CISM Certification MCQ Multiple Choice Questions - Page 2 for Practice

CISM Certification MCQ Questions for Practice

31. What is the purpose of incident management?

32. Which phase comes first in incident response?

33. What is the primary goal of incident containment?

34. What is the purpose of lessons learned after an incident?

35. What is a security awareness program designed to do?

36. Which attack relies on manipulating people rather than systems?

37. What is phishing?

38. What is the purpose of vendor risk management?

39. Which document defines security requirements for vendors?

40. What is the purpose of security metrics?

41. Which metric measures the frequency of incidents?

42. What is governance primarily concerned with?

43. What is the purpose of a security steering committee?

44. Which framework is commonly used for IT governance?

45. What does COBIT stand for?

46. What is risk assessment?

47. What is the purpose of data classification?

48. Which classification level typically requires the highest protection?

49. What is a compensating control?

50. What is the purpose of encryption?

51. Which authentication method provides the strongest assurance?

52. What is the primary goal of access management?

53. Which security principle ensures accountability?

54. What is a Key Risk Indicator (KRI)?

55. What is a Key Performance Indicator (KPI)?

56. What is the primary objective of information security strategy?

57. Which process ensures security requirements are incorporated into projects?

58. What is the best indicator of a mature security program?

59. Which CISM domain focuses on creating and managing security programs?

60. What is the ultimate goal of CISM practices?

Tags

Multiple Choice Questions and Answers on CISM Certification

CISM Certification Multiple Choice Questions and Answers

CISM Certification Trivia Quiz

CISM Certification Question and Answer PDF Online