exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 181 discussion

Actual exam question from Isaca's CISM
Question #: 181
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to include when reporting information security risk to executive leadership?

  • A. Key performance objectives and budget trends
  • B. Security awareness training participation and residual risk exposures
  • C. Risk analysis results and key risk indicators (KRIs)
  • D. Information security risk management plans and control compliance
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
afb4b17
1 month, 1 week ago
The key words here are " risk analysis results". These are not intended for executive management. The outcome of security awareness training and residual risk exposure are two items that both meet the criterion of interesting for executive leadership.
upvoted 2 times
...
oluchecpoint
5 months, 2 weeks ago
Selected Answer: C
Risk analysis results and KRIs
upvoted 1 times
...
DrTee
5 months, 4 weeks ago
Selected Answer: C
Risk analysis results and KRIs provide the most concise and impactful information for executive leadership: Risk analysis results: Explain the identified risks, their likelihood, and potential impact on the organization's business objectives (e.g., financial losses, reputational damage). Key risk indicators (KRIs): Provide measurable data points that monitor the current state of risks and potential changes in their severity.
upvoted 1 times
...
Learner76
7 months, 3 weeks ago
Security awareness training, most important? Really?
upvoted 2 times
...
oluchecpoint
10 months, 2 weeks ago
C. Risk analysis results and key risk indicators (KRIs) When reporting information security risk to executive leadership, the most important information to include is risk analysis results and key risk indicators (KRIs). These provide a clear picture of the current state of security, potential vulnerabilities, and the impact of those vulnerabilities on the organization. Executive leadership needs this information to make informed decisions about how to prioritize resources and make strategic decisions related to information securitY
upvoted 1 times
...
Hugo1717
10 months, 3 weeks ago
Selected Answer: C
When reporting information security risk to executive leadership, it's essential to provide them with a clear understanding of the organization's risk landscape and the effectiveness of risk management efforts. Option C, "Risk analysis results and key risk indicators (KRIs)," is the most important to include. Options A, B, and D contain valuable information, but they are not as crucial as risk analysis results and KRIs for executive decision-making when it comes to managing information security risks.
upvoted 1 times
...
karanvp
1 year ago
Tricky question. But answer would be B as the the answer says "Residual Risk Exposure" which must update to Sr.Leaders
upvoted 2 times
...
wello
1 year, 1 month ago
Selected Answer: C
KRIs for sure.
upvoted 1 times
...
richck102
1 year, 1 month ago
C. Risk analysis results and key risk indicators (KRIs)
upvoted 2 times
...
sedardna
1 year, 1 month ago
Selected Answer: C
c SIN DUDA
upvoted 1 times
...
dedfef
1 year, 3 months ago
Selected Answer: C
C to the moon
upvoted 2 times
...
bambs
1 year, 6 months ago
Selected Answer: C
Definitely C
upvoted 1 times
...
Ziggybooboo
1 year, 7 months ago
C for me too
upvoted 1 times
...
D2D2
1 year, 7 months ago
Selected Answer: C
I am going with C
upvoted 1 times
...
toffboi
1 year, 7 months ago
Selected Answer: C
I would go with C.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago