CISM Information Security Risk Management Practice Question
A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?
⚠ Common exam trap
A common mix-up: candidates confuse the purpose of risk assessment results—which is to prioritize based on business impact—with compliance or control reduction, leading them to select options like D or E that sound plausible but are not primary benefits of a risk-based approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Aligns security spending with business objectives
Option A is correct because risk assessment results tie each security project to the likelihood and impact of risks to business processes, so funding flows to initiatives that protect the organization's most important objectives and assets, aligning security spending with business priorities. Option B is correct because documented risk assessment outputs (identified threats, vulnerabilities, likelihood, and impact ratings) provide an auditable, defensible rationale for why specific security investments are chosen and prioritized, which is essential for justifying budgets to executives, auditors, and regulators. Option C is incorrect because risk-based prioritization still relies on qualitative analysis (for example, ordinal likelihood/impact scales) and often combines it with quantitative methods; it does not eliminate qualitative analysis. Option D is incorrect because risk assessment prioritization does not by itself guarantee compliance with all applicable regulations; compliance is a separate obligation that may require controls regardless of assessed risk level. Option E is incorrect because prioritizing projects by risk does not reduce the total number of security controls needed; it only orders which controls are implemented first, and a risk-based approach may even increase controls for high-risk areas.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Aligns security spending with business objectives
Why this is correct
Risk assessment results map each security project to the business risks it mitigates, so prioritisation directs spending toward initiatives protecting the most critical objectives. This satisfies the stem's requirement of aligning security investment with business goals.
- ✓
Provides a defensible justification for security investments
Why this is correct
Correct; risk-based approach supports business case for budget allocation.
- ✗
Eliminates the need for qualitative analysis
Why it's wrong here
Risk assessment outputs feed both qualitative and quantitative analysis; it does not remove the need for qualitative judgement, which remains essential for likelihood and impact scoring. It is tempting because risk-based prioritisation sounds purely quantitative, but qualitative analysis would be the correct emphasis when numeric data is unavailable or unreliable.
- ✗
Ensures compliance with all applicable regulations
Why it's wrong here
Risk-based prioritisation orders projects by exposure, not by regulatory mandate; a low-risk area may still carry compulsory obligations, so compliance is not guaranteed. It is tempting because regulators demand risk assessments, yet compliance-driven sequencing would be the correct framing when legal or contractual deadlines dictate the project order.
- ✗
Reduces the total number of security controls needed
Why it's wrong here
Prioritisation reorders and focuses controls; it does not necessarily reduce their total number, since high-risk areas may require additional or stronger controls. It is tempting because focusing effort on top risks appears to trim scope, but control reduction would be the correct objective only under a cost-optimisation mandate rather than a risk-prioritisation one.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.