Courseiva
Question 421 of 871
Information Security ProgrammediumMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

⚠ Common exam trap

The trap here is that candidates often jump to 'implement compensating controls' (Option D) as a quick fix, but CISM emphasizes that the first step must always be to understand the failure through root cause analysis before selecting any corrective action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a root cause analysis to determine why controls failed.

When controls are found ineffective, the security manager must first conduct a root cause analysis to identify why the controls failed. This aligns with the CISM's emphasis on corrective action based on understanding the underlying failure, such as misconfigured firewall rules, outdated signature databases, or improper access control lists (ACLs). Without this analysis, any subsequent remediation (like implementing compensating controls or increasing testing frequency) may address symptoms rather than the actual cause, leading to recurring failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a root cause analysis to determine why controls failed.

    Why this is correct

    Identifies systemic gaps; allows effective remediation.

  • Increase the frequency of control testing.

    Why it's wrong here

    Testing more often doesn't fix underlying issues.

  • Report the findings to management and accept the risk.

    Why it's wrong here

    Premature; risks may be misaccepted without understanding.

  • Implement compensating controls immediately.

    Why it's wrong here

    Reactive; without analysis, compensating controls may also fail.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.