
Certified Information Security Manager
Domain 2Objective 4
Risk Treatment / Risk Response Options CISM Practice Questions (Page 2)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
10concepts
20%of the exam
Questions 6–10
- 6
A multinational corporation is assessing the risk of a data breach in its cloud infrastructure. The risk appetite is low, but the board is concerned about the cost of controls. The security manager has identified three options: implement advanced threat detection (cost: $1M/year), purchase cyber insurance (premium: $500K/year), or accept the risk. The expected annual loss is $800K. The board wants to minimize residual risk while being cost-conscious. Which option should the security manager recommend?
Select an answer first - 7
A pharmaceutical company is considering a partnership with a contract research organization (CRO) to conduct clinical trials. The risk assessment identifies a high risk of intellectual property (IP) theft. The company's risk appetite is low, and the board wants to protect IP while still benefiting from the partnership. Which risk treatment approach is most appropriate?
Select an answer first - 8
Why is ongoing monitoring of risk treatment effectiveness important?
Select an answer first - 9
A manufacturing company decided to mitigate the risk of intellectual property theft by implementing data loss prevention (DLP) and access controls. The security manager must now develop a risk treatment plan. Which element is essential to include in the plan?
Select an answer first - 10
An organization decides to stop a business activity because the associated risk exceeds its risk appetite and no cost-effective controls can reduce it. Which risk treatment option is being applied?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.