CISM Information Security Programme Practice Question
During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?
⚠ Common exam trap
The trap is assuming that any security control (passwords, segmentation, scanning) compensates for missing encryption, when the specific risk — unauthorized data access — requires monitoring of data activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Database activity monitoring (DAM)
Database activity monitoring (DAM) is the most appropriate compensating control because it provides real-time visibility into database transactions, detects anomalous access, and can alert on or block unauthorized queries — all without requiring encryption that might impact performance. DAM addresses the risk of plaintext data exposure by monitoring who accesses it and how, enabling detection and response even if encryption is not feasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement strong password policies for database access
Why it's wrong here
Strong password policies authenticate database users but do not obscure the plaintext values, so a direct file or backup read still exposes customer data. It is tempting because it hardens access credentials, and it would be correct for reducing brute-force or credential-stuffing risk against the database.
- ✗
Network segmentation to isolate the database server
Why it's wrong here
Network segmentation restricts reachability to the database but leaves the plaintext data readable to anyone who reaches it, including through the application itself. It is tempting because it limits lateral movement, and it would be correct for containing a compromised host rather than protecting stored data at rest.
- ✗
Conduct more frequent vulnerability scans
Why it's wrong here
Frequent vulnerability scans detect software flaws but do not change the fact that stored records remain readable in plaintext. It is tempting because scanning is a recognised risk-reduction activity, and it would be correct for identifying unpatched components rather than compensating for absent encryption.
- ✓
Database activity monitoring (DAM)
Why this is correct
DAM monitors database transactions and alerts on suspicious access to plaintext records, detecting and logging exposure without altering application performance. It compensates for the absent encryption control by providing visibility and accountability, satisfying the performance constraint while reducing breach impact.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.