CISM Information Security Risk Management Practice Question
A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?
⚠ Common exam trap
The trap is conflating risk transfer (insurance) with risk reduction; candidates often pick insurance because it sounds responsible, but insurance only addresses financial impact, not the likelihood of recurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the risk by implementing stronger access controls
Mitigating the risk by implementing stronger access controls directly reduces the likelihood of a similar breach by addressing the root cause—weak or insufficient access management. This is the most appropriate response because the risk manager wants to reduce the probability of recurrence, which is the definition of risk mitigation. It is a targeted, proportionate control rather than an extreme business change or a financial transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid the risk by discontinuing online services
Why it's wrong here
Discontinuing online services removes the business model rather than the vulnerability that caused the breach, so likelihood of similar incidents elsewhere is unchanged. It tempts because avoidance eliminates risk entirely, which suits activities whose risk cannot be reduced to tolerance.
- ✗
Transfer the risk through cyber insurance
Why it's wrong here
Cyber insurance compensates financial losses after an incident but does not lower the likelihood of another breach occurring. It tempts because transfer is valuable for financing severe residual impact, yet the stem explicitly asks for a response reducing likelihood, which only mitigation achieves.
- ✗
Accept the risk
Why it's wrong here
Acceptance leaves the exposure untreated, so the likelihood of recurrence stays unchanged; it suits low-impact risks within tolerance where cost of treatment exceeds loss expectancy. Here a breach of personal data demands mitigation or transfer, not retention of the same vulnerability.
- ✓
Mitigate the risk by implementing stronger access controls
Why this is correct
Stronger access controls restrict who can reach personal data, directly lowering the probability of another unauthorised disclosure. Mitigation addresses the likelihood dimension the question specifies, unlike acceptance, avoidance or transfer, which do not reduce recurrence.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.