exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 202 discussion

Actual exam question from Isaca's CISM
Question #: 202
Topic #: 1
[All CISM Questions]

The PRIMARY objective of a risk response strategy should be:

  • A. threat reduction.
  • B. senior management buy-in.
  • C. appropriate control selection.
  • D. regulatory compliance.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 2 years, 2 months ago
Selected Answer: C
The primary objective of a risk response strategy should be the selection of appropriate controls to mitigate identified risks to an acceptable level. This involves making decisions about the best ways to treat risks, such as avoiding the risk, transferring the risk to another party, reducing the negative impact of the risk, or accepting the risk. The selection of appropriate controls is the foundation for effective risk management and helps ensure that resources are directed towards the most critical risks facing the organization. While other factors, such as regulatory compliance and senior management buy-in, may be important considerations in the risk response process, the primary objective should always be the selection of appropriate controls to effectively manage risks.
upvoted 8 times
...
edmamol
Most Recent 2 weeks, 3 days ago
Selected Answer: A
WE have to be able to distinguish between the key words, OBJECTIVE and FUNCTION. Threat reduction is the final desired outcome of the any Risk Response Strategy. you create a strategy to achieve an objective or a goal. I do not see how "Appropriate control selection" can be an end goal or an objective. it is clearly a function that drives the objective. You select appropriate controls in order to reduce threats so it can not be C but A
upvoted 1 times
...
Adabach
3 weeks, 3 days ago
Selected Answer: A
The primary objective of a risk response strategy is A. threat reduction. A risk response strategy aims to minimize the potential negative impacts of identified risks by taking proactive measures to reduce their likelihood or severity. This aligns with the goal of threat reduction, as it seeks to actively address and lessen the threats facing an organization.
upvoted 1 times
...
Adabach
4 weeks, 1 day ago
Selected Answer: A
A risk response strategy aims to minimize the likelihood or impact of identified risks. Threat reduction directly addresses the core concern of risks posing a threat to an organization.
upvoted 1 times
Adabach
4 weeks, 1 day ago
Selecting appropriate controls is a component of a risk response strategy, but it's not the ultimate objective. The goal is to use those controls to reduce threats.
upvoted 1 times
...
...
Jess20
6 months ago
Selected Answer: C
C.selection of controls You cannot reduce the threats, they are external, you cannot control them
upvoted 1 times
...
oluchecpoint
1 year, 6 months ago
Selected Answer: C
C. appropriate control selection.
upvoted 1 times
...
karanvp
1 year, 10 months ago
"A" is wrong as Threat can't be reduced
upvoted 2 times
...
richck102
1 year, 10 months ago
C. appropriate control selection.
upvoted 1 times
...
Q_K
2 years, 1 month ago
Selected Answer: C
Risk response can be in the form of risk mitigation, risk acceptance, risk avoidance, or risk transfer.
upvoted 3 times
...
baranikumar_v
2 years, 3 months ago
A. Reduction of threats/risks. Risk reduction is the objective of risk response plan by the way of avoid/transfer/accept/mitigate. D is incorrect as Use of appropriate control measures or mechanisms is part of mitigate strategy.
upvoted 1 times
...
aokisan
2 years, 4 months ago
Selected Answer: A
objective is to reduce the threat. C is not objective.
upvoted 1 times
User21
1 year, 11 months ago
Threat always remains constant, you can only reduce threat exposure or attack surface.
upvoted 1 times
...
...
D2D2
2 years, 5 months ago
Selected Answer: A
PRIMARY objective would be to reduce the threat.
upvoted 3 times
D2D2
2 years, 5 months ago
After further review in the ISACA manual... One of the Risk response options is to use appropriate control measures or mechanisms. So it may be C after all. What is your opinion?
upvoted 4 times
romero318
1 year, 11 months ago
Well if that is what the manual says......
upvoted 2 times
...
...
digualada
1 year, 10 months ago
Threats are external actors, you can't reduce them. The only thing you can do is to reduce your risk exposure to threats by applying proper controls
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago