
Certified Information Security Manager
Domain 2Objective 6
Risk Monitoring and Reporting CISM Practice Questions (Page 6)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
37questions here
8free pages
9concepts
20%of the exam
Questions 26–30
- 26
After a major security incident, the CISO conducts a post-incident review. The review reveals that the risk register did not include a specific risk that contributed to the incident. What is the most important follow-up action?
Select an answer first - 27
A multinational corporation has a board of directors that meets quarterly. The CISO needs to provide a concise overview of the organization's top risks, trends, and the effectiveness of risk treatment. Which reporting approach is most appropriate for this audience?
Select an answer first - 28
A key risk indicator for data breach exposure has exceeded its warning threshold and is now above the risk appetite. The risk owner has been notified but has not taken action. What should the CISO do next?
Select an answer first - 29
How can monitoring and reporting results be used to improve the risk management process?
Select an answer first - 30
A risk owner has completed a risk treatment plan that reduces the likelihood of a key risk from 'likely' to 'unlikely'. What is the most important action for the risk manager to take to maintain an accurate risk register?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.