mediumMultiple ChoiceObjective-mapped
CISM Practice Question: Given the exhibit, what is the MOST appropriate…
Exhibit
Refer to the exhibit. ``` SECURITY GOVERNANCE REPORT - Q4 20XX ======================================= Risk Appetite: Moderate (defined by board) Key Risk Indicator: % Systems with critical vulnerabilities > 30 days old Current Value: 8% Threshold: <5% (Red), 5-10% (Yellow), >10% (Green) Status: YELLOW Action Plan: Accelerate patching for high-risk assets ```
Given the exhibit, what is the MOST appropriate action for the information security manager?
⚠ Common exam trap
Many exam-takers confuse a KRI threshold breach with a security incident, leading them to choose crisis response (Option B) or immediate escalation (Option C), when in fact the correct action is to follow the pre-planned mitigation steps as part of normal risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement the action plan to reduce KRI value
The exhibit shows a Key Risk Indicator (KRI) trending above the defined threshold but within the risk appetite, meaning the risk is not yet critical. The information security manager should implement the existing action plan to reduce the KRI value back to an acceptable level, as this is a proactive risk treatment measure aligned with the organization's risk management framework. This avoids unnecessary escalation or crisis declaration while addressing the risk in a controlled manner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request board approval to accept the risk level
Why it's wrong here
Risk is within appetite, acceptance not needed.
- ✗
Declare a security crisis and mobilize incident response
Why it's wrong here
Not appropriate for yellow status.
- ✗
Escalate to the board for immediate decision
Why it's wrong here
Red status would require escalation.
- ✓
Implement the action plan to reduce KRI value
Why this is correct
Yellow status needs management action as planned.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.