Courseiva

CCNA Information Security Risk Management Questions

75 of 122 questions · Page 1/2 · Information Security Risk Management · Answers revealed

1
MCQmedium

After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?

A.Re-assess the risk using a different methodology
B.Lower the risk tolerance to match the residual risk
C.Seek management approval for acceptance or implement additional controls
D.Ignore the residual risk since controls are already in place
AnswerC

Residual risk above tolerance cannot simply be left; the risk owner must decide. Either obtain formal management approval to accept the elevated exposure or apply further controls to bring it within tolerance, preserving accountability and documented risk ownership.

Why this answer

When residual risk exceeds the established risk tolerance, the organization must either implement additional controls to reduce the risk further or formally accept the residual risk through management approval. This aligns with the risk treatment decision-making process in ISO 31000 and the CISM framework, where risk acceptance is a management responsibility. Option C correctly identifies these two valid paths.

Exam trap

The CISM exam often tests the misconception that risk assessment methodology changes can resolve residual risk issues, but the trap here is that candidates may choose Option A, thinking a different methodology will yield a more favorable result, when in fact the correct action is to treat the risk through additional controls or formal acceptance.

How to eliminate wrong answers

Option A is wrong because re-assessing with a different methodology does not change the actual risk level; it only changes the measurement, which is a form of risk avoidance through redefinition rather than proper treatment. Option B is wrong because lowering the risk tolerance to match the residual risk is a reactive and inappropriate response that undermines the risk appetite set by the organization; risk tolerance should drive control decisions, not be adjusted to fit uncontrolled risk. Option D is wrong because ignoring residual risk violates the fundamental principle of risk management that requires continuous monitoring and response when risk exceeds tolerance; controls do not absolve the organization from addressing unacceptable residual risk.

2
MCQmedium

A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?

A.Implement encryption for all data stored in the new region.
B.Review the board's risk appetite statement and tolerance levels for the new region.
C.Perform a gap analysis of current controls against the new region's regulatory requirements.
D.Conduct a business impact analysis (BIA) for all regional operations.
AnswerB

The board's risk appetite and tolerance levels provide the criteria for evaluating and treating risks. Aligning treatment with appetite requires first understanding what the board deems acceptable. This step ensures that subsequent risk assessments and control decisions are consistent with organizational objectives and regulatory constraints. It is the foundational step before any analysis or control implementation in the new region.

Why this answer

Aligning risk treatment with risk appetite begins with understanding the board's appetite and tolerance. The risk appetite statement defines the amount and type of risk the organization is willing to accept, which then guides the selection of controls. Only after this alignment can a gap analysis, BIA, or control implementation be effectively prioritized.

Thus, reviewing the board's risk appetite is the essential first step.

Exam trap

The trap here is assuming that a technical control like encryption or a BIA is the first step, when the board's risk appetite must be established to guide treatment decisions.

3
MCQhard

An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?

A.Accept the risk until the monitoring solution is deployed and document the decision.
B.Implement interim compensating controls such as privileged access review, session logging, and least privilege while planning the monitoring deployment.
C.Transfer the risk by purchasing cyber insurance covering insider fraud.
D.Defer the risk decision to the application owner because they own the budget.
AnswerB

Interim compensating controls reduce exposure immediately while the strategic control is deployed. Privileged access reviews, session logging, and least privilege directly address insider misuse of privileged accounts at low cost. This approach balances risk reduction with the budget and timeline constraints and demonstrates due diligence to regulators.

Why this answer

When a strategic control cannot be deployed quickly, interim compensating controls reduce exposure in the near term. Privileged access reviews, session logging, and least privilege target the insider misuse scenario directly and are feasible within budget. Acceptance, insurance-only transfer, or full delegation do not adequately address a high-likelihood compliance risk during the deployment gap.

Exam trap

The trap here is assuming that a planned future control justifies accepting the risk in the interim without compensating measures.

4
MCQhard

An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?

A.$400,000
B.$10,000,000
C.$500,000
D.$2,000,000
AnswerA

Annualised loss expectancy multiplies single loss expectancy by annualised rate of occurrence. A $2 million loss every five years gives an exposure factor of 0.2 per year, yielding $400,000. This satisfies the policy's quantitative requirement by expressing expected annual loss in monetary terms, enabling direct comparison against control costs.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, the ARO is 1/5 = 0.2 (one event every five years), and the SLE is $2,000,000. Thus, ALE = 0.2 × $2,000,000 = $400,000.

Exam trap

The trap here is that candidates often confuse the recurrence interval (every 5 years) with the ARO, mistakenly multiplying the loss by 5 instead of dividing, leading to the inflated $10,000,000 option.

How to eliminate wrong answers

Option B is wrong because $10,000,000 results from multiplying the loss ($2M) by 5 (the number of years between occurrences) instead of dividing, which incorrectly inflates the annualized loss. Option C is wrong because $500,000 would be the ALE if the ARO were 0.25 (once every 4 years), not the given 0.2. Option D is wrong because $2,000,000 is the single loss expectancy (SLE), not the annualized figure; it ignores the frequency of occurrence entirely.

5
Multi-Selecthard

Which THREE of the following are essential components of an information security risk management framework?

Select 3 answers
A.Incident response planning
B.Risk identification
C.Compliance auditing
D.Risk assessment
E.Risk treatment
AnswersB, D, E

Risk identification establishes which threats, vulnerabilities and assets fall within scope, feeding every later stage. This satisfies the framework requirement by ensuring exposures are discovered and recorded before analysis, treatment or monitoring can meaningfully occur.

Why this answer

Risk identification (B) is essential because the framework must first determine which threats, vulnerabilities, and assets exist before any risk can be analyzed or managed. Risk assessment (D) is essential because it evaluates the identified risks by determining likelihood and impact, often through qualitative or quantitative methods, to prioritize them. Risk treatment (E) is essential because it defines how the organization will respond to assessed risks through mitigation, transfer, acceptance, or avoidance, completing the core risk management cycle.

Incident response planning (A) is a reactive operational capability that supports risk management but is not one of the core framework components, and compliance auditing (C) is a assurance activity that verifies adherence to controls or regulations rather than a foundational risk management process.

Exam trap

The trap here is that candidates confuse operational security processes (like incident response) or compliance activities (like auditing) with the core risk management framework components, which are strictly risk identification, risk assessment, and risk treatment as defined by ISACA.

6
MCQmedium

An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$5,000
B.$10,000
C.$20,000
D.$2,500
AnswerA

ALE is derived by multiplying single loss expectancy by annualised rate of occurrence: $10,000 × 0.5 = $5,000. This quantifies the expected yearly financial loss from server failure, giving management a monetary figure for comparing against the cost of countermeasures.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Given an SLE of $10,000 and an ARO of 0.5, the ALE is $10,000 × 0.5 = $5,000. This represents the expected annual financial loss from server failures based on the frequency and impact of such events.

Exam trap

The trap here is that candidates often confuse ALE with SLE or incorrectly apply the ARO as a multiplier greater than 1, leading to answers like $20,000, instead of recognizing that an ARO of 0.5 means the loss is halved annually.

How to eliminate wrong answers

Option B is wrong because $10,000 equals the SLE, not the ALE; it ignores the ARO factor of 0.5, which reduces the annualized loss. Option C is wrong because $20,000 would result from multiplying SLE by 2 (or dividing ARO by 0.25), a common error of inverting the ARO or misapplying the formula. Option D is wrong because $2,500 would be the result of dividing SLE by 4 or multiplying by 0.25, possibly from confusing ARO with a percentage or miscomputing 0.5 × 10,000.

7
MCQhard

A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?

A.Transfer the risk to the terminal vendor through the existing support contract.
B.Implement compensating controls such as network segmentation and enhanced monitoring while the replacement proceeds.
C.Accept the risk because the CIO has committed to an 18-month replacement schedule.
D.Immediately disconnect all point-of-sale terminals until they are replaced.
AnswerB

Compensating controls reduce the likelihood and impact of exploitation during the transition period without halting store operations. Segmentation limits lateral movement from compromised terminals, and enhanced monitoring improves detection. This balances continuity with risk reduction and provides the board with a defensible interim position while the permanent remediation is completed.

Why this answer

When permanent remediation will take time, compensating controls allow the organization to reduce risk to a tolerable level while maintaining business operations. Network segmentation and enhanced monitoring address the unsupported platform's exposure without interrupting sales, and they give the CISO a defensible interim posture that can be revisited as the replacement program progresses.

Exam trap

The trap here is treating the choice as binary between shutting down and accepting, when interim compensating controls are the standard way to manage risk during a long remediation.

8
Multi-Selecteasy

Which TWO of the following are key components of an information security risk assessment? (Choose two.)

Select 2 answers
A.Threat identification
B.Security policy development
C.Incident response planning
D.Control implementation
E.Asset identification
AnswersA, E

Threat identification enumerates the sources and actors capable of exploiting vulnerabilities, forming the input that lets assessors determine which risks apply to each asset. Without it, likelihood estimates and subsequent risk calculations lack any credible basis.

Why this answer

Asset identification (E) is a foundational component of a risk assessment because you cannot evaluate risk without first knowing which information assets, systems, and data require protection and what value they hold to the organization. Threat identification (A) is equally essential, since risk is derived from identifying the threats (e.g., malware, insider abuse, natural disasters) that could exploit vulnerabilities and cause harm to those assets. Together, asset and threat identification feed into the core risk formula (risk = likelihood × impact), enabling analysts to prioritize risks and recommend treatment.

The other options do not belong: security policy development (B) is a governance/risk-treatment output, incident response planning (C) is a reactive capability built after risks are understood, and control implementation (D) is a risk-mitigation activity that follows the assessment rather than forming part of it.

Exam trap

The trap here is that candidates often confuse risk assessment activities (threat and asset identification) with downstream risk management steps like policy creation or control implementation, leading them to select options that are part of the broader risk management lifecycle but not the assessment itself.

9
Multi-Selectmedium

A security manager is building a risk register for a newly deployed customer relationship management platform. Which TWO of the following entries are most appropriate to record as risks rather than as controls or assets? (Choose two.)

Select 2 answers
A.The platform enforces role-based access control for all administrative functions.
B.A disgruntled employee could export the entire customer database before their account is disabled.
C.The platform is hosted in a tier III data center with redundant power and cooling.
D.The vendor's contract includes a 99.9 percent uptime service-level agreement.
E.Customer personally identifiable information could be exposed through a misconfigured API.
AnswersB, E

This entry pairs a threat actor with a weakness in the offboarding process and a potential data loss impact, which makes it a valid risk. It should be captured with likelihood, impact, and a risk owner so that controls such as behavior monitoring, least privilege, and rapid deprovisioning can be evaluated. It is not a control, because it describes what could go wrong rather than what is already in place.

Why this answer

A risk register records uncertain events that could affect objectives, expressed as a threat exploiting a weakness with a potential impact. The misconfigured API exposure and the disgruntled employee data export both meet that definition and require owners, likelihood, impact, and treatment. The access control, redundant data center, and service-level agreement are controls or assurances, not risks.

Exam trap

The trap here is confusing controls and assets with risks, when a risk must describe an uncertain future event with a potential adverse impact.

10
Multi-Selecthard

An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?

Select 3 answers
A.Organization's risk appetite
B.Likelihood of threat actors targeting the system
C.Effectiveness of existing security controls
D.Sensitivity of the data stored and processed
E.Ease of exploiting vulnerabilities in the system
AnswersB, D, E

Threat likelihood is a core component of inherent risk.

Why this answer

Inherent risk is the risk level before any security controls are applied. When evaluating inherent risk for a new cloud-based HR system, the likelihood of threat actors targeting the system (B) is a key factor because it directly influences the probability of a risk event occurring, independent of any existing or planned controls. This assessment considers the system's exposure, attractiveness to attackers, and the threat landscape specific to cloud HR platforms.

Exam trap

ISACA often tests the distinction between inherent risk and residual risk, trapping candidates who confuse control effectiveness (C) or risk appetite (A) as factors in inherent risk evaluation.

11
MCQhard

A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?

A.Perform a comprehensive model validation and sensitivity analysis
B.Increase the risk appetite to accommodate the underestimation
C.Replace the quantitative model with a qualitative risk assessment
D.Adjust the model parameters to align with observed losses
AnswerA

Validation tests the model's conceptual soundness, data quality and assumptions against realised losses, while sensitivity analysis identifies which inputs drive the 40% underestimation. Peer review alone does not detect calibration drift, so this directly addresses the board's accuracy concern.

Why this answer

When a quantitative risk model consistently underestimates actual losses by a material margin (40% here), the model itself is the problem — its assumptions, distributions, correlations, or data inputs are flawed. The risk manager's obligation is to validate the model independently and stress-test its sensitivity to key assumptions before the board relies on its outputs. Model validation and sensitivity analysis directly address the root cause (model risk) rather than masking the symptom.

Exam trap

CISM often tests the instinct to 'fix the number' (adjust parameters or appetite) rather than fix the process — candidates must recognize that independent validation, not parameter tuning, is the correct governance response to model risk.

How to eliminate wrong answers

Option B is wrong because increasing risk appetite to 'accommodate' underestimation is backwards — it accepts inaccurate reporting and increases exposure rather than fixing the model. Option C is wrong because replacing a quantitative model with qualitative assessment discards the firm's loss data and reduces rigor; it does not resolve the underlying model risk and may violate regulatory expectations for quantified cyber risk. Option D is wrong because simply tuning parameters to match observed losses is curve-fitting — it treats symptoms, can degrade the model's predictive validity, and bypasses the independent validation that model risk management (e.g., SR 11-7) requires.

12
MCQhard

An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?

A.Accept the risk since the risk owner has agreed.
B.Transfer the risk to an insurance company.
C.Insist on additional controls to reduce residual risk to at least 'medium'.
D.Recommend revising the risk appetite to accommodate this risk.
AnswerC

Residual risk equals inherent risk adjusted by control effectiveness. Partially effective controls on a high inherent risk likely leave residual risk above the mandated medium ceiling, so acceptance breaches risk appetite and additional controls are required.

Why this answer

The organization's risk appetite mandates that residual risk must be at 'medium' or lower. With an inherent risk of 'high' and controls rated 'partially effective', the residual risk remains above the acceptable threshold. Therefore, the best course is to insist on additional controls to bring residual risk down to at least 'medium', ensuring compliance with the risk appetite.

Exam trap

The trap here is that candidates may think the risk owner's acceptance is sufficient, but CISM emphasizes that risk acceptance must be within the risk appetite; otherwise, it is a violation of governance.

How to eliminate wrong answers

Option A is wrong because accepting the risk would violate the organization's risk appetite, which requires residual risk to be at 'medium' or lower; the risk owner's acceptance does not override policy. Option B is wrong because transferring the risk to insurance does not reduce the residual risk level; it only shifts financial impact, and the residual risk remains 'high' or 'medium-high', still exceeding the appetite. Option D is wrong because revising the risk appetite to accommodate a single project undermines the governance framework and sets a dangerous precedent; the risk appetite should be driven by strategic objectives, not by individual risks.

13
MCQmedium

A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?

A.Risk avoidance: immediately replace all POS systems with modern ones
B.Risk mitigation: implement compensating controls and schedule a phased upgrade
C.Risk acceptance: accept the risk because the business cannot afford replacement
D.Risk transfer: purchase cyber insurance to cover potential losses from POS attacks
AnswerB

Compensating controls (network segmentation, strict POS hardening, enhanced monitoring) reduce exposure from the unpatched OS while a phased upgrade preserves store operations and spreads cost, directly satisfying the stem's dual constraint of risk reduction and business continuity.

Why this answer

Risk mitigation with compensating controls and a phased upgrade balances risk reduction with business continuity. It acknowledges the high risk of outdated POS systems, implements immediate compensating controls (e.g., network segmentation, enhanced monitoring, virtual patching) to reduce exposure, and schedules a phased replacement to avoid operational disruption and spread costs over time.

Exam trap

CISM often tests the misconception that risk transfer (cyber insurance) eliminates risk — candidates must recognize that insurance only transfers financial impact, not the likelihood or operational impact of an attack, and is not a substitute for mitigation.

How to eliminate wrong answers

Option A is wrong because risk avoidance (immediate replacement) ignores the business unit's concerns about cost and disruption, and may not be feasible without causing operational failure. Option C is wrong because risk acceptance without any controls is inappropriate for a high-risk issue with known vulnerabilities — acceptance is only valid for low risks or when the cost of mitigation exceeds the potential loss. Option D is wrong because risk transfer via cyber insurance does not reduce the likelihood or impact of an attack — it only provides financial compensation after a loss, and insurers may deny claims for known unpatched vulnerabilities.

14
MCQhard

An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$250,000
B.$1,000,000
C.$125,000
D.$500,000
AnswerA

SLE equals asset value times exposure factor: $2,000,000 × 0.25 = $500,000. ALE equals SLE times ARO: $500,000 × 0.5 = $250,000. This satisfies the stem's quantitative inputs, yielding the expected annual loss from that risk.

Why this answer

The annualized loss expectancy (ALE) is calculated as ALE = AV × EF × ARO, where AV is the asset value ($2,000,000), EF is the exposure factor (0.25), and ARO is the annualized rate of occurrence (0.5). Multiplying these gives $2,000,000 × 0.25 × 0.5 = $250,000, which represents the expected annual financial loss from this risk.

Exam trap

The trap here is that candidates often forget to multiply by the ARO after computing SLE, or they confuse ARO with a percentage and incorrectly apply it as a divisor instead of a multiplier.

How to eliminate wrong answers

Option B ($1,000,000) is wrong because it incorrectly multiplies AV by EF only ($2,000,000 × 0.25 = $500,000) and then doubles it, or misapplies ARO as 1.0 instead of 0.5. Option C ($125,000) is wrong because it multiplies AV by ARO only ($2,000,000 × 0.5 = $1,000,000) and then divides by 8, or incorrectly halves the EF to 0.125. Option D ($500,000) is wrong because it calculates AV × EF ($2,000,000 × 0.25 = $500,000) but omits the ARO multiplier entirely, treating ARO as 1.0.

15
MCQmedium

A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?

A.Immediately terminate the vendor contract and migrate claims processing in-house.
B.Perform a risk assessment of the change in ownership and its impact on data protection obligations.
C.Report the acquisition to the regulator and await instructions before taking any action.
D.Accept the change because the vendor's service-level agreement remains unchanged.
AnswerB

A change in vendor ownership can alter legal jurisdiction, data handling practices, and breach notification obligations, so the risk manager must first assess the resulting risk to the organization. This assessment informs whether to renegotiate, add controls, or exit the relationship. Treating the acquisition as a trigger for reassessment aligns with continuous third-party risk management and gives decision-makers the facts they need.

Why this answer

A change of control at a critical vendor is a risk event that must be reassessed before any treatment decision. Because the contract lacks a change-of-control clause, the organization cannot rely on contractual levers and must understand the new legal, privacy, and operational exposure. Assessing first supports an informed choice among renegotiation, added controls, or managed exit, and preserves evidence of due diligence.

Exam trap

The trap here is assuming that an unchanged service-level agreement means unchanged risk, when ownership changes can alter legal jurisdiction and data protection obligations.

16
MCQeasy

A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?

A.The load balancer distributing traffic to the web servers.
B.The network firewall protecting the e-commerce environment.
C.The customer database containing personal and payment card information.
D.The web server hosting the e-commerce application.
AnswerC

The customer database is the most critical asset because it contains sensitive personal and payment card information. A breach of this data can lead to severe financial penalties, reputational damage, and legal liability. Regulations such as PCI DSS and GDPR impose strict requirements on protecting such data. Therefore, the database should be the primary focus of risk assessment and protection efforts.

Why this answer

The customer database is the most critical asset because it holds sensitive personal and payment card information. Its compromise would result in the most significant impact to the organization, including regulatory fines, financial loss, and reputational harm. While other components like servers, firewalls, and load balancers are important for operations and security, they support the protection of the data.

Risk assessments should prioritize assets based on the potential impact of their loss.

Exam trap

The trap here is focusing on infrastructure components like servers or firewalls instead of the data itself, which is the asset with the highest value and risk.

17
MCQhard

A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?

A.Transfer the risk by purchasing cyber insurance that covers clinical system outages.
B.Accept the risk and document it in the risk register with a review date.
C.Perform a residual risk assessment to determine if the compensating controls reduce risk to an acceptable level.
D.Immediately remove the application from the network until the vendor provides a patch.
AnswerC

Compensating controls change the risk picture, so the CISO must reassess residual risk. Network segmentation and enhanced monitoring may reduce likelihood or impact, but only a formal residual risk assessment can show whether the remaining risk is within tolerance. That assessment then informs whether to accept, further treat or escalate the risk, ensuring decisions are based on evidence rather than assumption.

Why this answer

When compensating controls are introduced, the risk profile changes and must be re-evaluated. A residual risk assessment determines whether segmentation and monitoring reduce the risk to a level the hospital can tolerate. Only after that assessment can leadership make an informed decision to accept, further mitigate or transfer the risk.

Acting without this step risks either unnecessary disruption or unrecognized exposure.

Exam trap

The trap here is assuming that implementing compensating controls automatically makes the risk acceptable, skipping the required residual risk assessment.

18
MCQhard

An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?

A.Approve the risk acceptance and document it in the risk register.
B.Validate the cost-benefit analysis and ensure the risk is accepted by the appropriate authority.
C.Transfer the risk by purchasing cyber insurance.
D.Implement compensating controls to reduce the risk to an acceptable level.
AnswerB

Risk acceptance decisions must be based on a valid cost-benefit analysis and approved by the authority whose level matches the risk. The security manager should verify the analysis and escalate for acceptance. This ensures due diligence and proper governance. Only after validation and authorization should the risk be marked as accepted in the register. This step is critical before any acceptance is finalized.

Why this answer

Before a risk can be accepted, the cost-benefit analysis must be validated, and acceptance must be authorized by the appropriate level of management based on the risk score. The security manager's role is to facilitate this process, ensuring that the decision is informed and within governance. Thus, validating the analysis and obtaining proper authorization is the correct next step.

Exam trap

The trap here is assuming that the security manager can simply approve risk acceptance or that any treatment can be applied without proper validation and authority.

19
Multi-Selecthard

A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)

Select 3 answers
A.Monetary value of potential losses
B.Detailed technical vulnerabilities
C.Likelihood of occurrence expressed as annual probability
D.Anecdotal stories of past incidents
E.Comparison of residual risk to risk appetite
AnswersA, C, E

Why this answer

Monetary value of potential losses (A) is correct because it translates technical risk into financial terms that board members understand, enabling informed decisions on resource allocation for risk mitigation. This aligns with the CISM focus on business-aligned risk communication, where quantitative metrics like Annualized Loss Expectancy (ALE) directly support cost-benefit analysis.

Exam trap

The trap here is that candidates often select 'Detailed technical vulnerabilities' (B) thinking it demonstrates thoroughness, but the board requires business-impact language, not technical depth.

Why the other options are wrong

B

Board members typically lack technical background; focus on business impact.

D

Anecdotes are not quantitative and may skew perception.

20
Multi-Selecteasy

Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Enforcing least privilege access controls
B.Implementing intrusion detection systems
C.Discontinuing a high-risk business process
D.Purchasing cyber insurance
E.Accepting the risk in a formal statement
AnswersA, B

Least privilege restricts each account to the permissions its role requires, shrinking the attack surface and limiting blast radius if credentials are compromised. It is a preventive administrative control that lowers inherent risk rather than transferring or accepting it.

Why this answer

Option A (Enforcing least privilege access controls) is a risk mitigation control because it reduces the likelihood and impact of unauthorized access by limiting users to only the permissions required for their role, directly lowering exposure to threats. Option B (Implementing intrusion detection systems) is also a mitigation control because it detects malicious activity and enables timely response, thereby reducing the potential damage from attacks. In contrast, Option C (Discontinuing a high-risk business process) is risk avoidance, as the activity is eliminated rather than controlled.

Option D (Purchasing cyber insurance) is risk transference, shifting financial consequences to an insurer. Option E (Accepting the risk in a formal statement) is risk acceptance, where no control is implemented and the risk is knowingly retained.

Exam trap

CISM often tests the confusion between risk mitigation and the other treatment options — candidates frequently misclassify insurance as mitigation when it is actually risk transference.

21
MCQmedium

A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?

A.Risks whose residual risk level exceeds the organization's defined risk appetite.
B.Risks that the security team has been unable to remediate within the current fiscal year.
C.Risks that received the highest inherent risk scores before any controls were applied.
D.Risks associated with systems that support the organization's most revenue-generating business processes.
AnswerA

Escalation for formal acceptance is driven by residual risk, not inherent risk, because implemented controls already reduce exposure. Only when the remaining exposure breaches the tolerance thresholds set by executive management does the risk require a decision at board level. Risks sitting inside appetite are managed by line management under delegated authority, so this criterion correctly routes decisions to the body empowered to accept them.

Why this answer

Board-level risk acceptance is triggered when residual risk exceeds the appetite and tolerance thresholds that executive management has established. Inherent scores, business criticality, and remediation delays are inputs to analysis but do not by themselves indicate that a decision above delegated authority is required. Routing only appetite-breaching residual risks keeps the committee focused on exposures that genuinely require formal acceptance.

Exam trap

The trap here is assuming that the highest-scoring or most business-critical risks automatically go to the board, when escalation is actually governed by residual risk exceeding documented risk appetite.

22
MCQeasy

A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerA

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. EDR detects and responds to malicious activity, thereby reducing the chance of successful POS malware or limiting its damage. The organization is taking action to lower the risk to an acceptable level. This is a classic example of mitigation.

Why this answer

Risk mitigation is the process of implementing controls to reduce the likelihood or impact of a risk. By deploying EDR, the organization aims to detect and respond to POS malware, thereby lowering the risk. Avoidance would mean stopping the activity, transfer would involve insurance, and acceptance would mean no action.

Therefore, mitigation is the correct treatment strategy.

Exam trap

The trap here is confusing mitigation with transfer or acceptance; implementing a control reduces risk rather than shifting or tolerating it.

23
MCQeasy

Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?

A.Data owner
B.Chief Information Security Officer (CISO)
C.Board of directors
D.Risk owner
AnswerD

The risk owner is accountable for identifying, assessing and managing risks within their business unit, owning the response decision and residual exposure. This satisfies the stem's requirement, distinguishing them from security staff who advise and from senior management who set appetite.

Why this answer

The risk owner is the individual within a business unit who is accountable for ensuring that information security risks are identified, assessed, and managed. This role owns the risk treatment plan and is responsible for implementing controls to reduce risk to an acceptable level, as defined by the organization's risk appetite.

Exam trap

The trap here is confusing the risk owner with the CISO, as candidates often assume the CISO owns all risks, but the CISO is responsible for the risk management process, not for owning specific business unit risks.

How to eliminate wrong answers

Option A is wrong because the data owner is responsible for classifying and protecting data assets, not for managing the overall risk process within a business unit. Option B is wrong because the CISO is an enterprise-level executive who oversees the information security program and risk management framework, but does not own the risks within individual business units. Option C is wrong because the board of directors provides oversight and sets risk appetite, but is not operationally responsible for identifying, assessing, and managing risks in a specific business unit.

24
MCQhard

A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?

A.Escalate the residual risk to the risk committee with a recommendation to accept the risk because the existing controls already reduce it below the original inherent score.
B.Initiate a new risk assessment to recalculate the inherent risk score, because the residual score may be inaccurate due to control effectiveness assumptions.
C.Implement additional technical controls immediately to reduce the residual risk below 12, then inform the risk committee of the change at the next quarterly meeting.
D.Present the residual risk to the risk committee with documented treatment options, including additional controls, risk transfer, or risk avoidance, and their associated costs and impacts.
AnswerD

The board policy requires escalation of residual risk above 12 for a formal treatment decision. The CISO's role is to provide the risk committee with sufficient information to choose among treatment options. Presenting the risk with options, costs, and impacts enables informed decision-making and complies with the established governance threshold, making this the most appropriate first action.

Why this answer

Because the residual risk exceeds the board-defined threshold of 12, the CISO must escalate it to the risk committee for a formal treatment decision. The most appropriate first action is to present the risk along with viable treatment options, costs, and business impacts so the committee can make an informed choice. This respects governance, ensures accountability, and provides the decision-makers with the information they need.

Exam trap

The trap here is assuming that because controls already reduced the risk from its inherent level, the residual risk can be accepted without escalation, ignoring the board's explicit threshold.

25
MCQhard

An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?

A.Recommend blocking the launch until the security team completes a full independent audit of the application.
B.Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.
C.Delegate the regulatory risk decision to the business unit's legal counsel and document the outcome.
D.Advise the unit to proceed with the launch and remediate regulatory gaps in a post-launch phase.
AnswerB

Assessing the launch against the new regulatory requirements gives leadership a factual view of the exposure, and presenting treatment options with business impact lets them make an informed risk-based decision. This respects the business unit's objectives while ensuring that regulatory risk is identified, evaluated, and consciously accepted or mitigated by the accountable owners.

Why this answer

Effective risk management supports business objectives by making risk visible and manageable rather than by blocking initiatives. Assessing the launch against the new regulations and presenting treatment options with their business impact allows leadership to weigh speed against compliance exposure and make a documented, risk-aware decision within their authority.

Exam trap

The trap here is believing the security manager should either block the launch outright or defer compliance, when the correct role is to assess the risk and enable an informed business decision.

26
MCQmedium

An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?

A.Escalate the vulnerability to senior management for acceptance.
B.Update the risk register with the new vulnerability.
C.Analyze the likelihood and impact of the vulnerability being exploited.
D.Select and implement controls to mitigate the vulnerability.
AnswerC

ISO 27005 sequences risk identification before risk analysis. Having identified the vulnerability, the organisation must next estimate the likelihood of exploitation and the resulting impact, which produces the risk level used for subsequent evaluation and treatment decisions.

Why this answer

According to ISO 27005, after risk identification (including discovering a new vulnerability), the next step is risk analysis, which involves assessing the likelihood and impact of the vulnerability being exploited. This analysis is required before any decision on risk treatment (e.g., mitigation, acceptance) can be made. Option C correctly identifies this sequential step in the ISO 27005 risk management process.

Exam trap

The trap here is that candidates confuse the order of the ISO 27005 phases, often jumping to risk treatment (selecting controls) or documentation (updating the register) before completing the mandatory risk analysis step.

How to eliminate wrong answers

Option A is wrong because risk acceptance is a decision made after risk evaluation (which follows risk analysis), not immediately after identification; escalating without analyzing likelihood and impact bypasses the structured ISO 27005 workflow. Option B is wrong because updating the risk register is a documentation activity that should occur after the risk has been analyzed and evaluated, not as the immediate next step after identification. Option D is wrong because selecting and implementing controls is part of risk treatment, which occurs only after risk analysis and risk evaluation have been completed, per the ISO 27005 lifecycle.

27
MCQmedium

A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?

A.Ask the provider to complete a security questionnaire and sign a confidentiality agreement
B.Request the provider's most recent independent audit report, such as SOC 2 Type II
C.Review the provider's public marketing materials and security whitepapers
D.Conduct a penetration test of the provider's infrastructure without notifying them
AnswerB

An independent audit report, such as SOC 2 Type II, provides validated evidence that the provider's controls operated effectively over a period. It covers security, availability, and confidentiality criteria and is issued by a third-party auditor. This gives the organization reliable assurance for risk assessment and vendor management, far more than self-attestations or marketing claims.

Why this answer

Independent audit reports such as SOC 2 Type II provide validated evidence that a third-party provider's controls operated effectively over a defined period. They are prepared by a qualified auditor and cover relevant trust services criteria, giving the organization reliable assurance for risk assessment and vendor management. Self-reported materials, questionnaires, or unauthorized testing do not offer the same level of independent, ongoing verification.

Exam trap

The trap here is accepting self-reported claims or questionnaires as sufficient assurance instead of requiring independent, period-based audit evidence.

28
MCQmedium

A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?

A.A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.
B.A benchmark comparison showing that peer companies spend more on security.
C.A list of all security tools currently deployed with their license costs.
D.A statement that the organization will comply with the regulation by the deadline.
AnswerA

A gap assessment maps existing controls to regulatory requirements and prioritizes remediation by risk, showing executives exactly where exposure exists and how it will be addressed. This aligns security investment with compliance obligations and provides a defensible, measurable plan. It demonstrates that the program is driven by both regulatory need and business risk rather than by technology preferences.

Why this answer

A gap assessment that maps controls to regulatory requirements and prioritizes remediation by risk directly demonstrates alignment between the security program and compliance obligations. It gives executives a clear view of exposure and a plan for closure. Tool inventories, commitment statements, and peer benchmarks lack the requirement-to-control mapping needed for a risk-based implementation plan.

Exam trap

The trap here is confusing budget justification artifacts, such as peer benchmarks or tool inventories, with evidence of compliance alignment.

29
MCQeasy

An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?

A.Perform a residual risk assessment
B.Purchase additional cyber insurance to cover future breaches
C.Conduct security awareness training for all employees
D.Update the information security policy to mandate stricter controls
AnswerA

After corrective controls are implemented, a residual risk assessment determines what risk remains, confirming whether treatment reduced exposure to an acceptable level or whether further action, transfer or acceptance is required before closing the change management gap.

Why this answer

After implementing corrective controls, the next step in the risk management process is to perform a residual risk assessment. This evaluates the remaining risk after controls are applied, ensuring that the organization's risk appetite is not exceeded. Without this assessment, the organization cannot confirm whether the implemented controls are sufficient or if additional measures are needed.

Exam trap

The trap here is that candidates often confuse the order of the risk management process, selecting a corrective action (like training or policy updates) instead of the required evaluation step (residual risk assessment) that validates control effectiveness before moving to other activities.

How to eliminate wrong answers

Option B is wrong because purchasing additional cyber insurance is a risk transfer strategy, not a next step after implementing controls; it does not address the root cause or validate control effectiveness. Option C is wrong because conducting security awareness training is a preventive control that should have been part of the corrective plan, but it is not the immediate next step after implementation; the organization must first assess residual risk to determine if training alone is adequate. Option D is wrong because updating the information security policy is a governance action that may follow the residual risk assessment, but it is not the immediate next step; policy changes should be informed by the residual risk findings.

30
MCQeasy

A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?

A.Implement encryption for all data in transit
B.Accept the risk because the likelihood of interception is low
C.Purchase cyber insurance to cover potential data breach costs
D.Discontinue all electronic transmission of patient data
AnswerA

TLS encryption for data in transit directly closes the identified HIPAA gap, protecting ePHI as it crosses the internet between endpoints. It is the specific technical safeguard addressing the audit finding, and is prioritised because unencrypted transmission is an active, ongoing breach exposure.

Why this answer

HIPAA's Security Rule requires covered entities to protect ePHI in transit using encryption or an equivalent alternative, and transmitting unencrypted EHRs over the internet is a direct violation. Implementing encryption for all data in transit is the prioritized risk treatment because it directly mitigates the identified vulnerability, is technically feasible, and aligns with regulatory requirements. Other options either avoid the risk, transfer it, or disrupt operations without fixing the root cause.

Exam trap

CISM often tests risk treatment selection, and candidates may choose risk acceptance or insurance because they sound pragmatic — the trap is forgetting that regulatory compliance obligations cannot be transferred or accepted away when a direct technical fix is available.

How to eliminate wrong answers

Option B is wrong because accepting the risk ignores HIPAA's mandatory encryption safeguard and the high impact of a breach involving patient data; likelihood being 'low' does not justify non-compliance. Option C is wrong because cyber insurance transfers financial impact but does not remediate the unencrypted transmission or satisfy the regulatory requirement. Option D is wrong because discontinuing all electronic transmission of patient data is an extreme operational disruption that would cripple care delivery and is not a proportionate or necessary control.

31
MCQhard

A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?

A.Adopt a quantitative risk assessment approach using monetary values for impact and annualized loss expectancy.
B.Enhance the qualitative scale by adding more levels (e.g., Very High, High, Medium, Low, Very Low).
C.Use a risk matrix that combines likelihood and impact into a single risk score.
D.Conduct a Delphi technique exercise with subject matter experts to reach consensus on risk ratings.
AnswerA

Quantitative risk assessment uses numerical data, such as monetary values and probabilities, to calculate expected losses. This provides an objective and consistent basis for comparing risks across business units. Senior management can use metrics like annualized loss expectancy (ALE) to prioritize investments. While quantitative methods require more data and effort, they meet the requirement for objectivity and comparability better than qualitative scales.

Why this answer

A quantitative risk assessment approach using monetary values and annualized loss expectancy provides objective, numerical data that can be consistently compared across business units. This meets senior management's requirement for a more objective and consistent methodology. Qualitative enhancements like more levels, risk matrices, or Delphi exercises still rely on subjective judgments and do not offer the same level of comparability or objectivity as quantitative methods.

Exam trap

The trap here is assuming that refining a qualitative method (e.g., adding levels or using Delphi) will achieve objectivity, when in fact only quantitative methods provide numerical, comparable data.

32
MCQmedium

A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?

A.A cost-benefit analysis showing a net benefit of $1,700,000 per year from the control.
B.The residual risk of $400,000 after the control is implemented.
C.The control's annualized cost of $300,000 compared with the total asset value of the patient-records system.
D.The likelihood and impact ratings of the threat before and after the control.
AnswerA

Subtracting the $300,000 annual control cost from the $2,000,000 in loss reduction ($2,400,000 ALE minus $400,000 residual ALE) yields a net benefit of $1,700,000 per year. This cost-benefit figure directly demonstrates that the investment produces a positive return, which is the clearest financial justification for the executive committee.

Why this answer

Cost-benefit analysis translates the risk reduction into a monetary figure that decision-makers can weigh against the control's annual cost. Here the control lowers expected annual loss by $2,000,000 while costing $300,000, producing a $1,700,000 net benefit. This quantitative justification is far more persuasive to an executive committee than residual risk, asset value, or qualitative ratings alone.

Exam trap

The trap here is assuming that presenting residual risk or qualitative likelihood and impact ratings is sufficient justification, when executives approving a specific annual spend need the quantified cost-benefit comparison.

33
Multi-Selectmedium

Which TWO of the following are common approaches to information security risk assessment?

Select 2 answers
A.Qualitative
B.Quantitative
C.Penetration testing
D.Vulnerability assessment
E.Business impact analysis
AnswersA, B

Qualitative assessment ranks risks using descriptive scales such as high, medium and low, drawing on expert judgement rather than numeric values. It satisfies the stem by being one of the two recognised risk assessment approaches, suiting scenarios where precise monetary estimates are impractical.

Why this answer

Options A and B are correct because information security risk assessment fundamentally follows two recognized methodologies: qualitative assessment (A), which uses subjective scales such as high/medium/low to rank risks based on expert judgment, and quantitative assessment (B), which assigns numeric monetary values and probabilities to calculate expected annual loss (e.g., SLE × ARO = ALE). These two approaches are the standard classifications taught in risk management frameworks such as NIST SP 800-30 and ISO/IEC 27005, and they can also be combined into a hybrid (semi-quantitative) method. Penetration testing (C) is a technical security testing technique that simulates attacks to find exploitable weaknesses, not a risk assessment approach itself.

Vulnerability assessment (D) identifies and catalogs known weaknesses but does not by itself evaluate risk in terms of likelihood and impact. Business impact analysis (E) is a separate BCP/DR activity that determines critical business functions and recovery requirements, not a general risk assessment methodology.

Exam trap

The trap here is that candidates confuse risk assessment approaches (qualitative/quantitative) with risk assessment activities (like penetration testing or vulnerability assessment), which are tools used within the assessment process but not the overarching methodology itself.

34
MCQhard

A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?

A.Ignore the individual risks as they are low priority
B.Use a risk aggregation model to assess cumulative impact and consider enterprise-level controls
C.Accept the risk because the probability of all occurring simultaneously is negligible
D.Treat each individual risk separately with minimal controls
AnswerB

A risk aggregation model quantifies cumulative impact across correlated low-likelihood, low-impact risks, exposing the combined exposure that siloed assessments miss. Enterprise-level controls then address that aggregate exposure, satisfying the stem's requirement to manage risks whose significance emerges only collectively rather than individually.

Why this answer

Risk aggregation models are specifically designed to quantify the cumulative impact of multiple low-level risks that, when combined, exceed the enterprise's risk appetite. This approach aligns with the CISM domain of Information Security Risk Management, where enterprise-level controls (e.g., centralized monitoring, compensating controls) are necessary to address systemic risk that individual risk treatments cannot mitigate. The key insight is that the combined probability of correlated or cascading events may be higher than the product of individual probabilities, especially when risks share common root causes.

Exam trap

The trap here is that candidates mistakenly apply the 'low probability, low impact' rule from individual risk assessment and ignore the need for aggregation, failing to recognize that the sum of many small risks can exceed the enterprise risk tolerance.

How to eliminate wrong answers

Option A is wrong because ignoring low-impact, low-probability risks violates the principle of risk aggregation; such risks can collectively create a significant exposure, especially if they share a common vulnerability or threat vector. Option C is wrong because accepting risk based on the assumption that the probability of all occurring simultaneously is negligible ignores the possibility of correlated events, where one risk triggers another, or where a single threat exploits multiple vulnerabilities at once. Option D is wrong because treating each individual risk separately with minimal controls fails to address the cumulative effect and may leave the enterprise exposed to a cascading failure that no single control can prevent.

35
MCQhard

An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?

A.$120,000; the project cost exceeds the annual benefit and should be rejected outright.
B.$40,000; the project should be approved because any reduction in high-impact risk is always cost-justified.
C.$120,000; the manager should compare it with the project cost and consider qualitative factors before recommending treatment.
D.$160,000; the project is justified because the reduction equals the current annualized loss expectancy.
AnswerC

The current annualized loss expectancy is 0.04 × $4,000,000 = $160,000, and after the project it is 0.01 × $4,000,000 = $40,000, giving an expected annual risk reduction of $120,000. Because the $900,000 project cost exceeds a single year's benefit, the manager must weigh multi-year benefit, risk appetite, regulatory requirements, and non-quantifiable impacts before recommending the investment. This is a sound risk-treatment analysis.

Why this answer

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence. Before the project the value is $160,000; after it is $40,000; the expected annual risk reduction is $120,000. The manager should treat this as one input, comparing it with the project cost and weighing qualitative and regulatory factors before recommending treatment.

Exam trap

The trap here is treating the residual annualized loss expectancy or the pre-control value as the benefit instead of subtracting the post-control value from the pre-control value.

36
MCQmedium

During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?

A.Implement compensating controls to reduce the risk
B.Accept the risk as a cost of doing business
C.Avoid the risk by decommissioning the system
D.Purchase cyber insurance to transfer the risk
AnswerA

Compensating controls directly address the unpatched vulnerabilities without requiring remediation the legacy system cannot support, reducing likelihood while preserving daily payment operations. Because the system is critical and cannot be patched, mitigation through alternative safeguards satisfies the risk-reduction requirement better than avoidance, transfer, or acceptance.

Why this answer

Implementing compensating controls, such as network segmentation, application-layer firewalls, or intrusion detection systems (IDS), directly reduces the residual risk of exploiting unpatched vulnerabilities in the legacy payment system without disrupting its critical daily operations. This aligns with the CISM principle that when a risk cannot be remediated (e.g., due to system criticality or vendor end-of-life), compensating controls are the primary treatment to bring risk within the organization's appetite.

Exam trap

The trap here is that candidates often confuse risk transfer (insurance) with risk mitigation, failing to recognize that insurance does not address the technical vulnerability itself, and that acceptance is only appropriate after a cost-benefit analysis shows residual risk is within tolerance.

How to eliminate wrong answers

Option B is wrong because accepting the risk as a cost of doing business is inappropriate when the likelihood of exploitation is high and the system is critical; acceptance is typically reserved for low-likelihood, low-impact risks after other treatments have been considered. Option C is wrong because avoiding the risk by decommissioning the system would halt daily operations, which is not feasible for a system critical to business continuity; avoidance is only viable when the function can be replaced or eliminated without severe operational impact. Option D is wrong because purchasing cyber insurance transfers the financial impact but does not reduce the likelihood or technical exploitability of the unpatched vulnerabilities; insurance is a risk transfer mechanism, not a primary treatment for high-likelihood technical risks.

37
MCQeasy

Which of the following is the primary purpose of communicating risk assessment results to senior management?

A.To comply with regulatory requirements
B.To enable informed decision-making about risk acceptance
C.To assign blame for security failures
D.To justify the security budget
AnswerB

Risk assessment results give senior management the likelihood and business impact figures needed to decide whether to accept, transfer, mitigate or avoid each risk. Communication therefore exists to support informed risk acceptance decisions at the level holding accountability for organisational risk.

Why this answer

The primary purpose of communicating risk assessment results to senior management is to provide the necessary information for informed decision-making regarding risk acceptance, transfer, or mitigation. Senior management holds the authority to accept residual risk based on a clear understanding of the potential impact and likelihood, which is a core tenet of the CISM framework for information security risk management.

Exam trap

The trap here is that candidates often confuse the operational goal of 'justifying the budget' (Option D) with the strategic governance purpose of 'enabling risk acceptance decisions,' but CISM emphasizes that risk communication to senior management is fundamentally about obtaining informed risk acceptance, not securing funding.

How to eliminate wrong answers

Option A is wrong because while regulatory compliance (e.g., GDPR, SOX) may require documentation of risk assessments, it is not the primary purpose; compliance is a secondary benefit, not the core driver for communication to senior management. Option C is wrong because risk assessment communication is a forward-looking, constructive process aimed at managing risk, not a retrospective exercise to assign blame for security failures, which would undermine trust and collaboration. Option D is wrong because although risk assessment results can support budget justifications, the primary purpose is to enable risk acceptance decisions, not to serve as a budget advocacy tool; budget justification is a downstream outcome, not the immediate objective.

38
Multi-Selecthard

A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)

Select 2 answers
A.Recording only qualitative ratings and omitting any quantitative data.
B.Reassessing all risks annually using a newly selected framework each cycle.
C.Adopting a common risk taxonomy and standardized likelihood and impact scales.
D.Allowing each business unit to define its own risk scoring methodology.
E.Documenting assessment criteria and assumptions in a repeatable methodology.
AnswersC, E

A shared taxonomy and calibrated scales ensure that a 'high likelihood' means the same thing in the finance unit as in the plant operations unit, making assessments comparable across the enterprise and allowing aggregation into an organizational risk profile. Without this consistency, ratings from different units cannot be meaningfully combined or trended.

Why this answer

Comparability across units and over time depends on consistent definitions and repeatable methods. A common taxonomy with calibrated scales lets assessments be aggregated, while a documented methodology lets different assessors and different years produce ratings that can be meaningfully compared. Local scoring variation, purely qualitative records, and rotating frameworks all undermine that consistency.

Exam trap

The trap here is assuming that flexibility and local ownership improve risk management, when uncoordinated scoring methods actually prevent the aggregation and trending that executive reporting requires.

39
MCQmedium

A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?

A.Engage external legal counsel to interpret the law’s requirements.
B.Implement encryption for all data at rest and in transit across the enterprise.
C.Conduct a gap analysis between the law’s requirements and the current security controls.
D.Update the information security policy to reference the new law.
AnswerC

A gap analysis is the logical first step because it identifies where the current program falls short of the legal requirements. Without understanding the gaps, the CISO cannot prioritize investments, assign resources or develop a credible compliance roadmap. The analysis provides the factual basis for all subsequent decisions, ensuring that remediation efforts target actual deficiencies rather than assumptions.

Why this answer

The first step in achieving compliance is to understand the difference between what the law requires and what the organization currently does. A gap analysis produces that understanding by mapping requirements to existing controls, identifying deficiencies and highlighting areas where evidence is missing. This allows the CISO to prioritize remediation, allocate budget and build a realistic compliance plan before making technical or policy changes.

Exam trap

The trap here is jumping to a visible technical or legal action instead of first measuring the organization’s current state against the new legal requirements.

40
MCQhard

A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?

A.Implement data classification and strict role-based access controls
B.Conduct continuous monitoring and logging of all system activities
C.Encrypt all data at rest and in transit using strong algorithms
D.Negotiate service-level agreements (SLAs) with cloud provider for uptime
AnswerA

Data classification identifies which records fall under each jurisdiction's data protection laws, and role-based access controls enforce least privilege across those categories. This satisfies the low-residual-risk appetite by limiting exposure of regulated personal data held in the multinational CRM.

Why this answer

The risk appetite allows only low residual risk, meaning controls must directly reduce the likelihood or impact of a data breach to an acceptable level. Data classification and strict role-based access controls (RBAC) are the most critical because they enforce least-privilege access to personal data, directly mitigating the primary risk of unauthorized exposure across jurisdictions with varying data protection laws. Without proper classification and RBAC, even encryption or monitoring cannot prevent an authorized user from improperly accessing or exfiltrating data, leaving residual risk above the low threshold.

Exam trap

The trap here is that candidates often select encryption (Option C) as the most critical control because it is a strong technical safeguard, but they overlook that encryption does not address the risk of authorized users misusing data, which is the primary driver of residual risk in a multi-jurisdictional environment with strict compliance requirements.

How to eliminate wrong answers

Option B is wrong because continuous monitoring and logging are detective controls that identify breaches after they occur, but they do not reduce the likelihood or impact of unauthorized access to meet a low residual risk appetite; they only provide visibility. Option C is wrong because encryption protects data confidentiality if data is intercepted or stolen, but it does not prevent authorized users from misusing access or violating data protection laws, so residual risk from insider threats remains high. Option D is wrong because SLAs for uptime address availability and business continuity, not data protection or compliance with privacy laws, and thus have no direct effect on the residual risk of unauthorized data access or legal non-compliance.

41
MCQmedium

An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?

A.Express security risks in business impact terms and integrate them into the enterprise risk register using common scales.
B.Convert all security risks into a single aggregate score and report only that score to ERM.
C.Report security risks separately to the CISO only, keeping ERM focused on financial and operational risks.
D.Report only risks that have already materialized as incidents so ERM deals with confirmed events.
AnswerA

Translating security risk into business impact, such as revenue loss, regulatory penalty, or service disruption, and recording it on the enterprise's common scales allows ERM to compare and aggregate it with other risk types. This integration supports enterprise prioritization and gives executives a coherent view of total risk exposure.

Why this answer

Integrating security risk into ERM requires translating technical exposure into business impact and using the enterprise's common scales so that cyber risk can be compared, aggregated, and prioritized alongside other risk types. This gives executives a unified view while preserving enough detail for ownership and treatment decisions.

Exam trap

The trap here is assuming that security risk is too technical for ERM and should stay in a separate report, when the real requirement is translation into business impact on shared scales.

42
MCQeasy

A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?

A.Purchase a comprehensive cyber insurance policy
B.Fire the IT staff responsible for the security failures
C.Conduct a risk assessment to identify assets, threats, and vulnerabilities
D.Immediately implement a backup and disaster recovery solution
AnswerC

A risk assessment identifies assets, threats and vulnerabilities, establishing the baseline that every later decision depends on. Without it, control selection, treatment options and programme scope lack justification, making it the appropriate initial step for this firm after its ransomware loss.

Why this answer

The first step in developing a risk management program, per the CISM framework, is to conduct a risk assessment. This identifies the specific assets (e.g., client data on the file server), threats (e.g., ransomware), and vulnerabilities (e.g., lack of backups, weak access controls) that led to the incident. Without this foundational analysis, any subsequent controls—such as backups or insurance—would be misaligned with the firm's actual risk profile, potentially wasting resources on ineffective measures.

Exam trap

The CISM framework emphasizes that risk management must begin with identification (risk assessment) before any treatment (mitigation, transfer, or acceptance). The trap here is that candidates jump to a technical fix (backups) or a financial fix (insurance) without first understanding the full scope of risks.

How to eliminate wrong answers

Option A is wrong because purchasing a cyber insurance policy before conducting a risk assessment is a reactive financial transfer that does not address the root causes of the attack (e.g., no backups, poor security posture). Insurance may also be denied or voided if the firm cannot demonstrate a proper risk management process. Option B is wrong because firing IT staff is a punitive, non-technical response that does not remediate the systemic security failures (e.g., lack of backup strategy, missing patch management).

It also ignores the owner's own responsibility for not prioritizing security investments. Option D is wrong because immediately implementing a backup solution without a prior risk assessment may lead to improper configuration (e.g., storing backups on the same network segment as the file server, allowing ransomware to encrypt them) or failure to address other critical vulnerabilities (e.g., weak authentication, unpatched software).

43
Matchingmedium

Match each risk management term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Risk level before controls are applied

Risk remaining after controls are implemented

Amount of risk the organization is willing to accept

Acceptable variation around the risk appetite

Process of modifying risk by applying controls

Why these pairings

Key risk management terms from CISM: Risk is the effect of uncertainty on objectives; controls are measures that modify risk; vulnerabilities are weaknesses that can be exploited; threats are potential causes of incidents. The distractor pairs swap risk with threat and control with vulnerability.

44
MCQmedium

An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?

A.Transfer the risk by purchasing cyber insurance
B.Avoid the risk by discontinuing the web application
C.Remediate the risk by implementing parameterized queries and input validation
D.Accept the risk because the likelihood is low after compensating controls
AnswerC

Parameterised queries separate SQL code from user-supplied data, and input validation rejects malformed input, eliminating the injection vector itself. This directly addresses the identified insufficient input validation, removing the high-likelihood risk rather than transferring or accepting it.

Why this answer

Parameterized queries (prepared statements) and input validation directly address the root cause of SQL injection by separating SQL logic from user-supplied data. This is a remediation (mitigation) strategy that reduces the likelihood of exploitation to an acceptable level, which aligns with the high-risk scenario described.

Exam trap

The trap here is that candidates often confuse risk transfer (insurance) with risk mitigation, or they incorrectly assume that accepting risk is a default option when the scenario clearly indicates a high-likelihood, high-impact vulnerability that can be directly fixed with a standard coding practice.

How to eliminate wrong answers

Option A is wrong because purchasing cyber insurance transfers the financial impact of a breach, not the technical risk itself; the SQL injection vulnerability remains exploitable, and insurance does not prevent data loss or regulatory penalties. Option B is wrong because avoiding the risk by discontinuing the web application would eliminate business functionality and is disproportionate when a proven technical control (parameterized queries) exists to mitigate the vulnerability. Option D is wrong because accepting the risk is only appropriate when residual risk is low after compensating controls, but the scenario states the likelihood is high and no compensating controls have been implemented; accepting without remediation would leave the organization exposed to a high-probability attack.

45
MCQeasy

Which of the following best describes residual risk?

A.Risk before any controls are applied
B.Risk that remains after implementing controls
C.The likelihood that a control will fail
D.The level of risk an organization is willing to accept
AnswerB

Residual risk is the exposure that persists once controls have been applied, since no safeguard eliminates every threat or vulnerability entirely. This directly satisfies the stem's requirement to describe risk remaining after treatment, distinguishing it from inherent risk, which exists before any mitigation is implemented.

Why this answer

Residual risk is defined in information security risk management as the risk that remains after management has implemented all planned controls. This concept is central to the CISM framework because it represents the exposure that must be accepted, transferred, or further mitigated by the organization. Unlike inherent risk (before controls), residual risk accounts for the effectiveness of the security measures in place.

Exam trap

The trap here is that candidates often confuse residual risk with risk appetite (Option D), but residual risk is the actual remaining exposure after controls, while risk appetite is the threshold for acceptable exposure.

How to eliminate wrong answers

Option A is wrong because it describes inherent risk, which is the risk level before any controls are applied, not the risk that remains after controls. Option C is wrong because it describes control risk or the likelihood of control failure, which is a component of residual risk calculation but not the definition of residual risk itself. Option D is wrong because it describes risk appetite or risk tolerance, which is the amount of risk an organization is willing to accept, not the actual risk remaining after controls.

46
MCQeasy

A mid-sized manufacturing firm has decided to transfer the risk of a ransomware attack on its production network by purchasing a cyber insurance policy. The policy includes a $1 million coverage limit and a $50,000 deductible. Six months later, a ransomware incident causes $400,000 in recovery costs. The insurer approves the claim. What is the organization's financial responsibility for this incident?

A.$400,000
B.$50,000
C.$350,000
D.$1,000,000
AnswerB

The deductible is the amount the organization must pay before the insurer covers the remaining loss. Since the $400,000 incident is within the $1 million policy limit and the claim is approved, the organization pays only the $50,000 deductible. The insurer covers the remaining $350,000, assuming no exclusions apply.

Why this answer

When a risk is transferred through insurance and the claim is approved, the organization bears the deductible while the insurer covers the covered loss above it, up to the policy limit. Here the loss is well below the limit, so the organization pays only the $50,000 deductible. This illustrates how insurance reduces financial impact but does not eliminate all residual risk.

Exam trap

The trap here is confusing the policy limit, the deductible, and the insurer's reimbursement amount with the organization's actual out-of-pocket responsibility.

47
MCQhard

In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?

A.Accept the risk because the control is not cost-justified.
B.Accept the risk because ALE after control is only $2,500.
C.Implement the control because it reduces ALE to $2,500.
D.Implement the control because ALE is $10,000, and control cost is only $12,000.
AnswerA

ALE equals SLE multiplied by ARO: $50,000 × 0.2 = $10,000. The control costs $12,000 annually while reducing expected loss to $2,500, a $7,500 benefit, so it is not cost-justified. Accepting the risk is therefore the most cost-effective response.

Why this answer

The ALE is calculated as SLE × ARO = $50,000 × 0.2 = $10,000. After implementing the control costing $12,000 per year, the residual ALE is $50,000 × 0.05 = $2,500. The annual cost of the control ($12,000) exceeds the reduction in ALE ($10,000 - $2,500 = $7,500), so the control is not cost-justified.

Therefore, accepting the risk is the most cost-effective response.

Exam trap

The trap here is that candidates often compare the control cost to the original ALE ($10,000) or to the residual ALE ($2,500) instead of comparing it to the reduction in ALE ($7,500), leading to incorrect cost-justification conclusions.

How to eliminate wrong answers

Option B is wrong because it states 'accept the risk because ALE after control is only $2,500' — this is a correct observation about the residual ALE but fails to compare the control cost ($12,000) against the reduction in ALE ($7,500), which is the key cost-benefit analysis. Option C is wrong because it says 'implement the control because it reduces ALE to $2,500' — this ignores that the control cost ($12,000) is greater than the reduction in ALE ($7,500), making it not cost-justified. Option D is wrong because it says 'implement the control because ALE is $10,000, and control cost is only $12,000' — this incorrectly implies that a control cost lower than the original ALE justifies implementation, but the correct comparison is between the control cost and the reduction in ALE (not the original ALE).

48
MCQhard

An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?

A.It automatically assigns the highest possible risk rating to all regulatory findings
B.It uses qualitative ratings only, avoiding numerical scores
C.It uses a defined and consistently applied risk scoring scale
D.It relies on the judgment of each local risk manager without central guidance
AnswerC

A defined, consistently applied scoring scale ensures that likelihood and impact ratings mean the same thing across business units and jurisdictions. This enables aggregation, comparison, and prioritization at the enterprise level. Without a common scale, risk results become subjective and cannot be reliably combined, undermining the bank's ability to manage risk holistically and report accurately to regulators and the board.

Why this answer

Consistency across business units and jurisdictions depends on a defined, uniformly applied risk scoring scale. This ensures that likelihood and impact ratings are comparable, allowing the bank to aggregate risks, prioritize investments, and report meaningfully to the board and regulators. Local judgment and qualitative input are valuable, but they must operate within a common framework to produce reliable enterprise risk information.

Exam trap

The trap here is assuming that local expertise or qualitative-only ratings can deliver consistency, when the key requirement is a defined and uniformly applied scoring scale.

49
MCQhard

During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?

A.Ignore the risk because the vendor is known
B.Terminate the vendor relationship immediately
C.Conduct a third-party risk assessment
D.Request the vendor's latest security certification
AnswerC

Conducting a third-party risk assessment obtains evidence of the vendor's controls, certifications, and breach history, replacing unclear posture with documented findings. That evidence supports contract terms, remediation demands, or termination decisions affecting sensitive data exposure.

Why this answer

When a vendor's security posture is unclear and they have access to sensitive data, the best course of action is to conduct a third-party risk assessment. This assessment evaluates the vendor's security controls, compliance with standards (e.g., ISO 27001, SOC 2), and contractual obligations before making any decisions. It provides the necessary evidence to determine if the risk is acceptable or requires mitigation, rather than acting on assumptions.

Exam trap

The trap here is that candidates may choose D, thinking a certification is a definitive proof of security, but CISM emphasizes that certifications are only one piece of evidence and must be supplemented with a current, context-specific risk assessment.

How to eliminate wrong answers

Option A is wrong because ignoring the risk based solely on vendor familiarity violates the principle of due care and could lead to data breaches; risk must be assessed regardless of relationship length. Option B is wrong because terminating the relationship immediately is a drastic, reactive measure that may disrupt business operations without first verifying the actual security posture; a risk assessment should precede such decisions. Option D is wrong because requesting the latest security certification alone is insufficient; certifications may be outdated, not cover all relevant controls, or be falsified, and a comprehensive assessment is needed to validate the vendor's current security state.

50
Multi-Selecthard

Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)

Select 3 answers
A.Lack of senior management support
B.Inability to quantify risks in financial terms
C.Too many controls implemented too quickly
D.Resistance to change from business units
E.Overly detailed risk appetite
AnswersA, B, D

Risk management programmes require governance sponsorship to allocate budget, enforce policy and resolve cross-functional conflicts. Absent senior management support, assessments stall, treatment plans go unfunded, and business units treat risk activities as optional rather than mandated.

Why this answer

Option A (Lack of senior management support) is correct because a risk management program requires executive sponsorship, budget, and authority to enforce policies; without it, risk initiatives stall and risk ownership cannot be driven across the organization. Option B (Inability to quantify risks in financial terms) is correct because translating technical or operational risk into monetary values (e.g., ALE = SLE × ARO) is difficult and often subjective, which hampers cost-benefit justification of controls and prioritization. Option D (Resistance to change from business units) is correct because risk management typically introduces new processes, ownership, and controls that business units may perceive as bureaucratic overhead, slowing adoption.

Option C is not a standard challenge in itself; implementing too many controls too quickly is a symptom of poor phasing rather than a recognized common implementation challenge. Option E is not a common challenge; a well-defined risk appetite is generally desirable, and the issue is more often an undefined or misaligned appetite, not one that is overly detailed.

Exam trap

ISACA CISM often tests the distinction between implementation challenges (e.g., lack of support, resistance, quantification difficulty) and operational symptoms (e.g., too many controls), so candidates mistakenly select 'too many controls' because it sounds like a problem, but it is not a root challenge of program implementation.

51
MCQeasy

A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?

A.Avoid the risk by discontinuing online services
B.Transfer the risk through cyber insurance
C.Accept the risk
D.Mitigate the risk by implementing stronger access controls
AnswerD

Stronger access controls restrict who can reach personal data, directly lowering the probability of another unauthorised disclosure. Mitigation addresses the likelihood dimension the question specifies, unlike acceptance, avoidance or transfer, which do not reduce recurrence.

Why this answer

Mitigating the risk by implementing stronger access controls directly reduces the likelihood of a similar breach by addressing the root cause—weak or insufficient access management. This is the most appropriate response because the risk manager wants to reduce the probability of recurrence, which is the definition of risk mitigation. It is a targeted, proportionate control rather than an extreme business change or a financial transfer.

Exam trap

The trap is conflating risk transfer (insurance) with risk reduction; candidates often pick insurance because it sounds responsible, but insurance only addresses financial impact, not the likelihood of recurrence.

How to eliminate wrong answers

Option A is wrong because avoiding the risk by discontinuing online services is a drastic business decision that eliminates the activity entirely, which is not proportionate or practical for most organizations and goes beyond reducing likelihood. Option B is wrong because transferring the risk through cyber insurance does not reduce the likelihood of a similar incident; it only shifts the financial impact. Option C is wrong because accepting the risk means taking no action, which fails to address the requirement to reduce the likelihood of future incidents.

52
MCQmedium

A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerD

Deploying a virtual patch and increasing monitoring reduces the likelihood that the vulnerability will be successfully exploited while the organization works toward a permanent fix. The risk source still exists, but compensating controls lower the exposure to an acceptable level. This is the defining characteristic of mitigation: reducing likelihood or impact through controls rather than eliminating, transferring, or simply accepting the exposure.

Why this answer

The organization is reducing the likelihood of exploitation through compensating technical controls while a permanent remedy is unavailable, which is the essence of risk mitigation. Avoidance would require removing the vulnerable function, transfer would require an insurer or contractual party to absorb the loss, and acceptance would mean taking no action. Virtual patching and monitoring modify the risk itself.

Exam trap

The trap here is labelling compensating controls as risk acceptance because the vulnerability cannot be patched, when any control that actively lowers likelihood or impact constitutes mitigation.

53
MCQmedium

A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?

A.Recommend immediate decommissioning of the legacy application.
B.Transfer the risk by purchasing additional cyber insurance coverage.
C.Compare the assessed risk exposure to the board's risk tolerance and present treatment options with residual risk estimates.
D.Accept the risk and document it in the risk register pending next year's assessment.
AnswerC

The board has defined a clear risk tolerance threshold, so the CISO's first duty is to determine whether the assessed risk exceeds that threshold and, if so, present treatment options that bring residual risk within tolerance. This aligns security decisions with business objectives and gives the board the comparative information it needs to approve a treatment strategy.

Why this answer

Because the board has articulated a specific risk tolerance threshold, the CISO must first evaluate the assessed risk against that threshold and then present treatment options with their residual risk implications. This ensures the recommendation is grounded in the organization's stated appetite and supports a defensible, business-aligned decision rather than an arbitrary technical fix.

Exam trap

The trap here is assuming that any high-risk finding automatically justifies a technical remedy such as decommissioning or insurance, when the governing step is comparing the exposure to the board's stated tolerance.

54
Multi-Selectmedium

An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)

Select 2 answers
A.Limiting access to the risk register to only the information security team
B.Assigning a risk owner for each entry who is accountable for treatment and monitoring
C.Reviewing and updating risk entries on a defined schedule and upon significant changes
D.Populating the register exclusively with technical vulnerabilities identified by scanners
E.Removing all risks that have been accepted by senior management to reduce clutter
AnswersB, C

Assigning a risk owner establishes clear accountability for managing each risk. The owner ensures that treatment plans are executed, residual risk is monitored, and status is reported. Without ownership, risks may languish without action or oversight. This is a fundamental requirement for an effective risk register and supports governance and auditability.

Why this answer

An effective risk register requires ongoing maintenance through scheduled and event-driven reviews, and clear assignment of risk owners who are accountable for treatment and monitoring. These two practices ensure the register stays current, actionable, and aligned with governance requirements. Removing accepted risks, restricting access, or limiting entries to technical vulnerabilities would reduce its value and completeness.

Exam trap

The trap here is treating the risk register as a static list of technical findings rather than a living, owned, and broadly scoped governance tool.

55
MCQeasy

A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?

A.Document the residual risk in the risk register and continue monitoring it on the normal reporting cycle.
B.Escalate the residual risk to senior management as a risk above the approved appetite.
C.Revise the risk appetite statement so the current residual risk falls within acceptable limits.
D.Immediately implement additional controls and then report the change in risk level.
AnswerB

When residual risk exceeds the documented risk appetite, the gap is a governance issue that must be escalated to the risk owners and senior management who set the appetite. They are accountable for deciding whether to fund additional controls, accept the deviation, or change business plans. Informing them first ensures the decision is made at the appropriate authority level.

Why this answer

Risk appetite defines the amount of risk leadership is willing to accept in pursuit of objectives. When residual risk exceeds that boundary, the information security manager's first obligation is to escalate the exception to senior management, who own the decision to remediate, accept, or adjust strategy. Acting unilaterally or rewriting the appetite statement would bypass proper governance.

Exam trap

The trap here is choosing immediate remediation or quietly adjusting the appetite statement, when the governance-correct first step is escalating the appetite breach to the accountable executives.

56
MCQeasy

An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?

A.Request an extension of the original project timeline from the vendor and continue monitoring.
B.Update the risk register to reflect the increased residual risk and report the treatment shortfall to the risk committee.
C.Close the original risk entry and open a new one describing the delayed identity governance implementation.
D.Reassign the identity governance project to the security team so it can be completed faster.
AnswerB

When an approved treatment is not progressing, the residual risk is higher than the committee believed when it accepted the plan. The security manager's first duty is to restore accurate risk visibility by updating the register and informing the same governance body that approved the treatment. This keeps decision-makers able to re-evaluate acceptance, reallocate resources, or approve interim compensating controls based on current facts.

Why this answer

Risk treatment plans are approved on the basis of projected residual risk, so slippage changes the factual basis of that approval. The security manager must first update the risk register and notify the risk committee, enabling it to decide whether to fund acceleration, accept the higher exposure temporarily, or mandate compensating controls. Execution and vendor actions come after risk visibility is restored.

Exam trap

The trap here is jumping to a project recovery action such as reassignment or vendor negotiation, when the immediate obligation is to restore accurate risk reporting to the body that approved the treatment.

57
MCQhard

An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?

A.A qualitative analysis using a defined likelihood and impact scale with calibrated subject matter expert judgment.
B.A quantitative analysis using annualized loss expectancy derived from industry breach cost benchmarks.
C.A hybrid analysis that assigns monetary values to every identified ERP risk regardless of data availability.
D.A control gap analysis mapped to ISO/IEC 27002 that ranks risks by the number of missing controls.
AnswerA

Qualitative analysis with a defined likelihood and impact scale suits the limited historical data and the two-week window, because it relies on calibrated expert judgment rather than statistical loss data. It still produces a defensible, repeatable ranking of ERP risks when the scales and calibration criteria are documented, meeting the executives' need for prioritized results quickly.

Why this answer

When historical loss data is scarce and results are needed quickly, a qualitative analysis with documented likelihood and impact scales and calibrated expert judgment is the most practical and defensible choice. It produces a consistent ranking without fabricating quantitative precision, and the documented scales allow reviewers to understand and challenge how each ERP risk was rated.

Exam trap

The trap here is equating defensibility with quantitative precision, when in a data-poor, time-constrained situation a well-calibrated qualitative method is more defensible than fabricated numbers.

58
Multi-Selecthard

Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)

Select 2 answers
A.Business continuity plan
B.Risk appetite and tolerance
C.Data classification scheme
D.Risk assessment methodology
E.Vulnerability scanning process
AnswersB, D

ISACA defines risk appetite and tolerance as core programme components: they express how much risk the organisation is willing to pursue or retain, and they bound every subsequent assessment, treatment and acceptance decision within the risk management framework.

Why this answer

ISACA defines risk appetite and tolerance (B) as key components because they establish the amount of risk an organization is willing to accept in pursuit of its objectives, providing the criteria against which risks are evaluated and prioritized. A risk assessment methodology (D) is also essential, as it defines the structured approach (e.g., identifying, analyzing, and evaluating risks per frameworks like ISO 31000 or NIST RMF) used to determine likelihood and impact consistently across the enterprise. Together, these two elements form the governance and analytical backbone of an information risk management program.

By contrast, a business continuity plan (A) is a response/recovery capability, a data classification scheme (C) is a supporting control/inventory tool, and vulnerability scanning (E) is a technical detection activity — all valuable, but none are the core program components ISACA identifies.

Exam trap

CISM often tests whether candidates can separate core risk management program components (appetite/tolerance, assessment methodology) from supporting controls and response plans (BCP, data classification, vulnerability scanning) — the trap is picking operational controls that feel risk-related but are not structural components.

59
MCQmedium

A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?

A.Mitigate by reducing the RTO to 1 hour through process automation
B.Transfer the risk by purchasing business interruption insurance
C.Accept the risk because the RTO is shorter than the MTD
D.Avoid the risk by replacing the system with a more reliable one
AnswerA

The RTO of 4 hours exceeds the 2-hour MTD, so the system cannot recover within tolerable downtime. Reducing the RTO to 1 hour through automation brings recovery inside the MTD, directly satisfying the stem's constraint and closing the gap.

Why this answer

The current RTO of 4 hours exceeds the MTD of 2 hours, meaning the system cannot be restored within the maximum tolerable downtime, resulting in unacceptable business impact. Reducing the RTO to 1 hour through process automation brings recovery time well within the MTD, effectively mitigating the risk to an acceptable level. This aligns with the risk management principle of applying controls to close the gap between RTO and MTD.

Exam trap

The trap here is that candidates mistakenly think accepting risk is valid when RTO is shorter than MTD, but the question presents the opposite scenario (RTO > MTD), making acceptance inappropriate; ISACA often tests this precise reversal to catch those who confuse RTO and MTD relationships.

How to eliminate wrong answers

Option B is wrong because transferring risk via business interruption insurance does not address the fundamental issue that the system cannot be restored within the MTD; insurance compensates for financial loss but does not prevent operational impact or data loss during the outage. Option C is wrong because accepting the risk is only appropriate when the RTO is shorter than the MTD, but here the RTO (4 hours) is longer than the MTD (2 hours), creating an unacceptable risk exposure. Option D is wrong because avoiding the risk by replacing the system is an extreme and costly measure that is not necessary when a less disruptive mitigation (reducing RTO) can achieve compliance with the MTD.

60
MCQeasy

An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerA

Applying the vendor patch reduces the likelihood that the vulnerability can be exploited, which lowers the overall risk exposure while the business activity continues. This is the defining characteristic of risk mitigation: implementing controls to reduce likelihood or impact. Patching is a classic preventive control within a vulnerability management program.

Why this answer

Risk mitigation involves applying controls that reduce the likelihood or impact of a risk while allowing the underlying business activity to continue. Patching a known vulnerability lowers the probability of exploitation, so it falls squarely into the mitigation category rather than avoidance, transfer, or acceptance, each of which describes a fundamentally different treatment approach.

Exam trap

The trap here is conflating any security action with avoidance or acceptance, when the decisive question is whether the action reduces exposure while the activity continues.

61
Multi-Selecthard

A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)

Select 2 answers
A.The name of the auditor who reviewed the risk.
B.The risk owner accountable for managing the risk.
C.The specific technical vulnerability that generated the risk.
D.The assessed likelihood and impact of the risk.
E.The date the risk was first identified.
AnswersB, D

A named risk owner is essential because risk treatment requires accountability. Without an owner, remediation actions may stall, and no one is responsible for monitoring changes in likelihood or impact. The owner ensures that the risk is assessed, treated and reported appropriately, and provides a clear point of contact for auditors and management. This element directly supports decision-making and follow-through.

Why this answer

A risk owner and assessed likelihood and impact are essential because they enable accountability and prioritization. The owner ensures action is taken, while likelihood and impact ratings allow the CISO to compare risks and decide on treatment. Other details, such as identification date, auditor name or a specific vulnerability, may be useful for context but do not directly drive risk treatment decisions.

Exam trap

The trap here is including descriptive or historical details that seem relevant but do not actually support the decision to treat, transfer, avoid or accept a risk.

62
MCQeasy

A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?

A.The amount and type of risk that the organization is willing to pursue or retain to achieve its objectives.
B.The residual risk that remains after all reasonable controls have been implemented.
C.The process of identifying, analyzing and evaluating risks to determine their significance.
D.The maximum level of risk that the organization can tolerate before exceeding its risk tolerance.
AnswerA

Risk appetite is a strategic statement of how much risk the organization is willing to accept in pursuit of its goals. It guides decision-making by setting boundaries for risk-taking and helps ensure that security investments align with business objectives. It is broader than tolerance and provides the context within which specific tolerances and thresholds are defined.

Why this answer

Risk appetite expresses the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. It is a strategic, governance-level concept that sets the boundaries for risk-taking and guides decisions about security investments and risk treatment. It is distinct from tolerance, which defines acceptable variation, and from assessment or residual risk, which are operational concepts.

Exam trap

The trap here is confusing risk appetite with risk tolerance or with operational risk concepts such as assessment and residual risk.

63
Multi-Selectmedium

Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)

Select 2 answers
A.Vendor security assessment ratings
B.Risk scenarios with likelihood and impact ratings
C.Detailed results of control testing
D.Risk treatment recommendations
E.Complete asset inventory
AnswersB, D

Risk scenarios with likelihood and impact ratings translate identified threats into structured, comparable entries, letting the report rank exposures objectively. This satisfies the best-practise requirement that a risk assessment report quantify and prioritise risk rather than merely list assets or controls.

Why this answer

Option B is correct because a risk assessment report must document identified risk scenarios together with their likelihood and impact ratings, which are the core analytical outputs that let stakeholders understand and prioritize each risk. Option D is correct because the report should provide risk treatment recommendations (such as mitigate, transfer, avoid, or accept) so decision-makers know how each identified risk should be addressed. Options A, C, and E are not key components of a risk assessment report: vendor security assessment ratings belong to third-party/vendor risk management artifacts, detailed control testing results are outputs of control testing or audit reports, and a complete asset inventory is an input to the risk assessment process rather than a required section of the report itself.

Exam trap

The trap here is that candidates often confuse the risk assessment report's output (risk scenarios and treatment recommendations) with inputs or supporting data (vendor ratings, control testing details, asset inventory), leading them to select options that are part of the process but not the final report.

64
MCQeasy

A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?

A.Use the asset's purchase value to determine priority
B.Assess the business impact of each asset's compromise
C.Perform a vulnerability scan and prioritize based on findings
D.Review historical incident reports for each asset
AnswerB

Business impact analysis ranks assets by the operational, financial and regulatory harm their compromise would cause. This satisfies the prioritisation criterion by tying assessment effort to consequence severity, ensuring the most critical assets receive attention first rather than being ranked by convenience or cost.

Why this answer

The best approach to prioritize assets for risk assessment is to assess the business impact of each asset's compromise because risk management focuses on the potential harm to business objectives, not on financial cost or technical vulnerabilities. Business impact analysis (BIA) evaluates criticality based on factors like revenue loss, regulatory penalties, and operational downtime, directly aligning asset priority with organizational risk appetite.

Exam trap

The trap here is that candidates often confuse 'asset value' with 'purchase cost' (Option A) or mistake technical severity (Option C) for business criticality, failing to recognize that risk management prioritization must be driven by business impact analysis, not by financial or technical metrics alone.

How to eliminate wrong answers

Option A is wrong because purchase value does not reflect the asset's criticality to business operations; a low-cost server hosting a critical database may have far higher impact than an expensive but non-essential workstation. Option C is wrong because vulnerability scan findings indicate technical weaknesses but ignore the business context; a high-severity vulnerability on a low-impact asset may be less urgent than a medium-severity vulnerability on a mission-critical system. Option D is wrong because historical incident reports only show past events, which may not capture emerging threats or changes in asset criticality, and can lead to reactive rather than proactive prioritization.

65
MCQmedium

A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?

A.Risk avoidance
B.Risk mitigation
C.Risk acceptance
D.Risk transfer
AnswerB

Implementing MFA reduces the likelihood of exploitation by adding a second authentication factor, lowering the inherent risk while retaining the activity. Mitigation treats risk through controls rather than transferring, avoiding or accepting it, matching the risk owner's decision.

Why this answer

Implementing multi-factor authentication (MFA) reduces the likelihood or impact of a security risk by adding additional authentication factors (e.g., something you know, something you have, something you are) beyond a weak password. This directly aligns with risk mitigation, which seeks to decrease the residual risk to an acceptable level through controls. The decision does not eliminate the risk entirely (avoidance), accept it without action, or transfer it to a third party.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk avoidance' because both involve implementing controls, but avoidance means eliminating the activity or technology entirely, whereas mitigation reduces but does not eliminate the risk.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean not implementing the online banking platform or removing the authentication module entirely, which is not the case. Option C is wrong because risk acceptance would involve acknowledging the risk and taking no further action, whereas MFA is an active control. Option D is wrong because risk transfer would involve shifting the financial impact of the risk to another party (e.g., via insurance or outsourcing), not implementing a technical control like MFA.

66
MCQhard

After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?

A.Increased audit findings
B.Regulatory fines for noncompliance
C.Inaccurate risk profile leading to uninformed decisions
D.Higher insurance premiums
AnswerC

Stale assessments no longer reflect current threats, vulnerabilities or asset values, so the recorded risk profile diverges from reality. This noncompliance with the annual review requirement directly satisfies the stem's consequence: decisions are made on outdated data, misdirecting controls and remediation funding.

Why this answer

C is correct because the primary purpose of a risk assessment is to provide an accurate, current risk profile that informs security decisions and resource allocation. When the assessment is two years out of date, the organization lacks visibility into new threats, vulnerabilities, and changes in the threat landscape, leading to uninformed decisions that can result in security gaps and increased exposure. This directly undermines the risk management process, making it the most significant consequence of noncompliance with the annual review policy.

Exam trap

The trap here is that candidates often focus on tangible, immediate consequences like fines or audit findings, but CISM emphasizes that the most significant impact of noncompliance is the erosion of the risk management process itself—specifically, the inability to make informed decisions based on an accurate risk profile.

How to eliminate wrong answers

Option A is wrong because increased audit findings are a secondary outcome of noncompliance, not the most significant consequence; audits may flag the missing review, but the core harm is the degraded decision-making capability. Option B is wrong because regulatory fines for noncompliance depend on specific legal or contractual requirements (e.g., GDPR, PCI DSS), and while possible, they are not guaranteed and are less impactful than the systemic failure to maintain an accurate risk profile. Option D is wrong because higher insurance premiums may result from a poor risk posture, but they are a financial consequence that follows from the underlying inaccurate risk profile, not the primary risk management failure itself.

67
MCQeasy

A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?

A.Report the vulnerability to the payment card brand immediately
B.Implement a web application firewall in front of the point-of-sale system
C.Validate the risk and determine its priority based on likelihood and impact
D.Purchase a cyber insurance policy to cover potential card replacement costs
AnswerC

The risk treatment process begins with validating the identified risk and prioritizing it using criteria such as likelihood, impact, and alignment with risk appetite. Only after the risk is confirmed and ranked can appropriate treatment options be evaluated. This ensures resources are directed to the most significant risks first and that treatment decisions are justified and consistent.

Why this answer

The risk treatment process starts with validating the identified risk and prioritizing it based on likelihood, impact, and risk appetite. Only after the risk is confirmed and ranked can the organization evaluate treatment options such as mitigation, transfer, avoidance, or acceptance. Jumping directly to a control, insurance, or external reporting bypasses this essential prioritization step and may misallocate resources.

Exam trap

The trap here is selecting an action that sounds responsible, such as implementing a control or reporting externally, without first validating and prioritizing the risk.

68
MCQhard

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

A.Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms
B.Accept the risk because the CSP has strong security certifications and the likelihood of a breach is low
C.Cancel the cloud migration and build a new private data center in a compliant location
D.Transfer the risk by purchasing cyber insurance that covers regulatory fines
AnswerA

Dedicated HSMs place cryptographic key custody under the organisation's control, while contractual region restrictions enforce data residency, directly addressing both identified gaps. Because the board's low risk appetite demands mitigation to an acceptable level, these controls reduce the CSP-dependent risks rather than merely accepting or transferring them.

Why this answer

It directly addresses the root causes: data residency non-compliance and lack of control over encryption keys. Requiring dedicated hardware security modules (HSMs) and restricting data storage to approved regions through contractual terms ensures that the organization retains control over key management and meets regulatory requirements. This aligns with the low risk appetite and the board's mandate to mitigate risks to an acceptable level.

Option B (accept the risk) is incorrect because it contradicts the board's mandate to mitigate all risks, and certifications alone do not guarantee compliance.

Option C (cancel migration) is too drastic and costly; the organization can achieve compliance with the CSP rather than abandoning the cloud migration.

Option D (transfer risk via insurance) does not achieve regulatory compliance; fines may still be imposed regardless of insurance coverage.

Exam trap

Candidates may mistakenly believe that accepting risk is viable when the CSP has strong certifications, but the board's mandate requires mitigation, not acceptance.

69
Multi-Selecthard

A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)

Select 2 answers
A.Rate every OT risk using only the maximum potential financial loss to keep scoring consistent.
B.Record each risk with an owner, inherent and residual ratings, and the linked business process or asset.
C.Exclude risks that already have compensating controls from the register to reduce noise.
D.Aggregate all OT findings into a single enterprise risk to simplify board reporting.
E.Map each OT risk to the relevant regulatory, contractual, or safety obligation it could affect.
AnswersB, E

Assigning an owner, documenting inherent and residual ratings, and linking to the affected process or asset makes the register actionable. Ratings show how controls change exposure, and linkage enables prioritization based on business impact. Without these elements, the register becomes a list that cannot drive treatment decisions or accountability in an OT context where safety and availability matter.

Why this answer

An effective risk register captures ownership, inherent and residual ratings, and business linkage, and it maps risks to the obligations they could affect. These practices enable prioritization and accountability. Aggregating findings, using only financial impact, or excluding controlled risks all reduce the register's usefulness for managing OT exposure where safety and availability are critical.

Exam trap

The trap here is treating a risk register as a simplified summary rather than a granular, owned, and obligation-linked inventory.

70
MCQeasy

A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?

A.Conduct a detailed cost-benefit analysis to convince the risk owner to upgrade, but do not escalate until the analysis is complete.
B.Accept the risk owner's decision and update the risk register to reflect the deferred treatment with a note of the risk owner's acceptance.
C.Implement a compensating control, such as strong application-layer encryption, to reduce the residual risk to an acceptable level without upgrading TLS.
D.Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
AnswerD

The risk owner's refusal exceeds their delegated authority because the risk appetite statement permits moderate residual risk only with CRO approval. Escalating to the risk management committee routes the accept, mitigate or defer decision to the body mandated to resolve it.

Why this answer

When a risk owner refuses to accept a risk that exceeds the organization's stated risk appetite and the risk owner also refuses to treat it, the information security manager must escalate through the defined governance channel — here, the risk management committee. The risk appetite statement only permits moderate residual risk with explicit CRO approval, so the head of network operations cannot unilaterally defer a high-rated regulatory risk. Escalation ensures the decision is made at the appropriate authority level with full visibility of regulatory and reputational exposure.

Exam trap

CISM often tests the misconception that a risk owner's decision is always final — candidates forget that risk acceptance authority is bounded by the organization's risk appetite and must be escalated when exceeded.

How to eliminate wrong answers

Option A is wrong because waiting for a cost-benefit analysis before escalating delays governance when the risk already exceeds appetite and the risk owner has refused treatment — escalation should not be contingent on further analysis. Option B is wrong because the risk owner cannot accept a risk that exceeds the documented risk appetite; only the CRO or risk management committee can authorize that acceptance. Option C is wrong because implementing a compensating control unilaterally bypasses the risk owner and the governance process, and application-layer encryption may not satisfy the specific regulatory mandate for TLS 1.3 in transit.

71
MCQhard

A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?

A.Accept the residual risk with formal sign-off from senior management
B.Adjust the risk appetite to 'moderate' to align with the residual risk
C.Transfer the risk by taking out an insurance policy
D.Approve additional controls to lower residual risk regardless of cost
AnswerA

Where further reduction costs $1 million and exceeds the expected benefit, the risk owner accepts the residual risk with formal senior management sign-off. This satisfies the stem's constraint of a low risk appetite against an uneconomic control.

Why this answer

The risk owner has determined that the cost to further reduce the residual risk ($1 million) exceeds the expected benefit, making additional controls economically unjustifiable. Since the company's risk appetite is 'low' for operational risks but the residual risk is 'high', the most appropriate action is to formally accept the residual risk with senior management sign-off, as this documents the decision and acknowledges the deviation from the stated risk appetite. This aligns with the CISM principle that risk acceptance is a valid treatment option when the cost of mitigation outweighs the benefit, provided it is approved at the appropriate level.

Exam trap

The trap here is that candidates confuse 'risk acceptance' with 'ignoring the risk' or assume that a low risk appetite always mandates mitigation, failing to recognize that formal acceptance with senior sign-off is a legitimate and required response when cost-benefit analysis shows mitigation is not justified.

How to eliminate wrong answers

Option B is wrong because adjusting the risk appetite to 'moderate' to align with the residual risk is a reactive and inappropriate approach; risk appetite should be set by the board based on strategic objectives, not changed to justify a single risk assessment outcome. Option C is wrong because transferring the risk via insurance does not reduce the residual risk rating; it only shifts the financial impact, and the high-speed trading platform's operational risk (e.g., latency, system failure) may not be fully insurable or cost-effective given the premium. Option D is wrong because approving additional controls regardless of cost violates the principle of cost-benefit analysis; the question explicitly states the cost exceeds the expected benefit, making this option economically unsound and contrary to risk management best practices.

72
MCQhard

A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?

A.The number of similar risks already identified in the risk register
B.The cost of the control compared to the asset's book value
C.The technical severity rating from the vulnerability scanner
D.The organization's risk appetite and tolerance
AnswerD

Risk appetite and tolerance define the amount and type of risk the organization is willing to accept in pursuit of its objectives. Treatment decisions must align with these thresholds. Without this context, a control decision may be inappropriate even if technically sound. This makes risk appetite and tolerance the primary factor guiding whether to accept, mitigate, transfer, or avoid the risk.

Why this answer

Risk treatment must be driven by the organization's risk appetite and tolerance, because these express how much risk leadership is willing to accept while pursuing objectives. Technical severity, control cost, and risk counts inform the analysis, but they do not determine acceptability. The chosen treatment should bring residual risk within tolerance and remain consistent with regulatory and business obligations.

Exam trap

The trap here is assuming that technical severity or control cost alone dictates risk treatment, rather than the organization's risk appetite and tolerance.

73
MCQeasy

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

A.To provide early warning signals of increasing risk
B.To report on past incidents and losses
C.To measure the effectiveness of security controls
D.To demonstrate compliance with regulations
AnswerA

A KRI tracks measurable metrics against defined thresholds, so deviations signal rising risk exposure before losses materialise. This satisfies the stem's focus on primary purpose: providing early warning that lets management act ahead of an incident rather than reporting it afterwards.

Why this answer

A Key Risk Indicator (KRI) is a metric used to provide an early warning signal that a risk exposure is approaching or exceeding acceptable thresholds. Unlike lagging indicators that report on past events, KRIs are forward-looking, enabling proactive risk mitigation before a risk materializes into a loss.

Exam trap

The trap here is that candidates often confuse KRIs with KPIs or KCIs, mistakenly thinking KRIs measure past performance or control effectiveness, when in fact KRIs are specifically designed to provide leading indicators of changing risk exposure.

How to eliminate wrong answers

Option B is wrong because reporting on past incidents and losses is the function of a Key Performance Indicator (KPI) or a loss event metric, not a KRI, which is forward-looking. Option C is wrong because measuring the effectiveness of security controls is the role of a Key Control Indicator (KCI) or control effectiveness metric, not a KRI, which focuses on risk exposure. Option D is wrong because demonstrating compliance with regulations is typically achieved through compliance audits and control testing, not through KRIs, which are designed to signal changes in risk levels rather than adherence to regulatory requirements.

74
Multi-Selectmedium

A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?

Select 2 answers
A.Aligns security spending with business objectives
B.Provides a defensible justification for security investments
C.Eliminates the need for qualitative analysis
D.Ensures compliance with all applicable regulations
E.Reduces the total number of security controls needed
AnswersA, B

Risk assessment results map each security project to the business risks it mitigates, so prioritisation directs spending toward initiatives protecting the most critical objectives. This satisfies the stem's requirement of aligning security investment with business goals.

Why this answer

Option A is correct because risk assessment results tie each security project to the likelihood and impact of risks to business processes, so funding flows to initiatives that protect the organization's most important objectives and assets, aligning security spending with business priorities. Option B is correct because documented risk assessment outputs (identified threats, vulnerabilities, likelihood, and impact ratings) provide an auditable, defensible rationale for why specific security investments are chosen and prioritized, which is essential for justifying budgets to executives, auditors, and regulators. Option C is incorrect because risk-based prioritization still relies on qualitative analysis (for example, ordinal likelihood/impact scales) and often combines it with quantitative methods; it does not eliminate qualitative analysis.

Option D is incorrect because risk assessment prioritization does not by itself guarantee compliance with all applicable regulations; compliance is a separate obligation that may require controls regardless of assessed risk level. Option E is incorrect because prioritizing projects by risk does not reduce the total number of security controls needed; it only orders which controls are implemented first, and a risk-based approach may even increase controls for high-risk areas.

Exam trap

The trap here is that candidates may confuse the purpose of risk assessment results—which is to prioritize based on business impact—with compliance or control reduction, leading them to select options like D or E that sound plausible but are not primary benefits of a risk-based approach.

75
Multi-Selectmedium

A retail company is building an information security risk register to support its risk management program. The risk manager wants to ensure the register captures the information needed to track and report risks to senior management. Which TWO of the following are essential elements that should be included for each identified risk? (Choose two.)

Select 2 answers
A.Risk owner and risk response
B.Likelihood and impact ratings
C.The name of the auditor who discovered the risk
D.The budget code of the department that reported the risk
E.A detailed list of every technical vulnerability associated with the risk
AnswersA, B

Every risk must have an accountable owner and a documented response, such as mitigate, transfer, avoid, or accept. The owner ensures follow-through, and the response defines the intended treatment. Without these, the register becomes a list of issues rather than a managed risk portfolio, and senior management cannot assign accountability or track remediation progress effectively.

Why this answer

A useful risk register must record who owns each risk and what response is planned, because accountability and treatment drive progress. It must also capture likelihood and impact so risks can be scored, compared, and prioritized consistently. Other details may be linked or tracked elsewhere, but these two elements are fundamental for managing and reporting risk to senior management.

Exam trap

The trap here is treating the risk register as a technical vulnerability log or administrative record rather than a management tool centered on ownership, response, and risk scoring.

Page 1 of 2 · 122 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Security Risk Management questions.