Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 3Objective 1

Program Foundation and Governance CISM Practice Questions (Page 1)

Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.

32questions here
7free pages
9concepts
33%of the exam

Questions 1–5

  1. 1foundation · easy

    Which of the following is an example of a security guideline?

    Select an answer first
  2. 2application · medium

    A hospital is implementing a new security program and needs to staff it appropriately. The CISO has identified the need for incident response, vulnerability management, and security awareness training. The hospital has a limited budget and cannot hire full-time specialists for every function. Which staffing strategy best addresses the program's needs within the budget constraint?

    Select an answer first
  3. 3foundation · easy

    What is the primary purpose of the NIST Cybersecurity Framework (CSF)?

    Select an answer first
  4. 4foundation · easy

    Which of the following is a common criterion used to classify information assets?

    Select an answer first
  5. 5application · medium

    A large manufacturing company has classified its engineering blueprints as 'Confidential'. The engineering department head is responsible for the blueprints, while the IT department manages the file servers where they are stored. A new product design is being developed, and the CISO needs to ensure that access is properly controlled. Which assignment of roles and responsibilities is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.