Courseiva

CISM Information Security Governance Practice Question

Which TWO factors are most important when prioritizing security investments? (Select TWO.)

⚠ Common exam trap

CISM often tests whether candidates default to cost or ease as the primary driver — the trap is picking 'cost of the solution' because budgets matter, but governance exams reward risk reduction and business alignment as the deciding factors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The level of risk reduction achieved

Option B (the level of risk reduction achieved) is correct because security investment prioritization should be driven by how much a control actually lowers identified risk, typically assessed through risk analysis that weighs likelihood and impact against the residual risk remaining after the control is applied. Option C (alignment with business objectives and strategy) is correct because security spending must support the organization's mission, compliance obligations, and strategic goals, ensuring that limited budget is directed toward protecting the assets and processes that matter most to the business. Options A, D, and E are not among the two most important factors: ease of implementation and cost are practical considerations but can lead to underinvesting in high-risk areas, and industry popularity is a weak justification since threat profiles and business contexts differ across organizations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ease of implementation

    Why it's wrong here

    Ease of implementation addresses delivery effort, not the risk or business value a control protects, so it cannot rank investment priorities. It tempts because low-effort controls ship quickly and show early progress, but that is a scheduling concern; prioritisation must follow risk exposure and potential business impact.

  • ✓

    The level of risk reduction achieved

    Why this is correct

    Prioritisation must weigh how much each investment actually reduces identified risk, since spend should target the greatest exposure. The level of risk reduction achieved is the direct measure of benefit, satisfying the constraint that limited budget be allocated where residual risk falls most.

  • ✓

    Alignment with business objectives and strategy

    Why this is correct

    Investments aligned with business objectives and strategy support the organisation's goals and priorities, ensuring security spending is treated as an enabler rather than an obstacle. This alignment secures executive backing and directs funding to controls that protect what the business most values.

  • ✗

    The cost of the security solution

    Why it's wrong here

    Purchase cost is a budget constraint, not a measure of risk reduction, so it cannot determine which investments rank highest. It tempts because budgets are finite and cheap controls are attractive, yet cost informs affordability after risk-based prioritisation, not the priority itself.

  • ✗

    The popularity of the solution in the industry

    Why it's wrong here

    Industry popularity does not reflect the risk reduction a control delivers to this organisation, so it cannot drive prioritisation. It tempts because widely adopted solutions appear validated and may ease hiring and support, yet popularity is a procurement consideration, not a measure of exposure or business impact.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.