CISM Information Security Governance Practice Question
An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Periodic review and renewal of exceptions
Effective exception management requires documentation, approval, and periodic review to prevent exceptions from becoming permanent risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Periodic review and renewal of exceptions
Why this is correct
Periodic review ensures exceptions remain valid.
- ✗
Publicizing the exception to all employees
Why it's wrong here
Publicizing is not necessary and may cause confusion.
- ✗
Automatic expiration of the exception after a defined period
Why it's wrong here
Exceptions should have a review date but automatic expiration may cause issues.
- ✓
Approval by the CISO or designated authority
Why this is correct
Approval ensures accountability.
- ✓
Documentation of the business justification
Why this is correct
Justification ensures the exception is necessary.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.