exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 495 discussion

Actual exam question from Isaca's CISM
Question #: 495
Topic #: 1
[All CISM Questions]

Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?

  • A. The information security operations matrix
  • B. Changes to information security risks
  • C. Information security program metrics
  • D. Results of a recent external audit
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
D2D2
Highly Voted 2 years, 1 month ago
Selected Answer: C
Metrics is best
upvoted 10 times
...
CarlLimps
Highly Voted 1 year, 10 months ago
Selected Answer: D
Folks, it's gotta be D. I can tell you that if I was sitting on a board. I would rely on an audit, especially 3rd party, to show me what the state of a security program is. Metrics would be my second choice.
upvoted 5 times
ddharia94
1 year, 6 months ago
I agree. External audit report is always better than the metrics
upvoted 1 times
...
wello
1 year, 7 months ago
Do you think you have the time to read an audit, its findings, and interpret it and relate it to business objectives then take a decision what to do???
upvoted 1 times
...
...
d3fa4d2
Most Recent 8 months, 2 weeks ago
Selected Answer: D
Metrics give best indication. But isn't external audit the most non biased.? wouldn't that show best indication
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
Selected Answer: C
Metrics can include key performance indicators (KPIs), such as the number of security incidents, incident response times, compliance with security policies, and other relevant data points that help the board understand how well the organization is managing its information security risks.
upvoted 2 times
...
richck102
1 year, 6 months ago
C. Information security program metrics
upvoted 1 times
...
wello
1 year, 7 months ago
Selected Answer: C
C. Information security program metrics
upvoted 1 times
...
Souvik124
1 year, 10 months ago
Information security program metrics (Option C) would BEST demonstrate the status of an organization's information security program to the board of directors.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...