Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1024 discussion

Actual exam question from Isaca's CISM
Question #: 1024
Topic #: 1
[All CISM Questions]

Which of the following should an information security manager do FIRST upon notification of a potential security risk associated with a third-party service provider?

  • A. Determine risk treatment options.
  • B. Conduct a vulnerability analysis.
  • C. Escalate to the third-party provider.
  • D. Conduct a risk analysis.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
4 months ago
D - While communication with the third-party provider is crucial, it’s not the initial step. Risk analysis should precede escalation. it’s essential to assess the risk. A risk analysis helps evaluate the impact, likelihood, and severity of the potential risk. It informs subsequent actions and decisions.
upvoted 1 times
...
AlexJacobson
9 months, 2 weeks ago
Selected Answer: C
I'd say it's C. The keyword here being "potential" so the first thing you do is validate what happened and whether it even happened. After that you can decide what to do next.
upvoted 2 times
AlexJacobson
9 months, 2 weeks ago
Then again, if you are notified about the risk associated with third-party provider (i.e. discovered the risk of relying on their services), then risk analysis is indeed the first thing you should do (B). Honestly, I'm not 100% sure what the question is asking... :/
upvoted 2 times
...
...
richck102
1 year ago
Selected Answer: D
D. Conduct a risk analysis.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...