
Certified Information Security Manager
Domain 2Objective 3
Risk Assessment and Analysis CISM Practice Questions (Page 6)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
8concepts
20%of the exam
Questions 26–30
- 26
A financial institution performs risk assessments annually. This year, it experienced a major data breach and also adopted a new cloud-based core banking system. The CISO must decide on the risk assessment schedule for the upcoming year. Which approach is most appropriate?
Select an answer first - 27
A software company performs a full risk assessment annually. Mid-year, the company acquires a smaller firm and integrates its customer database into the main network. According to risk assessment best practices, what should the company do?
Select an answer first - 28
A regional bank must justify its annual security budget to the board. The CISO has detailed historical loss data for past incidents (e.g., fraud losses, downtime costs) and needs to present risk in monetary terms that the board can compare against potential investments. Which risk assessment approach is most appropriate?
Select an answer first - 29
A hospital is assessing risks to its patient portal. The assessment team has identified that the portal stores sensitive health data, that a specific malware variant could exploit a known unpatched vulnerability, and that a breach could result in regulatory fines and reputational damage. Which combination of elements has the team identified?
Select an answer first - 30
A university is conducting a risk assessment for its online learning platform. The assessment team is identifying risks. Which of the following are examples of risk identification techniques? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.