exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 560 discussion

Actual exam question from Isaca's CISM
Question #: 560
Topic #: 1
[All CISM Questions]

Which of the following is the MOST important outcome of effective risk treatment?

  • A. Implementation of corrective actions
  • B. Elimination of risk
  • C. Timely reporting of incidents
  • D. Reduced cost of acquiring controls
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bambs
Highly Voted 1 year, 11 months ago
Selected Answer: A
risk cannot be eliminated they can only be reduced.
upvoted 9 times
dark_3k03r
1 year, 8 months ago
This is incorrect. Some risks can be eliminated completely through risk mitigation, transfer, or avoidance. But most risks are not totally addressed cause it is not cost-effective or practical... but it is possible in some cases.
upvoted 2 times
Marcelus1714
11 months, 2 weeks ago
It says "the most important outcome", not "the most desirable outcome". For sure you want to eliminate the risk at 100%, if possible, but the most IMPORTANT is A
upvoted 1 times
...
...
...
shootnot
Most Recent 8 months ago
A- because risk can never be eliminated!
upvoted 1 times
...
Salilgen
10 months ago
Selected Answer: A
A includes B (when feasible)
upvoted 1 times
...
AlexJacobson
11 months, 2 weeks ago
Selected Answer: B
Word "elimination" really bothers me, but it is the best answer, since since some risks can indeed be eliminated though risk treatment option such as risk avoidance. If you stop doing the thing that brings risk, you effectively eliminated the risk, for all intents and purposes.
upvoted 2 times
...
Soleandheel
1 year, 1 month ago
A. Implementation of corrective actions is the correct answer. B. Elimination of risk is an ideal that cannot be achieved. It's like striving for the ideal of perfection. According to CISM Review Manual: Preparing for ISACA Certified Information Security Manager Exam by Gwen Bettwy, Mark Williams, Mike Beevers, Eliminating risk is not always practical or feasible.
upvoted 1 times
...
Marcovic00
1 year, 1 month ago
Selected Answer: B
I dont like the word elimination but it is still the best answer
upvoted 1 times
...
Nillanash
1 year, 5 months ago
I go with A- Implementation of corrective actions. The manner in which B is worded is not the correct answer because risk can never be eliminated until there is no risk left. Risk can only be mitigated.
upvoted 2 times
...
richck102
1 year, 6 months ago
A. Implementation of corrective actions
upvoted 2 times
...
dark_3k03r
1 year, 8 months ago
Selected Answer: B
The goal of risk treatment is to reduce the level of risk to an acceptable level that aligns with the organization's risk appetite and objectives. The closest one to this is (B) Elimination of Risk. Rationale: A. Implementation of corrective actions is incorrect cause this takes place after the risk has been realized, but the goal of risk treatment is preventative (i.e. before the risk is realized) C. Timely reporting of incidents is great, but it does nothing to address risks. D. Reduced cost of acquiring controls is great, but it does not reduce the risk.
upvoted 4 times
...
Broesweelies
1 year, 11 months ago
The most important outcome of effective risk treatment is the elimination or reduction of risk to an acceptable level. This is accomplished by implementing appropriate controls and measures to mitigate the potential impact of identified risks. Other outcomes, such as implementation of corrective actions, timely reporting of incidents and reduced cost of acquiring controls, are important aspects of risk management, but they are ultimately secondary to achieving the primary goal of reducing or eliminating risk.
upvoted 4 times
jennarink13
1 year, 6 months ago
bruh, risk cannot be eliminated regardless how effective internal controls are
upvoted 1 times
AlexJacobson
11 months, 2 weeks ago
Yes, it can actually - risk avoidance.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...