Courseiva
Information Security ProgrameasyMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

Exhibit

Refer to the exhibit.
```
Risk Register Entry:
ID: RR-102
Risk: Data loss from unencrypted laptops
Current Controls: Full disk encryption policy (not enforced)
Likelihood: 3 (Medium)
Impact: 5 (Very High)
Risk Score: 15
Proposed Control: Enforce encryption via MDM
Residual Risk after control: 3 (Low)
```

Based on the risk register entry, what is the primary gap in the current controls?

⚠ Common exam trap

Candidates often assume a policy exists means the control is effective, but CISM emphasizes that a policy without technical enforcement (e.g., via MDM or NAC) is a gap, not a control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The policy exists but is not enforced technically

The risk register entry indicates that a mobile device management (MDM) policy exists but is not enforced through technical controls, such as device compliance checks or automated policy application. This creates a gap because the policy remains a paper-based directive without active enforcement mechanisms like certificate-based authentication or conditional access rules, leaving devices vulnerable to non-compliance and potential data breaches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The policy exists but is not enforced technically

    Why this is correct

    Policy without enforcement is ineffective.

  • MDM is not a suitable control

    Why it's wrong here

    MDM can enforce encryption effectively.

  • The risk score is too low to require action

    Why it's wrong here

    Score of 15 is high.

  • The likelihood of occurrence is low

    Why it's wrong here

    Likelihood is medium.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.