Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 1Objective 2

Legal, Regulatory and Contractual Requirements CISM Practice Questions (Page 2)

Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.

22questions here
5free pages
5concepts
17%of the exam

Questions 6–10

  1. 6expert · hard

    A multinational corporation operates in the EU, the US, and Asia. It processes personal data subject to GDPR, CCPA, and various local laws. The information security manager is tasked with designing a compliance management process that is both effective and efficient. Which approach best balances these objectives?

    Select an answer first
  2. 7foundation · easy

    An organization has just learned that a new regulation will require encryption of all personal data at rest. What should the information security manager do FIRST to assess the impact on governance?

    Select an answer first
  3. 8application · medium

    A manufacturing company is considering a new cloud-based HR system that will store employee personal data. The system is hosted in a country with different data protection laws. The information security manager must assess the impact of this decision on the organization's information security governance. What is the most critical factor to evaluate in this impact assessment?

    Select an answer first
  4. 9application · medium

    A credit card processing company is required to comply with PCI DSS. The information security manager is reviewing the network architecture and discovers that cardholder data is being transmitted over an internal network segment that is shared with non-cardholder systems. Which PCI DSS requirement is most directly violated?

    Select an answer first
  5. 10expert · hard

    A financial institution is subject to both PCI DSS and the Gramm-Leach-Bliley Act (GLBA). The information security manager is reviewing the security program and finds that the current controls meet PCI DSS but may not fully address GLBA's Safeguards Rule. What is the most appropriate action to ensure compliance with both?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.