CISM Information Security Risk Management Practice Question
Which TWO of the following are common approaches to information security risk assessment?
⚠ Common exam trap
Candidates often confuse risk assessment approaches (qualitative/quantitative) with risk assessment activities (like penetration testing or vulnerability assessment), which are tools used within the assessment process but not the overarching methodology itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Qualitative
Qualitative risk assessment uses subjective ratings (e.g., high, medium, low) based on expert judgment to evaluate the likelihood and impact of risks. It is a common approach because it is quick to perform and does not require precise numerical data, making it suitable for initial risk prioritization in information security management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Qualitative
Why this is correct
Uses descriptive scales.
- ✓
Quantitative
Why this is correct
Uses numerical data.
- ✗
Penetration testing
Why it's wrong here
A security test, not a risk assessment approach.
- ✗
Vulnerability assessment
Why it's wrong here
Part of risk assessment, not an approach.
- ✗
Business impact analysis
Why it's wrong here
Focuses on impact, not risk assessment.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.