
Certified Information Security Manager
Domain 1Objective 4
Information Security Strategy Development CISM Practice Questions (Page 8)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
40questions here
8free pages
12concepts
17%of the exam
Questions 36–40
- 36
What is the primary purpose of strategy formulation in information security?
Select an answer first - 37
A financial institution has completed a current state assessment and a target state definition. The gap analysis has identified several deficiencies: (1) no encryption for data at rest in legacy systems, (2) lack of a formal vendor risk management program, and (3) insufficient logging for critical financial transactions. The CISO has limited budget and must prioritize initiatives. The organization is facing an upcoming regulatory audit in six months. Which initiative should be prioritized first?
Select an answer first - 38
A CISO has implemented a security strategy with the objective of reducing the mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents. The CISO must define KPIs to monitor the strategy's effectiveness. Which KPI set is most appropriate for this objective?
Select an answer first - 39
Which of the following BEST describes the target state of information security?
Select an answer first - 40
Which of the following is a type of resource that should be considered in resource planning for security strategy implementation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.