
Certified Information Security Manager
Domain 1Objective 4
Information Security Strategy Development CISM Practice Questions (Page 6)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
40questions here
8free pages
12concepts
17%of the exam
Questions 26–30
- 26
A retail company's gap analysis reveals that the organization lacks multi-factor authentication (MFA) for remote access, has no formal incident response plan, and has outdated data classification policies. The CISO must prioritize strategic initiatives to close these gaps. Which initiative should be prioritized first?
Select an answer first - 27
What is the primary purpose of defining key performance indicators (KPIs) for the security strategy?
Select an answer first - 28
Which of the following is a key component of assessing the current information security posture?
Select an answer first - 29
A CISO has developed a security strategy that requires significant investment and changes to business processes. The board is divided: some members support the investment, while others are concerned about the cost and impact on operations. The CISO must communicate the strategy to gain approval. Which communication approach is most effective?
Select an answer first - 30
What is the primary purpose of obtaining approval from senior management for the security strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.