CISM Information Security Governance Practice Question
Which TWO factors are most important when prioritizing security investments? (Select TWO.)
⚠ Common exam trap
CISM often tests whether candidates default to cost or ease as the primary driver — the trap is picking 'cost of the solution' because budgets matter, but governance exams reward risk reduction and business alignment as the deciding factors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The level of risk reduction achieved
Option B (the level of risk reduction achieved) is correct because security investment prioritization should be driven by how much a control actually lowers identified risk, typically assessed through risk analysis that weighs likelihood and impact against the residual risk remaining after the control is applied. Option C (alignment with business objectives and strategy) is correct because security spending must support the organization's mission, compliance obligations, and strategic goals, ensuring that limited budget is directed toward protecting the assets and processes that matter most to the business. Options A, D, and E are not among the two most important factors: ease of implementation and cost are practical considerations but can lead to underinvesting in high-risk areas, and industry popularity is a weak justification since threat profiles and business contexts differ across organizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ease of implementation
Why it's wrong here
Ease of implementation addresses delivery effort, not the risk or business value a control protects, so it cannot rank investment priorities. It tempts because low-effort controls ship quickly and show early progress, but that is a scheduling concern; prioritisation must follow risk exposure and potential business impact.
- ✓
The level of risk reduction achieved
Why this is correct
Prioritisation must weigh how much each investment actually reduces identified risk, since spend should target the greatest exposure. The level of risk reduction achieved is the direct measure of benefit, satisfying the constraint that limited budget be allocated where residual risk falls most.
- ✓
Alignment with business objectives and strategy
Why this is correct
Investments aligned with business objectives and strategy support the organisation's goals and priorities, ensuring security spending is treated as an enabler rather than an obstacle. This alignment secures executive backing and directs funding to controls that protect what the business most values.
- ✗
The cost of the security solution
Why it's wrong here
Purchase cost is a budget constraint, not a measure of risk reduction, so it cannot determine which investments rank highest. It tempts because budgets are finite and cheap controls are attractive, yet cost informs affordability after risk-based prioritisation, not the priority itself.
- ✗
The popularity of the solution in the industry
Why it's wrong here
Industry popularity does not reflect the risk reduction a control delivers to this organisation, so it cannot drive prioritisation. It tempts because widely adopted solutions appear validated and may ease hiring and support, yet popularity is a procurement consideration, not a measure of exposure or business impact.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.