CISM Security Mgr Practice 202 practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q11To ensure that an organization's cybersecurity measures are both effective and justified, it is ESSENTIAL to:
✓ Correct answer: A. Perform a cost-benefit analysis for proposed cybersecurity measures
Answer: Perform a cost-benefit analysis for proposed cybersecurity measures A cost-benefit analysis should be conducted for each of the proposed cybersecurity measures to confirm that the costs of implementing these measures are justified by the reduction in risk or impact. Aligning measures with competitor strategies or assuring management without hard data won't ensure effectiveness. Business expansion plans are indirectly related. A cost-benefit analysis directly ensures that the proposed measures are necessary and suitable.
Q12A policy mandating regular security awareness training for employees falls under which type of security control?
✓ Correct answer: B. Managerial
Answer: Managerial The policy is a managerial control. Training sessions themselves could be operational, while the content delivery might involve technical controls. However, the creation and enforcement of the policy is managerial.
Q13Who would be the MOST interested in a Key Performance Indicator (KPI) that tracks the completion of mandatory information security training by employees?
✓ Correct answer: D. Information Security Manager
Answer: Information Security Manager The information security manager is responsible for ensuring that all employees understand and comply with security policies. Therefore, they would be most interested in tracking the completion of mandatory training. Human Resources (HR) is likely concerned with the administrative aspects of enrolling employees in training but not specifically tracking security training completion. The compliance officer would be more interested in ensuring compliance with regulations but not to the same day-to-day extent as the information security manager. Executive management would be more concerned with the overall compliance and improvement but not the specific tracking of training completion.
Q14A company plans to implement a remote work policy. The managers are concerned about the security of the information transmitted over various online communication tools. What measure is BEST to ensure the confidentiality of the transmitted data?
✓ Correct answer: C. End-to-end encryption
Answer: End-to-end encryption The best answer is end-to-end encryption, as it ensures that data transmitted over the internet remains confidential and cannot be intercepted by unauthorized parties. Using a VPN can provide some security but doesn't guarantee end-to-end encryption of data. Anti-virus software does not protect data transmitted over networks. Restricting the use of personal devices can limit potential security risks, but does not directly ensure the confidentiality of transmitted data.
Q15If a data center is managed by a third-party vendor but exclusively used by a single company, what type of hosting model is this?
✓ Correct answer: A. Dedicated hosting
Answer: Dedicated hosting This is the definition of dedicated hosting. It can be managed by a third-party vendor but is used exclusively by a single company. The key is that the hosting environment is dedicated to this single customer. If the hosting environment is shared with others, it would be shared or community hosting. Shared hosting allows multiple companies to use the same servers without knowing about each other's presence. Community hosting enables multiple organizations with similar requirements to share the environment and possibly even the data. Hybrid hosting blends at least two of the hosting models: dedicated, shared, and community.
Q16Which of the following is MOST likely to be an example of a key performance indicator (KPI) for assessing database performance?
✓ Correct answer: D. Average query response time
Answer: Average query response time Average query response time is an example of a key performance indicator (KPI). It measures the efficiency of database queries, indicating how quickly the database responds to requests. Number of unauthorized access attempts, detected malware incidents, and backup frequency are not KPIs directly related to database performance. While these metrics may be important for security and data protection, they do not measure the performance of database queries.
Q17In an organization, if a security mechanism is used to monitor and log network traffic based on specific rules, this mechanism is known as a(n):
✓ Correct answer: B. Intrusion Detection System (IDS)
Answer: Intrusion Detection System (IDS) An IDS is designed to monitor and log network traffic based on predefined rules and signatures. It does not actively block traffic but rather alerts the network administrator of any potentially malicious activity. In contrast, a firewall will block or allow traffic based on pre-configured rules, an IPS will block traffic based on a signature file or anomaly detection, and DRM controls access to digital content.
Q18In the context of ensuring data integrity while outsourcing data storage, which deployment model provides the BEST guarantee?
✓ Correct answer: D. Private cloud
Answer: Private cloud To ensure data integrity while outsourcing data storage, the best solution is a private cloud. A private cloud has infrastructure dedicated exclusively to one customer, which minimizes the risk of data corruption or unauthorized access by other tenants. Public, hybrid, and community clouds involve multiple tenants from different organizations, which increases the complexity and risk associated with maintaining data integrity.
Q19Offering a financial incentive to employees for reporting suspicious activities within a company could be considered a:
✓ Correct answer: B. Countermeasure
Answer: Countermeasure A financial incentive for employees to report suspicious activities is a countermeasure. It is not a preventive control as it does not prevent the suspicious activity from occurring. Instead, it is a response aimed at identifying and addressing the activity after it has happened. A safeguard is a preventive control put in place to protect assets. A corrective control aims at fixing the issues after an incident has occurred. Here, the financial incentive does neither of these directly but acts as a response mechanism.
Q20Your organization plans to outsource the management of its IT infrastructure to a third-party Managed Service Provider (MSP). When is the BEST time to conduct a risk assessment?
✓ Correct answer: C. On a continuous basis
Answer: On a continuous basis A risk assessment should be conducted before signing any contract, but that is not enough. Risk assessments should be performed on a continuous basis to adapt to changing conditions and new potential risks. Although six months into the service and immediately after the service begins are important times, they are not the best. Continuous assessment ensures that any emerging risks are promptly identified and managed.
Use the free CISM Security Mgr Practice 202 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.