
Certified Information Security Manager
Domain 1Objective 6
Strategic Planning (Budgets, Resources, Business Case) CISM Practice Questions (Page 2)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
24questions here
5free pages
6concepts
17%of the exam
Questions 6–10
- 6
Which of the following is an example of a security KPI?
Select an answer first - 7
A security manager has implemented a new security awareness program and needs to report its effectiveness to the executive committee. Which metric would best demonstrate the program's impact on reducing risk?
Select an answer first - 8
A security manager is implementing a new security strategy and needs to establish KPIs to measure its effectiveness. The strategy includes improving incident response and reducing the time to patch critical vulnerabilities. Which set of KPIs would best measure the success of this strategy?
Select an answer first - 9
A security manager needs to justify the purchase of a new data loss prevention (DLP) solution. The organization has experienced several small data leaks. Which element is most important to include in the business case?
Select an answer first - 10
A security manager is developing the annual security plan and must allocate a limited budget across several initiatives. The organization has just experienced a minor data breach and faces a new regulatory deadline in six months. Which allocation strategy best aligns with the strategic plan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.