Courseiva
Information Security Risk ManagementhardMultiple ChoiceObjective-mapped

CISM Information Security Risk Management Practice Question

A healthcare organization is merging with another entity and must integrate their IT systems. During due diligence, it is discovered that the acquired company has a high number of unpatched critical vulnerabilities in its electronic health record (EHR) system. The merger timeline is aggressive and the integration team wants to proceed as planned. As the risk manager, what is the best course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Recommend delaying the integration until vulnerabilities are patched.

Delaying integration until the critical vulnerabilities are patched is the most prudent action to prevent exploitation during and after integration. Proceeding with compensating controls may not be sufficient given the criticality, and accepting the risk could lead to a major breach. Insurance does not prevent the breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the risk because the vulnerabilities are in the legacy system which will be replaced.

    Why it's wrong here

    Until replacement, the system remains vulnerable and integration could expose it further.

  • Transfer the risk by purchasing cyber insurance for the combined entity.

    Why it's wrong here

    Insurance does not prevent the incident and may not cover all damages.

  • Recommend delaying the integration until vulnerabilities are patched.

    Why this is correct

    Delay remediates the root cause before exposure increases.

  • Proceed with integration but implement compensating controls like network segmentation.

    Why it's wrong here

    Compensating controls may not fully mitigate the risk from critical vulnerabilities.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.