Courseiva

CISM Information Security Risk Management Practice Question

A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?

⚠ Common exam trap

The trap is conflating risk transfer (insurance) with risk reduction; candidates often pick insurance because it sounds responsible, but insurance only addresses financial impact, not the likelihood of recurrence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigate the risk by implementing stronger access controls

Mitigating the risk by implementing stronger access controls directly reduces the likelihood of a similar breach by addressing the root cause—weak or insufficient access management. This is the most appropriate response because the risk manager wants to reduce the probability of recurrence, which is the definition of risk mitigation. It is a targeted, proportionate control rather than an extreme business change or a financial transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Avoid the risk by discontinuing online services

    Why it's wrong here

    Discontinuing online services removes the business model rather than the vulnerability that caused the breach, so likelihood of similar incidents elsewhere is unchanged. It tempts because avoidance eliminates risk entirely, which suits activities whose risk cannot be reduced to tolerance.

  • ✗

    Transfer the risk through cyber insurance

    Why it's wrong here

    Cyber insurance compensates financial losses after an incident but does not lower the likelihood of another breach occurring. It tempts because transfer is valuable for financing severe residual impact, yet the stem explicitly asks for a response reducing likelihood, which only mitigation achieves.

  • ✗

    Accept the risk

    Why it's wrong here

    Acceptance leaves the exposure untreated, so the likelihood of recurrence stays unchanged; it suits low-impact risks within tolerance where cost of treatment exceeds loss expectancy. Here a breach of personal data demands mitigation or transfer, not retention of the same vulnerability.

  • ✓

    Mitigate the risk by implementing stronger access controls

    Why this is correct

    Stronger access controls restrict who can reach personal data, directly lowering the probability of another unauthorised disclosure. Mitigation addresses the likelihood dimension the question specifies, unlike acceptance, avoidance or transfer, which do not reduce recurrence.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.