Courseiva

CISM Information Security Risk Management Practice Question

An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)

⚠ Common exam trap

The trap here is treating the risk register as a catch-all repository for technical inventories, when ownership and likelihood and impact ratings are the essential governance elements of each entry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The likelihood and impact ratings used to determine the risk level.

A risk register entry must identify who owns the risk and how severe it is. The named owner provides accountability for treatment and reporting, while likelihood and impact ratings establish the risk level that drives prioritization. Supporting details such as product versions, access lists, and network diagrams live in other repositories and should be referenced rather than embedded in the register.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The likelihood and impact ratings used to determine the risk level.

    Why this is correct

    Likelihood and impact ratings are core to any risk entry because they establish the risk level used for prioritization and comparison across the register. Without these ratings, the organization cannot consistently rank risks or track whether treatment reduces exposure over time. They also connect the entry to the risk analysis methodology and the organization's defined risk criteria.

  • ✓

    A named risk owner accountable for treatment decisions.

    Why this is correct

    Every risk entry needs an assigned owner who is accountable for selecting and executing treatment and for reporting status. Without ownership, risks linger unresolved because no one is answerable. The owner is typically the business or process leader who controls the affected asset, not the security team, ensuring that treatment decisions align with business priorities and that accountability is clear.

  • ✗

    The complete network diagram of the data center hosting the asset.

    Why it's wrong here

    Network diagrams are architecture documentation referenced during assessment, not components of an individual risk entry. Embedding full diagrams makes the register unwieldy and duplicates information maintained elsewhere. The risk entry should instead reference the affected asset or process, leaving detailed topology in the configuration management or architecture repository where it is version controlled.

  • ✗

    The specific antivirus product version deployed on affected endpoints.

    Why it's wrong here

    Product version details belong in asset or configuration inventories, not in the risk register entry itself. A risk register captures the risk statement, its causes, likelihood, impact, and treatment. Recording a specific endpoint product version adds maintenance burden and becomes stale quickly, while contributing nothing to understanding or managing the underlying risk.

  • ✗

    The names of every employee who has access to the affected system.

    Why it's wrong here

    Full access lists are access management records, not risk register content. Including them would bloat the register with volatile data that changes constantly and is better maintained in identity and access management systems. The register should describe the risk and its treatment, not serve as a personnel or entitlement inventory for the affected system.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.