Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 174 discussion

Actual exam question from Isaca's CISM
Question #: 174
Topic #: 1
[All CISM Questions]

Which of the following components of an information security risk assessment is MOST valuable to senior management?

  • A. Residual risk
  • B. Return on investment (ROI)
  • C. Mitigation actions
  • D. Threat profile
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ATT5832
1 month, 1 week ago
Selected Answer: B
Senior management is most concerned about ROI, which includes any impact to the residual risk brought on by the investment.
upvoted 1 times
...
Soleandheel
1 year ago
B. Return on investment (ROI). Guys this is what is most important to senior management. Senior management is looking at the results on the overall business. What is the return on the company's investment in said program. The ROI is key metric that senior management reviews to determine if an activity in the business was worth it or not.
upvoted 2 times
AlexJacobson
10 months ago
ROI is not calculated during risk assessment, residual risk is.
upvoted 4 times
...
...
oluchecpoint
1 year, 2 months ago
A. Residual risk Residual risk refers to the level of risk that remains after mitigation measures have been implemented. Senior management is primarily concerned with understanding the overall risk exposure and what risks are still present even after taking preventive and mitigative actions. This information helps them make informed decisions about resource allocation, risk tolerance, and strategic planning.
upvoted 2 times
...
richck102
1 year, 5 months ago
A. Residual risk
upvoted 2 times
...
Broesweelies
1 year, 10 months ago
Selected Answer: A
A. Residual risk is considered the most valuable component of an information security risk assessment to senior management according to ISACA. It allows them to understand the remaining level of risk after mitigation actions have been implemented, and make informed decisions about how to allocate resources to further reduce risk.
upvoted 3 times
...
MyKasala
1 year, 10 months ago
Selected Answer: A
A is correct
upvoted 2 times
...
baranikumar_v
1 year, 10 months ago
D. Threat profile Threat Profile gives you a composite picture of the most important and relevant cyber threats to your organization and how those threats are likely to materialize and impact you and your partners, now and in the future. Say for example the threat profile for a manufacturing industry(NIST IR8183) will look different from the threat profile for a smart grid(NIST IR2051).
upvoted 2 times
...
aokisan
1 year, 11 months ago
Selected Answer: B
management need to evaluate the value of cost.
upvoted 1 times
Ziggybooboo
1 year, 11 months ago
ROI of what, a risk assessment was completed, no risk treatment carried
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...