Courseiva

CISM Information Security Risk Management Practice Question

Which TWO of the following are common approaches to information security risk assessment?

⚠ Common exam trap

Candidates often confuse risk assessment approaches (qualitative/quantitative) with risk assessment activities (like penetration testing or vulnerability assessment), which are tools used within the assessment process but not the overarching methodology itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Qualitative

Options A and B are correct because information security risk assessment fundamentally follows two recognized methodologies: qualitative assessment (A), which uses subjective scales such as high/medium/low to rank risks based on expert judgment, and quantitative assessment (B), which assigns numeric monetary values and probabilities to calculate expected annual loss (e.g., SLE × ARO = ALE). These two approaches are the standard classifications taught in risk management frameworks such as NIST SP 800-30 and ISO/IEC 27005, and they can also be combined into a hybrid (semi-quantitative) method. Penetration testing (C) is a technical security testing technique that simulates attacks to find exploitable weaknesses, not a risk assessment approach itself. Vulnerability assessment (D) identifies and catalogs known weaknesses but does not by itself evaluate risk in terms of likelihood and impact. Business impact analysis (E) is a separate BCP/DR activity that determines critical business functions and recovery requirements, not a general risk assessment methodology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Qualitative

    Why this is correct

    Qualitative assessment ranks risks using descriptive scales such as high, medium and low, drawing on expert judgement rather than numeric values. It satisfies the stem by being one of the two recognised risk assessment approaches, suiting scenarios where precise monetary estimates are impractical.

  • ✓

    Quantitative

    Why this is correct

    Quantitative assessment assigns numeric values, typically monetary, to asset value, threat frequency and loss magnitude, producing an annualised loss expectancy. It satisfies the stem as the second recognised approach, enabling cost-benefit comparison of controls against identified risks.

  • ✗

    Penetration testing

    Why it's wrong here

    Penetration testing validates exploitable weaknesses in a deployed system; it does not identify, analyse and evaluate risks against assets. It is tempting because testing feeds vulnerability data into assessments, and would be correct as a control-validation or assurance activity once the risk assessment has already been completed.

  • ✗

    Vulnerability assessment

    Why it's wrong here

    Vulnerability assessment identifies technical weaknesses in assets; it does not estimate likelihood and impact against business objectives, which is what risk assessment approaches such as quantitative and qualitative analysis do. It is tempting because scan output often feeds a risk assessment, and it would be the right choice when the task is enumerating exploitable flaws rather than ranking risk.

  • ✗

    Business impact analysis

    Why it's wrong here

    Business impact analysis determines the consequences of disruption to critical business functions and their recovery requirements; it supplies impact data to risk assessment rather than being an approach to assessing risk itself. It is tempting because BIA output frequently underpins risk registers, and it would be correct when establishing recovery priorities and continuity requirements.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.