation.
Risk-based vulnerability prioritization combines CVSS severity, asset criticality (business impact), and threat intelligence (active exploitation) rather than CVSS score alone.
11. Implement Just-in-Time privileged access using: What is the MOST effective privileged access management approa
- Remove DBA access to the databases containing PII and health records, and instead require formal business-unit approval for each individual access request to those sensitive systems.Incorrect. Removing access entirely and requiring business unit approval would severely impair operational effectiveness and may create delays that exceed the stated 2-hour emergency access requirement. The solution must balance security controls with operational requirements. Business unit approval is also the wrong control point—privileged access governance should involve the security team, not data owners, for every individual DBA task.
- Implement quarterly password rotation for all DBA service accounts and require every DBA to authenticate with an individual named account rather than continuing to use the current shared service accounts across all production databases.Incorrect. Individual accounts with quarterly password rotation is an improvement over shared accounts but fails to address the fundamental risk: persistent standing access to all 200 databases. DBAs with standing access can access any database at any time, creating insider threat risk and a large blast radius if credentials are compromised. The rotation interval also remains long for privileged access.
- Implement Just-in-Time (JIT) privileged access using a Privileged Access Management (PAM) solution that grants temporary, just-enough access to specific databases for approved tasks, with session recording and an emergency access pathway. ✓Correct. JIT privileged access addresses the core risk: standing persistent access. A PAM solution provides: (1) Just-in-Time access—DBAs request access to specific databases for specific tasks with time limits (4-hour window, auto-revoked), eliminating standing access. (2) Just-enough access—access is scoped to the specific databases needed for the task, not all 200. (3) Session recording—all privileged sessions are recorded for forensic accountability. (4) Emergency access pathway—break-glass procedures with immediate access and mandatory post-use review, with audit notification. This approach reduces the blast radius of compromised credentials, enables insider threat detection, and satisfies regulatory requirements for PII and health record access.
- Implement Multi-Factor Authentication (MFA) for all DBA accounts and review the production database access logs on a monthly basis to detect any inappropriate or anomalous privileged activity.Incorrect. MFA is an authentication strength improvement but does not address standing access or scope. A DBA with MFA and standing access to all 200 databases still poses the same insider threat risk and credential compromise blast radius. Monthly audit log review is too infrequent for privileged access monitoring.
JIT privileged access through a PAM solution eliminates standing access, scopes access to specific tasks, records all sessions, and provides an emergency pathway—addressing insider threat and credential compromise risks.
12. Level 2 means the organization's security practices are ad: How should the CISM respond?
- The CMMI maturity scale does not genuinely apply to security programs and should be replaced with a security-specific framework such as the NIST Cybersecurity Framework implementation tiers, which are far better suited for all future board-level security reporting and program improvement tracking.Incorrect. CMMI is widely applied to security programs and is recognized by ISACA and many regulatory bodies as a valid security program maturity measurement tool. The question is how to interpret the results accurately for the board, not whether to change the framework.
- Level 2 sits below the minimum maturity level required for regulated financial organizations, so the board should immediately fund a comprehensive Level 3 upgrade program in order to avoid future examination and regulatory findings across all assessed domains.Incorrect. Regulatory requirements vary significantly by jurisdiction and regulation. Many regulators do not prescribe specific CMMI maturity levels. Asserting a universal minimum maturity requirement without specifying the applicable regulation is inaccurate and potentially alarmist.
- Level 2 is broadly satisfactory for most industries in the sector, so the board should concentrate only on closing the incident response gap down from Level 3 in order to understand the additional security investment that is needed.Incorrect. CMMI Level 2 indicates that processes are performed but may be inconsistent, reactive, and undocumented across contexts. Whether Level 2 is satisfactory depends entirely on the organization's risk profile, industry regulatory requirements, and threat environment—not a universal standard. Characterizing Level 2 as broadly satisfactory without context is misleading.
- Level 2 means the organization's security practices are ad hoc and reactive; Level 3 would indicate standardized, documented processes. The maturity gap means security effectiveness varies by team and depends on individual expertise rather than consistent process—creating variable risk exposure. ✓Correct. CMMI Level 2 (Managed) means processes are planned and executed in accordance with defined policies but may vary by project or team and lack organization-wide standardization. Level 3 (Defined) means processes are standardized organization-wide with consistent application. The practical implication: at Level 2, security effectiveness depends on the skill and experience of individual practitioners rather than consistent organizational process. Security outcomes vary by team, making risk exposure less predictable. The board should understand this as variable, person-dependent risk rather than consistent programmatic risk reduction.
CMMI Level 2 means security effectiveness depends on individual practitioner expertise rather than consistent organizational process, creating variable and less predictable risk exposure.
112 more Information Security Program questions
The remaining 112 questions in this domain are part of the full CISM bank — 497 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISM readiness — freeOther CISM domains
- Information Security Governance — 131 questions →
- Information Security Risk Management — 124 questions →
- Incident Management — 118 questions →
- All 497 CISM questions →