exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 100 discussion

Actual exam question from Isaca's CISM
Question #: 100
Topic #: 1
[All CISM Questions]

Which of the following would BEST enable effective decision-making?

  • A. Annualized loss estimates determined from past security events
  • B. A universally applied list of generic threats, impacts, and vulnerabilities
  • C. A consistent process to analyze new and historical information risk
  • D. Formalized acceptance of risk analysis by business management
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sbear123
2 days, 14 hours ago
Selected Answer: D
With D, the business side is at-least part of the equation.
upvoted 1 times
...
be91d94
1 week, 5 days ago
Selected Answer: D
What if the consistent process is awful? With D, the business side is at-least part of the equation.
upvoted 1 times
...
helg420
7 months, 2 weeks ago
Selected Answer: C
C. A consistent process to analyze new and historical information risk A consistent process to analyze both new and historical information risk would BEST enable effective decision-making. This approach ensures a systematic and continuous review of information risk that is relevant to the organization's context. It allows for informed decisions based on a comprehensive understanding of the current risk landscape as well as past experiences. By applying a consistent methodology, organizations can identify, assess, and prioritize risks accurately and efficiently, ensuring that decision-makers are equipped with timely and relevant information to guide their actions.
upvoted 1 times
...
peelu
1 year ago
Selected Answer: D
D. Formalized acceptance of risk analysis by business management.
upvoted 1 times
...
Cyberbug2021
1 year, 1 month ago
Selected Answer: D
The answer is D. Formalized acceptance of risk analysis by business management. Formalized acceptance of risk analysis by business management is the most crucial factor in enabling effective decision-making. This is because it ensures that risk analysis is not just an academic exercise but is integrated into the organization's overall decision-making process.
upvoted 1 times
...
Viperhunter
1 year, 1 month ago
Selected Answer: C
Effective decision-making in information security requires a consistent process to analyze both new and historical information risks. This involves continuously assessing and understanding the evolving threat landscape, vulnerabilities, and potential impacts on the organization's assets. A standardized risk analysis process provides a framework for making informed decisions regarding risk mitigation strategies and resource allocation.
upvoted 1 times
...
oluchecpoint
1 year, 3 months ago
C. A consistent process to analyze new and historical information risk. Effective decision-making in the context of information security and risk management often relies on a consistent and well-defined process for assessing and analyzing risks. This process should take into account both new and historical information to provide a comprehensive understanding of the current risk landscape. This approach enables organizations to make informed decisions about risk mitigation, resource allocation, and other security measures. While the other options (A, B, and D) can be important components of an overall risk management strategy, having a consistent and adaptable risk analysis process is fundamental to making sound decisions in this area.
upvoted 1 times
...
richck102
1 year, 7 months ago
C. A consistent process to analyze new and historical information risk
upvoted 1 times
...
Abhey
1 year, 7 months ago
Selected Answer: C
C. A consistent process to analyze new and historical information risk would best enable effective decision-making. Decision-making requires a systematic approach to evaluate the risks associated with the options available.
upvoted 2 times
...
CISM_newbie
1 year, 8 months ago
It's a matter of wording. In order to conduct a consistent process of analyzing new/historical risk info there should first be a formalized acceptance of risk analysis conducted by the business mgt team. Once this is established, than there should be a consistent review, just my thoughts.
upvoted 3 times
...
bambs
1 year, 8 months ago
Selected Answer: C
Effective decision-making in information security requires a consistent and repeatable process for analyzing risk. This process should take into account both new and historical information, and should be able to adapt to changing circumstances, such as new threats or changes to the business environment.
upvoted 3 times
...
Antonivs
1 year, 10 months ago
Selected Answer: C
C seems the best answer
upvoted 2 times
...
ZeeM12
1 year, 11 months ago
I originally selected C but it says "consistent" vs. D says "formalized".
upvoted 3 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: C
C. A consistent process to analyze new and historical information risk would BEST enable effective decision-making. This allows for the continual assessment and re-evaluation of risks, taking into account new and historical information, in order to make informed and effective decisions about risk management.
upvoted 3 times
ccKane
1 year, 10 months ago
A consistent process to analyze new and historical information risk is also an important factor in enabling effective decision-making. It provides a structured approach for evaluating risk and ensures that all relevant information is taken into account when making decisions. However, without the formalized acceptance of risk analysis by business management, the risk analysis process may not be integrated into the decision-making process of the organization and may not have the necessary influence on decision-making. Therefore D: Formalized acceptance of risk analysis by business management would BEST enable effective decision-making because it ensures that the risk analysis process is integrated into the decision-making process of the organization and that risk is taken into account when making decisions. This helps to ensure that decisions are made with a full understanding of the potential risks and consequences, leading to better and more informed decision-making.
upvoted 4 times
...
...
Prospect57
1 year, 11 months ago
Selected Answer: C
C should be the answer here. A consistent process would better help with decision making; directly answering the question more so than a process by which management approves.
upvoted 1 times
...
mad68
2 years, 1 month ago
Selected Answer: C
I clicked the wrong box, its' "C"
upvoted 3 times
...
mad68
2 years, 1 month ago
Selected Answer: D
You make better decisions with up to date relevant information.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago