exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 340 discussion

Actual exam question from Isaca's CISM
Question #: 340
Topic #: 1
[All CISM Questions]

Which of the following should be the PRIMARY outcome of an information security program?

  • A. Threat reduction
  • B. Strategic alignment
  • C. Risk elimination
  • D. Cost reduction
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
beever
Highly Voted 1 year, 5 months ago
Selected Answer: B
B is correct according to CISM RM 16th 3.1.5 - Stategic alignment is one of the Outcomes of Information Security Program
upvoted 11 times
...
aokisan
Highly Voted 1 year, 6 months ago
Selected Answer: A
outcome should be reduction of threat.
upvoted 6 times
CISSPST
12 months ago
Threats can be detected and prevented but cannot be reduced as they are not in the organization's direct control, unlike vulnerabilities. Information security exists to support business objectives, therefore, strategic alignment is the primary outcome.
upvoted 3 times
...
...
Josef4CISM
Most Recent 6 months ago
Selected Answer: B
Its B, because information security needs to support business objectives. Therefore, information security and business must be strategically aligned. Its NOT A, because the amount of threats is something that cannot be influenced by information security. A threat is something that inherently exists, regardless of the security posture of your organization (e.g., ransomware). Its NOT C, because risks will most likely not be completely eliminated. Instead, risks must be reduced and managed to a appropriate level. Its NOT D, because cost is not the major concern of information security (although its an important concern).
upvoted 1 times
...
oluchecpoint
10 months ago
B. Strategic alignment While all the options listed are important aspects of an information security program, strategic alignment is the primary outcome because it ensures that the security program is closely aligned with the overall goals and objectives of the organization. Information security should not be seen as a standalone function but rather as an integral part of an organization's strategic plan. It should support and enable the organization to achieve its mission and goals while managing risks effectively. Threat reduction, risk elimination, and cost reduction are all important, but they are means to achieve the broader goal of strategic alignment.
upvoted 2 times
...
karanvp
1 year ago
A and C may not be a correct answer as Thread can't be reduced and Risk can't be eliminated
upvoted 1 times
...
richck102
1 year ago
B. Strategic alignment
upvoted 3 times
...
wello
1 year, 1 month ago
Selected Answer: B
Strategic Alignment
upvoted 2 times
...
Dravidian
1 year, 2 months ago
Selected Answer: B
Option A would make more sense if it said Risk reduction but it says threat reduction. B - Strategic Alignment is the most suited for the question.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...