Courseiva

CISM Information Security Programme Practice Question

During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?

⚠ Common exam trap

The trap is assuming that any security control (passwords, segmentation, scanning) compensates for missing encryption, when the specific risk — unauthorized data access — requires monitoring of data activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Database activity monitoring (DAM)

Database activity monitoring (DAM) is the most appropriate compensating control because it provides real-time visibility into database transactions, detects anomalous access, and can alert on or block unauthorized queries — all without requiring encryption that might impact performance. DAM addresses the risk of plaintext data exposure by monitoring who accesses it and how, enabling detection and response even if encryption is not feasible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement strong password policies for database access

    Why it's wrong here

    Strong password policies authenticate database users but do not obscure the plaintext values, so a direct file or backup read still exposes customer data. It is tempting because it hardens access credentials, and it would be correct for reducing brute-force or credential-stuffing risk against the database.

  • ✗

    Network segmentation to isolate the database server

    Why it's wrong here

    Network segmentation restricts reachability to the database but leaves the plaintext data readable to anyone who reaches it, including through the application itself. It is tempting because it limits lateral movement, and it would be correct for containing a compromised host rather than protecting stored data at rest.

  • ✗

    Conduct more frequent vulnerability scans

    Why it's wrong here

    Frequent vulnerability scans detect software flaws but do not change the fact that stored records remain readable in plaintext. It is tempting because scanning is a recognised risk-reduction activity, and it would be correct for identifying unpatched components rather than compensating for absent encryption.

  • ✓

    Database activity monitoring (DAM)

    Why this is correct

    DAM monitors database transactions and alerts on suspicious access to plaintext records, detecting and logging exposure without altering application performance. It compensates for the absent encryption control by providing visibility and accountability, satisfying the performance constraint while reducing breach impact.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.