hardMultiple ChoiceObjective-mapped
CISM Practice Question: During an internal audit, it is discovered that…
During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?
⚠ Common exam trap
It's easy for candidates to confuse a lack of security awareness training (Option A) with the governance failure, but the scenario specifically highlights the absence of a formal procurement process, not a training gap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Absence of a procurement security policy
The scenario describes business units procuring cloud services without IT security involvement, which directly indicates the absence of a procurement security policy. Such a policy would mandate security review and approval before any cloud service acquisition, ensuring that security requirements are integrated into the procurement lifecycle. Without it, security is bypassed, leading to ungoverned shadow IT and potential compliance violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inadequate security awareness training
Why it's wrong here
Training might help but does not address the process gap.
- ✗
Lack of an incident response plan
Why it's wrong here
Incident response is separate from the procurement process.
- ✓
Absence of a procurement security policy
Why this is correct
A procurement policy should require security review before purchasing cloud services.
- ✗
Weak access control over cloud resources
Why it's wrong here
Access controls may be weak, but the fundamental issue is the governance process.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.