20+ practice questions focused on Information Security Risk Management — one of the most tested topics on the Certified Information Security Manager CISM exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Information Security Risk Management PracticeA multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?
Explanation: Given the organization's low risk appetite for data breaches, the most appropriate strategy is to avoid the risk entirely by not engaging vendors that cannot meet security requirements. This aligns with the principle that when risk exceeds the acceptable threshold, avoidance is the prioritized treatment. Avoidance eliminates the risk source, whereas other strategies like mitigation or transfer still retain some residual risk that may be unacceptable.
Refer to the exhibit. A security analyst reviews the firewall configuration and identifies a potential risk. What is the most likely risk?
Explanation: The exhibit shows a firewall rule that permits DNS traffic (UDP/TCP port 53) from the internal network to any external destination. This configuration allows internal hosts to perform DNS queries to external servers, which can be exploited for DNS tunneling—a technique where data is encapsulated within DNS queries and responses to bypass security controls and exfiltrate sensitive information. Since DNS traffic is typically allowed through firewalls, this creates a covert channel for data exfiltration, making option D the most likely risk.
Refer to the exhibit. A system administrator reviews the log and notices repeated failed SSH attempts from the same IP address. What is the most appropriate risk response?
Explanation: Implementing an account lockout policy after 3 failed attempts directly mitigates brute-force SSH attacks by preventing further authentication attempts from the same IP address. This is a standard risk response (risk reduction) that limits the attacker's ability to guess credentials without requiring changes to the SSH protocol or disabling remote access entirely.
Based on the exhibit, what is the MOST appropriate next step for the information security manager?
Explanation: Multifactor authentication (MFA) directly mitigates the most likely attack vector for the identified risk—credential theft or brute-force attacks—by requiring a second factor (e.g., a one-time password from a hardware token or biometric) in addition to the password. Since the exhibit (not shown) indicates a moderate likelihood but high impact, implementing MFA reduces the likelihood to a more acceptable level without requiring a change in risk appetite or transferring the risk. This aligns with the CISM principle of applying cost-effective controls to reduce residual risk to within the organization's risk tolerance.
During a risk assessment, an organization identifies a critical vulnerability in a legacy system that cannot be patched. The system's availability is crucial for business operations. Which of the following risk treatment strategies is MOST appropriate?
Explanation: When a critical vulnerability cannot be patched and the system must remain available for business operations, risk acceptance is the most appropriate strategy because it formally acknowledges the residual risk after all feasible controls have been considered. Senior management sign-off is required because the risk exceeds the organization's risk appetite, and acceptance documents the decision to operate with the known vulnerability. This approach aligns with the CISM principle that risk acceptance is a valid treatment when the cost of other treatments exceeds the benefit or when no other treatment is feasible.
+15 more Information Security Risk Management questions available
Practice all Information Security Risk Management questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Information Security Risk Management. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Information Security Risk Management questions on the CISM frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Information Security Risk Management is tested as part of the Certified Information Security Manager CISM blueprint. Practicing with targeted Information Security Risk Management questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CISM practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Information Security Risk Management is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Information Security Risk Management practice session with instant scoring and detailed explanations.
Start Information Security Risk Management Practice →