Courseiva

CISM Information Security Risk Management Practice Question

A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?

⚠ Common exam trap

The trap here is assuming quantitative analysis is always superior, when weak or missing data can make qualitative ranking more defensible for a new service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Qualitative analysis using structured scenario ranking with defined likelihood and impact scales.

When historical loss data is scarce, a structured qualitative analysis using consistent likelihood and impact scales lets the organization rank threats defensibly and allocate budget. It relies on expert judgment but remains repeatable and auditable, and it can transition to quantitative methods as actual incident and loss data become available for the new feature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Qualitative analysis using structured scenario ranking with defined likelihood and impact scales.

    Why this is correct

    Qualitative analysis with defined scales is appropriate when historical data is scarce, because it leverages expert judgment in a structured, repeatable way. Ranking scenarios by likelihood and impact gives leadership a defensible prioritization of threats and supports budget decisions. It can later be refined with quantitative data as the feature matures and incident information accumulates.

  • ✗

    A control self-assessment survey completed by the mobile development team.

    Why it's wrong here

    A control self-assessment gauges whether controls are designed and operating, but it does not rank external threats or estimate their business impact. It is useful for assurance and gap identification, not for the initial prioritization leadership requested. Using it as the primary method would leave the threat-ranking question unanswered and could introduce self-reporting bias.

  • ✗

    A penetration test of the mobile application to identify exploitable vulnerabilities.

    Why it's wrong here

    A penetration test identifies technical vulnerabilities but does not by itself prioritize business risk or compare threats for budget allocation. It is a control validation activity that can inform a risk assessment, yet it lacks the likelihood and impact framing leadership needs. Relying on it alone would produce a vulnerability list rather than a defensible risk ranking.

  • ✗

    Quantitative analysis using annualized loss expectancy derived from actuarial tables.

    Why it's wrong here

    Quantitative analysis is valuable but depends on reliable frequency and loss data. With limited historical data for a new mobile banking feature, actuarial tables may not reflect the specific threat landscape, producing false precision. Leadership would receive numbers that appear authoritative but rest on weak assumptions, which undermines defensibility rather than strengthening it.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.