Courseiva
Information Security ProgrammediumMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

Exhibit

Security Program Dashboard:
- Patch Compliance (30-day window): 85%
- Critical Vulnerability Remediation (48h): 95%
- High-Risk Vulnerability Remediation (60-day): 88%
- Risk Acceptance: 3% of findings
- Incident Response Plan Test: Annual, last test 14 months ago.

Refer to the exhibit. The CISO wants to improve the program. Which recommendation BEST addresses the main gap shown in the dashboard?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement automated patching for high-risk vulnerabilities

The dashboard shows high-risk vulnerability remediation at 88%, which is below the target. Implementing automated patching for high-risk vulnerabilities would directly address this gap by ensuring faster and more consistent remediation. Option B is incorrect because reducing the compliance target does not fix the underlying issue. Option C is incorrect because critical vulnerability remediation is already high. Option D is incorrect because increasing patch frequency for all systems may not specifically target the high-risk vulnerability gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement automated patching for high-risk vulnerabilities

    Why this is correct

    Automation can help reduce the 12% that exceed the 60-day window.

  • Reduce the compliance target for high-risk vulnerabilities to 90 days

    Why it's wrong here

    Lowering targets does not improve actual performance.

  • Focus on critical vulnerability remediation

    Why it's wrong here

    Critical remediation is already at 95%; improvement needed on high-risk.

  • Increase patch frequency for all systems

    Why it's wrong here

    Patch compliance is 85%, which may be acceptable; the gap is high-risk remediation time.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.