Courseiva
hardMultiple ChoiceObjective-mapped

CISM Practice Question: During an internal audit, it is discovered that…

During an internal audit, it is discovered that business units frequently purchase cloud services without involving the IT security department. Which governance deficiency does this scenario most clearly demonstrate?

⚠ Common exam trap

It's easy for candidates to confuse a lack of security awareness training (Option A) with the governance failure, but the scenario specifically highlights the absence of a formal procurement process, not a training gap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Absence of a procurement security policy

The scenario describes business units procuring cloud services without IT security involvement, which directly indicates the absence of a procurement security policy. Such a policy would mandate security review and approval before any cloud service acquisition, ensuring that security requirements are integrated into the procurement lifecycle. Without it, security is bypassed, leading to ungoverned shadow IT and potential compliance violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Inadequate security awareness training

    Why it's wrong here

    Training might help but does not address the process gap.

  • Lack of an incident response plan

    Why it's wrong here

    Incident response is separate from the procurement process.

  • Absence of a procurement security policy

    Why this is correct

    A procurement policy should require security review before purchasing cloud services.

  • Weak access control over cloud resources

    Why it's wrong here

    Access controls may be weak, but the fundamental issue is the governance process.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.