
Certified Information Security Manager
Domain 2Objective 3
Risk Assessment and Analysis CISM Practice Questions (Page 4)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
8concepts
20%of the exam
Questions 16–20
- 16
After a risk assessment, a healthcare organization needs to communicate the prioritized risks to senior management. The CISO wants a visual tool that shows the relative likelihood and impact of each risk at a glance. Which output is most appropriate?
Select an answer first - 17
A multinational corporation is assessing risks across its regional offices. The risk team has reliable loss data for the European region but only qualitative ratings for the Asia-Pacific region. The CISO needs a consolidated risk register that allows comparison across regions. Which approach best addresses this challenge?
Select an answer first - 18
What is the primary purpose of a risk heat map?
Select an answer first - 19
An organization decides to accept a risk because the cost of mitigation exceeds the potential loss. This decision is primarily influenced by which factor?
Select an answer first - 20
A financial services firm has identified three risks: (1) a high-likelihood, low-impact phishing campaign, (2) a low-likelihood, high-impact data breach, and (3) a medium-likelihood, medium-impact system outage. The firm's risk appetite is conservative, and it must prioritize using a risk matrix. Which risk should be addressed first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.