Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 202 discussion

Actual exam question from Isaca's CISM
Question #: 202
Topic #: 1
[All CISM Questions]

The PRIMARY objective of a risk response strategy should be:

  • A. threat reduction.
  • B. senior management buy-in.
  • C. appropriate control selection.
  • D. regulatory compliance.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: C
The primary objective of a risk response strategy should be the selection of appropriate controls to mitigate identified risks to an acceptable level. This involves making decisions about the best ways to treat risks, such as avoiding the risk, transferring the risk to another party, reducing the negative impact of the risk, or accepting the risk. The selection of appropriate controls is the foundation for effective risk management and helps ensure that resources are directed towards the most critical risks facing the organization. While other factors, such as regulatory compliance and senior management buy-in, may be important considerations in the risk response process, the primary objective should always be the selection of appropriate controls to effectively manage risks.
upvoted 5 times
...
Jess20
Most Recent 4 weeks ago
Selected Answer: C
C.selection of controls You cannot reduce the threats, they are external, you cannot control them
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: C
C. appropriate control selection.
upvoted 1 times
...
karanvp
1 year, 5 months ago
"A" is wrong as Threat can't be reduced
upvoted 2 times
...
richck102
1 year, 5 months ago
C. appropriate control selection.
upvoted 1 times
...
Q_K
1 year, 8 months ago
Selected Answer: C
Risk response can be in the form of risk mitigation, risk acceptance, risk avoidance, or risk transfer.
upvoted 3 times
...
baranikumar_v
1 year, 10 months ago
A. Reduction of threats/risks. Risk reduction is the objective of risk response plan by the way of avoid/transfer/accept/mitigate. D is incorrect as Use of appropriate control measures or mechanisms is part of mitigate strategy.
upvoted 1 times
...
aokisan
1 year, 11 months ago
Selected Answer: A
objective is to reduce the threat. C is not objective.
upvoted 1 times
User21
1 year, 6 months ago
Threat always remains constant, you can only reduce threat exposure or attack surface.
upvoted 1 times
...
...
D2D2
2 years ago
Selected Answer: A
PRIMARY objective would be to reduce the threat.
upvoted 3 times
D2D2
2 years ago
After further review in the ISACA manual... One of the Risk response options is to use appropriate control measures or mechanisms. So it may be C after all. What is your opinion?
upvoted 4 times
romero318
1 year, 6 months ago
Well if that is what the manual says......
upvoted 2 times
...
...
digualada
1 year, 5 months ago
Threats are external actors, you can't reduce them. The only thing you can do is to reduce your risk exposure to threats by applying proper controls
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...