Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1006 discussion

Actual exam question from Isaca's CISM
Question #: 1006
Topic #: 1
[All CISM Questions]

After a risk has been identified, analyzed, and evaluated, which of the following should be done NEXT?

  • A. Monitor the risk.
  • B. Prioritize the risk for treatment
  • C. Identify the risk owner.
  • D. Identify controls for risk mitigation.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Raj91188
1 month, 3 weeks ago
Selected Answer: C
C. Identify the risk owner. Risk ownership is critical because the risk owner is responsible for deciding how to manage the risk. This individual or entity is accountable for taking appropriate actions, whether that involves accepting, mitigating, transferring, or avoiding the risk. Without identifying the risk owner, it's difficult to move forward with risk treatment or monitoring. While prioritizing risks is important, the next step after risk evaluation should be identifying the risk owner. The owner can then be responsible for prioritizing and addressing the risk.
upvoted 1 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: B
Yep, after risk assessment (identification, analysis and evaluation) comes risk response/treatment. Now, I'm split between B and D, since the question says "risk" (singular), so what is there to prioritize (answer B). Then again, otpion D mentions just one of the possible risk treatment options (mitigation). Dunno, would go with B.
upvoted 1 times
...
richck102
1 year ago
Selected Answer: B
B. Prioritize the risk for treatment
upvoted 2 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: B
Once you've identified and analyzed the risks, it's important to prioritize them based on their potential impact and likelihood. This prioritization helps in deciding which risks should be addressed first and how to allocate resources for risk treatment. After prioritizing the risks, you can then proceed to identify controls for risk mitigation, identify the risk owner, and establish a plan to monitor the risks.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...