Courseiva

CISM Information Security Risk Management Practice Question

A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?

⚠ Common exam trap

The trap here is assuming that a vendor's SOC 2 attestation or SLA transfers responsibility for data copied outside the vendor's environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigate the risk by enforcing full-disk encryption, access controls, and a policy prohibiting unauthorized local copies.

The risk arises from hospital-controlled endpoints, so the effective treatment is mitigation through encryption, access control, and policy enforcement. Transfer and acceptance do not address the internal behavior, and avoidance of the vendor relationship is misdirected because the vendor is not the source of the exposure. Risk treatment should be matched to the party that actually controls the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk to the cloud vendor by amending the SLA to include the local workstations.

    Why it's wrong here

    Transferring risk requires another party to accept the financial consequences. The vendor has no control over hospital workstations and would not accept responsibility for data copied outside its environment. Amending the SLA cannot shift accountability for a practice performed by hospital staff on hospital endpoints, so this treatment is not viable.

  • ✗

    Accept the risk because the cloud vendor holds SOC 2 Type II attestation.

    Why it's wrong here

    A vendor's SOC 2 attestation covers the vendor's own controls, not the hospital's local storage practices. Accepting the risk would leave unencrypted protected health information exposed on workstations, which may violate HIPAA breach notification obligations. The attestation does not compensate for the loss of control at the hospital endpoint.

  • ✓

    Mitigate the risk by enforcing full-disk encryption, access controls, and a policy prohibiting unauthorized local copies.

    Why this is correct

    Mitigation reduces likelihood and impact through controls the hospital can enforce. Full-disk encryption protects data if a workstation is lost, access controls limit exposure, and policy with technical enforcement addresses the root behavior. This directly targets the risk introduced by staff copying images locally rather than relying on the vendor's controls.

  • ✗

    Avoid the risk by terminating the contract with the cloud vendor and returning to on-premises storage.

    Why it's wrong here

    Terminating the vendor relationship does not eliminate the local-copy behavior, which would persist regardless of where primary storage resides. Risk avoidance is disproportionate here because the identified risk stems from internal staff practices, not the vendor. The organization would incur significant cost without addressing the actual cause.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.