Courseiva
Information Security Risk ManagementhardMultiple SelectObjective-mapped

CISM Information Security Risk Management Practice Question

An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?

⚠ Common exam trap

ISACA often tests the distinction between inherent risk and residual risk, trapping candidates who confuse control effectiveness (C) or risk appetite (A) as factors in inherent risk evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Likelihood of threat actors targeting the system

Inherent risk is the risk level before any security controls are applied. When evaluating inherent risk for a new cloud-based HR system, the likelihood of threat actors targeting the system (B) is a key factor because it directly influences the probability of a risk event occurring, independent of any existing or planned controls. This assessment considers the system's exposure, attractiveness to attackers, and the threat landscape specific to cloud HR platforms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Organization's risk appetite

    Why it's wrong here

    Risk appetite is used to evaluate whether residual risk is acceptable, not to calculate inherent risk.

  • Likelihood of threat actors targeting the system

    Why this is correct

    Threat likelihood is a core component of inherent risk.

  • Effectiveness of existing security controls

    Why it's wrong here

    Control effectiveness is considered when assessing residual risk, not inherent risk.

  • Sensitivity of the data stored and processed

    Why this is correct

    Data sensitivity directly impacts the potential impact.

  • Ease of exploiting vulnerabilities in the system

    Why this is correct

    Ease of exploitation affects the likelihood of a risk event.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.