View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 101
What is the PRIMARY purpose of an information security risk assessment?
- To eliminate every identified vulnerability
- To identify and evaluate risks that could affect business objectives
- To select security products for every system
- To assign responsibility for all business decisions
Correct Answer: 2
Explanation
An information security risk assessment identifies and evaluates risks that could affect organizational objectives. It considers factors such as threats, vulnerabilities, likelihood, potential impact, existing controls, and business context. The purpose is not to eliminate every vulnerability because some vulnerabilities may have limited business significance or may be accepted based on organizational risk appetite. Selecting products is a potential outcome of risk treatment, not the primary purpose of assessment. Risk assessments provide management with information needed to prioritize risks and determine appropriate responses while considering business requirements, resources, and acceptable levels of exposure.
Question 102
Which factor should be considered FIRST when determining the impact of a security risk?
- The brand of security technology involved
- The number of security administrators available
- The potential effect on critical business objectives
- The age of the affected hardware
Correct Answer: 3
Explanation
Risk impact should be evaluated in relation to the consequences for business objectives and critical operations. A security event may affect confidentiality, integrity, availability, regulatory compliance, financial performance, customer trust, or other important organizational outcomes. Technical characteristics such as hardware age or security technology brand may provide context but do not independently determine business impact. The number of administrators is also not an impact measure. By focusing on business consequences, the security manager can communicate risk in terms that support management decision making and ensure that significant organizational exposures receive appropriate attention and treatment.
Question 103
A risk assessment identifies a highly probable threat with a significant potential business impact. How should the risk generally be treated?
- It should receive a high priority for management attention
- It should automatically be accepted
- It should be removed from the risk register
- It should be ignored until an incident occurs
Correct Answer: 1
Explanation
A risk characterized by both high likelihood and significant potential impact generally deserves prompt management attention because it can materially affect organizational objectives. The exact treatment should still consider existing controls, risk appetite, available resources, and other organizational risk criteria. The risk should not automatically be accepted simply because it is difficult to address, nor should it be removed from the risk register. Ignoring the risk until an incident occurs is reactive and can increase potential losses. Prioritization allows management to evaluate appropriate mitigation, transfer, avoidance, or acceptance options.
Question 104
Which statement BEST describes inherent risk?
- Risk remaining after all controls have been implemented
- Risk associated with an activity before considering existing controls
- Risk that management has formally accepted
- Risk transferred to a third party
Correct Answer: 2
Explanation
Inherent risk represents the level of risk associated with an activity, process, asset, or situation before considering the effect of existing controls or risk treatments. It helps organizations understand the exposure that exists naturally within a business activity. Residual risk, in contrast, is the risk remaining after controls have been considered or implemented. Risk acceptance describes a management decision about retaining exposure, while risk transfer involves shifting certain consequences to another party. Understanding inherent risk provides a useful baseline for evaluating how effectively controls reduce exposure and whether the remaining risk is acceptable.
Question 105
What is the PRIMARY purpose of identifying risk owners?
- To ensure accountability for managing identified risks
- To transfer every risk to the security department
- To eliminate the need for risk treatment
- To allow risks to remain undocumented
Correct Answer: 1
Explanation
Risk owners are accountable for ensuring that identified risks are appropriately managed within their area of responsibility. They may approve treatment decisions, monitor risk conditions, accept residual exposure when authorized, and ensure that appropriate actions are completed. Risk ownership should generally remain with the business or organizational function that has authority over the affected process or asset rather than automatically being assigned to security. Identifying owners also prevents risks from becoming unmanaged because everyone assumes someone else is responsible. Clear ownership strengthens accountability and supports effective communication between business and security functions.
Question 106
A security manager identifies a new threat that could significantly change an existing risk assessment. What should happen NEXT?
- Delete the previous risk assessment
- Reassess the affected risk using the new information
- Automatically purchase a security solution
- Accept the risk without further analysis
Correct Answer: 2
Explanation
New threat information can change the likelihood, impact, or overall exposure associated with an existing risk. The appropriate response is to reassess the affected risk using the new information and determine whether current controls and treatment remain adequate. Automatically purchasing technology before understanding the changed risk may result in inappropriate spending. Accepting the risk without analysis could leave management unaware of increased exposure. Deleting the previous assessment is also unnecessary because historical information may help demonstrate how risk changed over time. Risk assessments should be updated when meaningful changes occur.
Question 107
Which approach is MOST appropriate for estimating the likelihood of a security event?
- Base it solely on the cost of security software
- Consider threat capability, vulnerability, exposure, and relevant historical information
- Assume every threat has an equal probability
- Use the age of the affected system as the only factor
Correct Answer: 2
Explanation
Likelihood estimation should consider factors relevant to the probability of an event occurring, including threat capability and intent, vulnerability exposure, existing controls, attack opportunities, historical information, and environmental conditions. No single factor is sufficient in every situation. Assuming every threat has equal probability can distort risk prioritization, while software cost and system age do not directly establish event likelihood. The objective is to develop a reasonable and defensible estimate using available evidence. Where precise probabilities are unavailable, organizations may use qualitative or semi-quantitative methods consistent with their established risk assessment methodology.
Question 108
An organization has limited resources for risk treatment. Which risk should generally receive attention first?
- A low-impact risk affecting a noncritical process
- A high-impact risk that exceeds the organization’s tolerance
- A risk with the most recently created ticket
- A risk associated with the least expensive system
Correct Answer: 2
Explanation
When resources are limited, priority should generally be given to risks that pose significant business impact and exceed established risk tolerance or appetite. Such risks can materially affect organizational objectives and therefore require management attention. The age of a ticket or the cost of the affected system does not necessarily indicate the importance of a risk. A low-impact issue affecting a noncritical process may reasonably receive a lower priority. Risk-based prioritization helps ensure that available resources are directed toward exposures that could cause the greatest harm or that fall outside acceptable organizational limits.
Question 109
Which risk treatment strategy involves shifting the financial consequences of a risk to another party?
- Risk avoidance
- Risk reduction
- Risk transfer
- Risk acceptance
Correct Answer: 3
Explanation
Risk transfer involves shifting some of the financial or other consequences associated with a risk to another party. Insurance and certain contractual arrangements are common examples, although the exact scope of transferred responsibility depends on the agreement. Risk avoidance eliminates the activity or condition that creates the risk, while risk reduction applies controls to decrease likelihood or impact. Risk acceptance means consciously retaining the exposure. Transfer does not necessarily eliminate the underlying risk or organizational accountability, so management should understand what remains after the transfer arrangement is established.
Question 110
A business owner wants to accept a risk that falls within the organization’s defined risk appetite. What should the CISM ensure?
- The decision is documented and approved according to established authority
- The risk is immediately removed from monitoring
- All related security controls are disabled
- The risk is transferred to the IT department
Correct Answer: 1
Explanation
Even when a risk falls within organizational risk appetite, the acceptance decision should follow established governance and documentation requirements. The appropriate risk owner or authorized management representative should acknowledge the exposure and accept responsibility according to the organization’s defined authority. Accepted risks should remain visible and monitored because circumstances can change. Disabling related controls is not automatically justified, and transferring risk to IT does not replace formal ownership. Documentation provides accountability and establishes a record of why the organization chose to retain the exposure, which can be revisited when risk conditions change.
Question 111
Which activity BEST helps determine whether an existing control remains appropriate after a major business process change?
- Reviewing the control against the new process, risks, and requirements
- Keeping the control unchanged regardless of circumstances
- Removing the control before conducting an assessment
- Replacing the control with the most expensive alternative
Correct Answer: 1
Explanation
A significant business process change can alter information flows, users, dependencies, threats, vulnerabilities, and compliance requirements. The existing control should therefore be reviewed against the new process and its associated risks to determine whether it remains effective and appropriate. Keeping a control unchanged without assessment may leave gaps or create unnecessary restrictions. Removing it before analysis can increase exposure, while selecting an expensive alternative without evidence may waste resources. Control reviews should consider effectiveness, business requirements, residual risk, operational impact, and whether additional or modified controls are necessary.
Question 112
What is the PRIMARY purpose of a risk register?
- To provide a structured record of identified risks, ownership, status, and treatment
- To store employee performance evaluations
- To replace security policies
- To guarantee that risks will not occur
Correct Answer: 1
Explanation
A risk register provides a structured way to record and manage identified risks. Depending on the organization’s methodology, it may include risk descriptions, owners, likelihood, impact, treatment plans, status, target dates, and residual exposure. The register supports visibility, accountability, monitoring, and reporting. It does not replace security policies or guarantee that risks will not occur. Employee performance information is unrelated to its primary purpose. Maintaining an accurate risk register helps management understand the organization’s risk landscape and track whether treatment activities are progressing appropriately.
Question 113
A risk treatment plan has been approved, but implementation is significantly delayed. What should the CISM do?
- Ignore the delay until the next annual assessment
- Evaluate the effect of the delay and escalate significant exposure
- Close the risk because treatment was approved
- Remove the treatment plan from management reporting
Correct Answer: 2
Explanation
Approval of a risk treatment plan does not mean that the risk has been reduced. If implementation is delayed, the organization may continue to face the original exposure. The CISM should assess the effect of the delay, determine whether the risk now exceeds acceptable thresholds, and escalate significant concerns through the appropriate governance process. Closing the risk or removing it from reporting would create a misleading view of the organization’s exposure. Management may need to adjust priorities, provide resources, accept the temporary exposure, or implement interim controls while the planned treatment is completed.
Question 114
Which factor is MOST important when determining whether risk treatment is cost-effective?
- The number of security vendors available
- The relationship between treatment cost, risk reduction, and business value
- The popularity of the proposed technology
- The number of employees assigned to the project
Correct Answer: 2
Explanation
Cost-effectiveness should be evaluated by comparing the cost and operational consequences of a treatment with the amount of risk reduction and business value it provides. The analysis may include implementation expenses, ongoing maintenance, avoided losses, regulatory requirements, productivity effects, and the importance of the protected business process. Vendor availability or technology popularity does not establish value. Staffing requirements may affect cost but are only one part of the assessment. A cost-effective treatment does not necessarily mean the cheapest option; it means the investment provides an appropriate level of risk reduction relative to its overall cost and business impact.
Question 115
A risk assessment identifies a vulnerability that has no known threat exploiting it and has minimal business impact. What should the CISM do?
- Automatically classify it as the highest organizational risk
- Evaluate it in context and prioritize it according to established risk criteria
- Immediately shut down the affected system
- Purchase a new security control regardless of cost
Correct Answer: 2
Explanation
Risk should be evaluated in context rather than based solely on the existence of a vulnerability. The CISM should consider threat likelihood, exploitability, existing controls, asset criticality, potential impact, and organizational risk criteria. A vulnerability with minimal business impact and no meaningful threat exposure may receive a lower treatment priority than another issue affecting a critical process. Automatically shutting down systems or purchasing controls without analysis may create unnecessary operational and financial consequences. Contextual risk assessment enables management to prioritize resources toward exposures that are most relevant to organizational objectives.
Question 116
Which activity BEST supports identification of emerging information security risks?
- Monitoring changes in threats, technology, business processes, and the external environment
- Reviewing only historical incidents
- Limiting risk assessments to annual audits
- Ignoring changes that have not caused incidents
Correct Answer: 1
Explanation
Emerging risks can arise from changes in technology, business strategy, threat activity, regulations, suppliers, geopolitical conditions, and other external or internal factors. Monitoring these changes helps the organization identify new exposures before they develop into significant incidents. Historical incidents provide useful information but cannot reveal every future threat. Annual assessments may be part of a formal process but should not prevent reassessment when significant changes occur. Ignoring unexploited changes can leave the organization unprepared. Effective risk management combines ongoing environmental awareness with structured reassessment and appropriate escalation.
Question 117
A new regulation changes the organization’s data retention obligations. What should the CISM do FIRST from a risk perspective?
- Assess the impact of the requirement on existing processes and information risks
- Delete all retained information immediately
- Ignore the requirement until the next audit
- Transfer compliance responsibility to the storage vendor
Correct Answer: 1
Explanation
A change in data retention requirements can affect legal compliance, privacy, storage, business processes, information classification, and security risks. The CISM should first assess how the new requirement affects existing practices and identify gaps between current processes and required obligations. Immediately deleting information could violate other requirements or business needs, while ignoring the change creates compliance exposure. A storage vendor may have responsibilities under a contract, but the organization remains accountable for understanding its obligations. Impact assessment provides the basis for determining appropriate changes, controls, retention procedures, and responsibilities.
Question 118
Which situation BEST indicates that residual risk may have become unacceptable?
- A control remains operational
- A monitored risk exceeds the organization’s established tolerance
- A security product receives a software update
- An employee completes security training
Correct Answer: 2
Explanation
Residual risk becomes a management concern when the exposure remaining after controls exceeds the organization’s established risk tolerance or other defined acceptance criteria. The fact that a control remains operational does not prove that the remaining risk is acceptable. Software updates and employee training may improve security but do not independently determine residual risk. When risk exceeds tolerance, management should reassess treatment options, control effectiveness, business impact, and available resources. Appropriate action may include strengthening controls, avoiding the activity, transferring certain consequences, or obtaining formally authorized acceptance where permitted.
Question 119
A security manager wants to compare risk levels across several business units using a consistent methodology. What is MOST important?
- Applying standardized risk assessment criteria
- Allowing each unit to define its own risk scale
- Using only the number of vulnerabilities found
- Comparing only the security budgets of each unit
Correct Answer: 1
Explanation
Standardized risk assessment criteria allow risks from different business units to be evaluated and compared consistently. The methodology should define relevant factors such as likelihood, impact, risk categories, scoring or rating methods, and treatment thresholds. Allowing each business unit to use unrelated scales can make enterprise-level comparison difficult and potentially misleading. Vulnerability counts alone do not represent business risk because vulnerabilities differ in severity and context. Security budgets also do not measure risk. Consistency helps management prioritize enterprise risks, allocate resources, and communicate risk information using a common organizational framework.
Question 120
A risk owner requests that a significant risk be removed from the risk register because a treatment project has started. What should the CISM recommend?
- Remove it immediately because treatment has begun
- Keep the risk recorded until the exposure has been appropriately reassessed
- Replace the risk with the project name
- Mark the risk as eliminated without testing the treatment
Correct Answer: 2
Explanation
A risk should remain visible while treatment is being implemented because the original exposure may continue until controls become operational and effective. Once treatment is complete, the risk should be reassessed to determine the resulting residual risk and whether it falls within acceptable organizational criteria. Simply starting a project does not eliminate the underlying risk. Removing the risk prematurely could prevent management from seeing ongoing exposure and delays. Keeping the risk in the register supports accountability, progress tracking, and appropriate reassessment. This approach also helps management identify situations where treatment implementation does not achieve the expected risk reduction.