- 1191 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Certified Information Security Manager Exam Questions with Validated Answers
| Vendor: | Isaca |
|---|---|
| Exam Code: | CISM |
| Exam Name: | Certified Information Security Manager |
| Exam Questions: | 1191 |
| Last Updated: | August 20, 2026 |
| Related Certifications: | Certified Information Security Manager |
| Exam Tags: | ISACA Security Management Advanced Level Information Security Managers and Security Consultants |
Looking for a hassle-free way to pass the Isaca Certified Information Security Manager exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Isaca certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Isaca CISM exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Isaca CISM exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Isaca CISM exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Isaca CISM exam dumps today and achieve your certification effortlessly!
Which of the following is the PRIMARY outcome of a business impact analysis (BIA)?
The primary outcome of a BIA is the identification of critical business functions and prioritization of recovery efforts (D). CISM defines the BIA as the foundation for continuity and resilience planning, providing insight into impact, recovery priorities, and tolerable downtime. The other options represent secondary or unrelated benefits.
Which of the following should be the PRIMARY objective when establishing a new information security program?
According to the CISM Review Manual, the primary objective when establishing a new information security program is to execute the security strategy that has been defined and approved by the senior management. The security strategy provides the direction, scope, and goals for the information security program, and aligns with the business objectives and requirements. Minimizing organizational risk, optimizing resources, and facilitating operational security are possible outcomes or benefits of the information security program, but they are not the primary objective.
References= CISM Review Manual, 27th Edition, Chapter 3, Section 3.1.1, page 1151.
An organization is creating a risk mitigation plan that considers redundant power supplies to reduce the business risk associated with critical system outages. Which type of control is being considered?
A preventive control is a type of control that aims to prevent or reduce the occurrence or impact of potential adverse events that can affect the organization's objectives and performance. Preventive controls are proactive measures that are implemented before an incident happens, and they are designed to address the root causes or sources of risk.Preventive controls can also help the organization to comply with the relevant laws, regulations, standards, and best practices regarding information security1.
An example of a preventive control is a redundant power supply, which is a backup or alternative source of power that can be used in case of a power outage or failure. A redundant power supply can reduce the business risk associated with critical system outages, which can result from power disruptions caused by natural disasters, technical faults, human errors, or malicious attacks.A redundant power supply can provide the following benefits for information security2:
Maintain the availability and continuity of the critical systems and services that depend on power, such as servers, databases, networks, or applications. A redundant power supply can ensure that the critical systems and services can operate normally or resume quickly after a power outage or failure, minimizing the downtime and data loss that can affect the organization's operations, customers, or reputation.
Protect the integrity and reliability of the critical systems and data that are stored or processed by the power-dependent devices, such as computers, hard drives, or memory cards. A redundant power supply can prevent or reduce the damage or corruption of the critical systems and data that can be caused by sudden or unexpected power fluctuations, surges, or interruptions, which can compromise the accuracy, completeness, or consistency of the information.
Enhance the resilience and redundancy of the power infrastructure and network that supports the critical systems and services. A redundant power supply can provide an alternative or backup route for power delivery and distribution, which can increase the flexibility and adaptability of the power infrastructure and network to cope with different scenarios or conditions of power supply or demand.
The other options are not the type of control that is being considered by the organization. A corrective control is a type of control that aims to restore or recover the normal state or function of the affected systems or processes after an incident has occurred. A corrective control is a reactive measure that is implemented during or after an incident, and it is designed to address the consequences or impacts of risk.A corrective control can also help the organization to learn from the incident and improve its information security practices1. An example of a corrective control is a backup or restore system, which is a method of creating and restoring copies of the system or data that have been lost or damaged due to an incident.
A detective control is a type of control that aims to identify or discover the occurrence or existence of an incident or a deviation from the expected or desired state or behavior of the systems or processes. A detective control is a monitoring or auditing measure that is implemented during or after an incident, and it is designed to provide information or evidence of risk.A detective control can also help the organization to analyze or investigate the incident and determine the root cause or source of risk1. An example of a detective control is a log or alert system, which is a tool of recording or reporting the activities or events that have occurred or are occurring within the systems or processes.
A deterrent control is a type of control that aims to discourage or dissuade the potential perpetrators or sources of risk from initiating or continuing an incident or an attack. A deterrent control is a psychological or behavioral measure that is implemented before or during an incident, and it is designed to influence or manipulate the motivation or intention of risk.A deterrent control can also help the organization to reduce the likelihood or frequency of incidents or attacks1. An example of a deterrent control is a warning or notification system, which is a method of communicating or displaying the consequences or penalties of violating the information security policies or rules.References=Risk Control Techniques: Preventive, Corrective, Directive, And ...,Learn Different types of Security Controls in CISSP - Eduonix Blog
Which of the following provides the GREATEST assurance that existing controls meet compliance requirements?
The correct answer is A because independent audits provide objective assurance that existing controls meet compliance requirements. Independent auditors can evaluate whether controls are appropriately designed, implemented, documented, and operating effectively against regulatory, contractual, or policy requirements. Establishing compliance metrics is useful for monitoring trends and reporting status, but metrics may not provide sufficient independent validation. Reviewing security policies confirms whether requirements are documented, but it does not prove that controls are operating effectively. Performing risk assessments helps identify and evaluate risk, but risk assessment is not the same as compliance assurance. In CISM governance, independent assurance is important because management needs reliable evidence that controls are effective and obligations are being met. Audits also help identify gaps, exceptions, and remediation needs. Because compliance requires evidence and objective evaluation, independent audits provide the greatest assurance among the listed options.
Which of the following is the MOST important reason for an organization to communicate to affected parties that a security incident has occurred?
Complying with regulations regarding notification is the most important reason for an organization to communicate to affected parties that a security incident has occurred, as it helps to avoid legal penalties, fines, or sanctions that may result from failing to notify the relevant authorities, customers, or other stakeholders in a timely and appropriate manner. Additionally, complying with regulations regarding notification may also help to preserve the trust and reputation of the organization, as well as to facilitate the investigation and resolution of the incident.
References= CISM Review Manual 2022, page 3151; CISM Exam Content Outline, Domain 4, Task 4.5
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed