ExamGecko
Question list
Search
Search

Related questions

Question 117 - CISA discussion

Report
Export

Which of the following BEST indicates the effectiveness of an organization's risk management program?

A.
Inherent risk is eliminated.
Answers
A.
Inherent risk is eliminated.
B.
Residual risk is minimized.
Answers
B.
Residual risk is minimized.
C.
Control risk is minimized.
Answers
C.
Control risk is minimized.
D.
Overall risk is quantified.
Answers
D.
Overall risk is quantified.
Suggested answer: B

Explanation:

The effectiveness of a risk management program can be measured by how well it reduces the residual risk, which is the risk that remains after applying controls, to an acceptable level. Inherent risk is the risk that exists before applying any controls, and it cannot be eliminated completely. Control risk is the risk that the controls fail to prevent or detect a risk event, and it is a component of residual risk. Overall risk is not a meaningful metric for assessing the effectiveness of a risk management program, as it does not account for the impact and likelihood of different risk events.Reference:CISA Review Manual (Digital Version), Chapter 1, Section 1.2.2

asked 18/09/2024
Dean Pillay
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first