
Certified Information Security Manager
Domain 2Objective 4
Risk Treatment / Risk Response Options CISM Practice Questions (Page 1)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
10concepts
20%of the exam
Questions 1–5
- 1
A software development company identified a risk that a critical vulnerability in a third-party library could be exploited. The company cannot replace the library because it is essential to the product. The security manager must reduce the risk to an acceptable level. Which action best represents risk mitigation?
Select an answer first - 2
A university decided to mitigate the risk of unauthorized access to student records by implementing role-based access control (RBAC). The security manager is developing the risk treatment plan. Which element should be included to ensure the plan is actionable?
Select an answer first - 3
Which of the following is a key step in implementing risk treatment measures?
Select an answer first - 4
Which of the following lists the four primary risk treatment options as defined in information security risk management?
Select an answer first - 5
A small nonprofit organization identified a risk of phishing attacks. The likelihood is low and the impact is limited to minor disruption. The cost to implement advanced email filtering exceeds the potential loss. The board has a moderate risk appetite and has formally decided to accept the risk. What must the security manager do to ensure this decision is valid?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.