Certified Information Security Manager CISM · Free Practice Question Easy
Question 98
-
A
Ask the security team to perform a risk assessment.
-
B
Ask an external party to perform a penetration test.
-
C
Ask the CISO to perform a risk assessment.
-
D
Request to see the other organization’s security policies.
Reveal correct answer
Correct answer: C
Explanation
Correct Answer:
"Ask the CISO to perform a risk assessment." is correct. The best approach is to include the CISO in merger/acquisition proceedings so that latent risks can be identified prior to the close of the transaction.
Incorrect Answers:
"Request to see the other organization’s security policies." is incorrect because an examination of the other organization’s security policies reveals little about its security practices, as its policies may be aspirational only.
"Ask an external party to perform a penetration test." is incorrect because a penetration test would provide a narrow view of the other organization.
"Ask the security team to perform a risk assessment." is incorrect because the security team will probably not be able to participate in merger and acquisition due diligence activities, which are usually limited to a small number of executives.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
