
Certified Information Security Manager
Domain 3Objective 2
Program Implementation and Operations CISM Practice Questions (Page 3)
Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.
32questions here
7free pages
8concepts
33%of the exam
Questions 11–15
- 11
A security team has implemented a new web application firewall (WAF). To evaluate its effectiveness, the team wants to test how well it detects and blocks common attack patterns. Which testing method is most appropriate for this purpose?
Select an answer first - 12
What is a key component of planning the implementation of security controls?
Select an answer first - 13
A multinational corporation is implementing a security metrics program. The CISO wants a metric that demonstrates the program's value to the business, but the board is concerned about the cost of security. Which metric would best balance these two concerns?
Select an answer first - 14
A company is implementing a new access control system that will affect all employees. The project manager must create an implementation plan that minimizes disruption. Which element is most important to include in the plan?
Select an answer first - 15
Which of the following is a key characteristic of an effective security metric report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.