Courseiva

CISM Information Security Risk Management Practice Question

Which TWO of the following are key components of an information security risk assessment? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse risk assessment activities (threat and asset identification) with downstream risk management steps like policy creation or control implementation, leading them to select options that are part of the broader risk management lifecycle but not the assessment itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat identification

Asset identification (E) is a foundational component of a risk assessment because you cannot evaluate risk without first knowing which information assets, systems, and data require protection and what value they hold to the organization. Threat identification (A) is equally essential, since risk is derived from identifying the threats (e.g., malware, insider abuse, natural disasters) that could exploit vulnerabilities and cause harm to those assets. Together, asset and threat identification feed into the core risk formula (risk = likelihood × impact), enabling analysts to prioritize risks and recommend treatment. The other options do not belong: security policy development (B) is a governance/risk-treatment output, incident response planning (C) is a reactive capability built after risks are understood, and control implementation (D) is a risk-mitigation activity that follows the assessment rather than forming part of it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat identification

    Why this is correct

    Threat identification enumerates the sources and actors capable of exploiting vulnerabilities, forming the input that lets assessors determine which risks apply to each asset. Without it, likelihood estimates and subsequent risk calculations lack any credible basis.

  • ✗

    Security policy development

    Why it's wrong here

    Policy development sets organisational direction and requirements, which occurs before or after assessment rather than within it. It is tempting because policies govern the risk programme, yet the assessment components are identifying assets, threats, vulnerabilities and evaluating likelihood and impact; policy authorisation is a governance output, not an assessment input.

  • ✗

    Incident response planning

    Why it's wrong here

    Incident response planning defines actions taken after an event materialises, whereas risk assessment estimates likelihood and impact beforehand. It is tempting because both concern adverse events, but response planning belongs to the treatment and readiness phase; the assessment components are asset, threat and vulnerability identification with impact evaluation.

  • ✗

    Control implementation

    Why it's wrong here

    Control implementation executes selected treatments, which follows assessment rather than forming part of it. It is tempting because controls address identified risks, but assessment only identifies, analyses and evaluates risk; choosing and deploying controls is the treatment stage, so this sits downstream of the two required components.

  • ✓

    Asset identification

    Why this is correct

    Asset identification establishes what has value and therefore what requires protection, scoping the assessment so threats and vulnerabilities are evaluated against defined information assets rather than abstract categories. It underpins every subsequent likelihood and impact judgement.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.