
Certified Information Security Manager
Domain 2Objective 3
Risk Assessment and Analysis CISM Practice Questions (Page 7)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
8concepts
20%of the exam
Questions 31–35
- 31
A healthcare organization has a risk that spans multiple departments: IT manages the technical controls, legal handles regulatory compliance, and operations manages patient data access. The CISO needs to ensure the risk is managed effectively. Which action is most appropriate?
Select an answer first - 32
A company has completed a risk assessment and identified several risks. The CISO wants to ensure that the assessment results are used to drive decisions and actions, not just stored in a document. Which action best integrates the assessment into the risk management process?
Select an answer first - 33
A company has identified a risk related to its customer data processing. The CISO wants to ensure proper risk ownership. Which of the following are key responsibilities of a risk owner? (Select all that apply.)
Select an answer first - 34
A company has completed a risk assessment and needs to document the results. Which of the following are appropriate outputs of a risk assessment? (Select all that apply.)
Select an answer first - 35
A bank has a conservative risk appetite and must prioritize two risks: (1) a high-likelihood, low-impact phishing risk that affects many employees, and (2) a low-likelihood, high-impact fraud risk that could result in regulatory fines. The bank has limited resources and can only address one risk this quarter. Which risk should the bank prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.