
Certified Information Security Manager
Domain 2Objective 6
Risk Monitoring and Reporting CISM Practice Questions (Page 5)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
37questions here
8free pages
9concepts
20%of the exam
Questions 21–25
- 21
An organization is subject to GDPR and must demonstrate compliance with its data protection policies. The CISO wants to ensure that all employees are following the data handling procedures. Which activity is most directly aligned with this goal?
Select an answer first - 22
A healthcare organization must comply with HIPAA and has implemented a risk management program. The CISO wants to ensure that all security policies are being followed by employees. Which monitoring activity is most appropriate?
Select an answer first - 23
A financial services firm has established a risk appetite that tolerates a maximum of 15% of customer accounts with outdated security patches. The CISO wants to detect when the organization is approaching this threshold before it is breached. Which action best supports this objective?
Select an answer first - 24
What is the primary purpose of an ongoing risk monitoring process?
Select an answer first - 25
A KRI for a critical supplier has been trending upward for three months and is now at the warning threshold. The supplier is essential to operations, and replacing them would be costly. The CISO must decide whether to escalate. What is the most important factor in this decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.