exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 731 discussion

Actual exam question from Isaca's CISM
Question #: 731
Topic #: 1
[All CISM Questions]

Which of the following is a desired outcome of information security governance?

  • A. Penetration test
  • B. A maturity model
  • C. Improved risk management
  • D. Business agility
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yottabyte
7 months ago
Selected Answer: B
I will go with B here; Reason: the question asks about desired outcome of information security governance which doesn't necessarily mean improved risk management as risk management will encompass more that IT Security, there will be other risks like supply chain, vendor risk and it will not only involve IT or IT Security. Business agility involves more than IT and IT security, if the product delivered by the business is rock solid and better than competitors then IT and IT security may aid to that achievement but not solely the main responsibility for business agility. A maturity model will provide the current state and the future state we want to get to by the process of continuious improvement which is governance.
upvoted 2 times
...
wickhaarry
1 year, 1 month ago
A Business Agility Business Agility is a people-centred, organisation-wide capability that enables a business to deliver value to a world characterised by ever-increasing volatility, uncertainty, complexity, and ambiguity.
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: C
Option C
upvoted 2 times
...
richck102
1 year, 3 months ago
C. Improved risk management
upvoted 1 times
...
karanvp
1 year, 4 months ago
Can rely on default answer and apply that in exam?
upvoted 1 times
...
mad68
1 year, 5 months ago
Selected Answer: C
C. Improved risk management. Information security governance is the framework and processes implemented to ensure that information security aligns with business objectives, manages risks effectively, and supports organizational goals. One of the key objectives of information security governance is to improve risk management practices.
upvoted 2 times
...
bambs
1 year, 7 months ago
Selected Answer: C
A desired outcome of information security governance is improved risk management.
upvoted 4 times
...
it_expert_cism
1 year, 7 months ago
it should be C means improved risk management
upvoted 1 times
...
Souvik124
1 year, 8 months ago
The desired outcome of information security governance is improved risk management
upvoted 1 times
...
Broesweelies
1 year, 8 months ago
Selected Answer: C
C. Improved risk management. One of the desired outcomes of information security governance is improved risk management. Effective information security governance helps organizations to better understand and manage the risks that they face, and to implement appropriate controls and procedures to mitigate those risks. This helps to ensure that the organization's information assets are protected, and that the organization is better positioned to respond to security incidents. Other outcomes of information security governance, such as penetration testing, a maturity model, and business agility, may be important as well, but they are not as directly related to the goal of improved risk management.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago