
Certified Information Security Manager
Domain 2Objective 4
Risk Treatment / Risk Response Options CISM Practice Questions (Page 6)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
35questions here
7free pages
10concepts
20%of the exam
Questions 26–30
- 26
Which of the following is an example of a risk mitigation measure?
Select an answer first - 27
A retail chain is implementing a new multi-factor authentication (MFA) system to mitigate the risk of account takeover. The security manager needs to ensure the controls are effectively integrated into daily operations. Which action is most important for successful implementation?
Select an answer first - 28
A company outsources its payment processing to a third-party provider. The contract specifies that the provider is liable for any security breach in the payment system. Which risk treatment option is the company applying?
Select an answer first - 29
A mid-sized e-commerce company lacks in-house expertise to manage its web application firewall (WAF) and DDoS protection. A managed security service provider (MSSP) offers 24/7 monitoring and incident response for a fixed monthly fee. The company's risk appetite is moderate, and the board wants to reduce operational burden while maintaining security. Which risk treatment option is the company applying by contracting with the MSSP?
Select an answer first - 30
A risk has a potential financial impact of $50,000. The cost to implement a mitigation control is $80,000. The organization's risk appetite is low. Which risk treatment option is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.