Home/United States/IT & Cybersecurity/CISM Security Mgr Practice 202
IT & Cybersecurity · 2026 question bank

CISM Security Mgr Practice 202
Practice Test

Practice 1210+ real CISM Security Mgr Practice 202 questions with clear explanations, realistic mock exams, and progress tracking - free to start and fully offline.

$2.99/week$6.99/monthfull unlock, cancel anytime
30real questions
30free mock questions
Free sample · CISM Security Mgr Practice 202Q1 / 30
The National Institute of Standards and Technology (NIST) defines three categories of risk mitigation strategies in incident management. They are:
Correct — D. Answer: Avoidance, Transference, and Mitigation NIST defines the three categories of risk mitigation strategies as: Avoidance (eliminating the risk factor entirely through preventive measures) Transference (shifting the risk to a third party, typically through insurance or outsourcing) Mitigation (reducing the impact or likelihood of the risk through control measures)
↑ Tap an answer to check it
Practice all 30 questions

Heads up: the app and the web exam use separate accounts — a web unlock and an in-app purchase do not carry over. Buy on the web to practice on the web.

Watch & learn

CISM Security Mgr Practice 202 exam — full Q&A walkthrough

Every question read aloud with the answer explained. Play it on your commute, then test yourself.

▶ Full Q&A walkthrough📺 @CertsQuizPrep
Free practice

30 free CISM Security Mgr Practice 202 questions

Sampled across every topic area — not just the first page. Try them as a quiz or flip them as flashcards.

↓ PDF
  1. CISM Security Mgr Practice 202

    The National Institute of Standards and Technology (NIST) defines three categories of risk mitigation strategies in incident management. They are:

    Correct — D. Answer: Avoidance, Transference, and Mitigation NIST defines the three categories of risk mitigation strategies as: Avoidance (eliminating the risk factor entirely through preventive measures) Transference (shifting the risk to a third party, typically through insurance or outsourcing) Mitigation (reducing the impact or likelihood of the risk through control measures)
  2. CISM Security Mgr Practice 202

    An international bank is concerned that a cyber-attack could disrupt their primary trading network. They decide to set up an alternate trading site that can be operational immediately if such an attack occurs. Additionally, they want a tertiary site as a fallback option in case the secondary site is compromised. They have also specified that they want to reduce costs for this tertiary site. As the information security manager, what would you recommend for the tertiary site?

    Correct — C. Answer: Cold site A cold site is an appropriate choice for a bank expecting to rely on an alternative site (in this scenario: the secondary site) and needing a cost-effective tertiary option. If an extreme cyber-attack compromises the primary trading network, they can fail over to the alternate site. Once functional in the secondary site, they can then provision the cold site to become operational as needed. A hot site is not suitable because it does not align with the cost-reduction requirement for the tertiary site. A reciprocal agreement, which involves resource sharing with another entity, typically doesn't fit the banking industry's critical and sensitive operations. A mirror site is expensive and already operational, making it impractical as a backup for the alternate site. However, a bank might find a mirror site suitable as a primary or secondary option due to its real-time capabilities.
  3. CISM Security Mgr Practice 202

    Who is typically responsible for ensuring the proper handling and documentation of events during a disaster recovery process?

    Correct — B. Answer: Disaster Recovery Coordinator The Disaster Recovery Coordinator is responsible for ensuring that disaster recovery plans are executed properly and that all actions and events are documented accordingly. They oversee the disaster recovery process to minimize downtime and data loss. The CIO will oversee the broader security strategy while the Board of Directors are informed stakeholders, and the Network Administrator focuses on maintaining network functionality.
  4. CISM Security Mgr Practice 202

    What is the MAIN difference between symmetric and asymmetric encryption?

    Correct — C. Correct answer: The type of keys used for encryption and decryption In symmetric encryption, the same key is used for both encryption and decryption. In asymmetric encryption, a pair of related but different keys (public and private) is used for encryption and decryption. The complexity of the algorithm, speed, and type of data are not the primary differences. Symmetric encryption algorithms tend to be less complex and faster, whereas asymmetric encryption is more complex but provides better security for key exchange purposes.
  5. CISM Security Mgr Practice 202

    What is the primary difference between event correlation and anomaly detection?

    Correct — D. Answer: Event correlation links multiple related events to identify potential security incidents. Anomaly detection identifies deviations from a standard behavior. The primary difference between event correlation and anomaly detection is that event correlation links multiple related events based on predefined patterns or rules, while anomaly detection identifies deviations from normal behavior. Event correlation relies on finding relationships between different security events, potentially indicating an incident. Anomaly detection, on the other hand, looks for unusual behavior that deviates from established baselines, indicating potential unknown threats.
  6. CISM Security Mgr Practice 202

    A financial brokerage firm is preparing for a major market event that is expected to significantly increase their network traffic. They are concerned about their primary internet connection failing during peak trading hours. To ensure they remain operational in the event of a failure, what solution could they implement to MINIMIZE downtime?

    Correct — C. Answer: Redundant internet connections Redundant internet connections provide a backup internet link to switch to if the primary connection fails, thus ensuring continued operation with minimal downtime. Network load balancing distributes traffic efficiently but does not directly address redundancy in case of a primary connection failure. Cloud-based backup focuses on data backup rather than maintaining continuous network connectivity. A VPN secures connections but does not provide redundancy or backup internet links.
  7. CISM Security Mgr Practice 202

    In the Disaster Recovery Plan (DRP), there must be a section that ensures the availability of backup power supplies, communication devices, and essential software for continuity. What is this section typically called?

    Correct — A. Answer: Logistics This is the logistics section of the DRP — it ensures that necessary resources such as backup power supplies, communication devices, and essential software are available for continuity. The technical support team handles hardware and software issues. The emergency coordination team organizes response actions during an emergency. The RPO determines the maximum tolerable period data might be lost due to a major incident.
  8. CISM Security Mgr Practice 202

    What is the primary method for an information security manager to ensure that the organization's network configurations are secure and avoid unauthorized access?

    Correct — C. Answer: Regular vulnerability assessments Regular vulnerability assessments help identify weaknesses in network configurations and ensure they are secure, thus preventing unauthorized access. Approval by the legal department is not related to network security. Compliance with financial audits ensures financial integrity, not network security. An IT team’s capability cannot replace regular technical assessments for ensuring network security.
  9. CISM Security Mgr Practice 202

    Which of the following metrics is BEST to assess the effectiveness of a company's data loss prevention (DLP) strategy?

    Correct — B. Answer: Reduction in data breaches Monitoring the reduction in data breaches is the most effective measure of a DLP strategy's success, as it directly correlates with the primary goal of preventing data loss. The other options, while useful for specific security aspects, do not directly measure the effectiveness of the overall DLP strategy.
  10. CISM Security Mgr Practice 202

    After a data protection strategy has been created, what should happen NEXT?

    Correct — C. Answer: Executive approval A data protection strategy should be reviewed and approved by the executive team before it can be put into action. A vulnerability assessment is needed prior to creating a protection strategy; once developed, a strategy should be executed following proper approval. Monitoring compliance happens after the strategy has been implemented. Internal audits can be carried out at any stage, but they typically follow the approval process.
  11. CISM Security Mgr Practice 202

    To ensure that an organization's cybersecurity measures are both effective and justified, it is ESSENTIAL to:

    Correct — A. Answer: Perform a cost-benefit analysis for proposed cybersecurity measures A cost-benefit analysis should be conducted for each of the proposed cybersecurity measures to confirm that the costs of implementing these measures are justified by the reduction in risk or impact. Aligning measures with competitor strategies or assuring management without hard data won't ensure effectiveness. Business expansion plans are indirectly related. A cost-benefit analysis directly ensures that the proposed measures are necessary and suitable.
  12. CISM Security Mgr Practice 202

    A policy mandating regular security awareness training for employees falls under which type of security control?

    Correct — B. Answer: Managerial The policy is a managerial control. Training sessions themselves could be operational, while the content delivery might involve technical controls. However, the creation and enforcement of the policy is managerial.
  13. CISM Security Mgr Practice 202

    Who would be the MOST interested in a Key Performance Indicator (KPI) that tracks the completion of mandatory information security training by employees?

    Correct — D. Answer: Information Security Manager The information security manager is responsible for ensuring that all employees understand and comply with security policies. Therefore, they would be most interested in tracking the completion of mandatory training. Human Resources (HR) is likely concerned with the administrative aspects of enrolling employees in training but not specifically tracking security training completion. The compliance officer would be more interested in ensuring compliance with regulations but not to the same day-to-day extent as the information security manager. Executive management would be more concerned with the overall compliance and improvement but not the specific tracking of training completion.
  14. CISM Security Mgr Practice 202

    A company plans to implement a remote work policy. The managers are concerned about the security of the information transmitted over various online communication tools. What measure is BEST to ensure the confidentiality of the transmitted data?

    Correct — C. Answer: End-to-end encryption The best answer is end-to-end encryption, as it ensures that data transmitted over the internet remains confidential and cannot be intercepted by unauthorized parties. Using a VPN can provide some security but doesn't guarantee end-to-end encryption of data. Anti-virus software does not protect data transmitted over networks. Restricting the use of personal devices can limit potential security risks, but does not directly ensure the confidentiality of transmitted data.
  15. CISM Security Mgr Practice 202

    If a data center is managed by a third-party vendor but exclusively used by a single company, what type of hosting model is this?

    Correct — A. Answer: Dedicated hosting This is the definition of dedicated hosting. It can be managed by a third-party vendor but is used exclusively by a single company. The key is that the hosting environment is dedicated to this single customer. If the hosting environment is shared with others, it would be shared or community hosting. Shared hosting allows multiple companies to use the same servers without knowing about each other's presence. Community hosting enables multiple organizations with similar requirements to share the environment and possibly even the data. Hybrid hosting blends at least two of the hosting models: dedicated, shared, and community.
  16. CISM Security Mgr Practice 202

    Which of the following is MOST likely to be an example of a key performance indicator (KPI) for assessing database performance?

    Correct — D. Answer: Average query response time Average query response time is an example of a key performance indicator (KPI). It measures the efficiency of database queries, indicating how quickly the database responds to requests. Number of unauthorized access attempts, detected malware incidents, and backup frequency are not KPIs directly related to database performance. While these metrics may be important for security and data protection, they do not measure the performance of database queries.
  17. CISM Security Mgr Practice 202

    In an organization, if a security mechanism is used to monitor and log network traffic based on specific rules, this mechanism is known as a(n):

    Correct — B. Answer: Intrusion Detection System (IDS) An IDS is designed to monitor and log network traffic based on predefined rules and signatures. It does not actively block traffic but rather alerts the network administrator of any potentially malicious activity. In contrast, a firewall will block or allow traffic based on pre-configured rules, an IPS will block traffic based on a signature file or anomaly detection, and DRM controls access to digital content.
  18. CISM Security Mgr Practice 202

    In the context of ensuring data integrity while outsourcing data storage, which deployment model provides the BEST guarantee?

    Correct — D. Answer: Private cloud To ensure data integrity while outsourcing data storage, the best solution is a private cloud. A private cloud has infrastructure dedicated exclusively to one customer, which minimizes the risk of data corruption or unauthorized access by other tenants. Public, hybrid, and community clouds involve multiple tenants from different organizations, which increases the complexity and risk associated with maintaining data integrity.
  19. CISM Security Mgr Practice 202

    Offering a financial incentive to employees for reporting suspicious activities within a company could be considered a:

    Correct — B. Answer: Countermeasure A financial incentive for employees to report suspicious activities is a countermeasure. It is not a preventive control as it does not prevent the suspicious activity from occurring. Instead, it is a response aimed at identifying and addressing the activity after it has happened. A safeguard is a preventive control put in place to protect assets. A corrective control aims at fixing the issues after an incident has occurred. Here, the financial incentive does neither of these directly but acts as a response mechanism.
  20. CISM Security Mgr Practice 202

    Your organization plans to outsource the management of its IT infrastructure to a third-party Managed Service Provider (MSP). When is the BEST time to conduct a risk assessment?

    Correct — C. Answer: On a continuous basis A risk assessment should be conducted before signing any contract, but that is not enough. Risk assessments should be performed on a continuous basis to adapt to changing conditions and new potential risks. Although six months into the service and immediately after the service begins are important times, they are not the best. Continuous assessment ensures that any emerging risks are promptly identified and managed.
  21. CISM Security Mgr Practice 202

    Who within an organization is responsible for ensuring that data privacy regulations are adhered to within business processes?

    Correct — A. Answer: Data Protection Officer (DPO) The Data Protection Officer (DPO) is responsible for overseeing compliance with data privacy regulations within the organization. Compliance officers ensure that the company adheres to external regulations and internal policies, but they do not focus solely on data privacy. The CIO handles IT planning, budgeting, and performance. The Chief Privacy Officer (CPO) focuses on consumer data and privacy issues at a higher level within the organization.
  22. CISM Security Mgr Practice 202

    When designing an incident response plan, it is ESSENTIAL for the information security manager to:

    Correct — D. Answer: Ensure that senior management supports the incident response plan. Explanation: All answers detail important elements of incident response planning, but if senior management does not support the plan, it will be difficult to allocate the necessary resources. Senior management's support is critical for the effective implementation and continuous improvement of the incident response plan.
  23. CISM Security Mgr Practice 202

    In the context of developing an incident response plan, what is the FIRST step a security manager should take?

    Correct — B. Answer: Identify critical assets Explanation: Before a security manager can develop an effective incident response plan, it is essential to identify and prioritize the organization’s critical assets. This ensures that the response plan focuses on protecting the most valuable and vulnerable parts of the infrastructure.
  24. CISM Security Mgr Practice 202

    In a large corporation that employs both a Chief Information Security Officer (CISO) and an information security manager, which responsibility is more likely to be assigned to the CISO rather than the information security manager?

    Correct — D. Answer: Development of an enterprise-wide security governance framework A CISO is typically responsible for the strategic aspects of information security, which include the development of an enterprise-wide security governance framework. This role is more strategic and high-level compared to the tasks usually assigned to an information security manager, who focuses more on operational and tactical aspects, such as implementing controls, monitoring compliance, and managing incidents.
  25. CISM Security Mgr Practice 202

    In the context of incident response planning, what is another way to describe the concept of 'risk avoidance'?

    Correct — A. Answer: Risk elimination Risk elimination is synonymous with risk avoidance. Risk mitigation, risk transfer, and risk acceptance are different concepts within risk management. Risk mitigation involves reducing the impact or likelihood of a risk. Risk transfer refers to shifting the risk to another party. Risk acceptance means acknowledging the risk and choosing not to address it.
  26. CISM Security Mgr Practice 202

    In a healthcare organization, what is the first action the information security manager should take to establish a comprehensive patient data protection program?

    Correct — B. To build a successful patient data protection program, you must have management direction and support documented within a policy regarding data protection. With a policy in place, you can proceed with planning and allocating resources, conducting risk assessments using various methodologies, and then initiating projects to implement appropriate controls.
  27. CISM Security Mgr Practice 202

    If a company wants to ensure that only authorized devices can access its wireless network, what type of control should it implement?

    Correct — A. Answer: Wireless Access Control Wireless Access Control is used to ensure that only authorized devices can connect to a wireless network by verifying their credentials. An Intrusion Detection System (IDS) monitors network traffic for suspicious activity, but does not control access. A Virtual Local Area Network (VLAN) is used to partition a physical network into multiple, distinct segments. Encryption protects the confidentiality of data but does not control access to the network itself.
  28. CISM Security Mgr Practice 202

    What type of threat is represented by an employee unintentionally sharing sensitive internal documents with an unauthorized third party?

    Correct — A. Answer: Internal threat An internal threat is anyone inside an organization that poses potential harm to the organization. This can happen without malicious intent, such as accidentally sharing sensitive information. An external threat originates from outside the organization, such as hackers or competitive entities. A malicious insider is an employee intentionally causing harm or leak of sensitive data. Script kiddies are amateur hackers using pre-written code without real understanding; they pose as external threats.
  29. CISM Security Mgr Practice 202

    Which of the following is NOT an appropriate use of qualitative risk assessments?

    Correct — C. Answer: For calculating the annual loss expectancy Qualitative risk assessments are generally descriptive and do not provide hard numbers. They are suitable for: 1. Initial risk assessments to prioritize further analysis. 2. Situations where quantifiable data is unavailable. 3. Assessments for non-tangible aspects, such as reputation damage. Qualitative risk assessments should not be used for calculating specific values such as the annual loss expectancy, which requires quantitative data.
  30. CISM Security Mgr Practice 202

    When assessing new cybersecurity initiatives, determining the primary goals for these initiatives should use an iterative process based on:

    Correct — D. Answer: An analysis of costs and an evaluation of acceptable risk levels The correct primary goals for cybersecurity initiatives must be established by evaluating the financial requirements to reach the target state and assessing whether the risk levels are within acceptable thresholds.
Sample questions

CISM Security Mgr Practice 202 sample questions

Tap any question below to reveal the answer and a plain-English explanation.

CISM Security Mgr Practice 202 In the context of developing an incident response plan, what is the FIRST step a security manager should take?

A. Train the incident response team

B. Identify critical assets ✓

C. Deploy incident response tools

D. Assess current security measures

Correct — B. Answer: Identify critical assets Explanation: Before a security manager can develop an effective incident response plan, it is essential to identify and prioritize the organization’s critical assets. This ensures that the response plan focuses on protecting the most valuable and vulnerable parts of the infrastructure.

CISM Security Mgr Practice 202 In a large corporation that employs both a Chief Information Security Officer (CISO) and an information security manager, which responsibility is more likely to be assigned to the CISO rather than the information security manager?

A. Implementation of security controls

B. Monitoring compliance with security policies

C. Managing security incidents and responses

D. Development of an enterprise-wide security governance framework ✓

Correct — D. Answer: Development of an enterprise-wide security governance framework A CISO is typically responsible for the strategic aspects of information security, which include the development of an enterprise-wide security governance framework. This role is more strategic and high-level compared to the tasks usually assigned to an information security manager, who focuses more on operational and tactical aspects, such as implementing controls, monitoring compliance, and managing incidents.

CISM Security Mgr Practice 202 In the context of incident response planning, what is another way to describe the concept of 'risk avoidance'?

A. Risk elimination ✓

B. Risk mitigation

C. Risk transfer

D. Risk acceptance

Correct — A. Answer: Risk elimination Risk elimination is synonymous with risk avoidance. Risk mitigation, risk transfer, and risk acceptance are different concepts within risk management. Risk mitigation involves reducing the impact or likelihood of a risk. Risk transfer refers to shifting the risk to another party. Risk acceptance means acknowledging the risk and choosing not to address it.

CISM Security Mgr Practice 202 In a healthcare organization, what is the first action the information security manager should take to establish a comprehensive patient data protection program?

A. Conduct quantitative and qualitative risk assessments

B. Establish a policy from senior management ✓

C. Plan a meeting to determine resources

D. Initiate a project to implement controls

Correct — B. To build a successful patient data protection program, you must have management direction and support documented within a policy regarding data protection. With a policy in place, you can proceed with planning and allocating resources, conducting risk assessments using various methodologies, and then initiating projects to implement appropriate controls.

CISM Security Mgr Practice 202 If a company wants to ensure that only authorized devices can access its wireless network, what type of control should it implement?

A. Wireless Access Control ✓

B. Intrusion Detection System (IDS)

C. Virtual Local Area Network (VLAN)

D. Encryption

Correct — A. Answer: Wireless Access Control Wireless Access Control is used to ensure that only authorized devices can connect to a wireless network by verifying their credentials. An Intrusion Detection System (IDS) monitors network traffic for suspicious activity, but does not control access. A Virtual Local Area Network (VLAN) is used to partition a physical network into multiple, distinct segments. Encryption protects the confidentiality of data but does not control access to the network itself.

CISM Security Mgr Practice 202 What type of threat is represented by an employee unintentionally sharing sensitive internal documents with an unauthorized third party?

A. Internal threat ✓

B. External threat

C. Malicious insider

D. Script kiddie

Correct — A. Answer: Internal threat An internal threat is anyone inside an organization that poses potential harm to the organization. This can happen without malicious intent, such as accidentally sharing sensitive information. An external threat originates from outside the organization, such as hackers or competitive entities. A malicious insider is an employee intentionally causing harm or leak of sensitive data. Script kiddies are amateur hackers using pre-written code without real understanding; they pose as external threats.

CISM Security Mgr Practice 202 Which of the following is NOT an appropriate use of qualitative risk assessments?

A. When quantifiable data is not available

B. When assessing aspects like reputation damage

C. For calculating the annual loss expectancy ✓

D. As an initial step in a risk analysis process

Correct — C. Answer: For calculating the annual loss expectancy Qualitative risk assessments are generally descriptive and do not provide hard numbers. They are suitable for: 1. Initial risk assessments to prioritize further analysis. 2. Situations where quantifiable data is unavailable. 3. Assessments for non-tangible aspects, such as reputation damage. Qualitative risk assessments should not be used for calculating specific values such as the annual loss expectancy, which requires quantitative data.

CISM Security Mgr Practice 202 When assessing new cybersecurity initiatives, determining the primary goals for these initiatives should use an iterative process based on:

A. A comprehensive vulnerability analysis compared to industry standards

B. Implementing controls aligned with historical threat data

C. Management's ability to align cybersecurity with corporate culture

D. An analysis of costs and an evaluation of acceptable risk levels ✓

Correct — D. Answer: An analysis of costs and an evaluation of acceptable risk levels The correct primary goals for cybersecurity initiatives must be established by evaluating the financial requirements to reach the target state and assessing whether the risk levels are within acceptable thresholds.

What is on the exam

About the CISM Security Mgr Practice 202 test

Built around IT & Cybersecurity, this CISM Security Mgr Practice 202 question bank mirrors the real exam format instead of guessing at trick questions. Work through the free sample, read every explanation, then move on to full timed mock exams once you're ready.

You will be tested on

  • The core topics and terminology you'll be tested on
  • Rules, standards and best-practice procedures
  • Real-world scenarios and how to respond
  • Common mistakes and how to avoid them

How TheoryPractice helps you pass

  • Real exam-style questions with instant, detailed explanations
  • Full timed mock exams that mirror the real test format
  • Flashcards & quiz modes from the same question bank
  • Progress tracking so you know exactly when you're ready
Coverage

Topics in this question bank

Topic

The core topics and terminology you'll be tested on

Topic

Rules, standards and best-practice procedures

Topic

Real-world scenarios and how to respond

Topic

Common mistakes and how to avoid them

Unlock everything

Full CISM Security Mgr Practice 202 bank + unlimited mocks

Try 30 questions free. Unlock the complete CISM Security Mgr Practice 202 question bank, every explanation, and unlimited timed mock exams. Practice on any device.

Unlock CISM Security Mgr Practice 202 →
Cramming?
$2.99
/ week · per exam
Best value
$6.99
/ month · per exam
Questions

CISM Security Mgr Practice 202 test FAQ

Is the CISM Security Mgr Practice 202 hard?
The CISM Security Mgr Practice 202 is very passable when you study with realistic practice questions. Most people only find it tricky because the wording is unfamiliar. Practise in the real question format until you score consistently above the pass mark and you'll walk in confident.
How many questions are on the CISM Security Mgr Practice 202?
The exact number depends on the version of the CISM Security Mgr Practice 202 you sit. CISM Security Mgr Practice 202 includes a large bank of practice questions covering every topic, plus full-length mock exams set up to mirror the real test format and pass mark.
Can I practise the CISM Security Mgr Practice 202 for free?
Yes. You can practise a free sample of CISM Security Mgr Practice 202 questions on TheoryPractice in your browser, with answers and explanations. A web unlock adds the full question bank and unlimited timed mock exams for this exam.
Does CISM Security Mgr Practice 202 work offline?
The web practice works in your browser. If you prefer offline study, use the downloadable PDF or the mobile app where available, then return to the web version for timed mock exams and progress tracking.
Is CISM Security Mgr Practice 202 practice available in other languages?
Several of our apps support more than one language. Open the CISM Security Mgr Practice 202 listing on the App Store or Google Play to see the exact languages available for the CISM Security Mgr Practice 202.
How many CISM Security Mgr Practice 202 questions are there?
This bank covers 30 CISM Security Mgr Practice 202 practice questions, each with a plain-English explanation for the correct answer.
Is CISM Security Mgr Practice 202 practice free?
Yes — the sample questions on this page are free to practice. Unlock the full bank and timed mock exams when you're ready to go further.
Where can I practice the CISM Security Mgr Practice 202 online?
Right here on TheoryPractice, in your browser — no download required.