exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 394 discussion

Actual exam question from Isaca's CISM
Question #: 394
Topic #: 1
[All CISM Questions]

When making decisions on prioritizing risk mitigation activities, which of the following would provide senior management with the MOST comprehensive information?

  • A. Risk assessment report
  • B. Risk action plan
  • C. Risk register
  • D. Internal audit report
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CarlLimps
Highly Voted 1 year, 8 months ago
Selected Answer: C
C. I understand what Bro is saying below about answer A. But a risk register is to be more comprehensive then just one assessment, right? It should be way more comprehensive then a risk assessment. Two cents.
upvoted 7 times
Sborrainculo
1 year, 8 months ago
you understand that he's using chat GPT and therefore giving misleading answers?
upvoted 7 times
...
...
nezeranonymous
Most Recent 1 week ago
Selected Answer: A
A. Risk assessment report
upvoted 1 times
...
AlexJacobson
10 months ago
Selected Answer: C
A risk register is the inventory of all existing risks of an organization. The best method to understand any kind of risk is to review the risk register. It includes details of all risks along with relevant control activities. The most effective use of a risk register is to facilitate a thorough review of all risks on a periodic basis. So I'd say it's C.
upvoted 3 times
...
Saisharan
11 months, 3 weeks ago
A risk Assessment Report would help the senior management understand that what is the key things happening in the risk - So Option A is correct
upvoted 1 times
...
POWNED
11 months, 4 weeks ago
Selected Answer: C
Risk Assessment is used to identify, analyze, and evaluate effectiveness of controls, this is done after the risk has already been addressed. The correct answer is Risk Register.
upvoted 2 times
...
XJ
1 year ago
C- Risk assessment is a process of risk identification, evaluation and prioritization that would result in a formal risk assessment document. Risk register is a document that contains a list of all the risks identified by the company and prioritized in order of importance.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
A. Risk assessment report A risk assessment report typically includes an analysis of various risks, their likelihood, impact, and potential consequences, as well as recommended mitigation strategies. It often provides a broader and more comprehensive overview of risks compared to the other options listed.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: A
Risk register if normally a document that contains a list of all the risks identified by the company and prioritised in order of importance. IMHO Risk assessment is the process of risk identification, evaluation and prioritisation that would result in a formal risk assessment document and would include a Risk Register as well as risk maps, risk action plans, control activities and communication protocols.
upvoted 3 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
Risk Register. The risk assessment report produces a risk register which you will use to prioritize mitigations
upvoted 2 times
...
jennarink13
1 year, 4 months ago
C. Although RA results in prioritization of risks, the risk register is the most comprehensive source here which gives a view of the current risk profile and risk assessment results are reflected also in the risk register. Also, from CRISC QAE, the best value derived from the risk register is that it drives risk response. So yeah, C for me.
upvoted 3 times
...
richck102
1 year, 5 months ago
A. Risk assessment report
upvoted 2 times
...
dedfef
1 year, 7 months ago
Selected Answer: A
risk assesment will show likelihood and impact of relevant risks. Risk register will include non relevant risks
upvoted 1 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
A risk assessment report provides senior management with the most comprehensive information for making decisions on prioritizing risk mitigation activities. A risk assessment is a systematic process for identifying, evaluating, and prioritizing risks to an organization. A risk assessment report typically includes an analysis of the likelihood and impact of identified risks, as well as a recommendation for risk mitigation strategies and activities.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...