Courseiva

CISM Information Security Risk Management Practice Question

During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?

⚠ Common exam trap

A common mix-up: candidates confuse risk transfer (insurance) with risk mitigation (redundancy), or incorrectly assume that accepting the risk is acceptable when a clear, cost-effective mitigation exists, especially in a CISM scenario where the organization's risk appetite is not explicitly stated as high.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigate by moving the backup server to a geographically separate location.

Moving the backup server to a geographically separate location directly eliminates the single point of failure by ensuring that a localized disaster (e.g., fire, flood, power outage) at the primary data center does not simultaneously destroy both the primary and backup data. This is a classic risk mitigation strategy that reduces the likelihood and impact of data loss, aligning with the principle of geographic redundancy for disaster recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mitigate by moving the backup server to a geographically separate location.

    Why this is correct

    Relocating the backup server to a geographically separate location removes the shared data-centre failure domain, so a site-wide incident cannot destroy both primary and backup copies simultaneously. This mitigation directly addresses the identified single point of failure, restoring recoverability.

  • ✗

    Transfer the risk by purchasing business interruption insurance.

    Why it's wrong here

    Insurance compensates financial loss after an outage but does not restore data or remove the single point of failure, so recovery capability remains absent. It tempts because transfer is a valid response for financial consequences, yet it cannot satisfy the availability and recovery objectives the backup process exists to meet.

  • ✗

    Avoid the risk by discontinuing the backup process.

    Why it's wrong here

    Discontinuing backups removes the recovery capability entirely, converting a single point of failure into guaranteed unrecoverable data loss; the risk response should relocate or replicate the backup server to a separate data centre. Avoidance suits activities whose risk outweighs any benefit, not a control the organisation is obliged to retain.

  • ✗

    Accept the risk because the cost of mitigation is high.

    Why it's wrong here

    Acceptance leaves the single point of failure intact, so a data centre outage still destroys both primary and backup data; cost alone does not justify tolerating that exposure. It tempts when mitigation genuinely exceeds the asset's value, but here relocation or replication is feasible and the impact is severe.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.