
Certified Information Security Manager
Domain 2Objective 2
Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 3)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
28questions here
6free pages
6concepts
20%of the exam
Questions 11–15
- 11
A vulnerability scan of a hospital's network reveals the following issues: a critical remote code execution vulnerability on a public-facing web server, a high-severity SQL injection flaw in an internal patient records application, and a medium-severity missing security patch on a file server. The hospital has limited IT staff and must prioritize remediation. Which vulnerability should be addressed first?
Select an answer first - 12
A security manager is planning a vulnerability assessment for a new customer-facing web application. The application is hosted in a cloud environment and uses a mix of open-source components. The manager needs to identify vulnerabilities in the application code and its dependencies. Which combination of techniques would be most effective?
Select an answer first - 13
Who is the PRIMARY audience for reports on vulnerability status?
Select an answer first - 14
During a vulnerability assessment, a security analyst discovers that a critical web application has a SQL injection flaw. The application is behind a web application firewall (WAF) that has been configured to block common attack patterns. The analyst also notes that the WAF logs show no blocked SQL injection attempts in the past six months. What is the most likely root cause of this control deficiency?
Select an answer first - 15
A security manager at a financial institution is planning the annual vulnerability assessment program. The organization has a mix of legacy mainframe systems, modern cloud workloads, and a large number of IoT devices on the OT network. The mainframe cannot be scanned with active tools without risking outages, and the cloud workloads are ephemeral. Which approach best ensures comprehensive vulnerability identification while minimizing operational impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.