Courseiva

CISM Information Security Risk Management Practice Question

Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)

⚠ Common exam trap

Many candidates confuse the steps of the risk management process (identification, analysis, evaluation, communication) with the specific treatment options, leading them to select risk measurement or risk identification as valid treatments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk avoidance

According to ISO 31000, risk treatment options include avoiding the risk by deciding not to start or continue the activity that gives rise to it, which is why option A (Risk avoidance) is correct. ISO 31000 also recognizes retaining the risk by informed decision, which is option E (Risk retention), as a valid treatment option when the risk is accepted and no further action is taken. Options B (Risk measurement), C (Risk identification), and D (Risk communication) are not treatment options; they are elements of the risk assessment and communication processes within the ISO 31000 framework, not ways of modifying risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk avoidance

    Why this is correct

    Risk avoidance eliminates the activity or exposure generating the risk entirely, so the threat no longer applies. ISO 31000 lists it alongside modification, sharing and retention as a treatment option, and it suits risks whose residual exposure exceeds tolerance.

  • ✗

    Risk measurement

    Why it's wrong here

    Measurement quantifies identified risks and precedes treatment selection; it is not itself a treatment option. It is tempting because measurement underpins decisions, but ISO 31000 treatment options are avoid, reduce, transfer and accept. Measurement belongs to risk analysis and evaluation, not to the treatment set.

  • ✗

    Risk identification

    Why it's wrong here

    Identification discovers and records risks, an earlier process step, not a treatment choice. It is tempting because identification is central to risk management, but ISO 31000 treatment options are avoid, reduce, transfer and accept. Identification feeds analysis and evaluation before any treatment decision is made.

  • ✗

    Risk communication

    Why it's wrong here

    Risk communication is a clause of ISO 31000's framework and process, not one of the seven risk treatment options (avoid, pursue, remove, change, share, retain, accept). It is tempting because communication and consultation underpin the entire standard, and would be the right answer to a question about framework components rather than treatment.

  • ✓

    Risk retention

    Why this is correct

    Risk retention accepts the risk and its consequences without further treatment, whether deliberately after evaluation or by default. ISO 31000 recognises it as valid where the cost of other treatments exceeds the potential loss, or where residual risk remains after treatment.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.