CISM Information Security Risk Management Practice Question
A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
⚠ Common exam trap
The trap is selecting a technical tool (CASB) or contractual transfer as a silver bullet, when the question emphasizes consistent controls and audits across regions—a governance and compliance approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop and enforce cloud security baseline standards and conduct regular compliance audits.
Developing and enforcing cloud security baseline standards with regular compliance audits directly addresses the root cause: inconsistent controls and misconfigurations across regions. This proactive risk management approach ensures all business units adhere to a unified security posture, reducing the likelihood of data exposure incidents. It aligns with the CISM domain of risk management and control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to cloud providers by renegotiating contracts to include liability clauses.
Why it's wrong here
Contractual liability clauses shift financial consequence but cannot transfer operational responsibility for customer-side misconfigurations, which remain the organisation's under the shared responsibility model. Transfer suits risks where a third party genuinely owns the control, such as insured or fully outsourced functions.
- ✓
Develop and enforce cloud security baseline standards and conduct regular compliance audits.
Why this is correct
Baseline standards translate the shared responsibility model into enforceable configuration requirements, and compliance audits verify consistent application across every region. This directly addresses the misconfiguration root cause and the inconsistent control the CISO must eliminate.
- ✗
Implement a cloud access security broker (CASB) to monitor all cloud activities centrally.
Why it's wrong here
A CASB enforces policy and visibility over sanctioned and unsanctioned cloud usage, but it does not correct the underlying misunderstanding of shared responsibility that caused the misconfigurations. It fits environments needing data-loss prevention and shadow-IT discovery, not root-cause governance education.
- ✗
Accept the risk as inherent to cloud adoption and focus resources on incident response.
Why it's wrong here
Accepting the risk leaves the misconfiguration root cause unaddressed and abandons the CISO's requirement for consistent cross-region control, so incidents recur. Acceptance suits low-likelihood, low-impact risks within appetite, or where treatment cost exceeds expected loss.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.