CoStudy

HomeCertificationsCISM › Information Security Program — Operations, Architecture and Third Party

Information Security Program — Operations, Architecture and Third Party — CISM practice questions

66 multiple-choice questions and 31 flashcards on Information Security Program — Operations, Architecture and Third Party, about 17% of the CISM bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Information Security Program — Operations, Architecture and Third Party is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 66 of the bank's 400 multiple-choice questions — roughly 17% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Information Security Program — Operations, Architecture and Third Party practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

A strategic partner's integration cannot use the enterprise's standard authorisation model, and the delivery date is fixed. The BEST course of action is to:

  1. Block the integration until the partner adopts the enterprise's standard authorisation model
  2. Have the risk owner decide, informed by the exposure and the compensating controls now available
  3. Approve it as a standing exception because the partner revenue outweighs the residual exposure
  4. Route the integration through a proxy so that the deviation is not raised in architecture review

Answer: B — Have the risk owner decide, informed by the exposure and the compensating controls now available

B) Correct — deviations from standard are risk decisions belonging to the accountable owner, and the manager's job is to present exposure and options clearly enough for that decision to be informed. A) A flat block substitutes the security function's judgement for the business owner's. C) Approving on revenue grounds alone skips the analysis that makes the acceptance defensible. D) Engineering around a review to hide a deviation is a governance failure regardless of the technical merits.

Immediately after an acquisition, the business wants the acquired company's network connected to the parent's so integration can begin. The BEST approach is to:

  1. Connect the networks and then run a vulnerability assessment across the acquired estate
  2. Refuse any connectivity until the acquired estate fully meets the parent's control baseline
  3. Connect through a firewall configured to permit the traffic the acquired company requests
  4. Permit only the connectivity that specific integration needs require, assessed and time-bound

Answer: D — Permit only the connectivity that specific integration needs require, assessed and time-bound

D) Correct — risk-proportionate, purpose-specific and time-limited connectivity lets integration proceed while the unknown estate is assessed, which balances business urgency against inherited exposure. A) Connecting first and assessing later exposes the parent to whatever the acquired environment already contains. B) A full baseline before any connectivity is rarely achievable and makes security the blocker to the deal's value. C) Letting the acquired party define the rule set delegates the risk decision to the party whose posture is unverified.

Emergency changes routinely bypass the change advisory board. The BEST control design is to:

  1. Prohibit emergency changes to any system that falls within regulatory compliance scope
  2. Require the CISO to personally authorise every emergency change before it is applied
  3. Permit them under defined criteria, with mandatory retrospective review and approval
  4. Treat every emergency change as an incident and open a formal investigation into it

Answer: C — Permit them under defined criteria, with mandatory retrospective review and approval

C) Correct — emergency change is legitimate and necessary, so governance defines when it may be invoked and guarantees after-the-fact scrutiny, which preserves both speed and accountability. A) Prohibition in regulated scope guarantees that outages there cannot be fixed quickly. B) Routing every urgent fix through one individual creates a single point of delay and failure. D) Labelling all emergency changes as incidents wastes investigative capacity and discourages legitimate use of the path.

Which BEST reflects good practice in managing outsourcing and third-party risk?

  1. Executing a standard contract, which places the obligation to secure the service on the provider
  2. Risk-based due diligence, security terms with audit and breach notification, and ongoing monitoring
  3. Relying on the supplier's reputation and existing customer base as evidence of adequate controls
  4. Declining to use third parties at all so that no data ever leaves the organization's own environment
  5. Performing a single assessment at onboarding and treating the outcome as valid for the whole term

Answer: B — Risk-based due diligence, security terms with audit and breach notification, and ongoing monitoring

B describes a life cycle rather than an event: assess the provider in proportion to the risk it carries, embed security requirements, audit rights, breach notification and service levels in the contract, then monitor throughout the relationship and coordinate incident response across the boundary. A relies on paper alone. C substitutes reputation for evidence. D is an avoidance posture that is rarely viable commercially. E is the most common real failure, since provider risk changes long before the contract does.

For governance purposes, the security architecture documentation should PRIMARILY record:

  1. The approved product set and configuration standards for each technology domain in the estate
  2. The control objectives, where each is placed, and who owns and provides assurance over it
  3. The network topology diagrams for every environment the enterprise currently operates
  4. The sequence of projects that will deliver the target state over the coming planning cycle

Answer: B — The control objectives, where each is placed, and who owns and provides assurance over it

B) Correct — architecture at management level is a statement of control objectives, placement, ownership and assurance, which is what makes it governable and auditable over time. A) Product and configuration standards implement the architecture but change frequently and describe means, not intent. C) Topology diagrams are essential engineering artifacts yet do not express who is accountable for which control. D) A delivery roadmap is a plan, not an architecture, and it will not survive contact with changing priorities.

Under a shared responsibility model for infrastructure as a service, accountability for protecting enterprise data placed in the service:

  1. Remains with the enterprise, irrespective of the controls the provider operates
  2. Transfers to the provider for those controls listed in the provider's assurance report
  3. Is divided proportionally according to the service tier the enterprise has purchased
  4. Rests with the provider for storage layers and with the enterprise for network layers

Answer: A — Remains with the enterprise, irrespective of the controls the provider operates

A) Correct — operation of specific controls can be shared, but accountability for the enterprise's data and for its regulatory obligations is never outsourced. B) An assurance report evidences that the provider operates certain controls; it does not move accountability. C) Commercial tiers change service levels and support, not who answers for the data. D) The split of operated controls varies by service model and is not a clean storage-versus-network division.

Data flow mapping reveals that regulated data is decrypted at an integration broker sitting outside the regulated zone. The security manager's NEXT step should be to:

  1. Require the broker to be rebuilt inside the regulated zone before the next scheduled release
  2. Add the broker to the monitoring scope and record an exception in the enterprise risk register
  3. Instruct the integration team to implement end-to-end encryption that passes through the broker
  4. Assess the exposure and present treatment options to the accountable data owner

Answer: D — Assess the exposure and present treatment options to the accountable data owner

D) Correct — a newly identified gap is first analysed and then put to the owner with options; selecting the treatment before the exposure is understood is the recurring management error. A) Re-platforming may well be the right treatment, but mandating it pre-empts the owner's decision and the cost comparison. B) Monitoring plus an exception entry documents the gap without treating it or informing the decision-maker. C) End-to-end encryption is one candidate treatment and may be incompatible with what the broker must do to the data.

A reporting framework produces security reports for the board, for business unit heads and for IT operations. What should MOST vary between them?

  1. The underlying measurement data, which should be gathered separately for each reporting audience
  2. The level of aggregation and the specific decision each audience is being asked to make
  3. The reporting frequency, which should differ so that no two audiences receive the same trend line
  4. The risk appetite statement, restated at the level each audience is able to influence

Answer: B — The level of aggregation and the specific decision each audience is being asked to make

B) Correct — audience-appropriate reporting draws on one consistent data set but changes granularity and framing to match the decision rights of each audience. A) Recalculating data per audience destroys consistency and invites contradictory numbers in the same enterprise. C) Frequency may differ for practical reasons, but deliberately desynchronising it to prevent comparison is the wrong objective. D) Appetite is set once at enterprise level; cascading it into limits is possible, but restating the appetite itself per audience undermines its authority.

A review of non-human accounts used by applications and automation identifies a governance weakness. The MOST significant is that these identities:

  1. Are usually excluded from the enterprise's password complexity and rotation standard
  2. Cannot be enrolled in multifactor authentication in the majority of environments
  3. Often lack a named owner and any defined lifecycle for review, rotation and revocation
  4. Are typically created by development teams rather than by the central identity team

Answer: C — Often lack a named owner and any defined lifecycle for review, rotation and revocation

C) Correct — ownerless machine identities accumulate entitlements, outlive their purpose and are never recertified, which is the governance failure that turns them into standing attack paths. A) Exclusion from password standards is a symptom of the missing lifecycle rather than the underlying problem. B) Workload authentication uses certificates, keys and platform-issued credentials, so the absence of multifactor is not the defining issue. D) Who creates them matters less than whether anyone is accountable for reviewing them afterwards.

A critical supplier declines an on-site audit, offering instead a recent independent assurance report on its service. The BEST response is to:

  1. Insist on exercising the contractual right to audit, since third-party reports cannot evidence control operation
  2. Accept the report and close the review, as an independent auditor's opinion supersedes internal assessment
  3. Review the report's scope, period covered and noted exceptions against the services actually consumed
  4. Require the supplier to complete the enterprise's own security questionnaire in place of the assurance report

Answer: C — Review the report's scope, period covered and noted exceptions against the services actually consumed

C) Correct — an assurance report can satisfy the need, but only after management checks that the scope covers the service used, the period is current and the exceptions do not touch relied-upon controls. A) A well-scoped report over an operating period does evidence control operation; insisting on an audit ignores a valid alternative. B) Accepting without reading the scope and exceptions is the classic false comfort in third-party assurance. D) A self-completed questionnaire is weaker evidence than an independent opinion, so substituting it is a step backwards.

Information Security Program — Operations, Architecture and Third Party flashcards

4 cards from the 31 in this chapter.

AAA?

Authentication, Authorization, Accounting (audit logs).

IaaS/PaaS/SaaS responsibilities?

IaaS: most customer responsibility. PaaS: shared. SaaS: most provider.

Why is an availability SLA an insufficient measure of a provider's security performance?

Availability says nothing about confidentiality or integrity, about patching and vulnerability remediation timelines, incident notification speed, or control effectiveness. Security service levels must specify measurable, evidenced security obligations with remedies, or the SLA only guarantees the service is up while insecure.

A major cloud provider will not grant a right-to-audit clause. What is the acceptable alternative and what must the manager still do?

Accept independent third-party assurance — an in-scope certification such as ISO/IEC 27001:2022 or a service auditor's report — as substitute evidence. The manager must still review the scope, the period covered, exclusions and any exceptions noted, and map the provider's controls to the enterprise's own control requirements, documenting any gaps as residual risk for the risk owner.

Practise the full chapter

These are a sample. The full Information Security Program — Operations, Architecture and Third Party chapter runs 97 items with per-chapter progress tracking, on the web and in the iOS app.

Open CISM in CoStudy →

Other CISM chapters

All CISM practice questions →