Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 4

Risk Treatment / Risk Response Options CISM Practice Questions (Page 5)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

35questions here
7free pages
10concepts
20%of the exam

Questions 21–25

  1. 21application · medium

    A financial services firm processes high-value wire transfers. A risk assessment identified that a legacy payment gateway has a critical vulnerability that could allow unauthorized transactions. The vendor no longer provides patches, and the cost to replace the gateway is significant. The firm's risk appetite is low, and the board has mandated that no critical vulnerabilities remain unaddressed. Which risk treatment option should the security manager recommend?

    Select an answer first
  2. 22expert · hard

    A bank has decided to mitigate the risk of insider trading by implementing a new surveillance system. The risk treatment plan must be developed, but the bank has a tight budget and a strict deadline. Which approach should the security manager take to ensure the plan is realistic and achievable?

    Select an answer first
  3. 23foundation · easy

    Which of the following is typically included in a risk treatment plan?

    Select an answer first
  4. 24foundation · easy

    What is residual risk?

    Select an answer first
  5. 25foundation · easy

    Which of the following best describes risk transfer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.