Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Exam CISM Topic 7 Question 77 Discussion

Actual exam question for Isaca's CISM exam
Question #: 77
Topic #: 7
[All CISM Questions]

Which of the following is the PRIMARY benefit of implementing an information security governance framework?

Show Suggested Answer Hide Answer
Suggested Answer: A

Mitigate is the risk treatment option that has been applied by implementing a firewall in front of the legacy application because it helps to reduce the impact or probability of a risk. Mitigate is a process of taking actions to lessen the negative effects of a risk, such as implementing security controls, policies, or procedures. A firewall is a security device that monitors and filters the network traffic between the legacy application and the external network, blocking or allowing packets based on predefined rules. A firewall helps to mitigate the risk of unauthorized access, exploitation, or attack on the legacy application that cannot be patched. Therefore, mitigate is the correct answer.


https://simplicable.com/risk/risk-treatment

https://resources.infosecinstitute.com/topic/risk-treatment-options-planning-prevention/

https://www.enisa.europa.eu/topics/risk-management/current-risk/risk-management-inventory/rm-process/risk-treatment.

Contribute your Thoughts:

Jaclyn
1 months ago
Who cares about the business goals? I just want to hack the system and make a quick buck. Oh wait, this is a serious exam. Definitely go with B.
upvoted 0 times
Theola
3 days ago
User 2: Theola, that's not the right approach. We should prioritize balancing risks and controls to meet business goals.
upvoted 0 times
...
Edelmira
9 days ago
User 1: Who cares about the business goals? I just want to hack the system and make a quick buck.
upvoted 0 times
...
...
Whitley
1 months ago
A is not bad, but it feels a bit limiting. B covers the broader picture of aligning security with business objectives.
upvoted 0 times
Deeanna
6 days ago
User 1: I think A is good for defining responsibilities.
upvoted 0 times
...
...
Bong
1 months ago
Hmm, D sounds like it could be useful, but I don't think that's the PRIMARY benefit. I'll have to go with B on this one.
upvoted 0 times
...
Jimmie
2 months ago
Option C sounds tempting, but let's be real, security is about protecting the business, not maximizing revenue. B is the way to go.
upvoted 0 times
Johna
12 days ago
C) The framework provides a roadmap to maximize revenue through the secure use of technology.
upvoted 0 times
...
Paulina
18 days ago
B) The framework provides direction to meet business goals while balancing risks and controls.
upvoted 0 times
...
Justine
27 days ago
A) The framework defines managerial responsibilities for risk impacts to business goals.
upvoted 0 times
...
...
Glenna
2 months ago
The primary benefit is clearly B. The framework provides direction to meet business goals while balancing risks and controls. Anything else is just a secondary consideration.
upvoted 0 times
Corazon
13 days ago
True, but ultimately option B is what helps achieve business goals while managing risks.
upvoted 0 times
...
Viva
14 days ago
I think option A is also important, as it defines managerial responsibilities for risk impacts.
upvoted 0 times
...
Kris
21 days ago
I agree, option B is definitely the primary benefit.
upvoted 0 times
...
...
Rosalind
2 months ago
I believe B) The framework provides direction to meet business goals while balancing risks and controls is also important. It helps in achieving business objectives while managing risks.
upvoted 0 times
...
Sena
2 months ago
I agree with Ozell. Having clear responsibilities is crucial for effective information security governance.
upvoted 0 times
...
Ozell
3 months ago
I think the primary benefit is A) The framework defines managerial responsibilities for risk impacts to business goals.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77