Courseiva
mediumMultiple ChoiceObjective-mapped

CISM Practice Question: Given the exhibit, what is the MOST appropriate…

Exhibit

Refer to the exhibit.

```
SECURITY GOVERNANCE REPORT - Q4 20XX
=======================================
Risk Appetite: Moderate (defined by board)
Key Risk Indicator: % Systems with critical vulnerabilities > 30 days old
Current Value: 8%
Threshold: <5% (Red), 5-10% (Yellow), >10% (Green)
Status: YELLOW
Action Plan: Accelerate patching for high-risk assets
```

Given the exhibit, what is the MOST appropriate action for the information security manager?

⚠ Common exam trap

Many exam-takers confuse a KRI threshold breach with a security incident, leading them to choose crisis response (Option B) or immediate escalation (Option C), when in fact the correct action is to follow the pre-planned mitigation steps as part of normal risk management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement the action plan to reduce KRI value

The exhibit shows a Key Risk Indicator (KRI) trending above the defined threshold but within the risk appetite, meaning the risk is not yet critical. The information security manager should implement the existing action plan to reduce the KRI value back to an acceptable level, as this is a proactive risk treatment measure aligned with the organization's risk management framework. This avoids unnecessary escalation or crisis declaration while addressing the risk in a controlled manner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Request board approval to accept the risk level

    Why it's wrong here

    Risk is within appetite, acceptance not needed.

  • Declare a security crisis and mobilize incident response

    Why it's wrong here

    Not appropriate for yellow status.

  • Escalate to the board for immediate decision

    Why it's wrong here

    Red status would require escalation.

  • Implement the action plan to reduce KRI value

    Why this is correct

    Yellow status needs management action as planned.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.