Courseiva

CCNA Cism Risk Management Questions

22 of 97 questions · Page 2/2 · Cism Risk Management topic · Answers revealed

76
MCQeasy

A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?

A.Requiring the vendor to sign a non-disclosure agreement
B.Conducting a due diligence assessment before contracting
C.Performing a vulnerability scan of the vendor's network
D.Including a clause that transfers liability to the vendor
AnswerB

Pre-contract due diligence is the most critical to identify and mitigate risks early.

Why this answer

Conducting due diligence before contracting is essential to identify risks and ensure the vendor meets security requirements. Vulnerability scans are part of due diligence but not the most critical step. NDA and liability clauses are important but secondary to initial assessment.

77
Multi-Selectmedium

Which THREE of the following are typical steps in a qualitative risk assessment?

Select 3 answers
A.Estimate likelihood and impact using rating scales
B.Prioritize risks based on risk ratings
C.Identify assets and threats
D.Calculate annualized loss expectancy (ALE)
E.Assign monetary values to impact
AnswersA, B, C

Rating scales (e.g., 1-5) are qualitative.

Why this answer

Qualitative risk assessment uses ordinal rating scales (e.g., 1-5 or Low-Medium-High) to estimate likelihood and impact based on expert judgment, not precise numerical values. This approach is standard in frameworks like ISO 27005 and NIST SP 800-30, which define qualitative analysis as relying on subjective categorization rather than hard financial data.

Exam trap

The trap here is that candidates confuse qualitative and quantitative risk assessment steps, mistakenly selecting ALE or monetary assignment as part of qualitative analysis because they recall 'risk calculation' without distinguishing the method.

78
MCQmedium

A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?

A.The organization has no compensating controls in place
B.The cost to mitigate is higher than the potential financial loss from a breach
C.The risk is within the organization's risk appetite but the business impact is high
D.The vendor has a history of security incidents
AnswerB

If mitigation costs outweigh the expected loss, acceptance is a sound business decision.

Why this answer

Risk acceptance is justified when the cost of mitigation exceeds the potential financial loss from a breach. This aligns with the cost-benefit analysis principle in risk management: if the cost to implement controls (e.g., migrating to a more secure vendor or adding encryption) is higher than the expected loss (e.g., $50,000 in breach costs vs. $100,000 in mitigation), accepting the residual risk is economically rational. The decision must still ensure the risk is within the organization's risk appetite.

Exam trap

The trap here is that candidates often confuse risk acceptance with ignoring the risk, but CISM requires that acceptance be a deliberate, documented decision based on cost-benefit analysis, not merely a default when no controls exist.

How to eliminate wrong answers

Option A is wrong because having no compensating controls means the risk is entirely unmitigated, which would typically require avoidance or transfer, not acceptance, as acceptance still assumes some level of control or tolerance. Option C is wrong because a high business impact contradicts risk acceptance; even if the risk is within risk appetite, high impact usually demands mitigation or transfer to reduce potential damage. Option D is wrong because a vendor with a history of security incidents increases the likelihood of a breach, making acceptance imprudent unless the cost of mitigation is prohibitive and the risk is formally documented as accepted.

79
Multi-Selectmedium

Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)

Select 3 answers
A.Risk elimination
B.Risk transfer (sharing)
C.Risk avoidance
D.Risk mitigation (reduction)
E.Risk deferral
AnswersB, C, D

Transfer involves sharing risk with another party, e.g., insurance.

Why this answer

ISO 31000 defines risk transfer (sharing) as a valid risk treatment option, where the risk is shifted to another party, such as through insurance or outsourcing. This is a standard approach in information security risk management to reduce the financial impact of a risk event.

Exam trap

ISACA often tests the distinction between 'risk elimination' and 'risk avoidance' to trap candidates who confuse the two, as elimination implies complete removal of the risk source, which is rarely achievable in information security, while avoidance means not engaging in the risky activity at all.

80
Multi-Selectmedium

Which of the following are key components of an Information Security Risk Management program? (Select TWO.)

Select 2 answers
A.Establishing a risk management framework
B.Conducting vulnerability scanning
C.Performing risk assessment and treatment
D.Performing internal audits
AnswersA, C

Why this answer

A is correct because establishing a risk management framework is the foundational component of an Information Security Risk Management program. It defines the policies, procedures, and governance structure for identifying, assessing, and treating risks, aligning with standards like ISO 31000 or NIST SP 800-39. Without a framework, risk management activities lack consistency and accountability.

Exam trap

The trap here is that candidates confuse operational security activities (like vulnerability scanning or internal audits) with the strategic components of a risk management program, which are the framework and the risk assessment/treatment cycle.

Why the other options are wrong

B

Vulnerability scanning is a technical control, not a program component.

D

Audit is independent assurance, not part of the risk management program itself.

81
Matchingmedium

Match each business continuity term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Maximum time to restore a process after disruption

Maximum age of data that must be recovered

Plan to maintain business functions during disruption

Plan to restore IT infrastructure after disaster

Process to identify critical functions and dependencies

Why these pairings

Correct matches: A-BCP, B-DRP, C-BIA. Common confusions: MTD is about downtime, RPO is about data loss.

82
MCQmedium

Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?

A.To ensure compliance with regulatory requirements
B.To provide a consistent risk reporting structure across the enterprise
C.To support informed decision-making by aligning security risks with business objectives
D.To reduce the cost of risk management through shared resources
AnswerC

Why this answer

Integrating information security risk into ERM ensures that security risks are considered alongside business risks, enabling better prioritization and resource allocation. This alignment helps the organization make informed decisions that balance risk appetite and business objectives. The primary driver is to support strategic decision-making, not just compliance or reporting.

Exam trap

Candidates may choose 'To comply with regulatory requirements' because regulations often mandate risk management, but the primary reason is strategic alignment with business goals, not compliance.

Why the other options are wrong

A

Compliance is a benefit but not the primary reason; integration is about strategic alignment.

B

Consistent reporting is a result of integration, not the primary reason.

D

Cost reduction is a potential benefit but not the primary strategic reason.

83
Multi-Selecthard

An organization has a high residual risk after implementing all feasible controls. According to CISM best practices, which of the following should the information security manager do? (Select TWO.)

Select 2 answers
A.Escalate to senior management for risk acceptance
B.Document the risk in the risk register and accept it
C.Implement additional compensating controls
D.Immediately perform a new risk assessment
AnswersA, C

Why this answer

When residual risk remains high after all feasible controls are implemented, the information security manager should escalate the risk to senior management for formal risk acceptance (Option A). This aligns with CISM best practices, as senior management holds the authority to accept risks that exceed the organization's risk appetite. Additionally, implementing compensating controls (Option C) can further reduce residual risk to an acceptable level, even if primary controls are already in place.

Exam trap

The trap here is that candidates confuse 'documenting and accepting' (Option B) as sufficient, overlooking the CISM requirement that risk acceptance must be formally escalated to and approved by senior management, not just recorded by the security manager.

Why the other options are wrong

B

Documentation alone is not sufficient; escalation is needed for high residual risk.

D

A new assessment may be done later, but the immediate action is to escalate and consider additional controls.

84
Matchingmedium

Match each cryptographic term to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses same key for encryption and decryption

Uses public/private key pair

One-way transformation producing fixed-size digest

Provides authenticity and non-repudiation

Framework managing digital certificates and keys

Why these pairings

The correct matches are: Symmetric Encryption uses a shared key, Asymmetric Encryption uses a key pair, and Hash Function produces a one-way digest. Distractors confuse the purpose of digital signatures and the nature of PKI.

85
MCQeasy

Based on the exhibit, what is the MOST appropriate next step for the information security manager?

A.Recommend implementing multifactor authentication to reduce the risk
B.Accept the risk because the likelihood is only moderate
C.Reassess the risk with a higher risk appetite threshold
D.Transfer the risk by purchasing cyber insurance
AnswerA

Additional controls can lower the likelihood or impact, bringing the risk within appetite.

Why this answer

Multifactor authentication (MFA) directly mitigates the most likely attack vector for the identified risk—credential theft or brute-force attacks—by requiring a second factor (e.g., a one-time password from a hardware token or biometric) in addition to the password. Since the exhibit (not shown) indicates a moderate likelihood but high impact, implementing MFA reduces the likelihood to a more acceptable level without requiring a change in risk appetite or transferring the risk. This aligns with the CISM principle of applying cost-effective controls to reduce residual risk to within the organization's risk tolerance.

Exam trap

ISACA often tests the misconception that risk acceptance is a valid default response when likelihood is moderate, but the trap here is that acceptance requires the risk to be within the risk appetite after all cost-effective controls have been considered—not before.

How to eliminate wrong answers

Option B is wrong because accepting a risk with only moderate likelihood ignores the potential high impact; risk acceptance should only occur when the residual risk is within the organization's risk appetite after controls are applied, not as a default action. Option C is wrong because reassessing with a higher risk appetite threshold is a reactive and inappropriate approach—it artificially lowers the perceived risk rather than addressing the actual vulnerability, which violates the principle of risk management. Option D is wrong because transferring the risk via cyber insurance does not reduce the likelihood or impact of the security incident; it only provides financial compensation after a breach, and the organization still suffers operational and reputational damage, making it a less appropriate next step than implementing a preventive control like MFA.

86
MCQmedium

A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?

A.The organization will mitigate all risks to a low level
B.The organization will not invest in high-risk projects
C.The organization accepts no level of risk
D.The organization will accept up to $5M in potential loss for operational risks
AnswerD

Quantified risk appetite supports consistent decision-making.

Why this answer

A risk appetite statement for a financial institution must be quantifiable and specific to operational risk, aligning with regulatory frameworks like Basel III which require explicit loss thresholds. Stating a maximum acceptable loss of $5M provides a clear, measurable boundary for risk-taking decisions, enabling the board and management to balance risk and reward effectively.

Exam trap

The trap here is that candidates confuse risk appetite (the amount of risk accepted) with risk tolerance (the acceptable variation around that appetite) or risk avoidance, leading them to choose absolute statements like 'no risk' or 'low risk' instead of a quantifiable, business-aligned threshold.

How to eliminate wrong answers

Option A is wrong because 'mitigate all risks to a low level' implies a zero-risk posture that is impractical and costly; financial institutions must accept some risk to generate returns, and this statement lacks the quantifiable threshold needed for risk appetite. Option B is wrong because 'will not invest in high-risk projects' is too vague and absolute, ignoring that high-risk projects may be necessary for competitive advantage and can be managed within defined limits; it also fails to specify what constitutes 'high-risk' in measurable terms. Option C is wrong because 'accepts no level of risk' is unrealistic for any financial institution, as all operations carry inherent risk (e.g., credit risk, market risk), and such a statement would paralyze business activities and violate regulatory expectations for risk-based capital management.

87
Multi-Selecteasy

Which TWO of the following are risk treatment strategies as defined in ISO 27005?

Select 2 answers
A.Risk analysis
B.Risk monitoring
C.Risk avoidance
D.Risk transfer
E.Risk communication
AnswersC, D

Avoidance is a risk treatment strategy.

Why this answer

Risk avoidance is a defined risk treatment strategy in ISO 27005 where the organization decides to avoid the risk by not engaging in the activity that gives rise to it, such as discontinuing a service or choosing an alternative technology. Option C is correct because ISO 27005 explicitly lists risk avoidance as one of the four primary risk treatment options (avoidance, reduction, retention, and transfer).

Exam trap

The trap here is that candidates confuse the risk management process steps (like risk analysis, monitoring, and communication) with the specific risk treatment strategies defined in ISO 27005, leading them to select options that are activities rather than treatment methods.

88
Multi-Selectmedium

Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)

Select 2 answers
A.Risk avoidance
B.Risk measurement
C.Risk identification
D.Risk communication
E.Risk retention
AnswersA, E

Avoiding the risk by not undertaking the activity.

Why this answer

Risk avoidance is a valid risk treatment option per ISO 31000, where the organization decides to eliminate the risk by not engaging in or discontinuing the activity that gives rise to the risk. For example, in information security, this could mean choosing not to deploy a vulnerable legacy system or terminating a high-risk third-party integration. It directly reduces exposure to zero for that specific risk scenario.

Exam trap

The trap here is that candidates confuse the steps of the risk management process (identification, analysis, evaluation, communication) with the specific treatment options, leading them to select risk measurement or risk identification as valid treatments.

89
MCQhard

A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?

A.Risk appetite and tolerance are interchangeable terms
B.Risk appetite is set by regulatory bodies; tolerance is set by the board
C.Risk appetite is the specific limit for each risk; tolerance is the overall willingness to accept risk
D.Risk appetite is the general approach to risk; tolerance defines acceptable variation in performance
AnswerD

This correctly distinguishes between appetite and tolerance.

Why this answer

Risk appetite is the broad, high-level amount of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance translates that appetite into specific, measurable boundaries for individual risks. Option D correctly captures this relationship: appetite is the general approach, and tolerance defines the acceptable variation in performance metrics (e.g., a 5% deviation in revenue targets). This distinction is critical for aligning risk management with business strategy in information security risk management.

Exam trap

The trap here is that candidates often confuse the scope of the two terms, mistakenly thinking risk tolerance is the broader concept (Option C) or that they are synonymous (Option A), when in fact risk appetite is the overarching philosophy and tolerance is the specific, measurable boundary.

How to eliminate wrong answers

Option A is wrong because risk appetite and risk tolerance are not interchangeable; appetite is the overall willingness to accept risk, whereas tolerance is the specific, quantifiable limits applied to individual risks. Option B is wrong because risk appetite is set by the board of directors, not regulatory bodies; regulatory bodies may impose constraints, but appetite is an internal strategic decision. Option C is wrong because it reverses the definitions: risk tolerance is the specific limit for each risk, and risk appetite is the overall willingness to accept risk, not the other way around.

90
MCQeasy

Which of the following best describes the difference between risk appetite and risk tolerance?

A.Risk appetite is the maximum risk tolerance
B.Risk tolerance is the total risk, and risk appetite is the residual risk
C.Risk appetite is the amount of risk an organization is willing to accept, while risk tolerance is the acceptable variation around that appetite for specific objectives
D.Risk appetite is qualitative, and risk tolerance is quantitative
AnswerC

This is the standard definition.

Why this answer

Ly distinguishes risk appetite as the broad, strategic level of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance is the specific, measurable deviation allowed from that appetite for individual objectives or risks. This aligns with the ISACA CISM Review Manual, which defines risk appetite as the 'amount of risk an entity is willing to accept in pursuit of its mission' and risk tolerance as the 'acceptable level of variation relative to the achievement of objectives.' Understanding this distinction is critical for establishing proper risk management thresholds and ensuring that security controls are aligned with business goals.

Exam trap

The trap here is that candidates confuse risk appetite with risk tolerance by assuming they are synonyms or that one is a subset of the other in a purely quantitative sense, when in fact appetite is the strategic boundary and tolerance is the tactical wiggle room within that boundary for specific objectives.

How to eliminate wrong answers

Option A is wrong because risk appetite is not the maximum risk tolerance; rather, risk appetite sets the overall boundary, and risk tolerance defines the acceptable variance within that boundary for specific objectives. Option B is wrong because risk tolerance is not the total risk, nor is risk appetite the residual risk; residual risk is the risk remaining after controls are applied, which is a separate concept from both appetite and tolerance. Option D is wrong because both risk appetite and risk tolerance can be expressed in qualitative or quantitative terms; the distinction is not based on measurement type but on scope and specificity.

91
MCQhard

A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?

A.Develop and communicate a revised risk appetite statement approved by the board
B.Outsource all information security operations to a managed service provider
C.Immediately deploy a suite of technical security controls
D.Recommend the termination of the CEO for previous risk decisions
AnswerA

Correct; this aligns the organization's risk tolerance and guides behavior.

Why this answer

Developing and communicating a revised risk appetite statement approved by the board directly addresses the need to formalize risk management and change the risk culture. It provides clear guidance for decision-making, aligns with the board's demands, and respects the startup's limited resources by focusing on policy first. Other options are premature: deploying technical controls without policy support may be ineffective, outsourcing does not change internal culture, and terminating the CEO is an HR action that does not establish a risk program.

92
Multi-Selectmedium

A financial services company is updating its risk treatment plan for a high-risk legacy system that processes customer data. The risk owner has recommended acceptance of the risk. Which TWO conditions must be met for the risk acceptance to be valid according to ISACA CISM (Certified Information Security Manager) best practices?

Select 2 answers
A.The risk acceptance must be formally documented and signed off by the risk owner.
B.The risk acceptance must be subject to periodic review to ensure it remains acceptable.
C.The risk acceptance must include a detailed plan to reduce the risk level within one year.
D.The risk acceptance must be approved by the board of directors.
E.The risk owner must agree to implement compensating controls within a defined timeline.
AnswersA, B

Formal documentation and risk owner sign-off are key requirements for risk acceptance.

Why this answer

Risk acceptance requires formal documentation and approval by the risk owner (business owner). Periodic review is also necessary to ensure the risk remains acceptable. The board does not approve all accepted risks; only those exceeding certain thresholds.

Controls should be documented but are not required if risk is accepted.

93
MCQhard

A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?

A.Transfer the risk to cloud providers by renegotiating contracts to include liability clauses.
B.Develop and enforce cloud security baseline standards and conduct regular compliance audits.
C.Implement a cloud access security broker (CASB) to monitor all cloud activities centrally.
D.Accept the risk as inherent to cloud adoption and focus resources on incident response.
AnswerB

Standards and audits address the root cause by ensuring consistent understanding and adherence.

Why this answer

Developing and enforcing cloud security baseline standards and conducting regular compliance audits directly address the root cause of misconfigurations due to lack of understanding. A CASB provides monitoring but does not enforce standards. Transferring risk to cloud providers shifts liability but does not prevent misconfigurations.

Acceptance with focus on incident response is reactive and does not reduce likelihood.

94
MCQhard

During a risk assessment, an organization identifies a critical vulnerability in a legacy system that cannot be patched. The system's availability is crucial for business operations. Which of the following risk treatment strategies is MOST appropriate?

A.Risk mitigation by implementing compensating controls
B.Risk acceptance with formal sign-off by senior management
C.Risk transfer through cyber insurance
D.Risk avoidance by decommissioning the system
AnswerB

Why this answer

When a critical vulnerability cannot be patched and the system must remain available for business operations, risk acceptance is the most appropriate strategy because it formally acknowledges the residual risk after all feasible controls have been considered. Senior management sign-off is required because the risk exceeds the organization's risk appetite, and acceptance documents the decision to operate with the known vulnerability. This approach aligns with the CISM principle that risk acceptance is a valid treatment when the cost of other treatments exceeds the benefit or when no other treatment is feasible.

Exam trap

The trap here is that candidates often choose risk mitigation (compensating controls) because it seems proactive, but the question explicitly states the vulnerability 'cannot be patched' and the system is 'crucial for business operations,' making formal acceptance by senior management the required CISM answer when residual risk remains after all feasible controls.

Why the other options are wrong

A

Compensating controls are a form of mitigation, but the question says the system cannot be patched; however, compensating controls can still reduce risk. The key is that the vulnerability cannot be fixed, so mitigation may not be fully effective. The best answer is acceptance if no controls are cost-effective.

C

Insurance transfers financial risk but not operational risk; the vulnerability remains.

D

Decommissioning would avoid risk but is not acceptable because the system is critical.

95
MCQeasy

An information security manager is designing a risk dashboard for the board of directors. Which of the following key risk indicators (KRIs) would be MOST effective for monitoring changes in the organization's security posture related to third-party risk?

A.Average time to patch critical vulnerabilities in internal systems.
B.Number of third-party vendors with critical or high-risk security findings.
C.Number of successful phishing attacks against employees.
D.Percentage of vendors that have undergone security assessment in the last 12 months.
AnswerB

This is a leading KRI as it measures the current risk level from vendors, which can predict potential incidents.

Why this answer

KRIs should be leading indicators that predict risk changes. The number of third-party vendors with critical security findings is a direct measure of third-party risk and can indicate a rising risk trend before an incident occurs.

96
MCQmedium

A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?

A.Avoid the risk by discontinuing the process
B.Transfer the risk through insurance
C.Implement the control
D.Accept the risk
AnswerC

Net benefit: $400,000 loss reduction minus $100,000 cost = $300,000 savings.

Why this answer

The control reduces the annualized loss expectancy (ALE) from $500,000 to a much lower value (since likelihood drops from high to low). The annual cost of the control is $100,000, which is significantly less than the $500,000 expected loss without it. Implementing the control provides a positive return on investment (ROI) and is the most cost-effective risk mitigation strategy.

Exam trap

The trap here is that candidates may incorrectly assume that any control costing $100,000 is too expensive, failing to perform a proper cost-benefit comparison against the $500,000 expected loss, or they may confuse risk reduction with risk transfer or avoidance without evaluating financial justification.

How to eliminate wrong answers

Option A is wrong because avoiding the risk by discontinuing the process would eliminate the business benefit entirely, which is an extreme measure not justified when a cost-effective control exists. Option B is wrong because transferring the risk through insurance would still involve paying premiums (likely exceeding $100,000 annually) and does not reduce the likelihood of the threat; it only shifts financial impact. Option D is wrong because accepting the risk would mean tolerating an expected annual loss of $500,000, which is far greater than the $100,000 cost of the control, making it financially imprudent.

97
MCQhard

An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?

A.Accept the risk due to low likelihood
B.Avoid the risk by discontinuing the activity that generates it
C.Transfer the risk through insurance
D.Mitigate the risk by implementing controls to reduce impact
AnswerD

Mitigation reduces the impact to an acceptable level, aligning with moderate risk appetite.

Why this answer

ISO 31000's risk evaluation phase requires aligning treatment decisions with the organization's risk appetite. With a moderate risk appetite, a low-likelihood but very-high-impact risk cannot simply be accepted (as it exceeds appetite), nor is avoidance necessary since the likelihood is low. Mitigation through controls that reduce the impact is the most balanced approach, bringing the residual risk within the moderate appetite threshold.

Exam trap

The trap here is that candidates mistakenly equate low likelihood with low overall risk, leading them to choose acceptance (Option A), but CISM tests that risk appetite must be explicitly considered—a very high impact can still exceed appetite even if likelihood is low.

How to eliminate wrong answers

Option A is wrong because accepting a risk with very high impact, even if low likelihood, violates a moderate risk appetite—acceptance is only appropriate when residual risk falls within appetite, which it does not here. Option B is wrong because avoidance (discontinuing the activity) is a drastic measure typically reserved for risks that exceed appetite and cannot be cost-effectively mitigated; here, the low likelihood does not warrant complete cessation. Option C is wrong because transferring risk via insurance does not reduce the impact or likelihood—it only shifts financial consequences, and the organization still retains operational and reputational impact, which may still exceed its moderate risk appetite.

← PreviousPage 2 of 2 · 97 questions total

Ready to test yourself?

Try a timed practice session using only Cism Risk Management questions.