
Certified Information Security Manager
Domain 2Objective 3
Risk Assessment and Analysis CISM Practice Questions (Page 2)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
8concepts
20%of the exam
Questions 6–10
- 6
During risk identification, which activity involves recognizing potential sources of harm that could exploit a vulnerability?
Select an answer first - 7
A company is evaluating risks using a qualitative risk matrix. Which of the following factors are typically used to prioritize risks in this method? (Select all that apply.)
Select an answer first - 8
A company has completed a risk assessment and identified a high-risk vulnerability in its remote access solution. The CISO must decide how to integrate this finding into the broader risk management process. Which action is most appropriate?
Select an answer first - 9
What is the primary purpose of assigning risk ownership?
Select an answer first - 10
Which step in the risk management process directly follows risk assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.