nerdexam
Isaca

CISM · Question #353

An information security manager identified that a user's laptop did not have full disk encryption enabled and recommended this be configured immediately. Which type of risk treatment was applied?

The correct answer is D. Mitigation. The recommendation to enable full disk encryption is an example of mitigation, which involves taking actions to reduce the potential impact or likelihood of a risk. In this case, enabling encryption addresses the risk of unauthorized access to sensitive data in case the laptop is

Submitted by akirajp· Apr 18, 2026Information Security Risk Management

Question

An information security manager identified that a user's laptop did not have full disk encryption enabled and recommended this be configured immediately. Which type of risk treatment was applied?

Options

  • AAvoidance
  • BTransfer
  • CAcceptance
  • DMitigation

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    14% (4)
  • C
    11% (3)
  • D
    71% (20)

Explanation

The recommendation to enable full disk encryption is an example of mitigation, which involves taking actions to reduce the potential impact or likelihood of a risk. In this case, enabling encryption addresses the risk of unauthorized access to sensitive data in case the laptop is lost or

Topics

#Risk treatment#Mitigation#Security controls#Full Disk Encryption

Community Discussion

No community discussion yet for this question.

Full CISM Practice