HomeCISM Security Mgr Practice 202Questions 21–30
CISM Security Mgr Practice 202Part 3 of 3

CISM Security Mgr Practice 202 Exam Questions & Answers 2026 (21–30)

CISM Security Mgr Practice 202 practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CISM Security Mgr Practice 202 questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q21Who within an organization is responsible for ensuring that data privacy regulations are adhered to within business processes?

    • AData Protection Officer (DPO)
    • BCompliance officer
    • CChief Information Officer (CIO)
    • DChief Privacy Officer (CPO)
    Show answer

    ✓ Correct answer: A. Data Protection Officer (DPO)

    Answer: Data Protection Officer (DPO) The Data Protection Officer (DPO) is responsible for overseeing compliance with data privacy regulations within the organization. Compliance officers ensure that the company adheres to external regulations and internal policies, but they do not focus solely on data privacy. The CIO handles IT planning, budgeting, and performance. The Chief Privacy Officer (CPO) focuses on consumer data and privacy issues at a higher level within the organization.

  2. Q22When designing an incident response plan, it is ESSENTIAL for the information security manager to:

    • ADevelop a robust training program for all IT staff
    • BConduct frequent penetration testing to find vulnerabilities
    • CCreate a comprehensive incident documentation process
    • DEnsure that senior management supports the incident response plan
    Show answer

    ✓ Correct answer: D. Ensure that senior management supports the incident response plan

    Answer: Ensure that senior management supports the incident response plan. Explanation: All answers detail important elements of incident response planning, but if senior management does not support the plan, it will be difficult to allocate the necessary resources. Senior management's support is critical for the effective implementation and continuous improvement of the incident response plan.

  3. Q23In the context of developing an incident response plan, what is the FIRST step a security manager should take?

    • ATrain the incident response team
    • BIdentify critical assets
    • CDeploy incident response tools
    • DAssess current security measures
    Show answer

    ✓ Correct answer: B. Identify critical assets

    Answer: Identify critical assets Explanation: Before a security manager can develop an effective incident response plan, it is essential to identify and prioritize the organization’s critical assets. This ensures that the response plan focuses on protecting the most valuable and vulnerable parts of the infrastructure.

  4. Q24In a large corporation that employs both a Chief Information Security Officer (CISO) and an information security manager, which responsibility is more likely to be assigned to the CISO rather than the information security manager?

    • AImplementation of security controls
    • BMonitoring compliance with security policies
    • CManaging security incidents and responses
    • DDevelopment of an enterprise-wide security governance framework
    Show answer

    ✓ Correct answer: D. Development of an enterprise-wide security governance framework

    Answer: Development of an enterprise-wide security governance framework A CISO is typically responsible for the strategic aspects of information security, which include the development of an enterprise-wide security governance framework. This role is more strategic and high-level compared to the tasks usually assigned to an information security manager, who focuses more on operational and tactical aspects, such as implementing controls, monitoring compliance, and managing incidents.

  5. Q25In the context of incident response planning, what is another way to describe the concept of 'risk avoidance'?

    • ARisk elimination
    • BRisk mitigation
    • CRisk transfer
    • DRisk acceptance
    Show answer

    ✓ Correct answer: A. Risk elimination

    Answer: Risk elimination Risk elimination is synonymous with risk avoidance. Risk mitigation, risk transfer, and risk acceptance are different concepts within risk management. Risk mitigation involves reducing the impact or likelihood of a risk. Risk transfer refers to shifting the risk to another party. Risk acceptance means acknowledging the risk and choosing not to address it.

  6. Q26In a healthcare organization, what is the first action the information security manager should take to establish a comprehensive patient data protection program?

    • AConduct quantitative and qualitative risk assessments
    • BEstablish a policy from senior management
    • CPlan a meeting to determine resources
    • DInitiate a project to implement controls
    Show answer

    ✓ Correct answer: B. Establish a policy from senior management

    To build a successful patient data protection program, you must have management direction and support documented within a policy regarding data protection. With a policy in place, you can proceed with planning and allocating resources, conducting risk assessments using various methodologies, and then initiating projects to implement appropriate controls.

  7. Q27If a company wants to ensure that only authorized devices can access its wireless network, what type of control should it implement?

    • AWireless Access Control
    • BIntrusion Detection System (IDS)
    • CVirtual Local Area Network (VLAN)
    • DEncryption
    Show answer

    ✓ Correct answer: A. Wireless Access Control

    Answer: Wireless Access Control Wireless Access Control is used to ensure that only authorized devices can connect to a wireless network by verifying their credentials. An Intrusion Detection System (IDS) monitors network traffic for suspicious activity, but does not control access. A Virtual Local Area Network (VLAN) is used to partition a physical network into multiple, distinct segments. Encryption protects the confidentiality of data but does not control access to the network itself.

  8. Q28What type of threat is represented by an employee unintentionally sharing sensitive internal documents with an unauthorized third party?

    • AInternal threat
    • BExternal threat
    • CMalicious insider
    • DScript kiddie
    Show answer

    ✓ Correct answer: A. Internal threat

    Answer: Internal threat An internal threat is anyone inside an organization that poses potential harm to the organization. This can happen without malicious intent, such as accidentally sharing sensitive information. An external threat originates from outside the organization, such as hackers or competitive entities. A malicious insider is an employee intentionally causing harm or leak of sensitive data. Script kiddies are amateur hackers using pre-written code without real understanding; they pose as external threats.

  9. Q29Which of the following is NOT an appropriate use of qualitative risk assessments?

    • AWhen quantifiable data is not available
    • BWhen assessing aspects like reputation damage
    • CFor calculating the annual loss expectancy
    • DAs an initial step in a risk analysis process
    Show answer

    ✓ Correct answer: C. For calculating the annual loss expectancy

    Answer: For calculating the annual loss expectancy Qualitative risk assessments are generally descriptive and do not provide hard numbers. They are suitable for: 1. Initial risk assessments to prioritize further analysis. 2. Situations where quantifiable data is unavailable. 3. Assessments for non-tangible aspects, such as reputation damage. Qualitative risk assessments should not be used for calculating specific values such as the annual loss expectancy, which requires quantitative data.

  10. Q30When assessing new cybersecurity initiatives, determining the primary goals for these initiatives should use an iterative process based on:

    • AA comprehensive vulnerability analysis compared to industry standards
    • BImplementing controls aligned with historical threat data
    • CManagement's ability to align cybersecurity with corporate culture
    • DAn analysis of costs and an evaluation of acceptable risk levels
    Show answer

    ✓ Correct answer: D. An analysis of costs and an evaluation of acceptable risk levels

    Answer: An analysis of costs and an evaluation of acceptable risk levels The correct primary goals for cybersecurity initiatives must be established by evaluating the financial requirements to reach the target state and assessing whether the risk levels are within acceptable thresholds.

Free practice here. Timed mocks when you are ready.

Use the free CISM Security Mgr Practice 202 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.