Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 5

Risk and Control Ownership CISM Practice Questions (Page 1)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

24questions here
5free pages
6concepts
20%of the exam

Questions 1–5

  1. 1foundation · easy

    Which responsibility is typically assigned to a risk owner?

    Select an answer first
  2. 2application · medium

    A control owner is responsible for a firewall rule set that prevents unauthorized network access. The control owner has been asked to document the control's effectiveness for an annual review. Which action best demonstrates the control owner's responsibility?

    Select an answer first
  3. 3application · medium

    A risk owner has been managing a risk for several years. The risk has been consistently low and the controls are effective. The risk owner is considering whether to close the risk. What is the most appropriate action?

    Select an answer first
  4. 4foundation · easy

    What is the primary responsibility of a control owner?

    Select an answer first
  5. 5application · medium

    A regional bank has identified a high-risk vulnerability in its customer-facing mobile banking application. The CISO has assigned a risk owner to manage this risk. The risk owner has accepted the risk and documented the rationale. Six months later, the vulnerability remains unpatched and the risk owner has moved to a different department. Which action best reflects the ongoing responsibility of the original risk owner in this situation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.