Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 2

Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 1)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

28questions here
6free pages
6concepts
20%of the exam

Questions 1–5

  1. 1foundation · easy

    Which vulnerability assessment technique involves actively attempting to exploit a vulnerability to determine its real-world impact?

    Select an answer first
  2. 2expert · hard

    A security manager is developing a remediation plan for a critical vulnerability in a legacy application that is essential for business operations. The vendor has released a patch, but the patch requires a database upgrade that could cause downtime and is not fully tested. The organization has a maintenance window of only four hours on weekends. What should the manager do?

    Select an answer first
  3. 3foundation · easy

    Which factor is MOST important when prioritizing vulnerabilities for remediation?

    Select an answer first
  4. 4foundation · easy

    A vulnerability exists on a server that contains highly sensitive customer data. The vulnerability is known to be actively exploited in the wild. How should this vulnerability be prioritized?

    Select an answer first
  5. 5application · medium

    A security manager is developing a remediation plan for a set of vulnerabilities found in a web application. The application is scheduled for a major upgrade in six months. Some vulnerabilities can be fixed by configuration changes, while others require code changes. What should the manager include in the remediation plan?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.