
Certified Information Security Manager
Domain 2Objective 3
Risk Assessment and Analysis CISM Practice Questions (Page 5)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
8concepts
20%of the exam
Questions 21–25
- 21
Which document is the primary output of a risk assessment that lists identified risks, their likelihood, impact, and assigned owners?
Select an answer first - 22
A manufacturing company is analyzing the risk of a production line shutdown. Historical data shows the line fails once every five years, and each failure costs $500,000 in lost production and recovery. What is the annualized loss expectancy (ALE) for this risk?
Select an answer first - 23
A retail company has completed a risk assessment and identified a critical vulnerability in its customer payment system. The CISO needs to ensure that someone is accountable for implementing the remediation plan. Which action best fulfills the risk ownership requirement?
Select an answer first - 24
Which risk assessment methodology is most appropriate when an organization needs to express risk in monetary terms to support cost-benefit analysis of security controls?
Select an answer first - 25
What is the primary consideration when determining the frequency of regular risk assessments?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.