nerdexam
Isaca

CISA · Question #38

Which of the following components of a risk assessment is MOST helpful to management in determining the level of risk mitigation to apply?

The correct answer is A. Impact assessment. An impact assessment is the most helpful component of a risk assessment for management to determine the appropriate level of risk mitigation. It quantifies the potential damage or loss from a risk event, allowing management to prioritize and allocate resources effectively.

Submitted by joshua94· Apr 18, 2026Governance and Management of IT

Question

Which of the following components of a risk assessment is MOST helpful to management in determining the level of risk mitigation to apply?

Options

  • AImpact assessment
  • BControl self-assessment (CSA)
  • CRisk classification
  • DRisk identification

How the community answered

(30 responses)
  • A
    73% (22)
  • B
    3% (1)
  • C
    7% (2)
  • D
    17% (5)

Why each option

An impact assessment is the most helpful component of a risk assessment for management to determine the appropriate level of risk mitigation. It quantifies the potential damage or loss from a risk event, allowing management to prioritize and allocate resources effectively.

AImpact assessmentCorrect

An impact assessment quantifies the potential adverse effects (financial, operational, reputational) if a risk event occurs, allowing management to understand the severity of potential losses. Knowing the potential impact is crucial for making informed decisions about how much to spend and what level of resources to allocate for risk mitigation, ensuring efforts are commensurate with the risk.

BControl self-assessment (CSA)

Control self-assessment (CSA) is a method for evaluating the effectiveness of controls, not for determining the level of mitigation needed for identified risks.

CRisk classification

Risk classification categorizes risks but doesn't provide the detailed information about potential losses necessary for deciding mitigation levels.

DRisk identification

Risk identification involves finding potential risks, but without assessing their impact or likelihood, it doesn't inform the mitigation level.

Concept tested: Risk assessment components (Impact)

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf

Topics

#Risk Assessment#Impact Analysis#Risk Mitigation#Management Decision Making

Community Discussion

No community discussion yet for this question.

Full CISA Practice