
Certified Information Security Manager
Domain 1Objective 1
Organizational Culture CISM Practice Questions (Page 5)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
27questions here
6free pages
4concepts
17%of the exam
Questions 21–25
- 21
A security manager is designing a security awareness program for a company that has a culture of 'not invented here', where employees are skeptical of external ideas and prefer to develop their own solutions. What is the most effective way to promote a security-aware culture in this environment?
Select an answer first - 22
Which approach is most likely to encourage employees to adopt security-conscious behaviors in their daily work?
Select an answer first - 23
A security manager notices that employees frequently use personal cloud storage to share work files, despite a policy prohibiting it. The manager suspects the culture values convenience over security. What is the best way to address this behavior?
Select an answer first - 24
A multinational company's security team notices that employees in one regional office frequently share passwords and leave screens unlocked, despite mandatory annual training. The security manager wants to improve the security culture in that office. Which approach is most likely to be effective?
Select an answer first - 25
Which action best demonstrates that an organization has successfully aligned its culture with its security governance objectives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.