CISM

Information Risk Management

52 practice questions with explanations — 15 free to try

PassNova has 52 CISM practice questions on Information Risk Management, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Information Risk Management: example questions & answers

3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 52-question Information Risk Management bank is part of PassNova Premium.

  1. What is the FIRST step an information security manager should take when establishing a risk management program?

    • AIdentify and classify the organisation's information assets
    • BImplement encryption on all databases
    • CHire additional security analysts
    • DPurchase a risk management software platform to hold the register

    Answer: You cannot assess or treat risk without first identifying and classifying the assets to be protected; asset identification is the foundational step.

  2. During a risk assessment, the value of an asset is determined PRIMARILY by which of the following?

    • AThe original purchase price recorded in the fixed asset register
    • BIts importance to the organisation's business operations
    • CThe brand and specification of the hardware platform on which it runs
    • DThe number of users who currently hold access rights to it

    Answer: Asset value is driven by importance to business operations, since the impact of compromise depends on how the asset supports the organisation, not its purchase cost.

  3. An information security manager has identified a high risk. After analysis, the cost of mitigation greatly exceeds the potential loss. What is the MOST appropriate response?

    • AAccept the risk with appropriate management approval
    • BIgnore the risk entirely and document nothing
    • CImmediately shut down the affected business process until a cheaper control is found
    • DImplement the costly control regardless of the cost-benefit outcome

    Answer: When mitigation cost exceeds the potential loss, accepting the risk with documented management approval is the rational, risk-based decision.

Start practising Information Risk Management →