
Certified Information Security Manager
Domain 2Objective 6
Risk Monitoring and Reporting CISM Practice Questions (Page 1)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
37questions here
8free pages
9concepts
20%of the exam
Questions 1–5
- 1
A technology company is considering a new cloud service that will store customer data. The CISO wants to monitor the risk of data exposure. Which KRI would provide the most meaningful early warning of increasing risk?
Select an answer first - 2
When should a risk register be updated?
Select an answer first - 3
A CISO must report on a new critical vulnerability to both the board of directors and the IT operations team. The board needs to understand the business impact, while the IT team needs to know the technical details and required actions. What is the most effective reporting approach?
Select an answer first - 4
A CISO wants to provide the board with a high-level view of the organization's risk exposure, including the number of critical risks and the trend over time. Which set of metrics is most appropriate for this dashboard?
Select an answer first - 5
A CISO needs to present the organization's risk posture to the executive committee. The committee wants to see trends over the past year and the current status of top risks. Which dashboard technique is most effective for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.