Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 2

Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 2)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

28questions here
6free pages
6concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    After a major vulnerability remediation effort, the security manager needs to report progress to the board of directors. Which type of metric would be most useful for the board to understand the effectiveness of the remediation program?

    Select an answer first
  2. 7application · medium

    A security manager has identified a critical vulnerability in a legacy application that cannot be patched immediately because the vendor no longer provides updates. The application is essential for business operations. What should the manager include in the remediation plan?

    Select an answer first
  3. 8foundation · easy

    During a control deficiency analysis, which of the following is the MOST important factor to consider when determining the potential impact of a deficiency?

    Select an answer first
  4. 9expert · hard

    A security manager is investigating a data breach that occurred through a known vulnerability in a web server. The vulnerability had been identified in a scan six months ago, but it was not remediated because the IT team claimed that the server was not critical and the vulnerability was low risk. The server was later exposed to the internet due to a network configuration change. What is the primary control deficiency that allowed this breach?

    Select an answer first
  5. 10foundation · easy

    Which of the following is an example of a vulnerability in an information system?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.