CISM Information Security Risk Management Practice Question
A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop and enforce cloud security baseline standards and conduct regular compliance audits.
Developing and enforcing cloud security baseline standards and conducting regular compliance audits directly address the root cause of misconfigurations due to lack of understanding. A CASB provides monitoring but does not enforce standards. Transferring risk to cloud providers shifts liability but does not prevent misconfigurations. Acceptance with focus on incident response is reactive and does not reduce likelihood.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to cloud providers by renegotiating contracts to include liability clauses.
Why it's wrong here
Liability clauses transfer financial risk but do not prevent incidents.
- ✓
Develop and enforce cloud security baseline standards and conduct regular compliance audits.
Why this is correct
Standards and audits address the root cause by ensuring consistent understanding and adherence.
- ✗
Implement a cloud access security broker (CASB) to monitor all cloud activities centrally.
Why it's wrong here
A CASB monitors but does not enforce consistent security baselines.
- ✗
Accept the risk as inherent to cloud adoption and focus resources on incident response.
Why it's wrong here
Acceptance without mitigation does not reduce the risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.