Courseiva
Information Security Risk ManagementhardMultiple SelectObjective-mapped

CISM Communicating risk to board Practice Question

A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)

⚠ Common exam trap

The trap here is that candidates often select 'Detailed technical vulnerabilities' (B) thinking it demonstrates thoroughness, but the board requires business-impact language, not technical depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Monetary value of potential losses

Monetary value of potential losses (A) is correct because it translates technical risk into financial terms that board members understand, enabling informed decisions on resource allocation for risk mitigation. This aligns with the CISM focus on business-aligned risk communication, where quantitative metrics like Annualized Loss Expectancy (ALE) directly support cost-benefit analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Detailed technical vulnerabilities

    Why it's wrong here

    Board members typically lack technical background; focus on business impact.

  • Anecdotal stories of past incidents

    Why it's wrong here

    Anecdotes are not quantitative and may skew perception.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.

Monetary value of potential lossesCorrect answer
Detailed technical vulnerabilitiesWrong answer — click to see why

Why this is wrong here

Board members typically lack technical background; focus on business impact.

Anecdotal stories of past incidentsWrong answer — click to see why

Why this is wrong here

Anecdotes are not quantitative and may skew perception.

Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.