Courseiva

CISM Information Security Risk Management Practice Question

An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?

⚠ Common exam trap

The trap here is treating the residual annualized loss expectancy or the pre-control value as the benefit instead of subtracting the post-control value from the pre-control value.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$120,000; the manager should compare it with the project cost and consider qualitative factors before recommending treatment.

Annualized loss expectancy equals single loss expectancy multiplied by annualized rate of occurrence. Before the project the value is $160,000; after it is $40,000; the expected annual risk reduction is $120,000. The manager should treat this as one input, comparing it with the project cost and weighing qualitative and regulatory factors before recommending treatment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    $120,000; the project cost exceeds the annual benefit and should be rejected outright.

    Why it's wrong here

    This figure confuses the calculation. The current annualized loss expectancy is $160,000 (0.04 × $4,000,000) and the post-project value is $40,000 (0.01 × $4,000,000), so the reduction is $120,000. Even if the reduction were correctly identified, rejecting outright ignores qualitative factors such as regulatory obligations, safety, and reputational damage that can justify controls beyond pure quantitative return.

  • ✗

    $40,000; the project should be approved because any reduction in high-impact risk is always cost-justified.

    Why it's wrong here

    $40,000 is the residual annualized loss expectancy after the project, not the reduction. The benefit is $120,000 per year. Claiming that any reduction is automatically justified ignores cost-benefit analysis, risk appetite, and alternative treatments such as insurance or geographic redundancy, which may deliver comparable risk reduction at lower cost or with additional resilience benefits.

  • ✓

    $120,000; the manager should compare it with the project cost and consider qualitative factors before recommending treatment.

    Why this is correct

    The current annualized loss expectancy is 0.04 × $4,000,000 = $160,000, and after the project it is 0.01 × $4,000,000 = $40,000, giving an expected annual risk reduction of $120,000. Because the $900,000 project cost exceeds a single year's benefit, the manager must weigh multi-year benefit, risk appetite, regulatory requirements, and non-quantifiable impacts before recommending the investment. This is a sound risk-treatment analysis.

  • ✗

    $160,000; the project is justified because the reduction equals the current annualized loss expectancy.

    Why it's wrong here

    $160,000 is the current annualized loss expectancy, not the reduction. The reduction is the difference between the current and post-project values: $160,000 minus $40,000 equals $120,000. Presenting the pre-control figure as the benefit overstates the value of the project and would mislead decision-makers about the return on the proposed investment.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.