Courseiva

CISM Information Security Risk Management Practice Question

A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?

⚠ Common exam trap

The trap here is selecting an action that sounds responsible, such as implementing a control or reporting externally, without first validating and prioritizing the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Validate the risk and determine its priority based on likelihood and impact

The risk treatment process starts with validating the identified risk and prioritizing it based on likelihood, impact, and risk appetite. Only after the risk is confirmed and ranked can the organization evaluate treatment options such as mitigation, transfer, avoidance, or acceptance. Jumping directly to a control, insurance, or external reporting bypasses this essential prioritization step and may misallocate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the vulnerability to the payment card brand immediately

    Why it's wrong here

    Reporting to the payment card brand may be required under contractual or regulatory obligations, but it is not the first step in the internal risk treatment process. The organization must first validate and prioritize the risk to understand its severity and determine the appropriate response. External reporting without internal validation could lead to unnecessary escalation or incomplete information.

  • ✗

    Implement a web application firewall in front of the point-of-sale system

    Why it's wrong here

    Deploying a control is a risk mitigation action, which comes after the risk has been validated and prioritized. Implementing a control prematurely may address a low-priority risk or miss the actual root cause. The first step is to confirm the risk is real and significant, then select controls that align with the treatment strategy and risk appetite.

  • ✓

    Validate the risk and determine its priority based on likelihood and impact

    Why this is correct

    The risk treatment process begins with validating the identified risk and prioritizing it using criteria such as likelihood, impact, and alignment with risk appetite. Only after the risk is confirmed and ranked can appropriate treatment options be evaluated. This ensures resources are directed to the most significant risks first and that treatment decisions are justified and consistent.

  • ✗

    Purchase a cyber insurance policy to cover potential card replacement costs

    Why it's wrong here

    Purchasing insurance is a risk transfer treatment, but it should not be the first step. Before selecting a treatment, the organization must validate and prioritize the risk. Insurance may be part of the response, but jumping to it without confirming the risk's severity could result in inadequate or unnecessary coverage. The first step is to ensure the risk is properly understood and ranked.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.