CISM Information Security Risk Management Practice Question
A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?
⚠ Common exam trap
The trap here is focusing on infrastructure components like servers or firewalls instead of the data itself, which is the asset with the highest value and risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer database containing personal and payment card information.
The customer database is the most critical asset because it holds sensitive personal and payment card information. Its compromise would result in the most significant impact to the organization, including regulatory fines, financial loss, and reputational harm. While other components like servers, firewalls, and load balancers are important for operations and security, they support the protection of the data. Risk assessments should prioritize assets based on the potential impact of their loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The load balancer distributing traffic to the web servers.
Why it's wrong here
The load balancer ensures availability and performance, but it does not store sensitive data. Its failure would impact service availability, but the loss of confidentiality or integrity of customer data would have more severe consequences. Availability is important, but confidentiality and integrity of sensitive data are typically higher priorities in e-commerce. The load balancer is a supporting infrastructure component.
- ✗
The network firewall protecting the e-commerce environment.
Why it's wrong here
The firewall is a security control, not an asset to be protected in the same sense as data. While it is important for preventing unauthorized access, its compromise would be a failure of a control rather than the loss of a critical asset. The firewall's purpose is to protect the data; thus, the data itself is more critical. Risk assessments should prioritize assets based on their value to the organization.
- ✓
The customer database containing personal and payment card information.
Why this is correct
The customer database is the most critical asset because it contains sensitive personal and payment card information. A breach of this data can lead to severe financial penalties, reputational damage, and legal liability. Regulations such as PCI DSS and GDPR impose strict requirements on protecting such data. Therefore, the database should be the primary focus of risk assessment and protection efforts.
- ✗
The web server hosting the e-commerce application.
Why it's wrong here
The web server is important, but it is a component that supports the application. If compromised, it could lead to service disruption or data breach, but the data itself is often the primary target. Protecting the server is part of a defense-in-depth strategy, but the most critical asset is the data it processes. The server's value is derived from the data it handles.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.