
Certified Information Security Manager
Domain 2Objective 4
Risk Treatment / Risk Response Options CISM Practice Questions (Page 3)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
10concepts
20%of the exam
Questions 11–15
- 11
An organization has identified a risk of data loss due to hardware failure. Which of the following is a risk mitigation measure?
Select an answer first - 12
An organization has implemented controls to reduce a risk's likelihood from high to medium. The remaining risk is still above the organization's risk tolerance. What should the organization do?
Select an answer first - 13
What is the primary purpose of a risk treatment plan?
Select an answer first - 14
A financial institution is implementing a new security awareness training program to mitigate the risk of social engineering. The security manager needs to ensure the training is effective and integrated into the organization's culture. Which action is most important during the implementation phase?
Select an answer first - 15
A hospital's risk assessment identified a ransomware risk with an inherent likelihood of 4 (on a 5-point scale) and impact of 5. After implementing endpoint detection, offline backups, and staff training, the security manager estimates likelihood drops to 2 and impact to 4. The hospital's risk tolerance threshold is a risk score of 10 (likelihood × impact). What should the security manager do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.