Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 146 discussion

Actual exam question from Isaca's CISM
Question #: 146
Topic #: 1
[All CISM Questions]

Which of the following is the MOST relevant information to include in an information security risk report to facilitate senior management's understanding of impact to the organization?

  • A. Detailed assessment of the security risk profile
  • B. Risks inherent in new security technologies
  • C. Findings from recent penetration testing
  • D. Status of identified key security risks
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 10 months ago
Selected Answer: D
D it is.
upvoted 5 times
...
msky2k
Most Recent 2 months ago
Selected Answer: D
D it is
upvoted 1 times
...
helg420
6 months, 1 week ago
Selected Answer: D
D. Status of identified key security risks To facilitate senior management's understanding of the impact on the organization, the most relevant information to include in an information security risk report is the status of identified key security risks. Senior management needs concise and significant information that directly relates to the organization's strategic objectives and operational integrity. Providing them with the current status of key security risks (including their severity, potential impact on business operations, and the measures taken or proposed for mitigation) directly supports strategic decision-making. This information allows senior management to gauge how these risks might affect the organization's goals and what actions are needed to address them. Unlike the detailed technical specifics which might be less accessible to individuals without a technical background (options A, B, and C), focusing on the status of key risks provides a clear and immediate connection to business outcomes and priorities.
upvoted 3 times
...
gigig76
8 months ago
why C pen test finding is the answer?
upvoted 1 times
...
oluchecpoint
9 months, 3 weeks ago
Selected Answer: D
D. Status of identified key security risks The most relevant information to include in an information security risk report to facilitate senior management's understanding of the impact on the organization is the "Status of identified key security risks." This information provides senior management with a clear and concise overview of the organization's current security risk posture.
upvoted 1 times
...
learntstuff
11 months, 1 week ago
Selected Answer: D
senior management doesn't care about technical things. The just want to know what's going on, the effect it will have on the org., and if its going to get fixed. So D it is
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: D
A detailed assessment of the security risk profile, while comprehensive, may be too granular for senior management's level of understanding. Risks inherent in new security technologies may be relevant to long-term planning but not for immediate decision-making. Findings from recent penetration testing, while valuable, may require more technical expertise to interpret and contextualize. The status of identified key security risks, however, provides a direct and actionable update on the organization's most critical security concerns. It allows senior management to understand the progress made in mitigating these risks, identify any areas requiring additional attention, and make informed decisions about resource allocation and risk management strategies.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
D. Status of identified key security risks The most relevant information to include in an information security risk report to facilitate senior management's understanding of the impact on the organization is the "Status of identified key security risks." This information provides senior management with a clear and concise overview of the organization's current security risk posture.
upvoted 1 times
...
todush
1 year, 3 months ago
The results of penetration Testing should be integrated in the KRIs, so the right response is D.
upvoted 1 times
...
pc2502
1 year, 3 months ago
Its C only pen test reason :- The results of a Penetration Testing (PT) or Incident Response Process (IRP) relies heavily on security risk reports. Once the Penetration Testing is performed successfully, the analysts would create a report based on the findings of the test. After that, the security risk report would demonstrate what was discovered and what recommendations were provided, as well as ensuring that the risks were mitigated or eliminated altogether and findings of IP or IRP were conclusive.
upvoted 1 times
...
Kieran90
1 year, 4 months ago
Its C I think https://www.logsign.com/blog/the-main-elements-of-a-security-risk-analysis-report/
upvoted 2 times
...
jennarink13
1 year, 4 months ago
A is inclusive of all the choices mentioned
upvoted 1 times
...
karanvp
1 year, 5 months ago
The word "impact" match with the answer Pen Test> A Pen test pinpoint the actual impact by exploiting vulnerabilities.
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: A
Detailed assessment of the security risk profile. Risk profile is a holistic view of the risk for an organization.
upvoted 1 times
...
richck102
1 year, 5 months ago
D. Status of identified key security risks
upvoted 1 times
...
Abhey
1 year, 6 months ago
Selected Answer: D
This information provides a clear view of the organization's most significant risks and the potential impact they may have on the organization. It can help senior management make informed decisions about prioritizing security resources and funding, as well as provide a basis for ongoing risk management and mitigation efforts.
upvoted 1 times
...
MyExamPrep7854521
1 year, 8 months ago
Selected Answer: A
A. Detailed assessment of the security risk profile Which included D (Status of identified Risk Status)
upvoted 4 times
dark_3k03r
1 year, 7 months ago
Providing a detailed assessment of the security risk profile and discussing risks inherent in new security technologies may be important, but these pieces of information may not be as impactful as the status of identified key security risks. Senior management is responsible for making decisions that impact the organization's overall strategy, budget, and operations, and they need to understand the current state of the organization's security risks. Therefore, providing them with the status of identified key security risks will help them make informed decisions about the organization's security posture and allocate resources appropriately.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...