CISM Security Mgr Practice 202 practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q21Who within an organization is responsible for ensuring that data privacy regulations are adhered to within business processes?
✓ Correct answer: A. Data Protection Officer (DPO)
Answer: Data Protection Officer (DPO) The Data Protection Officer (DPO) is responsible for overseeing compliance with data privacy regulations within the organization. Compliance officers ensure that the company adheres to external regulations and internal policies, but they do not focus solely on data privacy. The CIO handles IT planning, budgeting, and performance. The Chief Privacy Officer (CPO) focuses on consumer data and privacy issues at a higher level within the organization.
Q22When designing an incident response plan, it is ESSENTIAL for the information security manager to:
✓ Correct answer: D. Ensure that senior management supports the incident response plan
Answer: Ensure that senior management supports the incident response plan. Explanation: All answers detail important elements of incident response planning, but if senior management does not support the plan, it will be difficult to allocate the necessary resources. Senior management's support is critical for the effective implementation and continuous improvement of the incident response plan.
Q23In the context of developing an incident response plan, what is the FIRST step a security manager should take?
✓ Correct answer: B. Identify critical assets
Answer: Identify critical assets Explanation: Before a security manager can develop an effective incident response plan, it is essential to identify and prioritize the organization’s critical assets. This ensures that the response plan focuses on protecting the most valuable and vulnerable parts of the infrastructure.
Q24In a large corporation that employs both a Chief Information Security Officer (CISO) and an information security manager, which responsibility is more likely to be assigned to the CISO rather than the information security manager?
✓ Correct answer: D. Development of an enterprise-wide security governance framework
Answer: Development of an enterprise-wide security governance framework A CISO is typically responsible for the strategic aspects of information security, which include the development of an enterprise-wide security governance framework. This role is more strategic and high-level compared to the tasks usually assigned to an information security manager, who focuses more on operational and tactical aspects, such as implementing controls, monitoring compliance, and managing incidents.
Q25In the context of incident response planning, what is another way to describe the concept of 'risk avoidance'?
✓ Correct answer: A. Risk elimination
Answer: Risk elimination Risk elimination is synonymous with risk avoidance. Risk mitigation, risk transfer, and risk acceptance are different concepts within risk management. Risk mitigation involves reducing the impact or likelihood of a risk. Risk transfer refers to shifting the risk to another party. Risk acceptance means acknowledging the risk and choosing not to address it.
Q26In a healthcare organization, what is the first action the information security manager should take to establish a comprehensive patient data protection program?
✓ Correct answer: B. Establish a policy from senior management
To build a successful patient data protection program, you must have management direction and support documented within a policy regarding data protection. With a policy in place, you can proceed with planning and allocating resources, conducting risk assessments using various methodologies, and then initiating projects to implement appropriate controls.
Q27If a company wants to ensure that only authorized devices can access its wireless network, what type of control should it implement?
✓ Correct answer: A. Wireless Access Control
Answer: Wireless Access Control Wireless Access Control is used to ensure that only authorized devices can connect to a wireless network by verifying their credentials. An Intrusion Detection System (IDS) monitors network traffic for suspicious activity, but does not control access. A Virtual Local Area Network (VLAN) is used to partition a physical network into multiple, distinct segments. Encryption protects the confidentiality of data but does not control access to the network itself.
Q28What type of threat is represented by an employee unintentionally sharing sensitive internal documents with an unauthorized third party?
✓ Correct answer: A. Internal threat
Answer: Internal threat An internal threat is anyone inside an organization that poses potential harm to the organization. This can happen without malicious intent, such as accidentally sharing sensitive information. An external threat originates from outside the organization, such as hackers or competitive entities. A malicious insider is an employee intentionally causing harm or leak of sensitive data. Script kiddies are amateur hackers using pre-written code without real understanding; they pose as external threats.
Q29Which of the following is NOT an appropriate use of qualitative risk assessments?
✓ Correct answer: C. For calculating the annual loss expectancy
Answer: For calculating the annual loss expectancy Qualitative risk assessments are generally descriptive and do not provide hard numbers. They are suitable for: 1. Initial risk assessments to prioritize further analysis. 2. Situations where quantifiable data is unavailable. 3. Assessments for non-tangible aspects, such as reputation damage. Qualitative risk assessments should not be used for calculating specific values such as the annual loss expectancy, which requires quantitative data.
Q30When assessing new cybersecurity initiatives, determining the primary goals for these initiatives should use an iterative process based on:
✓ Correct answer: D. An analysis of costs and an evaluation of acceptable risk levels
Answer: An analysis of costs and an evaluation of acceptable risk levels The correct primary goals for cybersecurity initiatives must be established by evaluating the financial requirements to reach the target state and assessing whether the risk levels are within acceptable thresholds.
Use the free CISM Security Mgr Practice 202 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.