Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 130 discussion

Actual exam question from Isaca's CISM
Question #: 130
Topic #: 1
[All CISM Questions]

Which of the following information BEST supports risk management decision making?

  • A. Results of a vulnerability assessment
  • B. Estimated savings resulting from reduced risk exposure
  • C. Average cost of risk events
  • D. Quantification of threats through threat modeling
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 6 months ago
Selected Answer: D
The correct answer is (D.) Quantification of threats through threat modeling is the correct answer as threat modeling identifies the threat and quantification lets you know the likelihood and impact which is needed for the decision-making process. Rationale: A. Results of a vulnerability assessment says what is vulnerable, but don't provide the context as to which to resolve. B. Estimated savings resulting from reduced risk exposure money is important, but this is too early in the stage for this. C. Average cost of risk events is incorrect cause money is important, but this is too early in the stage for this.
upvoted 9 times
...
oluchecpoint
Highly Voted 1 year, 2 months ago
B. Estimated savings resulting from reduced risk exposure. While all the options listed (A, B, C, and D) are valuable for risk management decision-making, estimated savings resulting from reduced risk exposure provides a direct link between risk management efforts and potential financial benefits. This information helps organizations assess the return on investment (ROI) for implementing specific risk mitigation measures.
upvoted 5 times
...
5fd6335
Most Recent 2 weeks, 5 days ago
it is D. Yes, quantifying threats through threat modeling is considered a key part of the risk management decision-making process, as it allows organizations to identify, analyze, and prioritize potential security risks by assigning numerical values to the likelihood and impact of different threats, enabling informed decisions about mitigation strategies and resource allocation.
upvoted 1 times
...
helg420
6 months, 1 week ago
Selected Answer: D
D. Quantification of threats through threat modeling Quantification of threats through threat modeling provides the most comprehensive information for supporting risk management decision-making. This approach not only identifies potential threats but also assesses their likelihood and potential impact in a structured manner. By understanding the specific threats to assets and evaluating their severity and probability, decision-makers can prioritize security measures more effectively. This allows for a strategic allocation of resources to address the most significant risks, ensuring that mitigation efforts are both efficient and effective.
upvoted 1 times
...
[Removed]
1 year ago
Selected Answer: B
Totally agree with oluchecpoint
upvoted 2 times
...
DavoA
1 year, 3 months ago
Selected Answer: D
Totally agree with dark_3k03r
upvoted 1 times
...
richck102
1 year, 5 months ago
A. Results of a vulnerability assessment
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: A
The results of a vulnerability assessment provide critical information regarding the potential weaknesses in an organization's systems and infrastructure. This information can be used to prioritize risk management efforts and allocate resources effectively. Vulnerability assessments can help identify potential security gaps and provide insights on how to address them, allowing organizations to make informed decisions about risk management. While the other options may provide useful information, they do not directly support risk management decision-making to the same extent as vulnerability assessment results.
upvoted 3 times
[Removed]
1 year, 4 months ago
these chatgpt answers are ruining the site. How can vulnerability assessment help Risk Management decisions?
upvoted 6 times
...
...
Abhey
1 year, 6 months ago
Selected Answer: A
A. Results of a vulnerability assessment would be the best information to support risk management decision making. Vulnerability assessments provide an inventory of vulnerabilities, as well as their likelihood of exploitation and potential impacts. This information can be used to determine which vulnerabilities should be addressed first and how to allocate resources to best mitigate risk.
upvoted 1 times
dark_3k03r
1 year, 6 months ago
Vulnerability assessment does not include the likelihood of it being exploited. That is done in the risk analysis process which uses vulnerability assessment as an input.
upvoted 1 times
...
...
dedfef
1 year, 8 months ago
Selected Answer: D
D is the correct answer
upvoted 3 times
...
Prospect57
1 year, 10 months ago
Selected Answer: A
A is my answer. I feel like understanding the results of a vulnerability assessment helps with risk management. Risks are in the form of vulnerabilities and threats.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...