CISM (CISM) General 3 — Questions and Answers
Question 1: During a risk assessment, the team identifies a vulnerability with a high likelihood but very low impact. How should this risk MOST likely be treated?
- Transfer the risk through cyber insurance
- Accept the risk without further action
- Implement costly countermeasures to eliminate it
- Mitigate it with low-cost controls proportional to impact (Correct answer)
Correct answer: Mitigate it with low-cost controls proportional to impact
Risk treatment should be proportional; high-likelihood, low-impact risks warrant lightweight mitigating controls rather than expensive remediation or acceptance.
Question 2: A third-party vendor has access to the organization's sensitive systems. Which control BEST reduces the associated risk?
- Requiring the vendor to purchase liability insurance
- Conducting periodic vendor security assessments and right-to-audit clauses (Correct answer)
- Limiting communication with the vendor to email only
- Requiring the vendor to sign a non-disclosure agreement
Correct answer: Conducting periodic vendor security assessments and right-to-audit clauses
Periodic assessments and right-to-audit clauses provide ongoing assurance that vendors maintain required security standards throughout the relationship.
Question 3: Which factor MOST influences the priority of information security risk treatment?
- The opinion of the IT department
- The likelihood and potential business impact of the risk (Correct answer)
- The cost of available security technologies
- The age of the affected systems
Correct answer: The likelihood and potential business impact of the risk
Risk prioritization is driven by the combination of likelihood and business impact, ensuring the most critical risks receive attention first.
Question 4: An organization accepts a residual risk. What does this mean?
- The risk has been fully eliminated through controls
- The risk has been transferred to an insurer
- The remaining risk after controls are applied is deemed tolerable (Correct answer)
- The risk assessment was incomplete
Correct answer: The remaining risk after controls are applied is deemed tolerable
Residual risk is what remains after controls are applied; accepting it means management finds the remaining exposure within tolerance.
Question 5: Which of the following is the PRIMARY purpose of a Business Impact Analysis (BIA)?
- To identify all IT assets in the organization
- To determine the criticality of business processes and recovery time requirements (Correct answer)
- To assign financial value to security incidents
- To map network topology for disaster recovery
Correct answer: To determine the criticality of business processes and recovery time requirements
A BIA identifies critical business functions, their dependencies, and the time within which they must be restored to avoid unacceptable consequences.
Question 6: A risk treatment option that involves sharing risk with another party, such as through outsourcing, is BEST described as:
- Risk avoidance
- Risk acceptance
- Risk mitigation
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Risk transfer shifts the financial or operational burden of a risk to a third party, such as an insurer or outsourced provider.
Question 7: When performing information risk assessments, which approach provides the MOST objective results?
- Relying solely on staff interviews
- Using only automated scanning tools
- Combining quantitative data with qualitative expert judgment (Correct answer)
- Copying results from a prior year's assessment
Correct answer: Combining quantitative data with qualitative expert judgment
A hybrid approach leverages measurable data for objectivity while using expert judgment to address gaps that tools and metrics cannot fully capture.
During a risk assessment, the team identifies a vulnerability with a high likelihood but very low impact.
How should this risk MOST likely be treated?