CISM

Information Security Program

50 practice questions with explanations — 15 free to try

PassNova has 50 CISM practice questions on Information Security Program, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Information Security Program: example questions & answers

3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 50-question Information Security Program bank is part of PassNova Premium.

  1. An information security program's objectives should be derived PRIMARILY from which of the following?

    • AThe most recent security conference recommendations
    • BThe latest security product features available on the market
    • CThe information security strategy and business requirements
    • DThe preferences of the network administration team

    Answer: Program objectives flow from the security strategy and business requirements so the program delivers outcomes the organisation actually needs.

  2. What is the MOST important success factor when implementing a security awareness training program?

    • ATesting employees once at the time of hiring and never again afterwards
    • BUsing the most expensive e-learning platform available
    • CTailoring the content to the audience and reinforcing it regularly
    • DDelivering all of the training material in a single annual classroom session

    Answer: Awareness is most effective when content is tailored to the audience and reinforced regularly, sustaining behaviour change rather than a one-off event.

  3. When selecting security controls for the information security program, what should be the PRIMARY consideration?

    • AThe number of controls that can be deployed within the current quarter
    • BThe set of controls used by the organisation's largest competitor
    • CThe level of risk the controls are intended to reduce
    • DThe vendor offering the largest discount on a multi-year licence

    Answer: Controls should be selected based on the risk they reduce, ensuring effort and spend are aligned to the organisation's actual exposure.

Start practising Information Security Program →