Courseiva
hardMultiple Choice

CISM Practice Question: The CISO of a mid-sized e-commerce company with…

You are the CISO of a mid-sized e-commerce company with 500 employees. The company recently suffered a data breach where an attacker exfiltrated customer credit card data from the production database. The investigation revealed that the breach originated from a compromised developer workstation. The developer had been granted direct access to the production database for troubleshooting purposes, a practice that had been in place for years. The security governance framework currently lacks a formal process for managing privileged access. The board has asked for immediate improvements to prevent recurrence. Which course of action BEST addresses the governance gap?

⚠ Common exam trap

Candidates often confuse technical controls (segmentation, patching, training) with governance controls (policies, processes, and oversight), leading them to select a solution that mitigates symptoms rather than the root governance gap of unmanaged privileged access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a privileged access management (PAM) solution with just-in-time access and session recording.

The core governance gap is the lack of a formal process for managing privileged access. Implementing a Privileged Access Management (PAM) solution with just-in-time (JIT) access and session recording directly addresses this by enforcing time-bound, auditable, and approved access to the production database, eliminating standing privileges. This aligns with the principle of least privilege and provides a governance mechanism to control, monitor, and revoke elevated access, which is the root cause of the breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a privileged access management (PAM) solution with just-in-time access and session recording.

    Why this is correct

    Implementing PAM with just-in-time access removes standing production database privileges from developer workstations, directly closing the governance gap of unmanaged privileged access. Session recording provides accountability and audit evidence, satisfying the board's demand for immediate, enforceable controls that prevent recurrence of the compromised-workstation exfiltration path.

  • ✗

    Segment the network to isolate production databases from developer workstations.

    Why it's wrong here

    Network segmentation reduces lateral movement but leaves the underlying governance gap: no formal process governing who holds privileged production access and why. It is tempting because isolating production is a sound defence-in-depth control, yet the board asked for privileged access management, which is the actual deficiency.

  • ✗

    Conduct security awareness training for all developers on password security.

    Why it's wrong here

    Awareness training on password security does not establish any formal process for managing privileged access, so the standing developer-to-production access persists unchanged. It is tempting because training is a cheap, visible control, but it targets user behaviour rather than the governance deficiency the board identified.

  • ✗

    Deploy endpoint protection and patch management for all workstations.

    Why it's wrong here

    Endpoint protection and patching harden the compromised workstation but do not create the missing privileged access governance process; the developer would still hold standing direct production database rights. It is tempting because endpoint controls are legitimate breach mitigations, yet they address the attack vector rather than the access governance gap.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.