Courseiva

CISM Information Security Programme Practice Question

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

⚠ Common exam trap

A common mix-up: candidates confuse 'compensating controls' (which are alternative controls for a specific requirement or deficiency) with the broader 'defense-in-depth' strategy. In the CISM context, defense-in-depth is the layered approach that uses multiple controls to provide redundancy, so that if one fails, others still provide protection. Compensating controls are a subset used when primary controls cannot be implemented, not the overall layered strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense-in-depth

Defense-in-depth (option D) is the correct approach because it implements multiple, overlapping layers of security controls (e.g., firewalls, IDS/IPS, endpoint protection, access controls) so that if one layer fails or is bypassed, subsequent layers continue to provide protection. This layered strategy reduces the likelihood of a single point of failure compromising the entire security posture, aligning with the CISM principle of risk mitigation through redundancy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Business-enabling controls

    Why it's wrong here

    Business-enabling controls are designed to support and not obstruct business processes, which is a design philosophy rather than a layering strategy. They fit scenarios where security must facilitate operations, not where multiple independent controls must overlap to absorb a single failure.

  • ✗

    Critical controls first

    Why it's wrong here

    Prioritising critical controls sequences remediation by risk impact; it does not itself create overlapping safeguards. That approach fits environments where resources are limited and the most damaging gaps must be closed first, rather than a requirement for redundant layers.

  • ✗

    Compensating controls

    Why it's wrong here

    Compensating controls substitute for a primary control that cannot be implemented, addressing a specific gap rather than layering independent defences. They suit cases such as legacy systems unable to support a required control, not the deliberate stacking of controls so one failure is absorbed by another.

  • ✓

    Defense-in-depth

    Why this is correct

    Defense-in-depth uses multiple layers of defense to protect assets.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.