Courseiva

CCNA Cism Risk Management Questions

47 of 122 questions · Page 2/2 · Cism Risk Management topic · Answers revealed

76
MCQhard

You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?

A.Hire two additional security analysts to improve monitoring and incident response.
B.Implement a formal vulnerability management program with defined remediation SLAs based on risk severity.
C.Increase cyber liability insurance coverage to $5 million to cover potential breach costs.
D.Rewrite the web application using a secure development framework to eliminate vulnerabilities.
AnswerB

Formal vulnerability management with risk-based remediation SLAs directly fixes the root cause: a known penetration-test finding left unremediated. Defined SLAs force prioritisation against competing work, matching the moderate risk appetite and the three-person team's limited capacity.

Why this answer

A formal vulnerability management program with defined remediation SLAs directly addresses the root cause: the known vulnerability was not patched due to competing priorities. By tying remediation timelines to risk severity (e.g., critical vulnerabilities patched within 7 days, high within 30 days), the company operationalizes its 'moderate' risk appetite and ensures that penetration test findings are acted upon before they can be exploited. This is the most cost-effective approach given the limited budget, as it leverages existing staff and processes rather than requiring new hires or expensive rewrites.

Exam trap

ISACA often tests the misconception that increasing insurance or hiring more staff is the primary solution to a risk management failure, when in fact the core issue is the lack of a process to enforce remediation of known vulnerabilities within the organization's risk appetite.

How to eliminate wrong answers

Option A is wrong because hiring two additional security analysts improves monitoring and incident response but does not fix the underlying issue of unpatched vulnerabilities; the attacker exploited a known vulnerability that should have been remediated, not a detection gap. Option C is wrong because increasing cyber liability insurance to $5 million only transfers financial risk after a breach, it does not prevent recurrence of the vulnerability exploitation and violates the principle of reducing risk to an acceptable level. Option D is wrong because rewriting the web application using a secure development framework is a long-term, high-cost solution that exceeds the limited budget and does not address the immediate need to remediate existing vulnerabilities; it also ignores the fact that the current application is already in production and needs a process for ongoing vulnerability management.

77
MCQmedium

A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?

A.Transfer the risk to the cloud vendor by amending the SLA to include the local workstations.
B.Accept the risk because the cloud vendor holds SOC 2 Type II attestation.
C.Mitigate the risk by enforcing full-disk encryption, access controls, and a policy prohibiting unauthorized local copies.
D.Avoid the risk by terminating the contract with the cloud vendor and returning to on-premises storage.
AnswerC

Mitigation reduces likelihood and impact through controls the hospital can enforce. Full-disk encryption protects data if a workstation is lost, access controls limit exposure, and policy with technical enforcement addresses the root behavior. This directly targets the risk introduced by staff copying images locally rather than relying on the vendor's controls.

Why this answer

The risk arises from hospital-controlled endpoints, so the effective treatment is mitigation through encryption, access control, and policy enforcement. Transfer and acceptance do not address the internal behavior, and avoidance of the vendor relationship is misdirected because the vendor is not the source of the exposure. Risk treatment should be matched to the party that actually controls the risk.

Exam trap

The trap here is assuming that a vendor's SOC 2 attestation or SLA transfers responsibility for data copied outside the vendor's environment.

78
MCQhard

During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?

A.Implement additional controls immediately
B.Document the risk as accepted
C.Escalate the residual risk to senior management
D.Reassess the risk using a different methodology
AnswerC

Escalating the residual risk to senior management satisfies the governance requirement when risk exceeds the appetite threshold. Senior management owns risk acceptance decisions beyond delegated authority, so the manager must present the residual exposure for a formal accept, mitigate further, or reject decision rather than absorbing it silently.

Why this answer

When residual risk exceeds the risk appetite threshold after planned controls, the security manager cannot simply accept or ignore it; the risk must be escalated to senior management because they hold the authority to decide whether to accept the risk, allocate additional budget for further controls, or adjust the risk appetite. This aligns with the CISM domain of Information Security Risk Management, where risk acceptance is a management decision, not an operational one.

Exam trap

The trap here is that candidates confuse operational risk acceptance (which a manager can do for low risks) with management-level risk acceptance required when residual risk exceeds the appetite threshold, leading them to incorrectly choose Option B.

Why the other options are wrong

A

While additional controls may be an option, the immediate next step is to escalate and get a decision.

B

Acceptance requires authorization from management, not unilateral action by the security manager.

D

Changing methodology may give different numbers but doesn't address the underlying issue.

79
MCQhard

After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?

A.Transfer the risk through insurance
B.Accept the residual risk as a business decision
C.Document the risk and escalate to senior management for acceptance
D.Implement additional controls regardless of cost
AnswerC

Residual risk exceeding appetite cannot be accepted by the risk manager alone; documenting the business owner's cost-benefit rationale and escalating preserves accountability. This satisfies the stem's constraint that the owner argues further mitigation costs outweigh benefits, placing acceptance authority with senior management.

Why this answer

When residual risk exceeds the risk appetite, the risk manager's role is to document the finding and escalate it to senior management, who own the decision to accept, mitigate, or transfer risk beyond appetite. The risk manager advises and facilitates; the business owner cannot unilaterally accept risk that breaches the organization's stated appetite. Escalation preserves governance and creates an auditable record.

Exam trap

The trap is confusing the business owner's accountability with the authority to accept risk above appetite, leading candidates to pick 'accept as a business decision' instead of escalation.

How to eliminate wrong answers

Option A is wrong because transferring risk via insurance is a mitigation strategy that must be chosen by the accountable owner after escalation — it is not the risk manager's default action and may not cover the specific risk. Option B is wrong because the business owner lacks authority to accept risk exceeding the enterprise risk appetite; acceptance at that level requires senior management or board sign-off. Option D is wrong because implementing controls 'regardless of cost' ignores the cost-benefit analysis the business owner raised and is not the risk manager's call to make unilaterally.

80
MCQmedium

A global insurance provider has completed a risk assessment for a new policyholder web portal. The risk treatment plan includes purchasing cyber insurance to transfer a portion of the financial impact. Which of the following is the PRIMARY consideration when evaluating this treatment option?

A.The number of other organizations that have purchased similar coverage
B.The insurer's ability to cover the full impact of a catastrophic breach
C.The cost of the premium relative to the potential financial impact and risk appetite
D.The speed at which the policy can be underwritten and bound
AnswerC

Risk transfer through insurance must be evaluated against the cost of the premium, the potential financial impact being transferred, and the organization's risk appetite. If the premium is disproportionate to the expected loss or the retained deductible remains outside tolerance, the treatment is ineffective. This comparison ensures the treatment is economically justified and aligned with business objectives.

Why this answer

Risk transfer via insurance is justified when the premium is reasonable relative to the potential loss and the residual risk after deductibles and limits remains within the organization's risk appetite. The other factors, such as speed, peer adoption, or hopes of full coverage, do not address the fundamental cost-benefit and risk tolerance alignment required for effective treatment selection.

Exam trap

The trap here is assuming that cyber insurance fully eliminates financial risk, when in reality it transfers only a portion and must be evaluated against cost and risk appetite.

81
Drag & Dropmedium

Order the steps for implementing a security awareness training program.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Training programs start with needs assessment, then content development, delivery, evaluation, and continuous improvement.

82
Multi-Selectmedium

A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)

Select 2 answers
A.Unpatched software on the EHR server.
B.Weak password policy allowing short passwords.
C.Natural disasters such as floods in the data center region.
D.A ransomware group targeting healthcare providers.
E.A disgruntled employee with administrative access.
AnswersA, B

Unpatched software is a weakness in the system that can be exploited by threats. It is a vulnerability because it represents a gap in security controls. Threats are external or internal actors or events that can exploit vulnerabilities. Unpatched software does not act on its own; it requires a threat to cause harm. Therefore, it is correctly classified as a vulnerability.

Why this answer

Vulnerabilities are weaknesses or gaps in controls that can be exploited by threats. Unpatched software and weak password policies are examples of such weaknesses because they represent deficiencies in security controls. Threats, on the other hand, are actors or events that can exploit vulnerabilities, such as disgruntled employees, ransomware groups, or natural disasters.

Correctly distinguishing between the two is essential for accurate risk assessment.

Exam trap

The trap here is confusing threats with vulnerabilities; a disgruntled employee is a threat actor, while unpatched software is a weakness.

83
MCQmedium

A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?

A.Select appropriate security controls
B.Conduct vulnerability scanning
C.Identify potential threat sources
D.Identify and classify information assets
AnswerD

Risk assessment begins with identifying and classifying the information assets the cloud system will hold, since sensitivity and value drive every subsequent threat, vulnerability, and impact analysis. Without an asset inventory, later likelihood and impact ratings lack a defensible basis.

Why this answer

In the risk assessment process, the first step is to identify and classify information assets because you cannot assess risks to assets you haven't identified. For a cloud-based system storing sensitive customer data, this means cataloging data types (e.g., PII, financial records), their locations (e.g., specific cloud storage buckets), and their classification levels (e.g., confidential, restricted) before any threat or vulnerability analysis can be meaningfully performed.

Exam trap

The trap here is that candidates often confuse the order of risk assessment steps, mistakenly thinking that identifying threats (Option C) comes first because threats are the 'active' element, but CISM emphasizes that asset identification is the foundational step that drives all subsequent analysis.

How to eliminate wrong answers

Option A is wrong because selecting security controls is a risk treatment step that occurs after risks have been assessed and prioritized, not at the beginning of the assessment. Option B is wrong because vulnerability scanning is a technical activity that identifies weaknesses in existing systems, but it cannot be effectively scoped or targeted without first knowing which assets are in scope and their classification. Option C is wrong because while identifying threat sources is important, it logically follows asset identification; you must know what assets you are protecting before you can determine which threats are relevant to those specific assets.

84
MCQeasy

Which of the following is the PRIMARY purpose of an information security risk assessment?

A.To eliminate all identified risks
B.To identify and evaluate risks in terms of likelihood and impact
C.To comply with regulatory requirements
D.To assign blame for security incidents
AnswerB

Identifying and evaluating risks by likelihood and impact is the core mechanism of risk assessment, producing the prioritised risk picture that drives subsequent treatment decisions. This directly satisfies the stem's demand for the primary purpose, since assessment precedes mitigation; auditing, control implementation and monitoring are separate downstream activities.

Why this answer

The primary purpose of an information security risk assessment is to identify and evaluate risks in terms of their likelihood and impact. This process enables an organization to prioritize risks and determine appropriate risk treatment options, such as mitigation, transfer, acceptance, or avoidance, based on a clear understanding of the risk landscape. Without this evaluation, any subsequent risk management decisions would lack a defensible basis.

Exam trap

The trap here is that candidates often confuse the purpose of a risk assessment with the purpose of risk treatment or compliance, leading them to select 'comply with regulatory requirements' as the primary purpose, when in fact compliance is a secondary benefit, not the core objective.

Why the other options are wrong

A

Eliminating all risks is impractical and not the primary purpose; risk assessment informs risk treatment decisions.

C

Compliance may be a driver but is not the primary purpose; the core is informed decision-making.

D

Risk assessment is proactive, not punitive.

85
MCQmedium

A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?

A.It documents the risk assessment results in a centralized risk register.
B.It aligns with the organization’s overall enterprise risk management framework.
C.It is reviewed and approved annually by the board of directors.
D.It uses a consistent set of defined likelihood and impact criteria.
AnswerD

Defined likelihood and impact criteria are the foundation of repeatability and comparability. When assessors apply the same scales and definitions across the cloud POS platform and subsequent assessments, results can be meaningfully compared, aggregated and trended. Without this consistency, quantitative or qualitative ratings become subjective and cannot reliably support risk-based decisions or demonstrate changes in risk posture over time.

Why this answer

Repeatability and comparability depend on consistent measurement criteria. By defining what likelihood and impact mean and how they are rated, the organization ensures that different assessors evaluating the cloud POS platform or other systems will produce results that can be compared and trended. Documentation, governance approval and ERM alignment support the process but do not by themselves eliminate subjective variation in risk ratings.

Exam trap

The trap here is confusing the governance and documentation attributes of a risk methodology with the measurement consistency that actually makes assessments repeatable and comparable.

86
Multi-Selectmedium

An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?

Select 2 answers
A.Determining acceptable risk levels
B.Analyzing threats and vulnerabilities
C.Monitoring incident response plans
D.Evaluating the effectiveness of existing controls
E.Selecting controls to mitigate risks
AnswersB, D

This is a core activity in risk identification and analysis.

Why this answer

Analyzing threats and vulnerabilities is a core step in the risk assessment process, as defined by the NIST SP 800-30 and ISO 31000 frameworks. This activity identifies potential threat sources and existing vulnerabilities that could be exploited, enabling the calculation of likelihood and impact for risk scenarios.

Exam trap

The trap here is confusing risk assessment (identify/analyze) with risk treatment (select controls) or risk evaluation (set acceptable levels), leading candidates to pick A or E instead of focusing on the core assessment activities B and D.

87
MCQmedium

An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?

A.Increase the control strength
B.Re-assess the risk and control effectiveness
C.Report to senior management
D.Accept the risk as residual
AnswerB

Re-assessing the risk and control effectiveness establishes whether the control was implemented as designed and whether residual risk was miscalculated. This diagnostic step must precede any further treatment decision, since the unchanged level may stem from poor implementation or an inaccurate original assessment.

Why this answer

When a control is implemented but the risk level remains unchanged, the risk manager must first re-assess the risk and control effectiveness to determine why the control failed to reduce the risk. This aligns with the CISM risk management process, which mandates that controls be evaluated for proper design and operation before any escalation or acceptance decisions are made. Without this re-assessment, the organization cannot know whether the control is misconfigured, insufficient, or simply not addressing the correct threat vector.

Exam trap

The trap here is that candidates mistakenly jump to 'increase control strength' (Option A) because they assume the control is simply too weak, rather than first verifying whether the control is actually functioning or correctly designed to address the specific risk.

How to eliminate wrong answers

Option A is wrong because increasing control strength without first understanding why the current control is ineffective could waste resources and may not address the root cause, such as a misconfiguration or incorrect threat model. Option C is wrong because reporting to senior management should occur only after the risk manager has performed a re-assessment and has a clear picture of the control failure and its implications. Option D is wrong because accepting the risk as residual is premature; the risk manager must first verify whether the control can be adjusted or replaced before deciding to accept an unchanged risk level.

88
MCQeasy

A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?

A.Accept the risk as it is already controlled
B.Evaluate the residual risk and decide on additional controls
C.Transfer the risk to a cyber insurance provider
D.Conduct another round of user awareness training
AnswerB

With spam filtering and awareness training already applied, the next step is evaluating residual risk and deciding whether additional controls are warranted. This satisfies the stem's constraint of determining what to do next to manage the phishing risk.

Why this answer

After implementing initial controls (spam filtering and user awareness training), the organization must evaluate the residual risk—the risk that remains after controls are applied. This step is required by the CISM risk management process to determine whether the residual risk level is acceptable or if additional controls are needed. Option B correctly follows the risk assessment lifecycle: identify risk, apply controls, assess residual risk, then decide on further action.

Exam trap

The trap here is that candidates assume existing controls are sufficient and jump to acceptance (Option A) or repeat training (Option D), without recognizing that the CISM process mandates a formal residual risk evaluation before any risk response decision.

How to eliminate wrong answers

Option A is wrong because accepting risk without evaluating residual risk violates the CISM risk management process; acceptance is only appropriate after confirming that residual risk is within the organization's risk appetite. Option C is wrong because transferring risk to a cyber insurance provider does not reduce the likelihood or impact of phishing attacks; it only provides financial compensation after a loss, and is not a next step before evaluating residual risk. Option D is wrong because conducting another round of user awareness training without first evaluating residual risk is premature; the effectiveness of the existing training must be measured to determine if additional training is necessary.

89
Drag & Dropmedium

Order the steps for implementing a data classification policy in an organization.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Data classification starts with defining categories, then procedures, training, labeling, and monitoring.

90
MCQeasy

An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?

A.Risk avoidance
B.Risk reduction
C.Risk acceptance
D.Risk transfer
AnswerC

Risk acceptance is appropriate because the mitigation cost exceeds the potential loss, making further controls economically unjustifiable. The organization formally acknowledges the residual risk and retains it, satisfying the stem's cost-benefit constraint. Senior management must approve this decision, and the risk should be monitored and reviewed periodically in case the inherent risk profile changes.

Why this answer

Risk acceptance is the appropriate treatment when the cost of mitigating a risk exceeds the potential loss it represents. In this scenario, since mitigation costs more than the expected loss, accepting the risk is the most economically justified and effective strategy. The organization consciously retains the risk and monitors it, rather than spending more to prevent it than the loss would cost.

Exam trap

CISM often tests the distinction between accepting a risk because it is cost-justified versus avoiding or transferring it, and candidates frequently default to 'mitigate' or 'transfer' without weighing the stated cost-versus-loss economics.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or process entirely to avoid the risk — this is typically more disruptive and costly than the loss itself, and may not be feasible for a critical business process. Option B is wrong because risk reduction (mitigation) involves implementing controls to lower the risk, which is exactly what the scenario says costs more than the potential loss, making it economically unjustified. Option D is wrong because risk transfer (e.g., insurance) shifts financial impact but does not eliminate the risk and may not be available or cost-effective for this specific exposure.

91
MCQmedium

An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerB

Risk acceptance is appropriate because the mitigation cost exceeds the potential loss, making transfer or avoidance economically unjustifiable. The manager formally acknowledges the residual risk, documents it, and retains it within the organisation's defined risk appetite, satisfying the cost-benefit constraint stated in the stem.

Why this answer

When the cost of mitigating a risk exceeds the potential loss, the most appropriate strategy is risk acceptance. This means the organization acknowledges the risk and decides to bear the potential loss, as the cost of mitigation is not justified. Risk acceptance is a valid treatment when the risk is within the organization's risk appetite.

Exam trap

CISM often tests the confusion between risk acceptance and risk mitigation, leading candidates to choose mitigation because the risk is high, without considering the cost-benefit analysis that makes acceptance the most appropriate strategy.

Why the other options are wrong

A

Mitigation cost exceeds potential loss, making it inefficient.

C

Transfer (e.g., insurance) may still be expensive; acceptance is more direct when cost of transfer also high.

D

Avoidance would mean discontinuing the activity, which may not be feasible or cost-effective.

92
MCQmedium

During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?

A.The impact of losing both primary and backup data is unacceptably high
B.The risk owner does not have authority to accept risks
C.Encryption is not required as the facility is secure
D.The cost of implementing encrypted offsite backups is minimal
AnswerA

Unencrypted onsite backups create correlated loss: a single physical event destroys primary and backup data together. That catastrophic availability and confidentiality impact outweighs the low likelihood the risk owner cites, so acceptance cannot be justified without encryption or offsite copies.

Why this answer

The core principle of risk acceptance requires that the residual risk be within the organization's risk appetite. In this scenario, the backup data is stored onsite without encryption, meaning a single physical breach (e.g., fire, theft, or natural disaster) could destroy both primary and backup data simultaneously. The impact of losing all data—potentially leading to business failure—is unacceptably high, outweighing the low likelihood of a physical breach.

The risk owner's acceptance is invalid because the risk exceeds the organization's risk tolerance, as per CISM's risk management framework.

Exam trap

A common misconception is that risk acceptance is always valid if the risk owner approves it. However, according to ISACA CISM principles, acceptance must align with the organization's risk appetite, and a high-impact risk cannot be accepted solely based on low likelihood.

How to eliminate wrong answers

Option B is wrong because the risk owner, typically a business process owner, generally has the authority to accept risks within their scope, unless explicitly restricted by policy; the question does not indicate such a restriction. Option C is wrong because it incorrectly assumes that a secure facility eliminates the need for encryption, but encryption is a critical control for data at rest to protect against unauthorized access even if physical security is breached (e.g., an insider threat or theft of storage media). Option D is wrong because the cost of implementing encrypted offsite backups is not the primary reason to challenge acceptance; risk acceptance decisions are based on risk appetite and impact, not solely on cost, and minimal cost does not automatically invalidate acceptance.

93
MCQeasy

A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?

A.Focus only on high and extreme risks
B.Use technical language to accurately describe vulnerabilities
C.Translate risk into potential financial impact
D.Present risk in qualitative terms only
AnswerC

Expressing risk as monetary exposure lets senior management weigh treatment costs against potential losses, directly supporting cost-benefit decisions. Qualitative labels alone rarely justify funding, whereas financial impact ties risk to the organisation's stated risk appetite and budget.

Why this answer

Translating risk into potential financial impact (Option C) is the best approach because it aligns risk with business objectives, enabling senior management to make cost-benefit decisions. Financial quantification, such as Annualized Loss Expectancy (ALE), provides a common language that executives understand, directly supporting informed decision-making on risk treatment options.

Exam trap

The trap here is that candidates may choose Option A (focusing only on high and extreme risks) because it seems efficient, but CISM emphasizes that risk communication must support informed decision-making across all risk levels, not just the most severe ones.

How to eliminate wrong answers

Option A is wrong because focusing only on high and extreme risks ignores residual risks and emerging threats, leading to incomplete risk posture visibility and potential blind spots in risk treatment. Option B is wrong because using technical language to describe vulnerabilities creates communication barriers with senior management, who need business-impact context rather than technical details. Option D is wrong because presenting risk in qualitative terms only (e.g., high/medium/low) lacks the precision needed for cost-benefit analysis, making it harder to prioritize investments and justify risk treatment decisions.

94
MCQeasy

An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?

A.Transfer the risk by purchasing cyber insurance and take no further action.
B.Accept the residual risk because existing controls already reduce it from high to medium.
C.Document the gap and recommend additional controls to bring residual risk within appetite.
D.Revise the risk appetite statement so that medium residual risk becomes acceptable.
AnswerC

When residual risk exceeds the defined appetite, the manager should document the deviation and propose treatment to close the gap. Recommending additional controls aligns the payment gateway with the organization's stated tolerance and gives leadership a clear decision point. This maintains the link between risk appetite, assessment results, and treatment planning, which is central to effective risk management.

Why this answer

Risk appetite defines the amount of risk the organization is willing to accept, and residual risk above that threshold requires treatment. The manager should document the deviation and recommend additional controls to reduce residual risk to a low level for the payment gateway, then present the options and costs to leadership for a decision consistent with governance.

Exam trap

The trap here is treating a reduction from high to medium as sufficient, when the defined appetite for payment card systems is low residual risk.

95
MCQeasy

A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?

A.Switch to a fully quantitative risk assessment methodology.
B.Use a hybrid approach that includes both qualitative and quantitative assessments.
C.Replace qualitative scales with precise monetary values.
D.Continue using qualitative method since it is simpler.
AnswerB

A hybrid approach keeps qualitative scales for rapid triage while adding quantitative values, such as monetary loss ranges or probabilities, that support cost-benefit and risk-appetite decisions. This closes the gap where qualitative ratings alone cannot feed quantitative analysis.

Why this answer

A hybrid approach (Option B) is most effective because it leverages qualitative scales for initial, rapid risk identification and prioritization, while quantitative data (e.g., ALE, SLE, ARO) provides the monetary rigor needed for cost-benefit analysis and management decisions. This aligns with ISACA's guidance that risk assessment should be tailored to the decision context, not purely one method.

Exam trap

The trap here is that candidates assume 'quantitative' is always superior, ignoring the practical need for a hybrid approach that balances qualitative speed with quantitative rigor for decision-making.

How to eliminate wrong answers

Option A is wrong because a fully quantitative methodology requires extensive historical data, precise probability estimates, and can be resource-prohibitive; it may also create a false sense of precision when data is uncertain. Option C is wrong because replacing qualitative scales with precise monetary values without a structured quantitative model (e.g., Monte Carlo simulation) ignores the inherent uncertainty in risk estimation and can lead to misleadingly exact figures. Option D is wrong because continuing with only qualitative methods fails to provide the objective monetary data required for decisions like insurance coverage or budget allocation, violating the CISM principle of aligning risk management with business needs.

96
MCQhard

A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?

A.Operational metrics such as number of firewalls and intrusion detection alerts
B.List of all past security incidents and their root causes
C.Detailed vulnerability scan results and patch levels
D.Summary of top risks, risk appetite alignment, and treatment status
AnswerD

Board members need aggregated top risks, explicit alignment with the stated risk appetite, and current treatment status to weigh strategic trade-offs. This satisfies the stem's requirement to support strategic risk-based decisions rather than operational detail or raw vulnerability listings.

Why this answer

The board requires strategic-level information to make risk-based decisions. Option D provides a summary of top risks, alignment with risk appetite, and treatment status, which directly supports strategic oversight. Operational details like firewall counts or patch levels are tactical and do not convey the business impact or risk posture needed for board-level decisions.

Exam trap

The trap here is that candidates confuse operational or technical details (like vulnerability scans or incident lists) with strategic risk information, failing to recognize that the board needs aggregated, business-aligned summaries to make informed decisions.

How to eliminate wrong answers

Option A is wrong because operational metrics such as number of firewalls and intrusion detection alerts are tactical, not strategic; they do not convey risk exposure or alignment with business objectives. Option B is wrong because a list of all past security incidents and root causes is historical and reactive, lacking forward-looking risk prioritization and treatment status. Option C is wrong because detailed vulnerability scan results and patch levels are technical and granular, overwhelming the board with data that does not summarize risk in business terms or show alignment with risk appetite.

97
MCQeasy

A retail company's risk committee is reviewing the annual risk assessment. The CISO notes that the organization's stated risk appetite for customer data confidentiality is low, but a business unit wants to launch a loyalty program that shares purchase history with a third-party analytics provider. Which of the following should the CISO do FIRST?

A.Approve the program because the third party has a strong security reputation.
B.Reject the program because any third-party data sharing exceeds a low risk appetite.
C.Perform a risk assessment of the proposed data sharing and compare the residual risk to the defined risk appetite.
D.Escalate the decision to the board of directors immediately.
AnswerC

The first step is to assess the risk introduced by sharing purchase history and determine whether residual risk falls within the low appetite for customer data confidentiality. This provides an objective basis for a recommendation or escalation. Only after assessment can the organization decide to accept, mitigate, transfer, or reject the initiative.

Why this answer

Risk decisions should begin with assessment. The CISO must evaluate the data-sharing risk and compare residual exposure to the organization's low confidentiality appetite before recommending acceptance, mitigation, or rejection. Approving on reputation, escalating without analysis, or rejecting categorically all skip the assessment step that makes the decision defensible.

Exam trap

The trap here is equating a low risk appetite with automatic rejection instead of requiring an assessment to determine residual risk.

98
MCQeasy

During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?

A.Mitigate by moving the backup server to a geographically separate location.
B.Transfer the risk by purchasing business interruption insurance.
C.Avoid the risk by discontinuing the backup process.
D.Accept the risk because the cost of mitigation is high.
AnswerA

Relocating the backup server to a geographically separate location removes the shared data-centre failure domain, so a site-wide incident cannot destroy both primary and backup copies simultaneously. This mitigation directly addresses the identified single point of failure, restoring recoverability.

Why this answer

Moving the backup server to a geographically separate location directly eliminates the single point of failure by ensuring that a localized disaster (e.g., fire, flood, power outage) at the primary data center does not simultaneously destroy both the primary and backup data. This is a classic risk mitigation strategy that reduces the likelihood and impact of data loss, aligning with the principle of geographic redundancy for disaster recovery.

Exam trap

The trap here is that candidates may confuse risk transfer (insurance) with risk mitigation (redundancy), or incorrectly assume that accepting the risk is acceptable when a clear, cost-effective mitigation exists, especially in a CISM scenario where the organization's risk appetite is not explicitly stated as high.

How to eliminate wrong answers

Option B is wrong because purchasing business interruption insurance transfers the financial risk of downtime but does not address the technical single point of failure; the backup data remains vulnerable to the same physical disaster as the primary server. Option C is wrong because discontinuing the backup process would avoid the risk of backup failure but introduces an unacceptable risk of permanent data loss, violating fundamental data protection and business continuity requirements. Option D is wrong because accepting the risk without justification is inappropriate when a cost-effective mitigation (moving the backup server) is available; the cost of mitigation is not inherently high, and the risk of total data loss typically outweighs the expense of geographic separation.

99
MCQmedium

A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?

A.Conduct a country risk assessment to identify threats and vulnerabilities specific to the region.
B.Implement a redundant data center in a stable region to ensure business continuity.
C.Accept the risk because the expansion is a strategic business decision.
D.Purchase political risk insurance to transfer the potential financial losses.
AnswerA

A country risk assessment is the foundational step to understand the geopolitical, regulatory, and physical security risks of operating in a new region. It identifies threats such as political instability, legal changes, and infrastructure reliability. This assessment provides the necessary context for the board to make an informed decision. Without it, any risk treatment or transfer decision would lack a factual basis and could expose the organization to unforeseen losses.

Why this answer

The correct first step is to conduct a country risk assessment. This provides the necessary information about the specific threats and vulnerabilities of operating in that region, enabling the board to make an informed decision. Other options like insurance, redundancy, or acceptance are all risk treatment strategies that should only be considered after the risk has been properly assessed and evaluated against the organization's risk appetite.

Exam trap

The trap here is assuming that risk treatment (insurance, redundancy, acceptance) should be initiated before a formal risk assessment is completed.

100
MCQeasy

A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?

A.Requiring the vendor to sign a non-disclosure agreement
B.Conducting a due diligence assessment before contracting
C.Performing a vulnerability scan of the vendor's network
D.Including a clause that transfers liability to the vendor
AnswerB

Due diligence before contracting identifies the vendor's security controls, data handling practises and compliance posture, allowing risks to be assessed and mitigated through contract terms before any customer data is shared. This satisfies the stem's requirement to manage risk at the earliest point, when the company still retains leverage to reject or renegotiate the engagement.

Why this answer

Conducting a due diligence assessment before contracting is the most critical step because it establishes whether the vendor has adequate security controls, compliance posture, and risk management practices before any data is shared. Without this upfront evaluation, contractual clauses and technical scans are built on an unknown foundation. Due diligence informs the entire vendor risk management lifecycle, including contract terms and ongoing monitoring.

Exam trap

The trap is choosing a contractual or technical control (NDA, liability clause, scan) as the 'most critical' step, when CISM consistently emphasizes that understanding the risk through due diligence must come first.

How to eliminate wrong answers

Option A is wrong because an NDA only protects confidentiality of information; it does not assess or mitigate the vendor's security and operational risks. Option C is wrong because a vulnerability scan of the vendor's network is typically not permitted without consent and provides only a point-in-time technical view, not a holistic risk assessment. Option D is wrong because liability transfer clauses are contractual risk-shifting mechanisms that do not reduce the actual likelihood or impact of a breach — and they are often unenforceable or insufficient when the vendor fails.

101
MCQmedium

A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?

A.Qualitative analysis using structured scenario ranking with defined likelihood and impact scales.
B.A control self-assessment survey completed by the mobile development team.
C.A penetration test of the mobile application to identify exploitable vulnerabilities.
D.Quantitative analysis using annualized loss expectancy derived from actuarial tables.
AnswerA

Qualitative analysis with defined scales is appropriate when historical data is scarce, because it leverages expert judgment in a structured, repeatable way. Ranking scenarios by likelihood and impact gives leadership a defensible prioritization of threats and supports budget decisions. It can later be refined with quantitative data as the feature matures and incident information accumulates.

Why this answer

When historical loss data is scarce, a structured qualitative analysis using consistent likelihood and impact scales lets the organization rank threats defensibly and allocate budget. It relies on expert judgment but remains repeatable and auditable, and it can transition to quantitative methods as actual incident and loss data become available for the new feature.

Exam trap

The trap here is assuming quantitative analysis is always superior, when weak or missing data can make qualitative ranking more defensible for a new service.

102
Multi-Selectmedium

Which THREE of the following are typical steps in a qualitative risk assessment?

Select 3 answers
A.Estimate likelihood and impact using rating scales
B.Prioritize risks based on risk ratings
C.Identify assets and threats
D.Calculate annualized loss expectancy (ALE)
E.Assign monetary values to impact
AnswersA, B, C

Qualitative risk assessment ranks threats using ordinal rating scales — such as low, medium or high — rather than monetary values. Estimating likelihood and impact this way satisfies the stem's requirement for a typical qualitative step, since it relies on expert judgement and descriptive rankings instead of the quantitative annualised loss figures used in quantitative analysis.

Why this answer

Option C is correct because identifying assets and threats is the foundational step of any risk assessment, including qualitative ones, since you must know what you are protecting and what could harm it before evaluating risk. Option A is correct because qualitative risk assessment characteristically uses subjective rating scales (such as High/Medium/Low or 1–5) to estimate likelihood and impact rather than numeric monetary values. Option B is correct because once risks are rated on those scales, the results are used to prioritize risks so that the highest-rated risks receive attention first.

Option D is not correct because calculating annualized loss expectancy (ALE = SLE × ARO) is a quantitative technique requiring monetary figures. Option E is not correct because assigning monetary values to impact is also a quantitative step, whereas qualitative assessment relies on descriptive or ordinal ratings.

Exam trap

The trap here is that candidates confuse qualitative and quantitative risk assessment steps, mistakenly selecting ALE or monetary assignment as part of qualitative analysis because they recall 'risk calculation' without distinguishing the method.

103
MCQmedium

A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?

A.The organization has no compensating controls in place
B.The cost to mitigate is higher than the potential financial loss from a breach
C.The risk is within the organization's risk appetite but the business impact is high
D.The vendor has a history of security incidents
AnswerB

Acceptance is justified when the mitigation cost exceeds the expected financial loss, since spending more than the exposure removes value. This economic comparison satisfies the stem's condition, provided the risk owner formally documents and monitors the retained risk.

Why this answer

Risk acceptance is justified when the cost of mitigation exceeds the potential financial loss from a breach. This aligns with the cost-benefit analysis principle in risk management: if the cost to implement controls (e.g., migrating to a more secure vendor or adding encryption) is higher than the expected loss (e.g., $50,000 in breach costs vs. $100,000 in mitigation), accepting the residual risk is economically rational. The decision must still ensure the risk is within the organization's risk appetite.

Exam trap

The trap here is that candidates often confuse risk acceptance with ignoring the risk, but CISM requires that acceptance be a deliberate, documented decision based on cost-benefit analysis, not merely a default when no controls exist.

How to eliminate wrong answers

Option A is wrong because having no compensating controls means the risk is entirely unmitigated, which would typically require avoidance or transfer, not acceptance, as acceptance still assumes some level of control or tolerance. Option C is wrong because a high business impact contradicts risk acceptance; even if the risk is within risk appetite, high impact usually demands mitigation or transfer to reduce potential damage. Option D is wrong because a vendor with a history of security incidents increases the likelihood of a breach, making acceptance imprudent unless the cost of mitigation is prohibitive and the risk is formally documented as accepted.

104
MCQhard

An information security manager is reviewing the organization's risk register and notices that a risk related to unpatched software has been assigned a risk score of 9 (on a scale of 1-10) with a note that the risk is 'accepted' because patching would disrupt a critical production system. Which of the following should the manager do NEXT?

A.Verify that the risk acceptance is documented and approved by the appropriate business owner.
B.Immediately implement a compensating control such as network segmentation to reduce the risk.
C.Update the risk register to reflect that the risk is mitigated by the acceptance decision.
D.Escalate the risk to the board of directors because a score of 9 is unacceptable.
AnswerA

Risk acceptance must be formally documented and approved by the business owner who has the authority to accept the risk on behalf of the organization. The information security manager should verify that this process was followed. If not, the acceptance is invalid and the risk remains unmanaged. This ensures accountability and alignment with the organization's risk appetite. The manager should not unilaterally change the risk treatment without proper authority.

Why this answer

The next step is to verify that the risk acceptance is properly documented and approved by the business owner. Risk acceptance is a formal process that requires accountability. If the acceptance is not valid, the manager can then take appropriate action, such as proposing compensating controls or escalating.

Verifying the process ensures that the organization's risk governance is upheld and that the decision to accept the risk was made at the correct level.

Exam trap

The trap here is assuming that a high risk score automatically warrants escalation or immediate mitigation, without first confirming that the risk acceptance was properly authorized.

105
Multi-Selectmedium

Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)

Select 3 answers
A.Risk elimination
B.Risk transfer (sharing)
C.Risk avoidance
D.Risk mitigation (reduction)
E.Risk deferral
AnswersB, C, D

Risk transfer (sharing) is an ISO 31000 treatment that shifts the financial impact of a threat to a third party, such as through insurance or outsourcing contracts. The organisation retains accountability, so it satisfies the stem's requirement for a valid treatment option.

Why this answer

According to ISO 31000, risk treatment options include avoiding the risk (Option C), which means deciding not to start or continue the activity that gives rise to the risk, thereby removing the exposure entirely. Option B, risk transfer (sharing), is also valid because it involves sharing the risk with another party, such as through insurance or contractual arrangements, while retaining some residual risk. Option D, risk mitigation (reduction), is correct because ISO 31000 recognizes modifying the likelihood and/or consequence of the risk to reduce it to an acceptable level.

Option A, risk elimination, is not one of the standard ISO 31000 treatment categories; while avoidance can eliminate exposure, 'elimination' is not the named treatment option. Option E, risk deferral, is not a recognized ISO 31000 risk treatment option, as postponing a risk does not by itself treat it and ISO 31000 does not list deferral among its treatment choices.

Exam trap

ISACA often tests the distinction between 'risk elimination' and 'risk avoidance' to trap candidates who confuse the two, as elimination implies complete removal of the risk source, which is rarely achievable in information security, while avoidance means not engaging in the risky activity at all.

106
Multi-Selectmedium

Which of the following are key components of an Information Security Risk Management program? (Select TWO.)

Select 2 answers
A.Establishing a risk management framework
B.Conducting vulnerability scanning
C.Performing risk assessment and treatment
D.Performing internal audits
AnswersA, C

Why this answer

A is correct because establishing a risk management framework is the foundational component of an Information Security Risk Management program. It defines the policies, procedures, and governance structure for identifying, assessing, and treating risks, aligning with standards like ISO 31000 or NIST SP 800-39. Without a framework, risk management activities lack consistency and accountability.

Exam trap

The trap here is that candidates confuse operational security activities (like vulnerability scanning or internal audits) with the strategic components of a risk management program, which are the framework and the risk assessment/treatment cycle.

Why the other options are wrong

B

Vulnerability scanning is a technical control, not a program component.

D

Audit is independent assurance, not part of the risk management program itself.

107
Matchingmedium

Match each business continuity term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Maximum time to restore a process after disruption

Maximum age of data that must be recovered

Plan to maintain business functions during disruption

Plan to restore IT infrastructure after disaster

Process to identify critical functions and dependencies

Why these pairings

Correct matches: A-BCP, B-DRP, C-BIA. Common confusions: MTD is about downtime, RPO is about data loss.

108
MCQmedium

Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?

A.To ensure compliance with regulatory requirements
B.To provide a consistent risk reporting structure across the enterprise
C.To support informed decision-making by aligning security risks with business objectives
D.To reduce the cost of risk management through shared resources
AnswerC

Embedding security risk within enterprise risk management lets leadership compare cyber exposure against strategic, financial and operational risks using one appetite statement. Security decisions then reflect business objectives rather than sitting in a separate silo, satisfying the need for informed, prioritised investment.

Why this answer

The primary purpose of integrating information security risk management into ERM is to enable informed decision-making by ensuring security risks are evaluated in the same language and context as business, financial, and operational risks. This alignment lets leadership prioritize investments and accept or mitigate risks based on their impact on business objectives, not in isolation. CISM emphasizes that security exists to support the business, so alignment with business objectives is the fundamental driver.

Exam trap

The trap is selecting compliance or reporting as the primary reason because they are visible, tangible outcomes — CISM consistently tests whether candidates understand that business alignment and informed decision-making, not compliance checkboxes, are the foundational purpose of risk integration.

Why the other options are wrong

A

Compliance is a benefit but not the primary reason; integration is about strategic alignment.

B

Consistent reporting is a result of integration, not the primary reason.

D

Cost reduction is a potential benefit but not the primary strategic reason.

109
MCQhard

A global retailer operates point-of-sale systems in 12 countries. The risk register shows a single entry titled 'Payment card data breach' with a likelihood of 4 and an impact of 5. A new CISO argues this entry is too coarse to support treatment decisions. Which action BEST improves the usefulness of the risk register for decision-making?

A.Transfer the risk to a cyber insurance policy and remove it from the active risk register.
B.Decompose the entry into distinct risk scenarios mapped to specific threat events, assets, and existing controls.
C.Replace the numeric likelihood and impact scores with a simple high, medium, or low qualitative rating.
D.Increase the impact rating to 5 and add a note that the risk is critical to the business.
AnswerB

A single aggregated risk cannot be treated because different scenarios within it call for different controls, owners, and funding. Breaking the entry into discrete scenarios such as memory-scraping malware at the POS terminal, third-party payment processor compromise, or insider skimming ties each to its own likelihood, impact, and control set. This granularity lets management compare treatment options and assign accountability, which is exactly what the register is meant to support.

Why this answer

Risk registers support decisions only when entries describe discrete scenarios that can be individually assessed, owned, and treated. Splitting an aggregated payment card breach entry into specific threat-asset-control combinations enables targeted control selection, meaningful residual scoring, and clear accountability. Merely re-scoring, downgrading to qualitative labels, or transferring to insurance leaves the underlying analytical deficiency untouched.

Exam trap

The trap here is treating a risk register as a scoring exercise, when its real value comes from decomposing broad categories into specific scenarios that can each be treated and monitored.

110
MCQmedium

A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?

A.The organization will mitigate all risks to a low level
B.The organization will not invest in high-risk projects
C.The organization accepts no level of risk
D.The organization will accept up to $5M in potential loss for operational risks
AnswerD

A quantified monetary threshold states risk appetite measurably, letting the institution compare exposures against a defined tolerance. Qualitative statements cannot be tested, whereas a $5M operational loss limit gives governance a clear boundary for accepting or escalating risk.

Why this answer

A risk appetite statement for a financial institution must be quantifiable and specific to operational risk, aligning with regulatory frameworks like Basel III which require explicit loss thresholds. Stating a maximum acceptable loss of $5M provides a clear, measurable boundary for risk-taking decisions, enabling the board and management to balance risk and reward effectively.

Exam trap

The trap here is that candidates confuse risk appetite (the amount of risk accepted) with risk tolerance (the acceptable variation around that appetite) or risk avoidance, leading them to choose absolute statements like 'no risk' or 'low risk' instead of a quantifiable, business-aligned threshold.

How to eliminate wrong answers

Option A is wrong because 'mitigate all risks to a low level' implies a zero-risk posture that is impractical and costly; financial institutions must accept some risk to generate returns, and this statement lacks the quantifiable threshold needed for risk appetite. Option B is wrong because 'will not invest in high-risk projects' is too vague and absolute, ignoring that high-risk projects may be necessary for competitive advantage and can be managed within defined limits; it also fails to specify what constitutes 'high-risk' in measurable terms. Option C is wrong because 'accepts no level of risk' is unrealistic for any financial institution, as all operations carry inherent risk (e.g., credit risk, market risk), and such a statement would paralyze business activities and violate regulatory expectations for risk-based capital management.

111
Multi-Selecteasy

Which TWO of the following are risk treatment strategies as defined in ISO 27005?

Select 2 answers
A.Risk analysis
B.Risk monitoring
C.Risk avoidance
D.Risk transfer
E.Risk communication
AnswersC, D

Risk avoidance eliminates the activity or asset that generates the risk entirely, removing the exposure rather than reducing or sharing it. ISO 27005 lists it alongside mitigation, transfer and retention as a distinct treatment strategy, satisfying the stem's definition.

Why this answer

Risk avoidance (C) is a valid ISO 27005 risk treatment strategy in which the organization eliminates the activity or condition that gives rise to the risk, thereby removing the exposure entirely. Risk transfer (D) is also a valid treatment strategy, where the risk is shared with or shifted to another party, such as through insurance or contractual agreements, while the organization retains ultimate accountability. These two belong to the ISO 27005 treatment options that also include risk modification/reduction and risk retention.

Risk analysis (A) is part of the risk assessment process, not a treatment strategy, as it identifies and evaluates risks. Risk monitoring (B) is an ongoing review and surveillance activity within the risk management process, not a treatment choice. Risk communication (E) is a supporting process for exchanging risk information among stakeholders, not a treatment strategy itself.

Exam trap

The trap here is that candidates confuse the risk management process steps (like risk analysis, monitoring, and communication) with the specific risk treatment strategies defined in ISO 27005, leading them to select options that are activities rather than treatment methods.

112
Multi-Selectmedium

Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)

Select 2 answers
A.Risk avoidance
B.Risk measurement
C.Risk identification
D.Risk communication
E.Risk retention
AnswersA, E

Risk avoidance eliminates the activity or exposure generating the risk entirely, so the threat no longer applies. ISO 31000 lists it alongside modification, sharing and retention as a treatment option, and it suits risks whose residual exposure exceeds tolerance.

Why this answer

According to ISO 31000, risk treatment options include avoiding the risk by deciding not to start or continue the activity that gives rise to it, which is why option A (Risk avoidance) is correct. ISO 31000 also recognizes retaining the risk by informed decision, which is option E (Risk retention), as a valid treatment option when the risk is accepted and no further action is taken. Options B (Risk measurement), C (Risk identification), and D (Risk communication) are not treatment options; they are elements of the risk assessment and communication processes within the ISO 31000 framework, not ways of modifying risk.

Exam trap

The trap here is that candidates confuse the steps of the risk management process (identification, analysis, evaluation, communication) with the specific treatment options, leading them to select risk measurement or risk identification as valid treatments.

113
MCQhard

A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?

A.Risk appetite and tolerance are interchangeable terms
B.Risk appetite is set by regulatory bodies; tolerance is set by the board
C.Risk appetite is the specific limit for each risk; tolerance is the overall willingness to accept risk
D.Risk appetite is the general approach to risk; tolerance defines acceptable variation in performance
AnswerD

Risk appetite sets the broad amount and type of risk the organisation is willing to pursue, while risk tolerance defines the acceptable variation around that target before escalation. This satisfies the stem's product-line scenario: appetite guides the general approach, tolerance bounds permissible performance deviation.

Why this answer

Risk appetite is the broad, high-level amount of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance translates that appetite into specific, measurable boundaries for individual risks. Option D correctly captures this relationship: appetite is the general approach, and tolerance defines the acceptable variation in performance metrics (e.g., a 5% deviation in revenue targets). This distinction is critical for aligning risk management with business strategy in information security risk management.

Exam trap

The trap here is that candidates often confuse the scope of the two terms, mistakenly thinking risk tolerance is the broader concept (Option C) or that they are synonymous (Option A), when in fact risk appetite is the overarching philosophy and tolerance is the specific, measurable boundary.

How to eliminate wrong answers

Option A is wrong because risk appetite and risk tolerance are not interchangeable; appetite is the overall willingness to accept risk, whereas tolerance is the specific, quantifiable limits applied to individual risks. Option B is wrong because risk appetite is set by the board of directors, not regulatory bodies; regulatory bodies may impose constraints, but appetite is an internal strategic decision. Option C is wrong because it reverses the definitions: risk tolerance is the specific limit for each risk, and risk appetite is the overall willingness to accept risk, not the other way around.

114
Multi-Selectmedium

An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)

Select 2 answers
A.The likelihood and impact ratings used to determine the risk level.
B.A named risk owner accountable for treatment decisions.
C.The complete network diagram of the data center hosting the asset.
D.The specific antivirus product version deployed on affected endpoints.
E.The names of every employee who has access to the affected system.
AnswersA, B

Likelihood and impact ratings are core to any risk entry because they establish the risk level used for prioritization and comparison across the register. Without these ratings, the organization cannot consistently rank risks or track whether treatment reduces exposure over time. They also connect the entry to the risk analysis methodology and the organization's defined risk criteria.

Why this answer

A risk register entry must identify who owns the risk and how severe it is. The named owner provides accountability for treatment and reporting, while likelihood and impact ratings establish the risk level that drives prioritization. Supporting details such as product versions, access lists, and network diagrams live in other repositories and should be referenced rather than embedded in the register.

Exam trap

The trap here is treating the risk register as a catch-all repository for technical inventories, when ownership and likelihood and impact ratings are the essential governance elements of each entry.

115
MCQmedium

A global insurance provider has just completed a quantitative risk assessment for a new claims-processing application. The assessment used the Annualized Loss Expectancy (ALE) formula and produced an ALE of $850,000 for the risk of a data breach. The vendor's proposed control has an Annualized Cost of the Safeguard (ACS) of $300,000 and a projected risk reduction of 60%. The CISO asks the information security manager to determine the cost-benefit of implementing this control. What is the net benefit (or loss) of the control?

A.$210,000 net benefit
B.$510,000 net benefit
C.$340,000 net benefit
D.$550,000 net loss
AnswerA

The control reduces ALE by 60%, so the mitigated ALE is $850,000 × 40% = $340,000. The risk reduction value is $850,000 − $340,000 = $510,000. Subtracting the ACS of $300,000 yields a net benefit of $210,000. This is the correct calculation of value delivered after control cost.

Why this answer

The control reduces the ALE by 60%, leaving a residual ALE of $340,000. The value of that reduction is $510,000. After deducting the $300,000 annual safeguard cost, the net benefit is $210,000.

This demonstrates a positive return and supports implementing the control, provided the quantitative assumptions are validated and the risk remains within tolerance.

Exam trap

The trap here is confusing residual ALE or gross risk reduction with net benefit, and omitting the ACS from the calculation.

116
MCQeasy

Which of the following best describes the difference between risk appetite and risk tolerance?

A.Risk appetite is the maximum risk tolerance
B.Risk tolerance is the total risk, and risk appetite is the residual risk
C.Risk appetite is the amount of risk an organization is willing to accept, while risk tolerance is the acceptable variation around that appetite for specific objectives
D.Risk appetite is qualitative, and risk tolerance is quantitative
AnswerC

Risk appetite sets the aggregate level of risk the organisation chooses to pursue, whereas risk tolerance defines the acceptable deviation from that level for specific objectives. The distinction is scope: appetite is enterprise-wide and directional, tolerance is objective-specific and bounded.

Why this answer

Ly distinguishes risk appetite as the broad, strategic level of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance is the specific, measurable deviation allowed from that appetite for individual objectives or risks. This aligns with the ISACA CISM Review Manual, which defines risk appetite as the 'amount of risk an entity is willing to accept in pursuit of its mission' and risk tolerance as the 'acceptable level of variation relative to the achievement of objectives.' Understanding this distinction is critical for establishing proper risk management thresholds and ensuring that security controls are aligned with business goals.

Exam trap

The trap here is that candidates confuse risk appetite with risk tolerance by assuming they are synonyms or that one is a subset of the other in a purely quantitative sense, when in fact appetite is the strategic boundary and tolerance is the tactical wiggle room within that boundary for specific objectives.

How to eliminate wrong answers

Option A is wrong because risk appetite is not the maximum risk tolerance; rather, risk appetite sets the overall boundary, and risk tolerance defines the acceptable variance within that boundary for specific objectives. Option B is wrong because risk tolerance is not the total risk, nor is risk appetite the residual risk; residual risk is the risk remaining after controls are applied, which is a separate concept from both appetite and tolerance. Option D is wrong because both risk appetite and risk tolerance can be expressed in qualitative or quantitative terms; the distinction is not based on measurement type but on scope and specificity.

117
MCQhard

A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?

A.Develop and communicate a revised risk appetite statement approved by the board
B.Outsource all information security operations to a managed service provider
C.Immediately deploy a suite of technical security controls
D.Recommend the termination of the CEO for previous risk decisions
AnswerA

A board-approved risk appetite statement directly constrains the CEO's override behaviour by formalising the tolerance level the board demands, satisfying the contractual obligation to protect customer data. Because the CEO currently sets appetite unilaterally, board endorsement shifts authority and gives the risk manager documented backing to challenge launches exceeding agreed thresholds.

Why this answer

Developing and communicating a revised risk appetite statement approved by the board directly addresses the need to formalize risk management and change the risk culture. It provides clear guidance for decision-making, aligns with the board's demands, and respects the startup's limited resources by focusing on policy first. Other options are premature: deploying technical controls without policy support may be ineffective, outsourcing does not change internal culture, and terminating the CEO is an HR action that does not establish a risk program.

118
MCQhard

A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?

A.Transfer the risk to cloud providers by renegotiating contracts to include liability clauses.
B.Develop and enforce cloud security baseline standards and conduct regular compliance audits.
C.Implement a cloud access security broker (CASB) to monitor all cloud activities centrally.
D.Accept the risk as inherent to cloud adoption and focus resources on incident response.
AnswerB

Baseline standards translate the shared responsibility model into enforceable configuration requirements, and compliance audits verify consistent application across every region. This directly addresses the misconfiguration root cause and the inconsistent control the CISO must eliminate.

Why this answer

Developing and enforcing cloud security baseline standards with regular compliance audits directly addresses the root cause: inconsistent controls and misconfigurations across regions. This proactive risk management approach ensures all business units adhere to a unified security posture, reducing the likelihood of data exposure incidents. It aligns with the CISM domain of risk management and control.

Exam trap

The trap is selecting a technical tool (CASB) or contractual transfer as a silver bullet, when the question emphasizes consistent controls and audits across regions—a governance and compliance approach.

How to eliminate wrong answers

Option A is wrong because transferring risk via contract clauses does not eliminate the organization's responsibility for misconfigurations under the shared responsibility model; the cloud provider cannot secure customer-configured resources. Option C is wrong because a CASB monitors cloud activity but does not enforce consistent configuration baselines or remediate misconfigurations; it is a detective, not a preventive, control for this issue. Option D is wrong because accepting the risk and focusing on incident response is a reactive approach that does not reduce the likelihood of future incidents, which is the CISO's goal.

119
MCQmedium

A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?

A.Avoid the risk by discontinuing the process
B.Transfer the risk through insurance
C.Implement the control
D.Accept the risk
AnswerC

The control costs $100,000 annually against a $500,000 expected annual loss, a five-to-one return, so it reduces exposure far more cheaply than bearing it. Implementing the control is justified because the avoided loss substantially exceeds the mitigation spend.

Why this answer

The control reduces the annualized loss expectancy (ALE) from $500,000 to a much lower value (since likelihood drops from high to low). The annual cost of the control is $100,000, which is significantly less than the $500,000 expected loss without it. Implementing the control provides a positive return on investment (ROI) and is the most cost-effective risk mitigation strategy.

Exam trap

The trap here is that candidates may incorrectly assume that any control costing $100,000 is too expensive, failing to perform a proper cost-benefit comparison against the $500,000 expected loss, or they may confuse risk reduction with risk transfer or avoidance without evaluating financial justification.

How to eliminate wrong answers

Option A is wrong because avoiding the risk by discontinuing the process would eliminate the business benefit entirely, which is an extreme measure not justified when a cost-effective control exists. Option B is wrong because transferring the risk through insurance would still involve paying premiums (likely exceeding $100,000 annually) and does not reduce the likelihood of the threat; it only shifts financial impact. Option D is wrong because accepting the risk would mean tolerating an expected annual loss of $500,000, which is far greater than the $100,000 cost of the control, making it financially imprudent.

120
MCQhard

A healthcare organization is conducting a risk assessment for a new telehealth platform that will process protected health information. The assessment team proposes using a qualitative approach because of tight deadlines. Which of the following is the MOST significant limitation of relying solely on qualitative risk assessment for this initiative?

A.It takes significantly longer to complete than a quantitative assessment
B.It cannot incorporate input from clinical staff who understand patient workflows
C.It requires specialized statistical software that the organization may not have licensed
D.It may produce inconsistent ratings that are difficult to compare across systems or justify to regulators
AnswerD

Qualitative risk assessments use descriptive scales such as high, medium, and low, which depend on subjective judgment and can vary between assessors and sessions. This makes it hard to compare risks across different systems consistently or to provide quantitative evidence to regulators. For a telehealth platform handling protected health information, defensible and repeatable risk prioritization is critical, so this limitation is the most significant.

Why this answer

Qualitative risk assessment relies on subjective judgment and descriptive scales, which can lead to inconsistent ratings across assessors and make it difficult to compare risks or provide defensible evidence to regulators. For a telehealth platform processing protected health information, the organization needs consistent, auditable risk prioritization, so the lack of repeatability and comparability is the most significant limitation.

Exam trap

The trap here is confusing the speed advantage of qualitative assessment with its analytical limitations, when the real issue is subjectivity and lack of comparability.

121
Multi-Selecthard

A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)

Select 2 answers
A.Delegate full authority for risk acceptance to the subsidiary's local management without oversight.
B.Allow the subsidiary to retain its existing risk assessment templates to preserve continuity with prior years.
C.Require the subsidiary to use the parent company's approved risk assessment methodology, scales, and scoring criteria.
D.Instruct the subsidiary to report only risks that exceed the enterprise risk appetite threshold.
E.Perform independent validation of a sample of the subsidiary's assessments by the parent company's security team.
AnswersC, E

Consistent methodology is foundational to comparability and reliability. When the subsidiary scores likelihood and impact using the parent's defined scales and criteria, its outputs can be aggregated, trended, and compared against enterprise appetite without translation errors. Divergent methodologies produce ratings that look comparable numerically but rest on different assumptions, which silently corrupts enterprise-level reporting and prioritization decisions.

Why this answer

Reliability of subsidiary risk data rests on two pillars: a common methodology so outputs are comparable, and independent validation so the process is actually followed and conclusions are evidence-based. Filtering reported risks, retaining divergent templates, and delegating acceptance without oversight each undermine one or both pillars, leaving the parent unable to trust or aggregate subsidiary assessments.

Exam trap

The trap here is assuming that post-acquisition integration is mainly about collecting risk lists, when reliable assurance requires both standardized methodology and independent validation of the subsidiary's work.

122
MCQhard

An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?

A.Accept the risk due to low likelihood
B.Avoid the risk by discontinuing the activity that generates it
C.Transfer the risk through insurance
D.Mitigate the risk by implementing controls to reduce impact
AnswerD

Low likelihood with very high impact exceeds a moderate appetite because the potential consequence is severe. Reducing impact through controls lowers the residual severity to an acceptable level, whereas acceptance or transfer would leave the organisation exposed.

Why this answer

ISO 31000's risk evaluation phase requires aligning treatment decisions with the organization's risk appetite. With a moderate risk appetite, a low-likelihood but very-high-impact risk cannot simply be accepted (as it exceeds appetite), nor is avoidance necessary since the likelihood is low. Mitigation through controls that reduce the impact is the most balanced approach, bringing the residual risk within the moderate appetite threshold.

Exam trap

The trap here is that candidates mistakenly equate low likelihood with low overall risk, leading them to choose acceptance (Option A), but CISM tests that risk appetite must be explicitly considered—a very high impact can still exceed appetite even if likelihood is low.

How to eliminate wrong answers

Option A is wrong because accepting a risk with very high impact, even if low likelihood, violates a moderate risk appetite—acceptance is only appropriate when residual risk falls within appetite, which it does not here. Option B is wrong because avoidance (discontinuing the activity) is a drastic measure typically reserved for risks that exceed appetite and cannot be cost-effectively mitigated; here, the low likelihood does not warrant complete cessation. Option C is wrong because transferring risk via insurance does not reduce the impact or likelihood—it only shifts financial consequences, and the organization still retains operational and reputational impact, which may still exceed its moderate risk appetite.

← PreviousPage 2 of 2 · 122 questions total

Ready to test yourself?

Try a timed practice session using only Cism Risk Management questions.