Official Bank 0/965

Certified Information Security Manager Exam (CISM) - Isaca Actual Exam Questions

Last updated on May 02, 2026

97% Exam Compliance
965 Total Questions
1
Question

The PRIMARY objective of performing a post-incident review is to:

Options
A

re-evaluate the impact of incidents

B

identify vulnerabilities

C

identify control improvements.

D

identify the root cause.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

Reviewing which of the following would be MOST helpful when a new information security manager is developing an information security strategy for a non-regulated organization?

Options
A

Management's business goals and objectives

B

Strategies of other non-regulated companies

C

Risk assessment results

D

Industry best practices and control recommendations

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

An information security manager is working to incorporate media communication procedures into the security incident communication plan. It would be MOST important to include:

Options
A

a directory of approved local media contacts

B

pre-prepared media statements

C

procedures to contact law enforcement

D

a single point of contact within the organization

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Which of the following would be the GREATEST obstacle to implementing incident notification and escalation processes in an organization with high turnover?

Options
A

Lack of knowledgeable personnel

B

Lack of communication processes

C

Lack of process documentation

D

Lack of alignment with organizational goals

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Who is BEST suited to determine how the information in a database should be classified?

Options
A

Database analyst

B

Database administrator (DBA)

C

Information security analyst

D

Data owner

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.