nerdexam
Isaca

CISM · Question #796

An information security team has started work to mitigate findings from a recent penetration test. Which of the following presents the GREATEST risk to the organization?

The correct answer is D. Risk classification of penetration test findings was not performed. The greatest risk comes from not performing risk classification on the findings. Without classification, the organization cannot prioritize remediation efforts, allocate resources effectively, or understand the business impact of the vulnerabilities. "Risk classification helps…

Submitted by packet_pusher· Apr 18, 2026Information Security Risk Management

Question

An information security team has started work to mitigate findings from a recent penetration test. Which of the following presents the GREATEST risk to the organization?

Options

  • ASome findings were reclassified to low risk after evaluation
  • BNot all findings from the penetration test report were fixed
  • CThe penetration testing report did not contain any high-risk findings
  • DRisk classification of penetration test findings was not performed

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    24% (6)
  • C
    12% (3)
  • D
    60% (15)

Explanation

The greatest risk comes from not performing risk classification on the findings. Without classification, the organization cannot prioritize remediation efforts, allocate resources effectively, or understand the business impact of the vulnerabilities. "Risk classification helps determine the priority for mitigating vulnerabilities and enables risk- informed decisions." Even if some findings are unfixed or reclassified, the lack of any classification process undermines the whole risk management effort.

Topics

#Risk Management#Penetration Testing Remediation#Vulnerability Management#Risk Classification

Community Discussion

No community discussion yet for this question.

Full CISM Practice