{"id":22225,"date":"2026-09-25T11:43:06","date_gmt":"2026-09-25T11:43:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22225"},"modified":"2026-09-25T11:43:06","modified_gmt":"2026-09-25T11:43:06","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>What should determine the frequency of security risk assessments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk should influence the frequency of security risk assessments because organizations with significant changes, high-risk environments, or critical operations may require more frequent reassessment. Assessment frequency should also consider changes in technology, threats, regulations, business processes, and organizational objectives. A fixed schedule may be useful, but significant changes should trigger an assessment even if the normal review date has not arrived. CISM emphasizes continuous risk management rather than treating risk assessment as a one-time activity. Risk assessments should provide management with current information for prioritizing treatment, allocating resources, and maintaining exposure within acceptable limits.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which document records identified organizational risks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy manual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Training plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset invoice<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register records identified risks and commonly includes information such as risk descriptions, affected assets or processes, likelihood, potential impact, risk owners, treatment decisions, and current status. It provides a structured way to monitor risks and track management actions over time. The register should be maintained as conditions change because new threats, vulnerabilities, business changes, and treatment activities can alter risk levels. CISM emphasizes maintaining visibility of organizational risk so management can make informed decisions. A risk register supports this objective by providing a consistent record for monitoring, reporting, escalation, and reassessment.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>What is inherent risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk after controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk before controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk after acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk after recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Inherent risk is the level of risk that exists before considering the effect of security controls or other risk treatments. It represents the exposure created by the nature of a business activity, asset, threat, or vulnerability under existing conditions without accounting for mitigating measures. Understanding inherent risk helps organizations evaluate how much protection is needed and how effective current controls are at reducing exposure. After controls are considered, the remaining exposure is generally referred to as residual risk. CISM emphasizes distinguishing these concepts because accurate risk assessment supports appropriate treatment decisions and management understanding of security exposure.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Who should normally own a business risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security vendor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network technician<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External auditor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The risk owner is the individual or organizational role accountable for managing a specific business risk and making or approving appropriate treatment decisions. Security professionals can provide analysis, recommendations, and technical expertise, but accountability should reside with the appropriate business authority. The risk owner should understand the potential impact of the risk and have sufficient authority to accept, mitigate, transfer, or avoid it. CISM emphasizes clear ownership because security teams should not independently accept business risks on behalf of management without appropriate authority. Defined ownership also improves monitoring, escalation, and accountability for treatment actions.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which factor should influence risk treatment priority?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk impact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office location<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee age<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk impact should influence treatment priority because risks that could cause significant harm to critical business objectives may require more immediate attention. Organizations should also consider likelihood, regulatory obligations, risk tolerance, existing controls, dependencies, and available treatment options. Prioritizing solely by the number of vulnerabilities or technical severity may produce misleading results if business context is ignored. CISM emphasizes a business-focused risk management approach in which security risks are evaluated according to their potential organizational consequences. This enables management to direct limited resources toward exposures that could materially affect important services, information, or objectives.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>What should happen when a risk treatment is delayed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document and monitor it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accept automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When risk treatment is delayed, the risk should remain documented and be monitored until appropriate treatment is completed or management makes another authorized decision. Delays may occur because of resource constraints, technical dependencies, business priorities, or implementation complexity, but they do not eliminate the underlying exposure. The organization should understand the consequences of delaying treatment and determine whether interim controls are necessary. CISM emphasizes maintaining visibility of risks throughout their lifecycle. A documented and monitored risk allows management to track responsibility, deadlines, changes in exposure, and whether escalation is required if the risk becomes unacceptable.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which situation should trigger a risk reassessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">New threat<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office repainting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff celebration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Furniture replacement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A new threat should trigger a risk reassessment when it could materially affect the organization\u2019s existing security exposure. New threats may arise from changes in attack techniques, geopolitical conditions, technology, suppliers, regulations, or business operations. The organization should determine whether existing controls remain appropriate and whether the likelihood or impact of relevant risks has changed. CISM emphasizes continuous monitoring because risk conditions are dynamic. Reassessment allows management to update risk treatment priorities, strengthen controls, adjust monitoring, or accept newly understood exposure when appropriate. Significant changes should not wait for the next scheduled assessment cycle.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>What is the purpose of a risk appetite statement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define acceptable exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">List technical controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule training<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Describe office rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk appetite statement defines the amount and type of risk the organization is generally willing to accept while pursuing its objectives. It provides management direction for risk-taking and helps establish boundaries for security and business decisions. Security strategies and risk treatment decisions should be consistent with these boundaries. Risk appetite should be established by appropriate senior management or governance authority because it reflects organizational objectives and business considerations rather than only technical security concerns. CISM emphasizes that understanding risk appetite supports consistent decision-making and helps security leaders determine when risks should be treated, monitored, or escalated.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which risk response transfers responsibility to another party?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk transfer involves shifting some or all financial or operational consequences of a risk to another party, commonly through insurance, contracts, outsourcing arrangements, or other formal agreements. Transfer does not necessarily eliminate the underlying risk, and the organization may still retain responsibilities or consequences depending on the arrangement. Management should understand what obligations remain after transfer and verify that contractual or insurance provisions provide the expected protection. CISM emphasizes selecting risk treatment according to organizational circumstances and risk appetite. Transfer should therefore be based on a clear assessment of cost, effectiveness, residual exposure, and the responsibilities of all parties involved.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which response eliminates an activity that creates unacceptable risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk avoidance eliminates the activity, process, technology, or condition that creates the unacceptable exposure. This approach may involve discontinuing a service, declining a high-risk activity, or changing a business process so that the underlying risk no longer exists in its original form. Avoidance can be appropriate when the potential impact is too high or when effective treatment is impractical. However, management should consider business consequences because stopping an activity may also prevent expected benefits. CISM emphasizes balancing security risk with business objectives, meaning avoidance should be considered within the broader organizational decision-making and risk management framework.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>What should management receive from a security risk report?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Relevant risk information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Raw log files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee messages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware inventory only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management should receive relevant risk information that supports informed decisions about security priorities, resources, treatment, and organizational exposure. Reports should communicate significant risks in understandable business terms and may include likelihood, impact, trends, existing controls, treatment status, and decisions requiring management attention. Raw technical information can be useful to security teams but may not provide executives with sufficient context. CISM emphasizes audience-appropriate reporting because different stakeholders require different levels of detail. Effective risk reporting should focus attention on material exposures and clearly explain how those risks could affect business objectives, operations, compliance, or organizational resilience.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>What should happen when a control becomes ineffective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess the gap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Close the risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a control becomes ineffective, the organization should assess the resulting security gap and determine whether additional treatment is necessary. The assessment should identify why the control failed, which assets or processes are affected, and whether the resulting exposure exceeds acceptable risk. Management may choose to strengthen, replace, redesign, or supplement the control depending on the circumstances. CISM emphasizes control effectiveness and continuous improvement rather than assuming that implemented controls will remain effective permanently. Findings should be documented, assigned to responsible owners, and monitored until corrective action restores an acceptable level of protection.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which factor should influence the cost-effectiveness of a control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expected risk reduction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Expected risk reduction should be considered when evaluating whether a security control is cost-effective. Management should compare the control\u2019s implementation and operating costs with the potential reduction in likelihood or impact and the business value of addressing the risk. Other considerations may include regulatory requirements, operational effects, dependencies, and the availability of alternative treatments. A low-cost control is not necessarily valuable if it provides little meaningful protection, while an expensive control may be justified for a critical exposure. CISM emphasizes business-oriented security decisions that balance protection, cost, risk tolerance, and organizational objectives.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>What should happen when risk criteria are inconsistent across departments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore differences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standardize criteria<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove assessments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unlimited exceptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk criteria should be standardized sufficiently to provide consistent evaluation across departments while allowing appropriate consideration of business context. Without common criteria, similar risks may receive very different ratings and treatment decisions, making enterprise-level prioritization difficult. Standardized criteria can define scales for likelihood, impact, risk levels, and escalation thresholds. CISM emphasizes governance and consistent risk management so management can compare exposures and allocate resources effectively. Business units may provide additional context, but their assessments should remain compatible with the organization\u2019s overall risk framework. Consistency improves reporting, decision-making, monitoring, and accountability.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>What should determine whether a risk requires escalation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk threshold<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor distance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk thresholds should determine whether a risk requires escalation because they establish predefined boundaries for management attention and decision-making. When a risk exceeds an established threshold, the responsible party should escalate it to the appropriate risk owner or governance authority. Thresholds can help organizations respond consistently instead of relying on subjective judgments during stressful situations. They should reflect risk appetite, business impact, regulatory requirements, and organizational responsibilities. CISM emphasizes clear governance and accountability, making escalation criteria an important component of effective risk management. Thresholds should also be reviewed periodically to ensure they remain appropriate for changing business and threat conditions.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which activity helps identify whether a security investment achieved its intended result?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Outcome measurement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff polling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor comparison<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Outcome measurement helps determine whether a security investment achieved its intended result by comparing actual performance with predefined objectives and expected benefits. Measures may include risk reduction, control effectiveness, improved resilience, compliance outcomes, reduced incident impact, or improved business capability. Simply completing an implementation project does not prove that the investment delivered meaningful value. CISM emphasizes measuring security outcomes in relation to business objectives and risk expectations. Management should review results periodically and determine whether additional improvements are needed. Effective measurement also helps justify future investments and ensures that security resources continue to support organizational priorities.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>What should happen when a risk treatment creates a new significant risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accept automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a risk treatment creates a new significant risk, the organization should reassess the situation and determine whether additional treatment or management action is necessary. Security controls can sometimes introduce operational, privacy, availability, or other risks that were not present previously. A treatment decision should therefore consider both the intended benefit and potential unintended consequences. CISM emphasizes holistic risk management rather than evaluating controls in isolation. The new exposure should be documented, assessed according to organizational criteria, and assigned to an appropriate owner. Management can then determine whether the resulting risk remains within acceptable limits.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which activity supports enterprise-wide risk visibility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent reporting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Central risk monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local spreadsheets only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal discussions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Central risk monitoring supports enterprise-wide visibility by allowing management to understand significant risks across departments, business units, technologies, and third parties. Centralized visibility can help identify common exposures, dependencies, emerging trends, and risks that may be underestimated when viewed only within individual departments. Business units can still maintain detailed local information, but enterprise-level reporting should use consistent definitions and criteria. CISM emphasizes governance and integrated risk management because security risks can affect multiple parts of an organization. Effective central monitoring supports prioritization, escalation, resource allocation, and informed management decisions across the enterprise.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>What should be done when a risk owner leaves the organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Close the register<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a risk owner leaves the organization, ownership should be reassigned to an appropriate individual with sufficient authority and knowledge to manage the exposure. Risks should not remain without accountable ownership because treatment decisions, monitoring, and escalation could be delayed. The organization should update the risk register and related governance records and communicate the change to relevant stakeholders. CISM emphasizes clear accountability throughout the risk management lifecycle. Management should also review whether organizational changes have affected the risk itself or its treatment requirements. Maintaining current ownership ensures that significant risks continue to receive appropriate oversight.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>What is the main goal of information security risk management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate every risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Support informed decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase security spending<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all technology<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The main goal of information security risk management is to support informed decisions that keep organizational risk within acceptable boundaries while enabling business objectives. Risk cannot usually be eliminated completely, and attempting to remove every possible risk may be impractical or unnecessarily expensive. Effective risk management identifies, assesses, prioritizes, treats, monitors, and communicates risks so management can make appropriate decisions. CISM emphasizes balancing protection with business needs rather than pursuing security in isolation. A mature risk management process helps organizations understand exposure, allocate resources effectively, address significant threats, and maintain alignment between security activities and enterprise objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 381 What should determine the frequency of security risk assessments? Office schedule Business risk Employee preference Vendor location Correct Answer: 2 Explanation Business risk should influence the frequency of security risk assessments because organizations with significant changes, high-risk environments, or critical operations may [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22225"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22225"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22225\/revisions"}],"predecessor-version":[{"id":22226,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22225\/revisions\/22226"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}