ExamGecko
Question list
Search
Search

Question 8 - CISM discussion

Report
Export

Which of the following is an example of risk mitigation?

A.
Purchasing insurance
Answers
A.
Purchasing insurance
B.
Discontinuing the activity associated with the risk
Answers
B.
Discontinuing the activity associated with the risk
C.
Improving security controls
Answers
C.
Improving security controls
D.
Performing a cost-benefit analysis
Answers
D.
Performing a cost-benefit analysis
Suggested answer: C

Explanation:

Improving security controls is an example of risk mitigation, which is the process of reducing the likelihood or impact of a risk. Risk mitigation can be achieved by implementing various strategies, such as purchasing insurance, discontinuing the activity associated with the risk, or improving security controls. Purchasing insurance is a form of risk transfer, which is the process of shifting the responsibility or burden of a risk to another party. Discontinuing the activity associated with the risk is a form of risk avoidance, which is the process of eliminating or avoiding a potential source of harm.Performing a cost-benefit analysis is a form of risk evaluation, which is the process of assessing the costs and benefits of different options to manage a risk.Reference= CISM Review Manual, 16th Edition, page 1741; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 802

asked 01/10/2024
jim eagleton
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first