Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 1Objective 2

Legal, Regulatory and Contractual Requirements CISM Practice Questions (Page 4)

Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.

22questions here
5free pages
5concepts
17%of the exam

Questions 16–20

  1. 16application · medium

    A software development company is engaging a third-party vendor to perform penetration testing on its production application. The contract includes a clause that the vendor will not be liable for any damages resulting from the testing. The information security manager is concerned about this clause. What is the most appropriate action?

    Select an answer first
  2. 17foundation · easy

    What is the PRIMARY objective of a compliance management process in information security governance?

    Select an answer first
  3. 18application · medium

    A bank is required to comply with both PCI DSS and local banking regulations. The information security manager is designing a compliance monitoring process. Which approach is most effective for ensuring ongoing compliance with both sets of requirements?

    Select an answer first
  4. 19foundation · easy

    Which of the following is an example of a legal requirement that an information security manager should consider when developing security governance?

    Select an answer first
  5. 20foundation · easy

    What is the PRIMARY purpose of assessing the impact of legal, regulatory, and contractual requirements on information security governance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.