exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 393 discussion

Actual exam question from Isaca's CISM
Question #: 393
Topic #: 1
[All CISM Questions]

Determining the risk for a particular threat/vulnerability pair before controls are applied can be expressed as:

  • A. the likelihood of a given threat attempting to exploit a vulnerability.
  • B. the magnitude of the impact, should a threat exploit a vulnerability.
  • C. a function of the cost and effectiveness of controls over a vulnerability.
  • D. a function of the likelihood and impact, should a threat exploit a vulnerability.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jess20
1 month, 2 weeks ago
Selected Answer: D
D. a function of the likelihood and impact, should a threat exploit a vulnerability
upvoted 1 times
...
Agamennore
4 months, 2 weeks ago
Selected Answer: D
Risk involve impact and likelihood
upvoted 1 times
...
richck102
6 months, 3 weeks ago
D. a function of the likelihood and impact, should a threat exploit a vulnerability.
upvoted 2 times
...
mad68
8 months ago
Selected Answer: D
The correct answer is D. Determining the risk for a particular threat/vulnerability pair before controls are applied involves assessing both the likelihood of a given threat attempting to exploit a vulnerability and the magnitude of the impact that would result if the threat successfully exploits the vulnerability. Risk is often expressed as a function of the likelihood and impact of a threat exploiting a vulnerability. The likelihood refers to the probability or frequency of the threat event occurring, while the impact refers to the potential harm or damage that would result from the successful exploitation of the vulnerability. By considering both factors, organizations can better understand and prioritize their risks, allowing them to allocate appropriate resources and implement effective controls.
upvoted 2 times
...
Broesweelies
11 months, 3 weeks ago
Selected Answer: D
Determining the risk for a particular threat/vulnerability pair is a function of the likelihood and impact of the threat exploiting the vulnerability. The likelihood of a given threat attempting to exploit a vulnerability is an important factor in assessing the risk, as it determines the probability that the vulnerability will be exploited. The magnitude of the impact, should a threat exploit a vulnerability, is also an important factor, as it determines the potential harm or damage that could result from the exploitation of the vulnerability. Together, the likelihood and impact of a threat exploiting a vulnerability provide a comprehensive understanding of the risk associated with the threat/vulnerability pair. Cost and effectiveness of controls over a vulnerability is also important but it doesn't determine the risk level before controls are applied.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago