exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 99 discussion

Actual exam question from Isaca's CISM
Question #: 99
Topic #: 1
[All CISM Questions]

When scoping a risk assessment, assets need to be classified by:

  • A. sensitivity and criticality.
  • B. likelihood and impact.
  • C. threats and opportunities.
  • D. redundancy and recoverability.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SHERLOCKAWS
3 weeks, 1 day ago
Selected Answer: B
When talking about RISK ASSESSMENT it's likelihood and impact that need to be addressed. sensitivity and criticality are important for DLP or even BCP planning.
upvoted 1 times
...
sphenixfire
1 year, 1 month ago
Selected Answer: A
CISM AIO, 2nd > Asset Classification "In asset classification, an organization assigns an asset to a category representing usage or risk. In an information security program, the purpose of asset classification is to deter- mine, for each asset, its level of criticality to the organization. Criticality can be related to information sensitivity...."
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
B. Likelihood and Impact. This classification helps in evaluating the potential risks and their significance in terms of how likely they are to occur and what impact they might have on the organization.
upvoted 2 times
AlexJacobson
9 months, 3 weeks ago
Risks are evaluated by likelihood and impact, not assets. Assets are evaluated by their value, ergo sensitivity and criticality. And only based on that you do risk assessment of those assets.
upvoted 1 times
oluchecpoint
9 months, 2 weeks ago
Correct A is right
upvoted 1 times
...
...
...
CrackyPatch
1 year, 5 months ago
Selected Answer: A
A. sensitivity and criticality.
upvoted 2 times
...
richck102
1 year, 5 months ago
A. sensitivity and criticality.
upvoted 1 times
...
Ziggybooboo
2 years, 1 month ago
I think this is B as that aligns with Risk better
upvoted 1 times
k4d4v4r
2 years, 1 month ago
A is correct. You measure a risk by Likelihood x impact but the asset classification is based on sensitivity and criticality
upvoted 13 times
cosmo4ng
2 years ago
agreed
upvoted 3 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago