Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 2

Vulnerability and Control Deficiency Analysis CISM Practice Questions (Page 6)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

28questions here
6free pages
6concepts
20%of the exam

Questions 26–28

  1. 26foundation · easy

    Which of the following is a key component of an effective remediation plan?

    Select an answer first
  2. 27application · medium

    A security manager is planning a vulnerability assessment for a new cloud-based application that uses serverless functions and managed databases. The application is deployed in a DevOps environment with frequent changes. Which assessment approach is most appropriate?

    Select an answer first
  3. 28expert · hard

    A security manager has implemented a vulnerability remediation program and needs to report to senior management on its effectiveness. The manager has the following data: the number of vulnerabilities identified, the number remediated, the average time to remediate, and the number of vulnerabilities that remain open. Which metric would be most meaningful to senior management to demonstrate the program's success?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISM

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.