Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1334 discussion

Actual exam question from Isaca's CISA
Question #: 1334
Topic #: 1
[All CISA Questions]

When evaluating an information security risk assessment, what is MOST important to review to gain an understanding of how risk is reduced?

  • A. Inherent risk
  • B. Residual risk
  • C. Mitigation efforts
  • D. Control effectiveness
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
blehbleh
3 weeks, 4 days ago
Selected Answer: C
This is C. You have to know mitigation efforts are put in place.
upvoted 1 times
...
1e71ed5
3 months, 3 weeks ago
Any view about Residual Risk - When evaluating an information security risk assessment, Residual Risk is the most important to review to understand how effectively risks have been reduced. Here’s why: • Residual Risk represents the level of risk remaining after all mitigation efforts and controls have been applied. It directly shows the effectiveness of these risk management strategies in reducing the overall risk. • Mitigation Efforts and Control Effectiveness are important for understanding what measures are in place and how well they work. However, Residual Risk provides the final measure of the risk that still exists after these efforts, making it the most direct indicator of how much risk has been successfully reduced.
upvoted 2 times
...
Swallows
5 months, 3 weeks ago
Selected Answer: C
While both options C and D are relevant in assessing risk reduction, reviewing mitigation efforts (option C) offers a broader understanding of the proactive measures taken by the organization to mitigate security risks comprehensively.
upvoted 1 times
...
a84n
6 months, 2 weeks ago
Selected Answer: C
Answer is C Mitigation efforts refer to the actions taken to reduce or mitigate identified risks. while option D Control effectiveness refers to the extent to which implemented controls achieve their intended objectives.
upvoted 2 times
...
MJORGER
7 months, 1 week ago
Selected Answer: D
D. Control effectiveness Control effectiveness is a measure of how well controls are reducing risk. By evaluating the effectiveness of controls, you can understand how much risk is being mitigated.
upvoted 3 times
...
Sibsankar
9 months ago
Mitigation efforts refer to the actions and controls put in place to reduce the impact and likelihood of identified risks. so, the right choice is C.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...