CISM Information Security Risk Management Practice Question
A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?
⚠ Common exam trap
The trap here is assuming that risk treatment (insurance, redundancy, acceptance) should be initiated before a formal risk assessment is completed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a country risk assessment to identify threats and vulnerabilities specific to the region.
The correct first step is to conduct a country risk assessment. This provides the necessary information about the specific threats and vulnerabilities of operating in that region, enabling the board to make an informed decision. Other options like insurance, redundancy, or acceptance are all risk treatment strategies that should only be considered after the risk has been properly assessed and evaluated against the organization's risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a country risk assessment to identify threats and vulnerabilities specific to the region.
Why this is correct
A country risk assessment is the foundational step to understand the geopolitical, regulatory, and physical security risks of operating in a new region. It identifies threats such as political instability, legal changes, and infrastructure reliability. This assessment provides the necessary context for the board to make an informed decision. Without it, any risk treatment or transfer decision would lack a factual basis and could expose the organization to unforeseen losses.
- ✗
Implement a redundant data center in a stable region to ensure business continuity.
Why it's wrong here
Implementing redundancy is a risk mitigation strategy that requires significant investment. It should not be the first action before a risk assessment is conducted, as it may not be the most appropriate or cost-effective control. The organization might decide to avoid the risk entirely or accept it based on the assessment. Taking action before assessment could lead to wasted resources and unaddressed risks.
- ✗
Accept the risk because the expansion is a strategic business decision.
Why it's wrong here
Risk acceptance is a valid treatment option, but it must be based on a thorough understanding of the risk and the organization's risk appetite. Accepting the risk without assessment is negligent and could lead to significant losses. The CISO's role is to inform the decision, not to bypass the risk management process. The board needs the assessment to make an informed choice about whether to accept, avoid, transfer, or mitigate the risk.
- ✗
Purchase political risk insurance to transfer the potential financial losses.
Why it's wrong here
Purchasing insurance before assessing the risk is premature. While risk transfer is a valid treatment option, it should only be selected after the risk is identified, analyzed, and evaluated. Insurance may not cover all types of losses (e.g., data compromise, intellectual property theft) and could be unnecessary if the risk is deemed acceptable or avoidable. The FIRST step is always to understand the risk before deciding on treatment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.