Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 128 discussion

Actual exam question from Isaca's CISM
Question #: 128
Topic #: 1
[All CISM Questions]

Which of the following is the MOST important reason for performing a cost-benefit analysis when implementing a security control?

  • A. To ensure that the mitigation effort does not exceed the asset value
  • B. To ensure that benefits are aligned with business strategies
  • C. To present a realistic information security budget
  • D. To justify information security program activities
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
david124
1 week, 4 days ago
Selected Answer: B
Going on B boys
upvoted 1 times
...
usercism007
5 months, 3 weeks ago
Select Answer: A Why the question is the MOST important reason and option A is right. If you see option B is talks about the Objective/Goal.
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: B
B. This approach helps in making informed decisions about which security controls to implement, prioritizing them based on their alignment with business goals, and justifying the allocation of resources to security activities in a way that makes sense for the organization as a whole.
upvoted 1 times
...
POWNED
11 months, 4 weeks ago
Selected Answer: A
Going to have to go with A for this one and this is why. Lots of the CISM questions revolve around stakeholders and costs. B seems like a throw off answer for test takers that do not know what they are talking about, never have I ever seen "ensure that benefits are aligned with business strategies" when talking about a cost benefit analysis, and this is coming from someone who has the Project+ certification. Again this test leans heavily on stakeholders and cost keep this in mind for future questions.
upvoted 3 times
...
marcelus
1 year, 1 month ago
if the control is not aligned with business strategies we don't really care if it costs more than the asset value..
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
B. This approach helps in making informed decisions about which security controls to implement, prioritizing them based on their alignment with business goals, and justifying the allocation of resources to security activities in a way that makes sense for the organization as a whole.
upvoted 1 times
...
Goseu
1 year, 3 months ago
Selected Answer: A
A seems relevant.
upvoted 1 times
...
jjj378
1 year, 5 months ago
B. To ensure that benefits are aligned with business strategies
upvoted 1 times
...
richck102
1 year, 5 months ago
B. To ensure that benefits are aligned with business strategies
upvoted 3 times
...
Abhey
1 year, 6 months ago
Selected Answer: A
Performing a cost-benefit analysis helps to determine whether the cost of implementing a security control is justified by the benefits that it provides. By analyzing the potential costs and benefits of a control, an organization can ensure that the mitigation effort does not exceed the value of the asset being protected. This allows for a more efficient use of resources and helps to prioritize the implementation of security controls based on their expected impact.
upvoted 2 times
...
jcmu11
1 year, 7 months ago
Selected Answer: B
Answer B: The MOST important reason for performing a cost-benefit analysis when implementing a security control is to ensure that benefits are aligned with business strategies. By conducting a cost-benefit analysis, the information security manager can evaluate the potential benefits of a security control against the costs of implementation and maintenance. This enables the manager to identify controls that provide the best return on investment and align with the organization's overall business strategies. It also helps in prioritizing security controls and making informed decisions about which security measures to implement.
upvoted 3 times
[Removed]
1 year, 4 months ago
bro stop using chatgpt
upvoted 6 times
[Removed]
1 year, 3 months ago
Fr... It's literally A, says directly in ISACA's review manual..... "A cost-benefit analysis should be performed to justify the investment in controls to mitigate risks. Controls should not be more costly than the impact of the risk event's consequences if it occurs. The cost of implementing and maintaining controls (mitigation) should not exceed the value of the asset at risk." Dudes have no idea how bad chatgpt can be with tight questions, especially ones based specifically on specific editions, not just "In general".
upvoted 4 times
seric01
8 months, 2 weeks ago
CHAGPT suggests A.
upvoted 1 times
...
...
...
...
jcmu11
1 year, 7 months ago
Answer B: The MOST important reason for performing a cost-benefit analysis when implementing a security control is to ensure that benefits are aligned with business strategies. By conducting a cost-benefit analysis, the information security manager can evaluate the potential benefits of a security control against the costs of implementation and maintenance. This enables the manager to identify controls that provide the best return on investment and align with the organization's overall business strategies. It also helps in prioritizing security controls and making informed decisions about which security measures to implement.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...