CISM Information Security Risk Management Practice Question
An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?
⚠ Common exam trap
ISACA often tests the distinction between inherent risk and residual risk, trapping candidates who confuse control effectiveness (C) or risk appetite (A) as factors in inherent risk evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Likelihood of threat actors targeting the system
Inherent risk is the risk level before any security controls are applied. When evaluating inherent risk for a new cloud-based HR system, the likelihood of threat actors targeting the system (B) is a key factor because it directly influences the probability of a risk event occurring, independent of any existing or planned controls. This assessment considers the system's exposure, attractiveness to attackers, and the threat landscape specific to cloud HR platforms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Organization's risk appetite
Why it's wrong here
Risk appetite is used to evaluate whether residual risk is acceptable, not to calculate inherent risk.
- ✓
Likelihood of threat actors targeting the system
Why this is correct
Threat likelihood is a core component of inherent risk.
- ✗
Effectiveness of existing security controls
Why it's wrong here
Control effectiveness is considered when assessing residual risk, not inherent risk.
- ✓
Sensitivity of the data stored and processed
Why this is correct
Data sensitivity directly impacts the potential impact.
- ✓
Ease of exploiting vulnerabilities in the system
Why this is correct
Ease of exploitation affects the likelihood of a risk event.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.