Certified Information Security Manager CISM · Free Practice Question Medium
Question 13
- A Compliance risk
- B Breach risk
- C Compliance risk and breach risk
- D No specific risk
Reveal correct answer
Correct answer: C
Explanation
Correct Answer:
Compliance risk and breach risk is correct. An organization that is knowingly in a state of noncompliance with an applicable cybersecurity law or regulation faces the risk of a breach because of the lack of a required control or safeguard. Further, the organization faces compliance risk that may be in the form of fines, penalties, or sanctions.
Incorrect Answers:
No specific risk is incorrect because organizations face risks if they are not compliant with applicable cybersecurity regulation.
Breach risk and Compliance risk are incorrect because they are incomplete answers.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
