Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CISM Risk Domain Exam Questions & Answers (Grade A+).docx

Rating
-
Sold
-
Pages
31
Grade
A+
Uploaded on
22-05-2026
Written in
2025/2026

CISM Risk Domain Exam Questions & Answers (Grade A+).docx

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Content preview

CISM Risk Domain Exam Questions &
Answers (Grade A+)
Security Review -
correct answer ✅Used to determine the current state of security
for various program components.


Impact Analysis -
correct answer ✅Determine potential impact in the event of the
loss of a resource


Threat Assessment -
correct answer ✅Evaluate the type, scope and nature of events or
actions that can result in adverse consequences; identification is
made of the threats that exist against enterprise assets.


FIRST step in effectively integrating risk management into business
processes? -
correct answer ✅Analyzing the workflow will be essential to
understanding process vulnerabilities and where risk may exist in
integrating risk management into business processes.


Change Management -
correct answer ✅Overall process to assess and control risk
scenarios introduced by changes.

,CISM Risk Domain Exam Questions &
Answers (Grade A+)
Goal of Threat Analysis -
correct answer ✅Understand how the enterprise is positioned in
the threat landscape. Threat analysis also supports decisions to
prioritize control activities to mitigate the most critical risk. Threat
analysis is an important factor in calculating risk value.


Intrinsic Risk -
correct answer ✅Result of underlying internal and external factors
that are not readily subject to controls.


Systemic Risk -
correct answer ✅Collapse of an entire system as a result of the risk
imposed by system interdependencies.


Residual Risk -
correct answer ✅Risk to an enterprise as a result of its internal
and external operations. Risk after apply controls.


Operational Risk -
correct answer ✅risk to an enterprise as a result of its internal and
external operations such Denial of Service.

,CISM Risk Domain Exam Questions &
Answers (Grade A+)
Asset Valuation -
correct answer ✅Provides a cost representation of what the
enterprise stands to lose in the event of a major compromise.


Cross-Site Request Forgery Attack -
correct answer ✅XSRF exploits inadequate authentication
mechanisms in web applications that rely only on elements such as
cookies when performing a transaction. It is a type of website
attack in which unauthorized commands are transmitted from a
trusted user. Cross-site scripting attacks inject malformed input.


Security Gap Analysis -
correct answer ✅Process that measures all security controls in
place against control objectives, which will identify gaps.


Objective of a vulnerability assessment -
correct answer ✅A vulnerability assessment identifies
vulnerabilities so that they may be considered for mitigation. By
giving management a complete picture of the vulnerabilities that
exist, a vulnerability assessment program allows management to
prioritize those vulnerabilities deemed to pose the greatest risk.

, CISM Risk Domain Exam Questions &
Answers (Grade A+)
Vulnerabilities -
correct answer ✅ulnerabilities uncovered should be evaluated and
prioritized based on whether there is a credible threat, the impact
if the vulnerability is exploited, and the cost of mitigation. If there is
a potential threat but little or no impact if the vulnerability is
exploited, the risk is less and may not require controls to address it.


Gap Analysis -
correct answer ✅A gap analysis documents the tasks that must be
completed to move from the current state to the desired state, and
the level of effort may readily be determined. A gap analysis is
required for various components of the strategy previously
discussed, such as maturity levels, each control objective, and each
risk and impact objective.


At what point should a risk assessment of a new process occur to
determine appropriate controls? It should occur -
correct answer ✅throughout the entire life cycle of the process. A
risk assessment should be conducted throughout the entire life
cycle of a new or changed process. This allows an understanding of
how implementation of an early control will affect control needs
later.

Written for

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Document information

Uploaded on
May 22, 2026
Number of pages
31
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$15.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Chloelunar University Of Nevada-Las Vegas
Follow You need to be logged in order to follow users or courses
Sold
96
Member since
2 year
Number of followers
6
Documents
14296
Last sold
3 days ago

Get study materials, exam answer packs, step-by-step assignment solutions, and much more. Learn more effectively and quickly. After acquiring any document, please always provide a review to ensure that our consumers are completely satisfied.Best Wishes!!!!!!

3.5

17 reviews

5
7
4
4
3
1
2
0
1
5

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions