exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 972 discussion

Actual exam question from Isaca's CISM
Question #: 972
Topic #: 1
[All CISM Questions]

Which of the following is MOST effective in monitoring an organization's existing risk?

  • A. Vulnerability assessment results
  • B. Security information and event management (SIEM) systems
  • C. Periodic updates to risk register
  • D. Risk management dashboards
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HN2025
1 month ago
Selected Answer: C
Dashboard are not meant for monitoring, I think C which allows for continuous monitoring of the statues of the risk in the risk register which is updated frequently
upvoted 1 times
...
Uncle_Lucifer
8 months, 3 weeks ago
Selected Answer: D
SIEM is for monitoring threats and possible incidents. Risk management is different, and SIEM is not appriopriate for such task. D is the only viable answer. Why is the answer showing B as the best when more people selected D?
upvoted 1 times
...
koala_lay
10 months, 1 week ago
Selected Answer: D
Out of the options provided, the most effective method for monitoring an organization's existing risk would likely be D. Risk management dashboards. Risk management dashboards are specifically designed to provide a comprehensive overview of an organization's risk landscape. They consolidate and display relevant risk information in a visually accessible format, allowing stakeholders to quickly identify and assess potential risks. These dashboards typically include key risk indicators, metrics, and trends, enabling organizations to track risk levels, monitor mitigation efforts, and make informed decisions based on real-time data. security information and event management (SIEM) systems (option B) are valuable tools for identifying and addressing specific security vulnerabilities and incidents, they may not provide the broader context needed for comprehensive risk monitoring.
upvoted 2 times
...
richck102
10 months, 1 week ago
Selected Answer: D
D. Risk management dashboards
upvoted 2 times
...
oluchecpoint
10 months, 4 weeks ago
Selected Answer: B
B. Security information and event management (SIEM) systems SIEM systems are highly effective in monitoring an organization's existing risk. SIEM systems collect and analyze data from various sources, including network devices, servers, applications, and security logs. They provide real-time monitoring, correlation, and analysis of security events and incidents. By analyzing this data, SIEM systems can detect anomalies, potential threats, and vulnerabilities in the organization's environment.
upvoted 3 times
...
Saisharan
11 months, 3 weeks ago
Option B - it is most effective monitoring and real-time visibility into existing risks
upvoted 2 times
AlexJacobson
7 months ago
heh good luck on your CISM with this level of knowledge... xD
upvoted 2 times
...
AlexJacobson
7 months ago
SIEM is literally monitoring events, not even the incidents, let alone risks.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago