Threat and vulnerability assessments provide essential information to estimate and understand the level of risk facing an organization. By identifying potential threats and vulnerabilities, organizations can assess the likelihood and potential impact of various security incidents. This risk estimation forms the basis for making informed decisions about security controls, investments, and setting control objectives. While threat and vulnerability assessments contribute to elements of the organization's security posture (option D) and may influence control objectives (option C), the primary purpose is to assess and estimate the level of risk.
Threat and vulnerability assessments are important PRIMARILY because they are needed to estimate risk (Option B).
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Viperhunter
7 months, 1 week agocidigi
1 year, 4 months agoPOWNED
1 year, 5 months agoInvisibleComrade
1 year, 6 months agorichck102
1 year, 11 months agoSouvik124
2 years, 2 months ago