Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 3Objective 2

Program Implementation and Operations CISM Practice Questions (Page 2)

Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.

32questions here
7free pages
8concepts
33%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the PRIMARY basis for designing security controls?

    Select an answer first
  2. 7application · medium

    A financial services firm wants to measure the effectiveness of its new endpoint detection and response (EDR) program. The CISO wants a metric that directly reflects the program's contribution to reducing business risk. Which metric would best align with this objective?

    Select an answer first
  3. 8application · medium

    A company has implemented a new firewall and wants to verify that it is correctly blocking unauthorized traffic. Which testing method would provide the most direct evidence of the firewall's effectiveness?

    Select an answer first
  4. 9foundation · easy

    What is the FIRST step after identifying a control deficiency during testing?

    Select an answer first
  5. 10foundation · easy

    What is the PRIMARY difference between a vulnerability assessment and a penetration test?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.