CISM Information Security Risk Management Practice Question
A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?
⚠ Common exam trap
CISM often tests the instinct to 'fix the number' (adjust parameters or appetite) rather than fix the process — candidates must recognize that independent validation, not parameter tuning, is the correct governance response to model risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a comprehensive model validation and sensitivity analysis
When a quantitative risk model consistently underestimates actual losses by a material margin (40% here), the model itself is the problem — its assumptions, distributions, correlations, or data inputs are flawed. The risk manager's obligation is to validate the model independently and stress-test its sensitivity to key assumptions before the board relies on its outputs. Model validation and sensitivity analysis directly address the root cause (model risk) rather than masking the symptom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perform a comprehensive model validation and sensitivity analysis
Why this is correct
Validation tests the model's conceptual soundness, data quality and assumptions against realised losses, while sensitivity analysis identifies which inputs drive the 40% underestimation. Peer review alone does not detect calibration drift, so this directly addresses the board's accuracy concern.
- ✗
Increase the risk appetite to accommodate the underestimation
Why it's wrong here
Raising the risk appetite merely redefines the tolerance threshold; it does not correct the 40% loss underestimation, so board reporting remains inaccurate and capital misstated. Risk appetite statements exist to set acceptable exposure boundaries, and would be the right lever only when current exposure genuinely sits within a deliberately chosen, board-approved tolerance.
- ✗
Replace the quantitative model with a qualitative risk assessment
Why it's wrong here
Qualitative assessment discards the quantification the board needs for capital and loss reporting, and does not diagnose why the Monte Carlo inputs understate losses. Qualitative methods suit early-stage or data-poor environments where credible loss distributions cannot be built, not a firm already running a peer-reviewed quantitative model.
- ✗
Adjust the model parameters to align with observed losses
Why it's wrong here
Back-fitting parameters to observed losses treats the symptom while leaving the underlying model risk — flawed distributions, dependencies or missing scenarios — unvalidated, so future estimates stay unreliable. Parameter calibration is correct once model logic is independently validated, not as a substitute for that validation.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.