[2026] New CITM exam Free Sample Questions to Practice [Q24-Q40]

4/5 - (1 vote)

[2026] New CITM exam Free Sample Questions to Practice

Cover Real CITM Exam Questions Make Sure You 100% Pass

EXIN CITM Exam Syllabus Topics:

Topic Details
Topic 1
  • Project Management: This domain is aimed at an IT Project Manager and encompasses planning, executing, and controlling IT projects. It includes managing scope, time, cost, quality, and risks, applying project methodologies, engaging stakeholders, and delivering projects that meet business requirements.
Topic 2
  • IT Strategy: This section of the exam measures the skills of an IT Strategy Manager and covers the development and alignment of IT strategy with business objectives. It emphasizes creating strategic plans to support organizational goals, understanding emerging technologies, and ensuring that IT investments contribute to competitive advantage and operational efficiency.
Topic 3
  • Risk Management: This domain evaluates the capabilities of an IT Risk Manager and involves identifying, assessing, and mitigating IT-related risks. It addresses developing risk frameworks, compliance management, and proactive measures to safeguard IT assets and operations.
Topic 4
  • Information Security Management: This section targets an Information Security Manager and focuses on protecting information assets from threats. It covers policy development, security controls implementation, incident response, data protection, and compliance with legal and regulatory requirements to maintain confidentiality, integrity, and availability.
Topic 5
  • IT Organization: This domain targets an IT Operations Manager and focuses on the design and management of IT organizational structures. It includes defining roles and responsibilities, establishing governance frameworks, managing resources effectively, and fostering collaboration to support IT service delivery and business needs.

 

Q24. One of the company’s assets is valued at $200,000.00. Based on historical data, the exposure factor is 25%, and the Annual Loss Expectancy (ALE) is calculated at $100,000.00. What is the Annualized Rate of Occurrence (ARO)?

 
 
 

Q25. The team responsible for network security has proposed a firewall as the preferred control for the network perimeter. How is this type of control categorized?

 
 
 
 

Q26. Lately, the support desk is receiving several requests for password resets from individuals who appear to be unknown to the organization. Possible criminal activities are suspected, and the organization wishes to address this issue in their information security awareness program. What is the area that requires awareness?

 
 
 
 

Q27. Little to no budget is available for hiring new staff for the IT service desk. What is the ideal method of sourcing knowing that little time is available?

 
 
 
 

Q28. Business is changing fast, resulting in the need to formally appoint a new staff member responsible for guiding the process in a controlled manner. Which role does apply?

 
 
 
 

Q29. What is the Critical Success Factor (CSF) in IT services review?

 
 
 
 

Q30. As part of feedback collection techniques, it is suggested to include anonymous feedback. What would be the most likely reason for this?

 
 
 
 

Q31. In business continuity planning, the maximum age of the data to restore in the event of a disaster is considered which of the following?

 
 
 
 

Q32. The new system (application) is ready for adoption (implementation). The customer is concerned that an instant change-over from the current system to the new system will create a large impact on the user base.
You are requested to propose an approach for adoption. Which of the items listed below is recommended?

 
 
 
 

Q33. When selecting a new vendor, continuity needs to be guaranteed as much as possible. At a minimum, which criteria are considered?

 
 
 
 

Q34. From the list below, which activity is not considered to be an activity in the software development phase?

 
 
 
 

Q35. In system (application) development, a use case (user story) is a list of steps defining interactions between a role and a system to achieve a goal. What type of requirement is mentioned here?

 
 
 
 

Q36. In project management, what is the objective of a ‘lessons learned’ report?

 
 
 
 

Q37. One particular incident repeatedly occurs every first day of the working week. As part of problem management, it is decided to gather a group of technical specialists to conduct problem analysis. Which technique is recommended?

 
 
 
 

Q38. A selection process for new IT staff has started. The Human Resource department has requested to follow the corporate staff hiring protocol. One mandatory item to be included is additional screening. What is verified by doing this?

 
 
 
 

Q39. Senior management is concerned fraudulent activities may take place during large financial transactions. To reduce the risk of fraud, it expects the proper controls to be in place. Which security principle is in need of the highest attention?

 
 
 
 

Q40. Before the marketing department will decide on a new advertising campaign, it wants to be able to gain more insights into the customer, being able to predict the products customers will purchase in the near future. What is a ‘must-have’ criterion in terms of the technology the marketing department is interested in?

 
 
 
 

Real CITM Quesions Pass Certification Exams Easily: https://www.dumpleader.com/CITM_exam.html

         

Related Links: www.stes.tyc.edu.tw telegra.ph www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below