nerdexam
Isaca

CISM · Question #27

Which of the following is the PRIMARY reason for granting a security exception?

The correct answer is C. The risk is justified by the benefit to the business. A security exception is primarily granted when the inherent security risk is deemed acceptable because the business benefits gained by allowing the deviation outweigh the potential consequences of the risk.

Submitted by hassan_iq· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the PRIMARY reason for granting a security exception?

Options

  • AThe risk is justified by the cost to security.
  • BThe risk is justified by the benefit to security.
  • CThe risk is justified by the benefit to the business.
  • DThe risk is justified by the cost to the business.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    88% (35)
  • D
    8% (3)

Why each option

A security exception is primarily granted when the inherent security risk is deemed acceptable because the business benefits gained by allowing the deviation outweigh the potential consequences of the risk.

AThe risk is justified by the cost to security.

"The risk is justified by the cost to security" is circular and illogical; security costs are incurred to manage risk, not justify it.

BThe risk is justified by the benefit to security.

"The risk is justified by the benefit to security" implies that taking a risk would somehow enhance security, which is generally not the case for an exception.

CThe risk is justified by the benefit to the business.Correct

Security exceptions are granted when the identified security risk, after thorough assessment, is demonstrably outweighed by a significant business benefit, such as enabling a critical project or maintaining essential operations that would otherwise be halted. This decision acknowledges the risk but prioritizes business enablement under controlled conditions.

DThe risk is justified by the cost to the business.

"The risk is justified by the cost to the business" suggests taking a risk because it's expensive not to, which is part of the cost-benefit analysis but doesn't fully capture the benefit aspect that justifies the exception.

Concept tested: Security exception rationale

Topics

#Security Exceptions#Risk Acceptance#Business Alignment#Risk Justification

Community Discussion

No community discussion yet for this question.

Full CISM Practice