exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 130 discussion

Actual exam question from Isaca's CISM
Question #: 130
Topic #: 1
[All CISM Questions]

Which of the following information BEST supports risk management decision making?

  • A. Results of a vulnerability assessment
  • B. Estimated savings resulting from reduced risk exposure
  • C. Average cost of risk events
  • D. Quantification of threats through threat modeling
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oluchecpoint
Highly Voted 1 year, 9 months ago
B. Estimated savings resulting from reduced risk exposure. While all the options listed (A, B, C, and D) are valuable for risk management decision-making, estimated savings resulting from reduced risk exposure provides a direct link between risk management efforts and potential financial benefits. This information helps organizations assess the return on investment (ROI) for implementing specific risk mitigation measures.
upvoted 10 times
...
dark_3k03r
Highly Voted 2 years ago
Selected Answer: D
The correct answer is (D.) Quantification of threats through threat modeling is the correct answer as threat modeling identifies the threat and quantification lets you know the likelihood and impact which is needed for the decision-making process. Rationale: A. Results of a vulnerability assessment says what is vulnerable, but don't provide the context as to which to resolve. B. Estimated savings resulting from reduced risk exposure money is important, but this is too early in the stage for this. C. Average cost of risk events is incorrect cause money is important, but this is too early in the stage for this.
upvoted 9 times
...
nezeranonymous
Most Recent 2 weeks, 1 day ago
Selected Answer: B
Effective risk management decision-making relies on understanding the business impact of mitigating risks. Estimated savings from reduced risk exposure: Provide a clear cost-benefit view Help prioritize controls and investments Support communication with senior management and stakeholders ISACA emphasizes that risk-informed decisions should be made using quantitative, value-driven data — especially related to financial impact and risk reduction.
upvoted 1 times
...
hohan
4 months, 2 weeks ago
Selected Answer: B
The answer is B. Risk management decision-making requires actionable, business-focused information. Estimated savings from reduced risk exposure provide a clear, quantifiable measure of the financial benefits of mitigating risks. This aligns with CISM's emphasis on linking risk management to business objectives and demonstrating the value of risk mitigation to stakeholders.
upvoted 2 times
...
Vishalgupta26
5 months, 2 weeks ago
Selected Answer: B
This provides a clear financial basis for decision-making, allowing decision-makers to assess the value of mitigating a risk versus the cost of implementing controls. Understanding how much money can be saved by reducing the exposure to risk helps prioritize risk management actions and allocate resources effectively.
upvoted 1 times
...
5fd6335
7 months ago
it is D. Yes, quantifying threats through threat modeling is considered a key part of the risk management decision-making process, as it allows organizations to identify, analyze, and prioritize potential security risks by assigning numerical values to the likelihood and impact of different threats, enabling informed decisions about mitigation strategies and resource allocation.
upvoted 1 times
...
helg420
1 year ago
Selected Answer: D
D. Quantification of threats through threat modeling Quantification of threats through threat modeling provides the most comprehensive information for supporting risk management decision-making. This approach not only identifies potential threats but also assesses their likelihood and potential impact in a structured manner. By understanding the specific threats to assets and evaluating their severity and probability, decision-makers can prioritize security measures more effectively. This allows for a strategic allocation of resources to address the most significant risks, ensuring that mitigation efforts are both efficient and effective.
upvoted 1 times
...
[Removed]
1 year, 6 months ago
Selected Answer: B
Totally agree with oluchecpoint
upvoted 2 times
...
DavoA
1 year, 10 months ago
Selected Answer: D
Totally agree with dark_3k03r
upvoted 1 times
...
richck102
2 years ago
A. Results of a vulnerability assessment
upvoted 1 times
...
mad68
2 years ago
Selected Answer: A
The results of a vulnerability assessment provide critical information regarding the potential weaknesses in an organization's systems and infrastructure. This information can be used to prioritize risk management efforts and allocate resources effectively. Vulnerability assessments can help identify potential security gaps and provide insights on how to address them, allowing organizations to make informed decisions about risk management. While the other options may provide useful information, they do not directly support risk management decision-making to the same extent as vulnerability assessment results.
upvoted 3 times
[Removed]
1 year, 11 months ago
these chatgpt answers are ruining the site. How can vulnerability assessment help Risk Management decisions?
upvoted 7 times
...
...
Abhey
2 years ago
Selected Answer: A
A. Results of a vulnerability assessment would be the best information to support risk management decision making. Vulnerability assessments provide an inventory of vulnerabilities, as well as their likelihood of exploitation and potential impacts. This information can be used to determine which vulnerabilities should be addressed first and how to allocate resources to best mitigate risk.
upvoted 1 times
dark_3k03r
2 years ago
Vulnerability assessment does not include the likelihood of it being exploited. That is done in the risk analysis process which uses vulnerability assessment as an input.
upvoted 1 times
...
...
dedfef
2 years, 2 months ago
Selected Answer: D
D is the correct answer
upvoted 3 times
...
Prospect57
2 years, 4 months ago
Selected Answer: A
A is my answer. I feel like understanding the results of a vulnerability assessment helps with risk management. Risks are in the form of vulnerabilities and threats.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...