TechNuggets Academy

Information Security Program

Free Certified Information Security Manager practice — 6 questions on Information Security Program, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Information Security Program
The board wants a metric that provides an early warning of increasing information security risk exposure before an incident occurs, rather than a historical count of events. Which metric BEST serves this purpose?
A rising percentage of critical assets breaching the patching SLA is a key risk indicator (KRI) — it predicts a growing exposure to exploitation before an incident materializes, giving management time to act.
Question 2 of 6 · Domain 3: Information Security Program
An organization is finalizing a contract with a cloud service provider to process data classified as highly sensitive. The provider holds a current ISO/IEC 27001 certification covering its overall operations. What should the CISM require before contract sign-off?
Certifications like ISO 27001 have a defined scope that may not cover the exact service, environment, or data flows being contracted. A right-to-audit clause plus ongoing independent assessment gives continuing assurance specific to the actual risk, which is essential for highly sensitive data.
Question 3 of 6 · Domain 3: Information Security Program
A legacy system that can no longer receive vendor patches processes sensitive data on the internal network. Budget does not allow replacement this cycle. Which compensating control is the BEST response?
When the primary control (patching) cannot be applied, isolating the system through segmentation, restricting access, and increasing monitoring reduces the likelihood and impact of exploitation — this is the standard compensating-control approach management should select and document.
Question 4 of 6 · Domain 3: Information Security Program
For security requirements to be effectively integrated into the SDLC at the lowest cost and highest effectiveness, at which phase should they FIRST be formally documented and validated?
Security requirements defined during requirements gathering and design allow controls to be architected in from the start, which is far less costly and more effective than retrofitting controls later; this is the CISM-recommended approach to secure SDLC integration.
Question 5 of 6 · Domain 3: Information Security Program
A phishing simulation program has run quarterly for two years, but the click rate has plateaued at 12% despite ongoing generic training. What should the CISM do NEXT?
A plateaued click rate indicates the generic training is no longer effective for the remaining at-risk population. Root-cause analysis and targeted, role-based training address the specific behaviors driving continued failures, which is the program-management response expected of a CISM.
Question 6 of 6 · Domain 3: Information Security Program
Which statement correctly describes the relationship between a security control framework (such as a functions/categories model) and a detailed control catalog/standard when designing a security program?
Frameworks organize security activities into high-level functions/categories to guide program structure and governance communication, while detailed control catalogs provide the specific, implementable controls that map to those categories — the two are complementary, not interchangeable.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →