exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 297 discussion

Actual exam question from Isaca's CISM
Question #: 297
Topic #: 1
[All CISM Questions]

Which of the following would provide the MOST useful information when prioritizing controls to be added to a system?

  • A. The risk register
  • B. Balanced scorecard
  • C. Compliance requirements
  • D. Baseline to industry standards
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oluchecpoint
11 months, 1 week ago
Selected Answer: A
A. The risk register: A risk register documents and assesses the various risks associated with a system. It helps organizations identify and prioritize risks based on their potential impact and likelihood. Prioritizing controls based on the identified risks is a common and effective approach to security and risk management.
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
A. The risk register: A risk register documents and assesses the various risks associated with a system. It helps organizations identify and prioritize risks based on their potential impact and likelihood. Prioritizing controls based on the identified risks is a common and effective approach to security and risk management.
upvoted 1 times
...
richck102
1 year, 7 months ago
A. The risk register
upvoted 1 times
...
jaiz
1 year, 10 months ago
Selected Answer: A
A risk register is a document or tool used to identify, assess, and prioritize risks in a project or organization. It typically includes information on the likelihood and potential impact of each risk, as well as any mitigation strategies that have been developed. The risk register helps organizations proactively manage risks and minimize their impact.
upvoted 2 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: A
A. The risk register would provide the MOST useful information when prioritizing controls to be added to a system. A risk register is a document that identifies, assesses, and prioritizes potential risks to an organization's assets, and it can be used to inform the development of security controls. The other options (B, C, and D) can provide useful information as well, but a risk register would be the most direct and informative way to identify and prioritize specific controls that need to be added to a system in order to mitigate identified risks.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...