Free ISACA CISM Actual Exam Questions - Question 7 Discussion
Question No. 7
Which of the following is the BEST indication ofa successful information security culture?
Select one option, then reveal solution.
US
ZC
Zain C.
2026-02-20
B, because if users can spot and report issues, culture is actually working.
0
ZC
Zain C.
2026-02-16
C seems about structure, but does that alone prove culture success?
0
ZC
Zain C.
2026-02-16
B imo, cause knowing and reporting incidents shows real user engagement.
0
SH
Sami H.
2026-01-23
A/C? Regular pen testing shows ongoing commitment, but having roles aligned with job functions (C) ensures accountability, which is also crucial for a true security culture. Could argue both reflect success differently.
0
OC
Omar C.
2026-01-19
Maybe B, since actual user awareness beats just having resources or roles.
0
OC
Omar C.
2026-01-16
Option B feels right here since a successful security culture depends a lot on users spotting and reporting issues. But the explanation could dig deeper into why that’s key. Anyone got a better breakdown?
0