Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 132 discussion

Actual exam question from Isaca's CISM
Question #: 132
Topic #: 1
[All CISM Questions]

Which of the following should be the PRIMARY driver for selecting and implementing appropriate controls to address the risk associated with weak user passwords?

  • A. The organization's risk tolerance
  • B. The organization's culture
  • C. The cost of risk mitigation controls
  • D. Direction from senior management
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
User21
Highly Voted 1 year, 6 months ago
Selected Answer: B
Its always people people people, if the people choose to use weak passwords then its a risk, culture eats strategy for breakfast. If you use a technical control to force, then they will end up writing down the complex password on a sticky note and sticking it to the monitor. People should be trained to select a strong password and manage it appropriately.
upvoted 5 times
...
ntgc
Most Recent 1 month ago
Selected Answer: A
A = because The organization tolerance for risk will determine their approach and mitigation strategies.
upvoted 2 times
...
alifjouj
2 months, 2 weeks ago
Selected Answer: A
risk level is the driver to implement controls
upvoted 1 times
...
Salilgen
9 months ago
Selected Answer: C
From CISM Review Manual: "3.8.1 Managing Risk Through Controls Controls can be physical, technical or administrative. The choise of controls must be based on a number of considerations including ensuring their effectiveness, thei cost or potential restriction to business activities, and their optimal form of control."
upvoted 3 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: A
A. The organization's risk tolerance. Risk tolerance is a critical factor in determining the appropriate controls for managing security risks, including those related to weak user passwords. The level of risk that an organization is willing to accept or tolerate will guide decisions about the strength and rigor of controls needed to mitigate the risk effectively. It involves assessing the potential impact of password-related vulnerabilities and aligning control measures accordingly. While other factors like the organization's culture, cost considerations, and direction from senior management are important, they should all be influenced by the organization's risk tolerance when making decisions about password security controls.
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: A
risk tolerance
upvoted 1 times
...
Manix
1 year ago
Selected Answer: B
B. Risk appetite will determine that action must be done, but what action would be will determine corporate culture.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
A. The organization's risk tolerance. Risk tolerance is a critical factor in determining the appropriate controls for managing security risks, including those related to weak user passwords. The level of risk that an organization is willing to accept or tolerate will guide decisions about the strength and rigor of controls needed to mitigate the risk effectively. It involves assessing the potential impact of password-related vulnerabilities and aligning control measures accordingly. While other factors like the organization's culture, cost considerations, and direction from senior management are important, they should all be influenced by the organization's risk tolerance when making decisions about password security controls.
upvoted 1 times
...
todush
1 year, 3 months ago
A : Access control has to primarily align with organization's risk tolerance. Organization culture may influence the choice of technology, but it cannot be at the expense of strategic risk tolerance.
upvoted 1 times
...
Jae_kes
1 year, 5 months ago
Selected Answer: A
A: The organization's risk tolerance.
upvoted 1 times
...
richck102
1 year, 5 months ago
A. The organization's risk tolerance
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: A
he PRIMARY driver for selecting and implementing appropriate controls to address the risk associated with weak user passwords should be A) The organization's risk tolerance. The organization's risk tolerance will help to determine the level of risk the organization is willing to accept and what controls are appropriate to manage the risk of weak user passwords. Factors such as the potential impact of a password breach, the likelihood of such a breach occurring, and the value of the assets protected by passwords will be considered in determining the appropriate controls.
upvoted 1 times
...
Abhey
1 year, 6 months ago
Selected Answer: A
The level of risk that an organization is willing to accept should guide the selection and implementation of controls to mitigate the risk of weak user passwords.
upvoted 1 times
...
bambs
1 year, 7 months ago
Selected Answer: A
The PRIMARY driver for selecting and implementing appropriate controls to address the risk associated with weak user passwords should be the organization's risk tolerance. Risk tolerance is the level of risk that an organization is willing to accept or tolerate, and it guides the selection of controls that are appropriate for managing the identified risks.
upvoted 1 times
...
jaiz
1 year, 8 months ago
Selected Answer: A
Why organization's culture become a primary driver ? Culture is more important than risk tolerance?
upvoted 1 times
...
Rowlandmarc
1 year, 8 months ago
Selected Answer: A
A would be the answer me personally because the tolerance would dictate the apropropriate options available to the business before then looking at cost of mitigating controls. If no options available meet budget then the budget or risk tolerance needs to change either way...
upvoted 1 times
...
Broesweelies
1 year, 10 months ago
Selected Answer: A
It is A according to ISACA.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...