CISM Information Security Risk Management Practice Question
Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
⚠ Common exam trap
Many candidates confuse the steps of the risk management process (identification, analysis, evaluation, communication) with the specific treatment options, leading them to select risk measurement or risk identification as valid treatments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk avoidance
According to ISO 31000, risk treatment options include avoiding the risk by deciding not to start or continue the activity that gives rise to it, which is why option A (Risk avoidance) is correct. ISO 31000 also recognizes retaining the risk by informed decision, which is option E (Risk retention), as a valid treatment option when the risk is accepted and no further action is taken. Options B (Risk measurement), C (Risk identification), and D (Risk communication) are not treatment options; they are elements of the risk assessment and communication processes within the ISO 31000 framework, not ways of modifying risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk avoidance
Why this is correct
Risk avoidance eliminates the activity or exposure generating the risk entirely, so the threat no longer applies. ISO 31000 lists it alongside modification, sharing and retention as a treatment option, and it suits risks whose residual exposure exceeds tolerance.
- ✗
Risk measurement
Why it's wrong here
Measurement quantifies identified risks and precedes treatment selection; it is not itself a treatment option. It is tempting because measurement underpins decisions, but ISO 31000 treatment options are avoid, reduce, transfer and accept. Measurement belongs to risk analysis and evaluation, not to the treatment set.
- ✗
Risk identification
Why it's wrong here
Identification discovers and records risks, an earlier process step, not a treatment choice. It is tempting because identification is central to risk management, but ISO 31000 treatment options are avoid, reduce, transfer and accept. Identification feeds analysis and evaluation before any treatment decision is made.
- ✗
Risk communication
Why it's wrong here
Risk communication is a clause of ISO 31000's framework and process, not one of the seven risk treatment options (avoid, pursue, remove, change, share, retain, accept). It is tempting because communication and consultation underpin the entire standard, and would be the right answer to a question about framework components rather than treatment.
- ✓
Risk retention
Why this is correct
Risk retention accepts the risk and its consequences without further treatment, whether deliberately after evaluation or by default. ISO 31000 recognises it as valid where the cost of other treatments exceeds the potential loss, or where residual risk remains after treatment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.