exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 327 discussion

Actual exam question from Isaca's CISM
Question #: 327
Topic #: 1
[All CISM Questions]

When preventive controls to appropriately mitigate risk are not feasible, which of the following is the MOST important action for the information security manager?

  • A. Identifying unacceptable risk levels
  • B. Assessing vulnerabilities
  • C. Evaluating potential threats
  • D. Managing the impact
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 10 months, 3 weeks ago
Selected Answer: D
Risk is a function of probability and impact. When mitigating risk there are only two things that can be mitigated to reduce risk: Probability and impact. The probability is reduced by preventative controls. This means that the only thing left to reduce is impact option (D). Rationale: (A) The identification has already been done (B) the vulnerability has already been identified that is how the controls were selected to mitigate the risk as best as possible. (C) The threat has already been identified as controls has already been applied.
upvoted 12 times
...
9e4dc07
Most Recent 1 month, 1 week ago
Selected Answer: A
It is required to identify residual risk after applying the controls and then take actions ( Risk mitigation methods) on residual risk based on risk appetite
upvoted 1 times
...
Soleandheel
3 months, 1 week ago
A. Identifying unacceptable risk levels is the correct answer. For those of you who say D. Managing the impact, keep in mind that you cannot manage the risk impact without first of all identifying if the risk level is acceptable or not. If the risk is within the company's risk appetite level then Managing the impact can happen. However, if the risk exceeds the company's risk appetite then eliminating the risk will be the next step. Managing the impact will not be relevant in that case. So A. is the correct answer.
upvoted 2 times
...
oluchecpoint
5 months, 3 weeks ago
D. Managing the impact
upvoted 1 times
...
Hugo1717
6 months, 1 week ago
Selected Answer: A
The correct answer is A. Identifying unacceptable risk levels. Explanation: When preventive controls to mitigate risk are not feasible, the most important action for the information security manager is to identify unacceptable risk levels. Here's why this option is the most important: A. Identifying unacceptable risk levels: In situations where preventive controls are not feasible, it's important to assess the potential risks that remain and determine if they are at an unacceptable level for the organization. Identifying unacceptable risk levels helps prioritize resources for appropriate risk treatment strategies, which could include alternative controls, risk acceptance, risk avoidance, or risk transfer. D. Managing the impact: Managing the impact is a key consideration, but identifying unacceptable risk levels comes before managing the impact. If risk levels are deemed unacceptable, strategies to manage the impact would be determined.
upvoted 3 times
...
[Removed]
7 months, 3 weeks ago
Selected Answer: D
The whole job of Information Security is managing the impact
upvoted 1 times
...
richck102
8 months, 4 weeks ago
A. Identifying unacceptable risk levels
upvoted 1 times
...
sedardna
9 months, 1 week ago
Creo que D es la única viable. Ya has aceptado el riesgo...
upvoted 1 times
...
mad68
9 months, 3 weeks ago
Selected Answer: A
A. Identifying unacceptable risk levels. In situations where preventive controls cannot adequately mitigate the identified risks, it is crucial for the information security manager to identify and understand the unacceptable risk levels. This involves assessing the potential impact and likelihood of the risks materializing and determining whether they exceed the organization's risk tolerance or acceptable levels of risk. By identifying unacceptable risk levels, the information security manager can focus on implementing appropriate risk management strategies, such as risk acceptance, risk transfer, or risk mitigation through other means.
upvoted 1 times
...
Abhey
10 months, 2 weeks ago
Selected Answer: A
When preventive controls to appropriately mitigate risk are not feasible, the MOST important action for the information security manager is to identify unacceptable risk levels. This involves determining the level of risk that the organization is willing to accept based on the potential impact to the organization and the likelihood of the threat occurring. From there, the organization can make an informed decision on whether to accept the risk or implement other controls to manage the risk.
upvoted 1 times
...
it_expert_cism
11 months, 4 weeks ago
Answer should be A or not
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago