Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 259 discussion

Actual exam question from ISC's CISSP
Question #: 259
Topic #: 1
[All CISSP Questions]

Which of the following is a risk matrix?

  • A. A tool for determining risk management decisions for an activity or system.
  • B. A database of risks associated with a specific information system.
  • C. A two-dimensional picture of risk for organizations, products, projects, or other items of interest.
  • D. A table of risk management factors for management to consider.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rollizo
Highly Voted 2 years, 1 month ago
Selected Answer: C
it could be C: https://www.microtool.de/en/knowledge-base/what-is-a-risk-matrix/
upvoted 8 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
YesPlease
Most Recent 11 months, 2 weeks ago
Selected Answer: C
Answer C) Yes it is a tool...but it does not determine what decisions you are going to make on risk management.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
A risk matrix is a two-dimensional picture of risk for organizations, products, projects, or other items of interest. It is a tool used during risk assessment to define the level of risk by considering the category of probability or likelihood against the category of consequence severity. Therefore, the correct answer is; C. A two-dimensional picture of risk for organizations, products, projects, or other items of interest.
upvoted 1 times
Soleandheel
11 months, 2 weeks ago
A risk matrix typically visualizes risk by plotting two factors, usually the likelihood of an event occurring and the potential impact or consequence of that event.
upvoted 1 times
...
...
Voxycs
1 year, 1 month ago
who wrote this question?
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: A
According to the CISSP Official Study Guide (9th Edition), the risk matrix is a tool to map probability and impact for criticality prioritization. It is just a tool and is not specific to any particular project or product. Therefore, option C is incorrect.
upvoted 3 times
...
sausageman
1 year, 8 months ago
Such bad wording.. leave so much for interpretation even know we all know what a risk matrix is or what it looks like
upvoted 2 times
...
RVoigt
1 year, 9 months ago
Selected Answer: C
From the CISSP Official Study Guide pg 77 - "A risk matrix or risk heat map is a form of risk assessment that is performed on a basic graph or chart. It is sometimes labeled as a qualitative risk assessment. The simplest form of a risk matrix is a 3x3 grid comparing probability and damage potential."
upvoted 3 times
...
DJOEK
1 year, 10 months ago
Selected Answer: C
A risk matrix is a two-dimensional chart that represents a visual representation of the risks associated with a specific activity, system, project, or organization. It typically includes two axes, one measuring the likelihood of a risk occurring and the other measuring the potential impact if it does occur. The resulting chart can be used to identify and prioritize risks based on their likelihood and impact. The risks are assigned to cells within the matrix, with each cell representing a particular level of risk. Typically, it will use different colors, shapes, or labels to indicate a specific level of risk which allows a quick visualization of the risks and their levels. A. A tool for determining risk management decisions for an activity or system. D. A table of risk management factors for management to consider. Both are related to risk management process, but not a specific tool.
upvoted 3 times
...
oudmaster
1 year, 11 months ago
Why not C?
upvoted 1 times
...
Jamati
2 years ago
Selected Answer: A
I think both A & C are correct, but A is more correct.
upvoted 3 times
...
rdy4u
2 years, 1 month ago
Selected Answer: A
A risk matrix is a matrix that is used during risk assessment to define the level of risk by considering the category of probability or likelihood against the category of consequence severity. This is a simple mechanism to increase visibility of risks and assist management decision making. https://en.wikipedia.org/wiki/Risk_matrix
upvoted 2 times
...
kptest12
2 years, 1 month ago
Selected Answer: A
https://fortsafe.com/managing-cybersecurity-risks-using-a-risk-matrix/
upvoted 2 times
...
krassko
2 years, 1 month ago
Selected Answer: A
Yes, it's A
upvoted 3 times
...
CuteRabbit168
2 years, 1 month ago
Selected Answer: A
It is possibly A https://www.wrike.com/blog/what-is-risk-matrix/#What-is-a-risk-assessment-matrix-in-project-management
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...