
Certified Information Security Manager
Domain 2Objective 2
Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 5)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
28questions here
6free pages
6concepts
20%of the exam
Questions 21–25
- 21
Which vulnerability assessment technique is MOST appropriate for identifying missing security patches on a large number of servers?
Select an answer first - 22
Which of the following BEST describes the primary purpose of vulnerability identification in an information security program?
Select an answer first - 23
A security manager is planning a vulnerability assessment for a critical industrial control system (ICS) environment. The environment includes legacy PLCs that cannot tolerate active scanning, and the network is segmented from the corporate network. The manager needs to identify vulnerabilities without disrupting operations. Which technique is most appropriate?
Select an answer first - 24
A security analyst is conducting a vulnerability assessment of a new web application. The analyst has already performed an authenticated scan and found several vulnerabilities. To gain a deeper understanding of the exploitability and business impact, what should the analyst do next?
Select an answer first - 25
A security manager discovers that a critical server has been missing security patches for several months, despite a policy requiring monthly patching. The patch management team states that they have been applying patches, but the server still shows missing patches. What is the most likely root cause of this control deficiency?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.