Courseiva

CISM · topic practice

Information Security Risk Management practice questions

CISM Domain 2 covers risk identification, analysis, evaluation, treatment, and monitoring aligned to organizational risk appetite and tolerance. Questions test quantitative methods like SLE, ARO, and ALE, qualitative heat maps, control selection, residual risk calculation, and communicating risk to senior leadership. Expect scenario-based judgment calls on ownership, acceptance, and escalation rather than pure definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Security Risk Management

What the exam tests

What to know about Information Security Risk Management

You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.

Calculating SLE, ARO, and ALE to justify or reject a safeguard's cost

Distinguishing inherent risk, residual risk, risk appetite, and risk tolerance

Assigning risk ownership to business process owners, not information security

Selecting risk treatment: mitigate, transfer, avoid, or accept with approval

Watch out for

Common Information Security Risk Management exam traps

  • ▸Confusing risk appetite (desired level) with risk tolerance (acceptable deviation) and applying them interchangeably in scenario answers
  • ▸Treating residual risk as zero after controls are implemented instead of recalculating likelihood and impact
  • ▸Assuming information security owns business risk; accountability stays with the business process or asset owner

Practice set

Information Security Risk Management questions

20 questions · select your answer, then reveal the explanation

A multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?

Refer to the exhibit. A security analyst reviews the firewall configuration and identifies a potential risk. What is the most likely risk?

Exhibit

Refer to the exhibit.

Exhibit:
```
CISCO ASA Firewall Config Snippet
access-list INSIDE extended permit tcp 10.0.0.0 255.255.255.0 any eq 443
access-list INSIDE extended permit udp 10.0.0.0 255.255.255.0 any eq 53
access-list OUTSIDE extended deny ip any any
```

Refer to the exhibit. A system administrator reviews the log and notices repeated failed SSH attempts from the same IP address. What is the most appropriate risk response?

Exhibit

Refer to the exhibit.

Exhibit:
```
Log Entry:
Jan 15 09:23:45 server1 sshd[1234]: Failed password for root from 10.0.0.5 port 22 ssh2
Jan 15 09:23:47 server1 sshd[1235]: Failed password for admin from 10.0.0.5 port 22 ssh2
Jan 15 09:23:50 server1 sshd[1236]: Failed password for root from 10.0.0.5 port 22 ssh2
Jan 15 09:23:52 server1 sshd[1237]: Failed password for admin from 10.0.0.5 port 22 ssh2
```

Based on the exhibit, what is the MOST appropriate next step for the information security manager?

Exhibit

Refer to the exhibit.

```
Risk Assessment Log
Date: 2025-03-01
Asset: Database Server DB-01
Threat: Unauthorized access
Vulnerability: Weak password policy
Current Controls: Password complexity enabled, account lockout after 5 failed attempts
Likelihood: 3 (Moderate)
Impact: 4 (Major)
Risk Level: 12 (High)
Risk Appetite Threshold: 10
```

During a risk assessment, an organization identifies a critical vulnerability in a legacy system that cannot be patched. The system's availability is crucial for business operations. Which of the following risk treatment strategies is MOST appropriate?

An organization has a high residual risk after implementing all feasible controls. According to CISM best practices, which of the following should the information security manager do? (Select TWO.)

Match each risk assessment activity with the correct phase of the risk management lifecycle:

Activities: 1. Identify assets and threats 2. Determine risk level 3. Select controls to reduce risk 4. Monitor risk over time

Phases: A. Risk Assessment B. Risk Treatment C. Risk Monitoring D. Risk Communication (not used)

A security manager is evaluating risk treatment options for a high-risk vulnerability. Drag each option to the correct risk treatment category.

Options: - Apply a vendor patch - Purchase cyber insurance - Decommission the system - Accept the risk with formal sign-off - Install a WAF (Web Application Firewall)

Categories: - Mitigate - Transfer - Avoid - Accept

Answer choices are not available in this preview. Open the full question page for the complete review.

Which of the following are key components of an information security risk management program? (Select TWO)

Order the steps for conducting an internal audit of an information security management system (ISMS) based on ISO 27001.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each cryptographic term to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses same key for encryption and decryption

Uses public/private key pair

One-way transformation producing fixed-size digest

Provides authenticity and non-repudiation

Framework managing digital certificates and keys

Which THREE of the following are valid methods to identify information security risks? (Choose three.)

A company is choosing a risk assessment methodology for a new cloud-based application. The CISO prefers a method that uses monetary values and numerical probabilities to compute annual loss expectancy. Which methodology should be selected?

During a risk assessment, an organization identifies that a legacy system processes credit card data and has a high likelihood of being exploited. The cost to remediate the vulnerability is $500,000, while the potential loss from a breach is $2 million with a 30% annual probability. What is the most appropriate risk treatment decision based on this information?

Which TWO of the following are valid risk response options?

Which host should be prioritized for risk mitigation based on the vulnerability scan results?

Exhibit

Refer to the exhibit.

Vulnerability Scan Summary Report
11-Jun-2023 04:15:42

Host: 192.168.10.25
Total vulnerabilities: 12
Critical: 2
High: 4
Medium: 3
Low: 3

Host: 192.168.10.30
Total vulnerabilities: 8
Critical: 0
High: 1
Medium: 5
Low: 2

Host: 192.168.10.35
Total vulnerabilities: 20
Critical: 5
High: 6
Medium: 7
Low: 2

An employee emails a spreadsheet containing employee salaries to all staff by mistake. According to the exhibit, what is the minimum handling requirement that was violated?

Exhibit

Refer to the exhibit.

{
  "dataClassification": {
    "public": {
      "description": "Information that can be disclosed to anyone",
      "handling": "No special protection required"
    },
    "internal": {
      "description": "Information for internal use only",
      "handling": "Must be stored on internal systems, encrypted in transit"
    },
    "confidential": {
      "description": "Sensitive information with legal or contractual obligations",
      "handling": "Must be encrypted at rest and in transit, access on a need-to-know basis"
    },
    "highlyConfidential": {
      "description": "Information that could cause severe reputational damage if disclosed",
      "handling": "All 'confidential' protections plus multifactor authentication, data loss prevention, and quarterly access reviews"
    }
  }
}

Which of the following is the most significant risk in this architecture?

Exhibit

Refer to the exhibit.

Network Architecture Description:
- Internet facing web server (DMZ)
- Application server (internal trust zone)
- Database server (restricted zone)
- All zones separated by firewalls
- Admin access to database server requires VPN + jump host
- All traffic from web server to application server encrypted with TLS 1.3
- Application server has direct access to database using SQL authentication

A financial institution is implementing a risk management program and needs to select a methodology that balances quantitative and qualitative factors, complies with regulatory requirements, and provides a consistent framework for risk assessment across business units. Which methodology would best meet these requirements?

Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Security Risk Management sessions

Start a Information Security Risk Management only practice session

Every question in these sessions is drawn from the Information Security Risk Management domain — nothing else.

Related practice questions

Related CISM topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISM exam test about Information Security Risk Management?
You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Security Risk Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Security Risk Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISM topics?
Use the topic links above to move to related areas, or go back to the CISM question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISM exam covers. They are not copied from any real exam or dump site.