Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISM topic 1 question 167 discussion

Actual exam question from Isaca's CISM
Question #: 167
Topic #: 1
[All CISM Questions]

Which of the following should be the MOST important consideration when prioritizing risk remediation?

  • A. Evaluation of risk
  • B. Duration of exposure
  • C. Comparison to risk appetite
  • D. Impact of compliance
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
03allen
1 week, 6 days ago
Selected Answer: A
Evaluate the risk to determine the business impact and risk level, which help to prioritize the controls.
upvoted 1 times
...
nuel_12
1 month ago
Selected Answer: C
C prioritize remediation of any risk depend on the organizational appetited of risk
upvoted 1 times
...
e891cd1
1 month, 3 weeks ago
C..I think the primary word is "Prioritize" which means to determine the order of things..Comparison to risk appetite will clearly determine the order of importance doing a full evaluation or doing a full assessent is to broad i think for this question although two of them is equally important but the context of the question i would go with C
upvoted 1 times
...
shervin2s
2 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
Marcelus1714
2 months, 4 weeks ago
Selected Answer: C
Could be C because it says "when prioritizing risk remediation", meaning that the risks were already evaluated, now we need to compare against Risk appetite?
upvoted 1 times
...
oluchecpoint
3 months, 1 week ago
Selected Answer: C
C. Comparison to risk appetite All the factors listed are important in risk prioritization, the comparison to the organization's risk appetite should be the guiding principle. It ensures that risk mitigation efforts are in line with the organization's strategic objectives and tolerance for risk, helping prioritize remediation efforts effectively.
upvoted 1 times
...
POWNED
4 months, 1 week ago
Selected Answer: C
Answer is C. Need to limit mitigation efforts in order to stay in line with the risk appetite.
upvoted 2 times
...
oluchecpoint
8 months, 1 week ago
C. Comparison to risk appetite All the factors listed are important in risk prioritization, the comparison to the organization's risk appetite should be the guiding principle. It ensures that risk mitigation efforts are in line with the organization's strategic objectives and tolerance for risk, helping prioritize remediation efforts effectively.
upvoted 1 times
...
pc2502
9 months, 1 week ago
here they are talkin about risk remediation so A is wrong answer
upvoted 1 times
...
jennarink13
10 months, 1 week ago
Going with A. Risk appetite does not facilitate prioritisation, risk assessment does. Risk appetite would tell you that risk response is adequate and not how they should be prioritised. This has a similar question in CRISC QAE.
upvoted 1 times
...
Andreu
10 months, 2 weeks ago
Selected Answer: C
You need to evaluate the risk in relation to the organization's risk appetite, therefore C.
upvoted 1 times
...
wello
11 months, 1 week ago
Selected Answer: A
Evaluation of Risk
upvoted 1 times
...
richck102
11 months, 2 weeks ago
A. Evaluation of risk
upvoted 1 times
...
mad68
1 year ago
Selected Answer: C
Comparison to risk appetite refers to assessing the identified risks in relation to the organization's tolerance for risk. Risk appetite defines the level of risk that an organization is willing to accept in pursuit of its objectives. It takes into account factors such as strategic goals, operational requirements, legal and regulatory obligations, and the organization's overall risk culture. When prioritizing risk remediation efforts, it is crucial to align them with the organization's risk appetite. By comparing identified risks to the risk appetite, organizations can determine the level of priority for remediation. This ensures that resources are allocated effectively and that risks are addressed in a manner consistent with the organization's risk tolerance and strategic objectives. While the other options may also have relevance in the risk prioritization process, they are not as fundamental as aligning with risk appetite:
upvoted 4 times
[Removed]
10 months, 2 weeks ago
this is a chatgpt answer and wrong
upvoted 4 times
...
...
bambs
1 year, 1 month ago
Selected Answer: D
While all the options listed are important considerations when prioritizing risk remediation, the impact of compliance (Option D) should be the most important consideration. Compliance with legal, regulatory, and contractual obligations is critical for any organization, and failure to comply can result in significant legal, financial, and reputational consequences.
upvoted 1 times
...
pcheng
1 year, 1 month ago
Selected Answer: A
Risk assessment always is the key
upvoted 2 times
...
MyExamPrep7854521
1 year, 2 months ago
Selected Answer: D
D:Impact of compliance Risk Already evaluated then considering Risk mitigation prioritization.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...