
Certified Information Security Manager
Domain 2Objective 2
Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 4)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
28questions here
6free pages
6concepts
20%of the exam
Questions 16–20
- 16
What is the primary purpose of a remediation plan?
Select an answer first - 17
After implementing a remediation plan, the security manager wants to ensure that the fixes are effective and that no new vulnerabilities have been introduced. What is the most appropriate action?
Select an answer first - 18
What is the primary goal of control deficiency analysis?
Select an answer first - 19
What is the primary purpose of monitoring the effectiveness of remediation efforts?
Select an answer first - 20
A security manager has a limited budget and must prioritize remediation of vulnerabilities across the organization. The following vulnerabilities have been identified: a critical vulnerability in a public-facing web server that is actively exploited in the wild, a high-severity vulnerability in an internal HR system that is not exposed to the internet, and a medium-severity vulnerability in a file server that contains sensitive data but is only accessible internally. The web server is not critical to business operations, but the HR system is. Which vulnerability should be remediated first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.