exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 29 discussion

Actual exam question from Isaca's CISM
Question #: 29
Topic #: 1
[All CISM Questions]

Deciding the level of protection a particular asset should be given is BEST determined by:

  • A. the corporate risk appetite.
  • B. a risk analysis.
  • C. a threat assessment.
  • D. a vulnerability assessment.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AWSgenio
Highly Voted 1 year, 4 months ago
At 1st i thought A. After re-reading the question, which "should" be given vs "will" be given. "Should be given" will be determined by Risk Analysis. "Will be given" will be risk appetite. So B for me.
upvoted 12 times
BamBamBigalo
1 year, 1 month ago
Thats a good exam tip, thank you
upvoted 2 times
...
...
Josef4CISM
Highly Voted 10 months, 2 weeks ago
A risk analysis includes the analysis of applicable threats by determining its applicability to the organization, its likelihood of impact and the severity of impact thereby deriving to a risk. Answer A is wrong, because the decision how to treat the risk is PARTIALLY determined by the organizations risk appetite. The risk treatment (including factors like an organizations risk appetite) is PART of a comprehensive risk analysis. Therefore, answer B is correct.
upvoted 6 times
...
Prat1597
Most Recent 1 week, 6 days ago
Selected Answer: B
Level of protection an asset should receive depends on the asset value and risk associated with the asset. So the answer is B
upvoted 1 times
...
Syma
1 month, 3 weeks ago
Selected Answer: B
SO/IEC 27005:2018 – Defines risk analysis as a core activity in deciding what protection is needed. NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, stresses that protection decisions should be driven by formal risk analysis. Why not the others? A. The corporate risk appetite → Important for accepting or rejecting risk, but it doesn't determine asset-specific protection needs. C. A threat assessment → Identifies potential threats, but does not factor in impact or vulnerability, so it lacks full context. D. A vulnerability assessment → Identifies system weaknesses, but not their impact or the likelihood of exploitation — which are key to deciding protection levels.
upvoted 1 times
...
homeysl
1 month, 3 weeks ago
Selected Answer: A
Asset value
upvoted 1 times
...
6b41e93
7 months ago
Selected Answer: B
risk analysis provides the most detailed and relevant information for deciding the level of protection needed for a specific asset, as it integrates considerations of threats, vulnerabilities, impacts, and likelihoods.
upvoted 1 times
...
240b34b
9 months, 2 weeks ago
Risk analysis could be a contributing factor to the corporate risk appetite.
upvoted 1 times
...
greeklover84
9 months, 4 weeks ago
Selected Answer: B
Ι think B is correct
upvoted 2 times
...
iyke2k4
10 months, 4 weeks ago
B seems like the correct answer. My justification is that risk analysis is required to determine the risk level.
upvoted 4 times
...
RagazzoAlex
12 months ago
Selected Answer: B
The question is asking a bout a specific asset and specific here is a key work. risk appetite is more generic
upvoted 3 times
...
Thavee
1 year, 3 months ago
Selected Answer: A
Risk appetite
upvoted 1 times
...
yottabyte
1 year, 4 months ago
Selected Answer: B
Risk analysis can be performed to determine the level of protection required to be provided to an asset.
upvoted 2 times
...
shervin2s
1 year, 4 months ago
Selected Answer: A
Conducting a risk analysis allows for a comprehensive evaluation of the threats, vulnerabilities, and potential impacts associated with specific assets. By analyzing these factors, organizations can make informed decisions about the level of protection required for each asset. Explanation of why other options are not correct: A. The corporate risk appetite: While the corporate risk appetite influences overall risk management decisions, including the allocation of resources and the establishment of risk tolerance levels, it does not directly determine the level of protection for individual assets. Risk appetite provides a high-level framework for decision-making but must be translated into specific risk analysis for each asset.
upvoted 4 times
...
oluchecpoint
1 year, 5 months ago
Selected Answer: A
Risk appetite
upvoted 2 times
...
CISSPST
1 year, 6 months ago
Selected Answer: A
Risk analysis gives the level of risk, not level of protection. After a risk analysis, the business then evaluates the level of (inherent/existing) risk against acceptable risk levels (RISK APETITE) to decide the level of protection to be provided, in a manner that the residual risk is within acceptable risk levels.
upvoted 4 times
...
TamerBeSafe
1 year, 7 months ago
The Corporate Risk Appetite: it is a broad guideline and does not provide specific details on the level of protection for individual assets.
upvoted 1 times
...
Uncle_Lucifer
1 year, 7 months ago
Selected Answer: A
Majority are wrong. Should be risk appetite
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...