
Certified Information Security Manager
Domain 3Objective 3
Program Communication and External Management CISM Practice Questions (Page 5)
Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.
35questions here
7free pages
9concepts
33%of the exam
Questions 21–25
- 21
A CISO is preparing a monthly security report for the IT director, who is responsible for operational security. The IT director wants to understand the effectiveness of the security controls and identify areas for improvement. Which type of metrics would be most useful for this audience?
Select an answer first - 22
A company is about to implement a new identity and access management (IAM) system that will require employees to use multi-factor authentication (MFA) and change their passwords more frequently. The CISO anticipates resistance from employees. Which communication strategy is most likely to reduce resistance and increase adoption?
Select an answer first - 23
Which audience would MOST likely require communication focused on strategic security risks and resource needs?
Select an answer first - 24
What is the primary purpose of conducting a needs assessment before designing a security awareness program?
Select an answer first - 25
A company is contracting with a new software-as-a-service (SaaS) provider for customer relationship management (CRM). The provider will store customer data, including personal information. The CISO wants to ensure that the contract includes appropriate security requirements. Which clause is most important to include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.