Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 3Objective 3

Program Communication and External Management CISM Practice Questions (Page 6)

Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.

35questions here
7free pages
9concepts
33%of the exam

Questions 26–30

  1. 26foundation · easy

    What is the primary purpose of ongoing monitoring of a third-party service provider?

    Select an answer first
  2. 27application · medium

    A multinational manufacturing company has a security awareness program that relies on an annual 60-minute computer-based training (CBT) module. Completion rates are high, but the security team observes that employees still fall for phishing emails and mishandle sensitive data. The CISO wants to improve engagement and retention without a large budget increase. Which change is most likely to improve the program's effectiveness?

    Select an answer first
  3. 28application · medium

    After implementing a new security awareness program, the CISO wants to evaluate its effectiveness. The program includes phishing simulations, online training modules, and a reporting mechanism for suspicious emails. Which metric would provide the most direct evidence of behavior change?

    Select an answer first
  4. 29foundation · easy

    Why is it important to assess the security practices of a vendor's subcontractors?

    Select an answer first
  5. 30foundation · easy

    What is a fourth-party risk in the context of third-party risk management?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.