Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 6

Risk Monitoring and Reporting CISM Practice Questions (Page 7)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

37questions here
8free pages
9concepts
20%of the exam

Questions 31–35

  1. 31foundation · easy

    What is the purpose of maintaining and updating the risk register?

    Select an answer first
  2. 32foundation · easy

    Which situation would typically trigger risk escalation?

    Select an answer first
  3. 33foundation · easy

    Why is it important to tailor risk communication to different audiences?

    Select an answer first
  4. 34application · medium

    A security team needs to report a critical vulnerability to the IT operations team, which will be responsible for patching. The IT team is not familiar with security risk terminology. What is the best way to communicate the urgency?

    Select an answer first
  5. 35application · medium

    A manufacturing company has implemented a new production system that introduces several new risks. The CISO wants to ensure that these risks are continuously monitored to keep them within the organization's risk appetite. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.